"Time of Day","Process Name","PID","Operation","Path","Result","Detail" "19:13:28,4124619","EasyAntiCheat_launcher.exe","6076","Process Start","","SUCCESS","Parent PID: 4576, Command line: ""D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe"" -steam, Current directory: D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\, Environment: ; =::=::\ ; =D:=D:\Program Files (x86)\Steam ; ALLUSERSPROFILE=C:\ProgramData ; APPDATA=C:\Users\Administrator\AppData\Roaming ; CommonProgramFiles=C:\Program Files (x86)\Common Files ; CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files ; CommonProgramW6432=C:\Program Files\Common Files ; COMMON_MYDOCS=C:\Users\Public\Documents ; Compilers=C:\Code\Tools\Compilers ; COMPUTERNAME=DEVLA-PC ; ComSpec=C:\Windows\system32\cmd.exe ; FPS_BROWSER_APP_PROFILE_STRING=Internet Explorer ; FPS_BROWSER_USER_PROFILE_STRING=Default ; HOMEDRIVE=C: ; HOMEPATH=\Users\Administrator ; INSTALLDIR=D:\Program Files (x86)\Steam\steamapps\common\Apex Legends ; LOCALAPPDATA=C:\Users\Administrator\AppData\Local ; LOCAL_APPDATA=C:\Users\Administrator\AppData\Local ; LOGONSERVER=\\DEVLA-PC ; NUMBER_OF_PROCESSORS=4 ; OANOCACHE=1 ; OS=Windows_NT ; Path=D:\Program Files (x86)\Steam;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\dotnet;C:\Code\tools\.bin;C:\Code\tools\Cmder\bin;C:\Windows\Custom;C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\bin;C:\Code\Tools\Compilers\C\mingw\bin; ; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JSE;.WSF;.WSH;.MSC ; PROCESSOR_ARCHITECTURE=x86 ; PROCESSOR_ARCHITEW6432=AMD64 ; PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ; PROCESSOR_LEVEL=6 ; PROCESSOR_REVISION=3a09 ; ProgramData=C:\ProgramData ; ProgramFiles=C:\Program Files (x86) ; ProgramFiles(x86)=C:\Program Files (x86) ; ProgramW6432=C:\Program Files ; PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules ; PT8HOME=D:\Program Files\Cisco Packet Tracer 8.0 ; PUBLIC=C:\Users\Public ; QT_DEVICE_PIXEL_RATIO=auto ; ROOTDRIVE=D ; SESSIONNAME=Console ; STEAMID=76561198178935861 ; SteamPath=D:\Program Files (x86)\Steam ; SteamUser=tomifiu15 ; SystemDrive=C: ; SystemRoot=C:\Windows ; TEMP=C:\Users\ADMINI~1\AppData\Local\Temp ; TMP=C:\Users\ADMINI~1\AppData\Local\Temp ; USERDOMAIN=DEVLA-PC ; USERDOMAIN_ROAMINGPROFILE=DEVLA-PC ; USERNAME=Administrator ; USERPROFILE=C:\Users\Administrator ; USER_MYDOCS=D:\Users\Administrator\Documents ; ValvePlatformMutex=d:/program files (x86)/steam/steam.exe ; VBOX_MSI_INSTALL_PATH=D:\Program Files\Oracle\VirtualBox\ ; windir=C:\Windows ; _MSYS2_PREFIX=x86_64 ; SteamClientLaunch=1 ; SteamNoOverlayUI=1 ; EnableConfiguratorSupport=0 ; SDL_GAMECONTROLLER_ALLOW_STEAM_VIRTUAL_GAMEPAD=1 ; SDL_JOYSTICK_HIDAPI_STEAMXBOX=0 ; SteamStreamingHardwareEncodingNVIDIA=1 ; SteamStreamingHardwareEncodingAMD=1 ; SteamStreamingHardwareEncodingIntel=1 ; SteamGameId=1172470 ; SteamAppId=1172470 ; SteamOverlayGameId=1172470 ; SteamAppUser=tomifiu15 ; MESA_GLSL_CACHE_DIR=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470 ; MESA_GLSL_CACHE_MAX_SIZE=5G ; __GL_SHADER_DISK_CACHE_PATH=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\nvidiav1 ; __GL_SHADER_DISK_CACHE_APP_NAME=steamapp_shader_cache ; __GL_SHADER_DISK_CACHE_READ_ONLY_APP_NAME=steam_shader_cache;steamapp_merged_shader_cache ; __GL_SHADER_DISK_CACHE_SKIP_CLEANUP=1 ; AMD_VK_PIPELINE_CACHE_PATH=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\AMDv1 ; AMD_VK_PIPELINE_CACHE_FILENAME=steamapp_shader_cache ; AMD_VK_USE_PIPELINE_CACHE=1 ; STEAM_FOSSILIZE_DUMP_PATH=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\fozpipelinesv5\steamapprun_pipeline_cache ; STEAM_FOSSILIZE_DUMP_PATH_READ_ONLY=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\fozpipelinesv5\steam_pipeline_cache.foz;D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\fozpipelinesv5\steamapp_pipeline_cache.foz ; FOSSILIZE_APPLICATION_INFO_FILTER_PATH=D:\Program Files (x86)\Steam\fossilize_engine_filters.json ; ENABLE_VK_LAYER_VALVE_steam_fossilize_1=1 ; STEAM_COMPAT_MEDIA_PATH=D:\Program Files (x86)\Steam\steamapps\shad" "19:13:28,4124699","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 4348" "19:13:28,4145944","EasyAntiCheat_launcher.exe","6076","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Image Base: 0x70000, Image Size: 0x124000" "19:13:28,4146073","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\System32\ntdll.dll","SUCCESS","Image Base: 0x7ffdd1ff0000, Image Size: 0x1e0000" "19:13:28,4146188","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Image Base: 0x772b0000, Image Size: 0x18d000" "19:13:28,4147041","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value" "19:13:28,4147166","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4147558","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4147641","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4147747","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:28,4147837","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:28,4150364","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4151490","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\System32\wow64.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:05, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:05, ChangeTime: 2020. 01. 09. 4:42:23, AllocationSize: 319 488, EndOfFile: 319 352, FileAttributes: A" "19:13:28,4152202","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\wow64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4152526","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\wow64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4152725","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\wow64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4153071","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\System32\wow64.dll","SUCCESS","Image Base: 0x600b0000, Image Size: 0x51000" "19:13:28,4153491","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\wow64.dll","SUCCESS","" "19:13:28,4153863","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value" "19:13:28,4153982","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value" "19:13:28,4154094","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16" "19:13:28,4154611","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\wow64win.dll","NAME NOT FOUND","" "19:13:28,4155332","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\System32\wow64win.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:05, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:05, ChangeTime: 2020. 01. 09. 4:42:23, AllocationSize: 483 328, EndOfFile: 481 488, FileAttributes: A" "19:13:28,4155990","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\wow64win.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4156285","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\wow64win.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4156477","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\wow64win.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4156798","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\System32\wow64win.dll","SUCCESS","Image Base: 0x60030000, Image Size: 0x77000" "19:13:28,4157218","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\wow64win.dll","SUCCESS","" "19:13:28,4159656","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\System32\wow64log.dll","NAME NOT FOUND","" "19:13:28,4160223","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\System32\kernel32.dll","SUCCESS","Image Base: 0x2860000, Image Size: 0xae000" "19:13:28,4160736","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Image Base: 0x74a70000, Image Size: 0xd0000" "19:13:28,4161195","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\System32\user32.dll","SUCCESS","Image Base: 0x2860000, Image Size: 0x18e000" "19:13:28,4162035","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4162279","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows","SUCCESS","Name: \Windows" "19:13:28,4162398","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows","SUCCESS","" "19:13:28,4162722","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Wow64\x86","SUCCESS","Desired Access: Read" "19:13:28,4162866","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Wow64\x86\EasyAntiCheat_launcher.exe","NAME NOT FOUND","Length: 520" "19:13:28,4162933","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Wow64\x86\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: wow64cpu.dll" "19:13:28,4163030","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Wow64\x86","SUCCESS","" "19:13:28,4163819","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\System32\wow64cpu.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:05, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:05, ChangeTime: 2020. 01. 09. 4:42:23, AllocationSize: 24 576, EndOfFile: 22 392, FileAttributes: A" "19:13:28,4164588","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\wow64cpu.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4164909","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\wow64cpu.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4165114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\wow64cpu.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4165425","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\System32\wow64cpu.dll","SUCCESS","Image Base: 0x60020000, Image Size: 0xa000" "19:13:28,4165797","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\wow64cpu.dll","SUCCESS","" "19:13:28,4167366","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value" "19:13:28,4167484","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4167863","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4167946","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4168052","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4168116","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:28,4168206","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:28,4170429","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4171231","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Image Base: 0x74a70000, Image Size: 0xd0000" "19:13:28,4172058","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Image Base: 0x747a0000, Image Size: 0x1d7000" "19:13:28,4176888","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\3c74afb9-8d82-44e3-b52c-365dbf48382a","NAME NOT FOUND","Length: 524" "19:13:28,4177581","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\05f95efe-7f75-49c7-a994-60a55cc09571","NAME NOT FOUND","Length: 524" "19:13:28,4179076","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value" "19:13:28,4179204","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "19:13:28,4179348","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read" "19:13:28,4179425","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read" "19:13:28,4179573","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers","REPARSE","Desired Access: Query Value" "19:13:28,4179682","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value" "19:13:28,4179826","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4179890","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80" "19:13:28,4180019","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","" "19:13:28,4180211","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4180442","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem\","REPARSE","Desired Access: Read" "19:13:28,4180519","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","Desired Access: Read" "19:13:28,4180618","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4180679","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,4180769","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","" "19:13:28,4182116","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\apphelp.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:13, LastAccessTime: 2021. 02. 13. 20:41:08, LastWriteTime: 2017. 09. 29. 15:42:13, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 614 400, EndOfFile: 614 400, FileAttributes: A" "19:13:28,4182851","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\apphelp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4183171","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4183380","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\apphelp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4183745","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\apphelp.dll","SUCCESS","Image Base: 0x63430000, Image Size: 0x9a000" "19:13:28,4185083","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\apphelp.dll","SUCCESS","" "19:13:28,4185590","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\8ccca27d-f1d8-4dda-b5dd-339aee937731","NAME NOT FOUND","Length: 524" "19:13:28,4186205","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","Desired Access: Query Value" "19:13:28,4186401","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4186478","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LogFlags","NAME NOT FOUND","Length: 20" "19:13:28,4186561","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","" "19:13:28,4186789","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\18608e62-a628-49d9-8c02-55972e097d24","NAME NOT FOUND","Length: 524" "19:13:28,4187588","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","Desired Access: Query Value" "19:13:28,4187700","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4187774","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ShowDebugInfo","NAME NOT FOUND","Length: 20" "19:13:28,4187857","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","" "19:13:28,4188592","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4188813","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","BUFFER OVERFLOW","Information: Owner" "19:13:28,4188919","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Information: Owner" "19:13:28,4189028","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","" "19:13:28,4189887","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4190170","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ntdll.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4190275","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Information: Owner" "19:13:28,4190372","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","" "19:13:28,4191205","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4191475","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\kernel32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4191590","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Information: Owner" "19:13:28,4191780","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","" "19:13:28,4192909","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4193120","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\KernelBase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4193239","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Information: Owner" "19:13:28,4193338","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","" "19:13:28,4194265","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4194676","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4194782","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4194891","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4194990","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4195157","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4197476","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4197828","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:28,4197992","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4198066","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:28,4198184","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:28,4198332","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:28,4199022","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4199304","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:28,4199394","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:28,4200154","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4200401","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:28,4200491","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:28,4200741","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","CreationTime: 2021. 04. 12. 12:13:17, LastAccessTime: 2021. 04. 12. 12:13:17, LastWriteTime: 2021. 04. 12. 12:13:17, ChangeTime: 2021. 04. 12. 12:13:24, FileAttributes: ANCI" "19:13:28,4201071","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","" "19:13:28,4201680","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4201988","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:28,4202113","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4202181","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:28,4202287","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:28,4202428","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:28,4202546","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","CreationTime: 2021. 04. 12. 12:13:17, LastAccessTime: 2021. 04. 12. 12:13:17, LastWriteTime: 2021. 04. 12. 12:13:17, ChangeTime: 2021. 04. 12. 12:13:24, FileAttributes: ANCI" "19:13:28,4202742","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","" "19:13:28,4205590","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4205709","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4205831","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4205898","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:28,4205994","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:28,4206462","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:28,4207880","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:25, LastAccessTime: 2021. 02. 13. 20:03:47, LastWriteTime: 2017. 09. 29. 15:42:25, ChangeTime: 2020. 01. 09. 4:42:58, AllocationSize: 364 544, EndOfFile: 361 984, FileAttributes: A" "19:13:28,4208695","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4209022","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\AcLayers.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4210337","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4210770","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","Image Base: 0x73960000, Image Size: 0x27f000" "19:13:28,4211453","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","Image Base: 0x74100000, Image Size: 0xbd000" "19:13:28,4212303","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\user32.dll","SUCCESS","Image Base: 0x745c0000, Image Size: 0x175000" "19:13:28,4212919","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\win32u.dll","SUCCESS","Image Base: 0x73f70000, Image Size: 0x16000" "19:13:28,4213717","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\gdi32.dll","SUCCESS","Image Base: 0x750f0000, Image Size: 0x22000" "19:13:28,4214343","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\gdi32full.dll","SUCCESS","Image Base: 0x74360000, Image Size: 0x15e000" "19:13:28,4214910","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\msvcp_win.dll","SUCCESS","Image Base: 0x75120000, Image Size: 0x7c000" "19:13:28,4215440","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","Image Base: 0x74de0000, Image Size: 0x117000" "19:13:28,4216735","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\shell32.dll","SUCCESS","Image Base: 0x75f00000, Image Size: 0x1333000" "19:13:28,4217649","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\cfgmgr32.dll","SUCCESS","Image Base: 0x74030000, Image Size: 0x38000" "19:13:28,4218509","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\SHCore.dll","SUCCESS","Image Base: 0x749e0000, Image Size: 0x88000" "19:13:28,4219279","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","Image Base: 0x74b40000, Image Size: 0xbe000" "19:13:28,4219962","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\sspicli.dll","SUCCESS","Image Base: 0x73cd0000, Image Size: 0x20000" "19:13:28,4220417","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\cryptbase.dll","SUCCESS","Image Base: 0x73cc0000, Image Size: 0xa000" "19:13:28,4220902","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\bcryptprimitives.dll","SUCCESS","Image Base: 0x73f90000, Image Size: 0x57000" "19:13:28,4221460","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Image Base: 0x73cf0000, Image Size: 0x43000" "19:13:28,4222322","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\combase.dll","SUCCESS","Image Base: 0x75210000, Image Size: 0x246000" "19:13:28,4223230","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\windows.storage.dll","SUCCESS","Image Base: 0x75930000, Image Size: 0x5c6000" "19:13:28,4223987","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\advapi32.dll","SUCCESS","Image Base: 0x742e0000, Image Size: 0x78000" "19:13:28,4224814","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\shlwapi.dll","SUCCESS","Image Base: 0x74290000, Image Size: 0x45000" "19:13:28,4225661","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Image Base: 0x751a0000, Image Size: 0xe000" "19:13:28,4226841","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\powrprof.dll","SUCCESS","Image Base: 0x75070000, Image Size: 0x45000" "19:13:28,4227717","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\profapi.dll","SUCCESS","Image Base: 0x750c0000, Image Size: 0x14000" "19:13:28,4228580","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","Image Base: 0x75890000, Image Size: 0x93000" "19:13:28,4229510","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\setupapi.dll","SUCCESS","Image Base: 0x75460000, Image Size: 0x426000" "19:13:28,4230527","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","" "19:13:28,4245655","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\mpr.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:43:29, AllocationSize: 90 112, EndOfFile: 86 976, FileAttributes: A" "19:13:28,4246457","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\mpr.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4246842","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\mpr.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4247522","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\mpr.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4247891","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\mpr.dll","SUCCESS","Image Base: 0x73bf0000, Image Size: 0x17000" "19:13:28,4248468","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\mpr.dll","SUCCESS","" "19:13:28,4250113","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\sfc.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:24, LastAccessTime: 2021. 02. 13. 20:03:47, LastWriteTime: 2017. 09. 29. 15:42:24, ChangeTime: 2020. 01. 09. 4:43:35, AllocationSize: 4 096, EndOfFile: 2 560, FileAttributes: A" "19:13:28,4250918","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4251246","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\sfc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4251441","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\sfc.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4251772","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Image Base: 0x2820000, Image Size: 0x3000" "19:13:28,4251999","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","" "19:13:28,4252894","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\winspool.drv","SUCCESS","CreationTime: 2017. 09. 29. 15:42:27, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:27, ChangeTime: 2020. 01. 09. 4:43:43, AllocationSize: 421 888, EndOfFile: 419 328, FileAttributes: A" "19:13:28,4253712","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winspool.drv","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4254017","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winspool.drv","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4254677","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winspool.drv","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4254985","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\winspool.drv","SUCCESS","Image Base: 0x738f0000, Image Size: 0x6c000" "19:13:28,4255800","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winspool.drv","SUCCESS","" "19:13:28,4257096","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 192 512, EndOfFile: 189 112, FileAttributes: A" "19:13:28,4257808","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4258112","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4258298","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4258619","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","Image Base: 0x73630000, Image Size: 0x30000" "19:13:28,4259174","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","" "19:13:28,4260034","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 16. 16:14:10, AllocationSize: 98 304, EndOfFile: 97 152, FileAttributes: A" "19:13:28,4260717","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4261005","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4261188","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4261512","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Image Base: 0x73050000, Image Size: 0x19000" "19:13:28,4262028","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","" "19:13:28,4264039","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\sfc.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:24, LastAccessTime: 2021. 02. 13. 20:03:47, LastWriteTime: 2017. 09. 29. 15:42:24, ChangeTime: 2020. 01. 09. 4:43:35, AllocationSize: 4 096, EndOfFile: 2 560, FileAttributes: A" "19:13:28,4264851","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4265149","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\sfc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4265348","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\sfc.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4265659","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Image Base: 0x2820000, Image Size: 0x3000" "19:13:28,4265890","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","" "19:13:28,4267397","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:24, LastAccessTime: 2021. 02. 13. 20:03:47, LastWriteTime: 2017. 09. 29. 15:42:24, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 49 152, EndOfFile: 48 640, FileAttributes: A" "19:13:28,4268106","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4268405","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\sfc_os.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4268831","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4269145","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","Image Base: 0x738d0000, Image Size: 0x11000" "19:13:28,4269617","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","" "19:13:28,4272221","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:25, LastAccessTime: 2021. 02. 13. 20:03:47, LastWriteTime: 2017. 09. 29. 15:42:25, ChangeTime: 2020. 01. 09. 4:42:58, AllocationSize: 364 544, EndOfFile: 361 984, FileAttributes: A" "19:13:28,4273026","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:25, LastAccessTime: 2021. 02. 13. 20:03:47, LastWriteTime: 2017. 09. 29. 15:42:25, ChangeTime: 2020. 01. 09. 4:42:58, AllocationSize: 364 544, EndOfFile: 361 984, FileAttributes: A" "19:13:28,4274537","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Query Value" "19:13:28,4274688","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Query Value" "19:13:28,4274861","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4274938","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY","NAME NOT FOUND","Length: 120" "19:13:28,4275079","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY","NAME NOT FOUND","Length: 120" "19:13:28,4275733","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\NLS\Language","REPARSE","Desired Access: Read" "19:13:28,4275833","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\NLS\Language","SUCCESS","Desired Access: Read" "19:13:28,4275986","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Language","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4276054","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Language\InstallLanguageFallback","NAME NOT FOUND","Length: 16" "19:13:28,4276214","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Language","SUCCESS","" "19:13:28,4276339","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","REPARSE","Desired Access: Read" "19:13:28,4276423","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","Desired Access: Read" "19:13:28,4276529","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4276609","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","Index: 0, Name: en-US" "19:13:28,4276721","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4276798","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US","SUCCESS","Desired Access: Read" "19:13:28,4276913","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 273" "19:13:28,4277071","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\AlternateCodePage","NAME NOT FOUND","Length: 12" "19:13:28,4277151","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US","SUCCESS","" "19:13:28,4277212","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","NO MORE ENTRIES","Index: 1, Length: 512" "19:13:28,4277279","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","" "19:13:28,4277385","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete","REPARSE","Desired Access: Read" "19:13:28,4277471","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete","NAME NOT FOUND","Desired Access: Read" "19:13:28,4277609","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:28,4277712","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:28,4277869","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4278017","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4278078","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4278187","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read" "19:13:28,4278321","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","REPARSE","Desired Access: Read" "19:13:28,4278405","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","SUCCESS","Desired Access: Read" "19:13:28,4278536","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4278600","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512" "19:13:28,4278681","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","SUCCESS","" "19:13:28,4278742","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,4278844","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:28,4278924","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:28,4279046","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4279162","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4279219","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4279319","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "19:13:28,4279463","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4279598","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4279777","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Control Panel\Desktop\LanguageConfiguration","SUCCESS","Desired Access: Read" "19:13:28,4279915","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Control Panel\Desktop\LanguageConfiguration","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4279986","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKCU\Control Panel\Desktop\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512" "19:13:28,4280108","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Control Panel\Desktop\LanguageConfiguration","SUCCESS","" "19:13:28,4280169","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,4280281","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:28,4280387","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:28,4280518","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4280627","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4280685","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4280775","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "19:13:28,4280865","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4280919","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4281003","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Control Panel\Desktop","SUCCESS","Desired Access: Read" "19:13:28,4281086","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Control Panel\Desktop","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4281147","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","BUFFER OVERFLOW","Length: 12" "19:13:28,4281230","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","SUCCESS","Type: REG_MULTI_SZ, Length: 12, Data: en-US" "19:13:28,4281339","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Control Panel\Desktop","SUCCESS","" "19:13:28,4281400","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,4281503","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:28,4281590","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:28,4281708","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4281814","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4281869","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4281958","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached","SUCCESS","Desired Access: Read" "19:13:28,4282058","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Control Panel\Desktop\MuiCached","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4282119","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12" "19:13:28,4282183","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","SUCCESS","Type: REG_MULTI_SZ, Length: 14, Data: en-US" "19:13:28,4282270","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Control Panel\Desktop\MuiCached","SUCCESS","" "19:13:28,4282353","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,4284486","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4284790","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msvcrt.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4284906","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","Information: Owner" "19:13:28,4285005","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","" "19:13:28,4286160","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\win32u.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4286442","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\win32u.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4286542","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\win32u.dll","SUCCESS","Information: Owner" "19:13:28,4286654","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\win32u.dll","SUCCESS","" "19:13:28,4287504","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4287764","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ucrtbase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4287863","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","Information: Owner" "19:13:28,4287953","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","" "19:13:28,4288860","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\msvcp_win.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4289043","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msvcp_win.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4289140","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msvcp_win.dll","SUCCESS","Information: Owner" "19:13:28,4289229","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\msvcp_win.dll","SUCCESS","" "19:13:28,4290153","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\gdi32full.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4290333","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\gdi32full.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4290426","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\gdi32full.dll","SUCCESS","Information: Owner" "19:13:28,4290512","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\gdi32full.dll","SUCCESS","" "19:13:28,4291911","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\gdi32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4292167","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\gdi32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4292289","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\gdi32.dll","SUCCESS","Information: Owner" "19:13:28,4292453","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\gdi32.dll","SUCCESS","" "19:13:28,4293511","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\user32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4293806","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\user32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4293947","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\user32.dll","SUCCESS","Information: Owner" "19:13:28,4294076","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\user32.dll","SUCCESS","" "19:13:28,4295352","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\cfgmgr32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4295612","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cfgmgr32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4295711","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cfgmgr32.dll","SUCCESS","Information: Owner" "19:13:28,4295801","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\cfgmgr32.dll","SUCCESS","" "19:13:28,4296728","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\bcryptprimitives.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4296920","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\bcryptprimitives.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4297013","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\bcryptprimitives.dll","SUCCESS","Information: Owner" "19:13:28,4297100","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\bcryptprimitives.dll","SUCCESS","" "19:13:28,4297931","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\cryptbase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4298123","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cryptbase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4298219","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cryptbase.dll","SUCCESS","Information: Owner" "19:13:28,4298306","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\cryptbase.dll","SUCCESS","" "19:13:28,4299082","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4299339","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sechost.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4299435","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Information: Owner" "19:13:28,4299525","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sechost.dll","SUCCESS","" "19:13:28,4300471","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sspicli.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4300734","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sspicli.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4300830","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sspicli.dll","SUCCESS","Information: Owner" "19:13:28,4300923","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sspicli.dll","SUCCESS","" "19:13:28,4301811","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4302058","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\rpcrt4.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4302155","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","Information: Owner" "19:13:28,4302244","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","" "19:13:28,4303158","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\combase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4303444","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\combase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4303543","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\combase.dll","SUCCESS","Information: Owner" "19:13:28,4303630","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\combase.dll","SUCCESS","" "19:13:28,4304685","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\SHCore.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4304935","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\SHCore.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4305035","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\SHCore.dll","SUCCESS","Information: Owner" "19:13:28,4305121","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\SHCore.dll","SUCCESS","" "19:13:28,4306135","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\advapi32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4306427","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\advapi32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4306533","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\advapi32.dll","SUCCESS","Information: Owner" "19:13:28,4306642","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\advapi32.dll","SUCCESS","" "19:13:28,4307844","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\shlwapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4308104","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\shlwapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4308204","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\shlwapi.dll","SUCCESS","Information: Owner" "19:13:28,4308290","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\shlwapi.dll","SUCCESS","" "19:13:28,4309332","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4309519","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\kernel.appcore.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4309615","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Information: Owner" "19:13:28,4309724","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","" "19:13:28,4310708","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\powrprof.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4310971","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\powrprof.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4311068","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\powrprof.dll","SUCCESS","Information: Owner" "19:13:28,4311157","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\powrprof.dll","SUCCESS","" "19:13:28,4312068","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\profapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4312322","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\profapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4312418","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\profapi.dll","SUCCESS","Information: Owner" "19:13:28,4312504","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\profapi.dll","SUCCESS","" "19:13:28,4313470","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\windows.storage.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4313662","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\windows.storage.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4313755","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\windows.storage.dll","SUCCESS","Information: Owner" "19:13:28,4313848","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\windows.storage.dll","SUCCESS","" "19:13:28,4315074","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\shell32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4315314","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\shell32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4315420","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\shell32.dll","SUCCESS","Information: Owner" "19:13:28,4315506","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\shell32.dll","SUCCESS","" "19:13:28,4316850","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4317133","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\oleaut32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4317232","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","Information: Owner" "19:13:28,4317319","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","" "19:13:28,4318297","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\mpr.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4318569","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\mpr.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4318669","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\mpr.dll","SUCCESS","Information: Owner" "19:13:28,4318755","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\mpr.dll","SUCCESS","" "19:13:28,4319580","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\setupapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4319833","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\setupapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4319929","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\setupapi.dll","SUCCESS","Information: Owner" "19:13:28,4320016","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\setupapi.dll","SUCCESS","" "19:13:28,4320981","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4321225","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sfc.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4321324","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Information: Owner" "19:13:28,4321482","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","" "19:13:28,4322312","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4322591","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","BUFFER OVERFLOW","Information: Owner" "19:13:28,4322704","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","Information: Owner" "19:13:28,4322797","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","" "19:13:28,4323730","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4323980","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\bcrypt.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4324076","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Information: Owner" "19:13:28,4324166","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","" "19:13:28,4324997","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winspool.drv","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4325247","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winspool.drv","BUFFER OVERFLOW","Information: Owner" "19:13:28,4325343","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winspool.drv","SUCCESS","Information: Owner" "19:13:28,4325433","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winspool.drv","SUCCESS","" "19:13:28,4326325","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4326568","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sfc_os.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4326681","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","Information: Owner" "19:13:28,4326770","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","" "19:13:28,4327624","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read" "19:13:28,4327736","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","Desired Access: Read" "19:13:28,4327867","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4327941","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default)","SUCCESS","Type: REG_SZ, Length: 18, Data: 0006020E" "19:13:28,4331912","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\imm32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 143 360, EndOfFile: 143 152, FileAttributes: A" "19:13:28,4332614","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4332912","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4333015","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","AllocationSize: 143 360, EndOfFile: 143 152, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4333191","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\imm32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4333528","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","" "19:13:28,4334105","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\imm32.dll","SUCCESS","Image Base: 0x741c0000, Image Size: 0x25000" "19:13:28,4335565","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4335841","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\imm32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4335943","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","Information: Owner" "19:13:28,4336039","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","" "19:13:28,4336764","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value" "19:13:28,4336870","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","Desired Access: Query Value" "19:13:28,4336989","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4337059","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,4337188","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value" "19:13:28,4337268","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","Desired Access: Query Value" "19:13:28,4337361","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4337425","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20" "19:13:28,4337499","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled","NAME NOT FOUND","Length: 20" "19:13:28,4337579","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","" "19:13:28,4337643","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","" "19:13:28,4337749","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value" "19:13:28,4337832","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4338490","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a6d3c9ac-9128-522a-495a-1821191173c2","NAME NOT FOUND","Length: 524" "19:13:28,4339452","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4339596","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4339660","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4339766","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE","REPARSE","Desired Access: Read" "19:13:28,4339875","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:28,4339965","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4340032","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144" "19:13:28,4340154","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:28,4340235","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4340372","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4340526","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE","REPARSE","Desired Access: Read" "19:13:28,4340674","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:28,4340786","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4340854","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144" "19:13:28,4340934","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:28,4341014","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4341075","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4341181","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE","REPARSE","Desired Access: Read" "19:13:28,4341271","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:28,4341347","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4341412","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\AggressiveMTATesting","NAME NOT FOUND","Length: 144" "19:13:28,4341489","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:28,4341832","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4341906","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM","SUCCESS","Desired Access: Read" "19:13:28,4341986","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4342066","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,4342140","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:28,4342278","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,4342348","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:28,4342448","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,4342512","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:28,4342810","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,4342903","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4342986","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,4343054","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings","REPARSE","Desired Access: Read" "19:13:28,4343144","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings","SUCCESS","Desired Access: Read" "19:13:28,4343253","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,4343342","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4343400","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: Name" "19:13:28,4343506","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:28,4343612","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4343695","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: Name" "19:13:28,4343795","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:28,4343894","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4343949","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: Name" "19:13:28,4344042","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole","NAME NOT FOUND","Desired Access: Read" "19:13:28,4344125","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4344179","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: Name" "19:13:28,4344273","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft","SUCCESS","Desired Access: Read" "19:13:28,4344353","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Classes\Local Settings\Software\Microsoft","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4344654","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4344715","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4344821","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing","REPARSE","Desired Access: Read" "19:13:28,4344911","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole\Tracing","NAME NOT FOUND","Desired Access: Read" "19:13:28,4345292","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be","NAME NOT FOUND","Length: 524" "19:13:28,4345754","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f0558438-f56a-5987-47da-040ca75aef05","NAME NOT FOUND","Length: 524" "19:13:28,4347210","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\imm32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 143 360, EndOfFile: 143 152, FileAttributes: A" "19:13:28,4348455","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\imm32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 143 360, EndOfFile: 143 152, FileAttributes: A" "19:13:28,4348833","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f25bcd2e-2690-55dc-3bc4-07b65b1b41c9","NAME NOT FOUND","Length: 524" "19:13:28,4349167","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Display","REPARSE","Desired Access: Read" "19:13:28,4349266","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Display","NAME NOT FOUND","Desired Access: Read" "19:13:28,4349420","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4349536","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4349635","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4349731","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4349805","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EasyAntiCheat_launcher.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4349997","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Display","REPARSE","Desired Access: Read" "19:13:28,4350078","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Display","NAME NOT FOUND","Desired Access: Read" "19:13:28,4350235","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","REPARSE","Desired Access: Read" "19:13:28,4350331","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","Desired Access: Read" "19:13:28,4350421","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4350482","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20" "19:13:28,4350568","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","" "19:13:28,4350892","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Control Panel\Desktop","SUCCESS","Desired Access: Read" "19:13:28,4351017","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Control Panel\Desktop\EnablePerProcessSystemDPI","NAME NOT FOUND","Length: 520" "19:13:28,4351146","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Control Panel\Desktop","SUCCESS","" "19:13:28,4351643","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32","SUCCESS","Desired Access: Read" "19:13:28,4351810","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32\EasyAntiCheat_launcher","NAME NOT FOUND","Length: 172" "19:13:28,4351919","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32","SUCCESS","" "19:13:28,4352028","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read" "19:13:28,4355370","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4355476","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4355633","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","Desired Access: Read" "19:13:28,4355771","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4355860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,4355982","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","" "19:13:28,4356803","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4356890","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EasyAntiCheat_launcher.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4358388","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4359687","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4361303","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4363542","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108","NAME NOT FOUND","Length: 524" "19:13:28,4364042","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033","NAME NOT FOUND","Length: 524" "19:13:28,4364392","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a40b455c-253c-4311-ac6d-6e667edccefc","NAME NOT FOUND","Length: 524" "19:13:28,4364725","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:28,4365065","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:28,4366060","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4367650","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108","NAME NOT FOUND","Length: 524" "19:13:28,4368010","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033","NAME NOT FOUND","Length: 524" "19:13:28,4368353","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:28,4368667","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:28,4369655","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4370566","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ole32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:13, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:42:13, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 003 520, EndOfFile: 1 003 152, FileAttributes: A" "19:13:28,4371242","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4371560","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ole32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4371682","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","AllocationSize: 1 003 520, EndOfFile: 1 003 152, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4371858","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ole32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4372250","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","" "19:13:28,4372689","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4372759","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4372891","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4373125","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4373183","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4373279","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\system\CurrentControlSet\control\NetworkProvider\HwOrder","REPARSE","Desired Access: Read" "19:13:28,4373417","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\control\NetworkProvider\HwOrder","SUCCESS","Desired Access: Read" "19:13:28,4373552","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4373632","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4373686","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4373779","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\system\CurrentControlSet\control\NetworkProvider\ProviderOrder","REPARSE","Desired Access: Read" "19:13:28,4373860","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\control\NetworkProvider\ProviderOrder","SUCCESS","Desired Access: Read" "19:13:28,4373959","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\NetworkProvider\ProviderOrder","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4374556","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\0e0fe12b-e926-44d2-8cf1-8a62a6d44036","NAME NOT FOUND","Length: 524" "19:13:28,4375351","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f3a71a4b-6118-4257-8ccb-39a33ba059d4","NAME NOT FOUND","Length: 524" "19:13:28,4376560","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4377073","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\c69cb70a-3133-4cca-ab0e-046848effcda","NAME NOT FOUND","Length: 524" "19:13:28,4378828","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 2028" "19:13:28,4379094","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "19:13:28,4379363","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value" "19:13:28,4379482","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value" "19:13:28,4379607","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4379678","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16" "19:13:28,4379710","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe.Local","NAME NOT FOUND","" "19:13:28,4380277","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\MSIMG32.dll","NAME NOT FOUND","" "19:13:28,4380630","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4381137","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 8 192, EndOfFile: 7 168, FileAttributes: A" "19:13:28,4381256","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 616" "19:13:28,4381708","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ole32.dll","SUCCESS","Image Base: 0x744c0000, Image Size: 0xf7000" "19:13:28,4382006","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4382263","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 20:20:15, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:43:25, AllocationSize: 1 474 560, EndOfFile: 1 470 976, FileAttributes: A" "19:13:28,4382449","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\msimg32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4382657","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4382923","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4383000","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","Image Base: 0x73be0000, Image Size: 0x6000" "19:13:28,4383154","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4383343","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4383504","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","" "19:13:28,4383709","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","Image Base: 0x6c4a0000, Image Size: 0x16c000" "19:13:28,4383728","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 2936" "19:13:28,4384623","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","" "19:13:28,4386169","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4386474","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msimg32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4386612","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","Information: Owner" "19:13:28,4386711","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","" "19:13:28,4388097","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4388408","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ole32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4388514","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","Information: Owner" "19:13:28,4388607","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","" "19:13:28,4389883","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4389954","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4390085","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing","REPARSE","Desired Access: Read" "19:13:28,4390191","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole\Tracing","NAME NOT FOUND","Desired Access: Read" "19:13:28,4390608","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be","NAME NOT FOUND","Length: 524" "19:13:28,4390974","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f0558438-f56a-5987-47da-040ca75aef05","NAME NOT FOUND","Length: 524" "19:13:28,4392045","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 593 920, EndOfFile: 593 536, FileAttributes: A" "19:13:28,4393090","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:24, ChangeTime: 2021. 04. 13. 19:00:27, AllocationSize: 1 507 328, EndOfFile: 1 486 568, FileAttributes: ANCI" "19:13:28,4393559","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4393780","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4395861","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4396163","EasyAntiCheat_launcher.exe","6076","Load Image","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","Image Base: 0x73730000, Image Size: 0x193000" "19:13:28,4396846","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\psapi.dll","SUCCESS","Image Base: 0x741f0000, Image Size: 0x6000" "19:13:28,4397093","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WINMM.dll","NAME NOT FOUND","" "19:13:28,4397263","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","" "19:13:28,4398039","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\winmm.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:08, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:08, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 139 264, EndOfFile: 135 432, FileAttributes: A" "19:13:28,4398905","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winmm.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4399236","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmm.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4399434","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmm.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4399749","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\winmm.dll","SUCCESS","Image Base: 0x73670000, Image Size: 0x24000" "19:13:28,4400663","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winmm.dll","SUCCESS","" "19:13:28,4400737","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WINMMBASE.dll","NAME NOT FOUND","" "19:13:28,4401737","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:08, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:08, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 131 072, EndOfFile: 129 864, FileAttributes: A" "19:13:28,4401756","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:08, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:08, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 131 072, EndOfFile: 129 864, FileAttributes: A" "19:13:28,4401856","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:08, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:08, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 131 072, EndOfFile: 129 864, FileAttributes: A" "19:13:28,4402969","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4403049","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4403059","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4403197","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4403360","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4403383","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4403450","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4403562","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4403681","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4403925","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Image Base: 0x73070000, Image Size: 0x23000" "19:13:28,4404069","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Image Base: 0x2b10000, Image Size: 0x23000" "19:13:28,4404155","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Image Base: 0x4630000, Image Size: 0x23000" "19:13:28,4404457","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","" "19:13:28,4404544","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","" "19:13:28,4404864","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","" "19:13:28,4406426","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4406644","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winmmbase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4406773","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Information: Owner" "19:13:28,4406875","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","" "19:13:28,4407963","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winmm.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4408242","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winmm.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4408344","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winmm.dll","SUCCESS","Information: Owner" "19:13:28,4408447","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winmm.dll","SUCCESS","" "19:13:28,4409409","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\psapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4409691","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\psapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4409787","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\psapi.dll","SUCCESS","Information: Owner" "19:13:28,4409880","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\psapi.dll","SUCCESS","" "19:13:28,4410544","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4410727","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4410811","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","Information: Owner" "19:13:28,4410894","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","" "19:13:28,4413684","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4415605","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4415872","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4415945","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4416070","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,4416212","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4416292","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\pid","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4576" "19:13:28,4416401","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:28,4418303","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4418402","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4418521","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Read" "19:13:28,4418620","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4418700","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\SteamClientDll","SUCCESS","Type: REG_SZ, Length: 90, Data: D:\Program Files (x86)\Steam\steamclient.dll" "19:13:28,4418826","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:28,4419451","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten" "19:13:28,4420564","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 0, Length: 103, Priority: Normal" "19:13:28,4421160","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 103, Length: 74" "19:13:28,4481839","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 177, Length: 55" "19:13:28,4485691","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 232, Length: 105" "19:13:28,4491461","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4492384","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4492731","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4492846","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4493051","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4493404","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4494273","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4495069","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4495367","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4495460","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4495624","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4495938","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4496862","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4497558","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4497843","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4497943","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4498119","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4498452","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4499373","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4500492","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4500871","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4500980","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4501179","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4501522","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4502478","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4503177","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4503469","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4503565","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4503725","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4504036","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4504976","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4505768","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4506050","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4506147","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4506326","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4506647","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4507503","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4508251","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4509069","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4509841","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4510137","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4510236","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4510406","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4510720","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4511577","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4512244","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4512520","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4512622","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4512783","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4513100","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4514203","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4514883","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4515175","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4515271","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4515435","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4515746","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4516564","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4517273","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4517552","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4517645","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4517802","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4518094","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4521856","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4522622","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4522911","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4523027","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4523193","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4523501","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4524338","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4524973","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4525249","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4525342","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4525499","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4525794","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4526818","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4527469","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4527741","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4527834","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4527991","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4528315","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4529197","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4529823","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4530089","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4530179","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4530333","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4530628","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4531446","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4532110","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4532369","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4532459","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4532613","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4532899","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4533668","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4534281","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4534541","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4534630","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4534784","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4535070","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4535852","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4536552","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4537273","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4537889","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4538155","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4538245","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4538402","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4538688","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4539499","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4540112","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4540372","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4540461","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4540615","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4540897","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4541709","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4542334","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4542597","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4542687","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4542841","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4543123","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4543893","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4544502","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4544762","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4544852","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4545006","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4545285","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4546289","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steamcompat.inf","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "19:13:28,4546574","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 337, Length: 74" "19:13:28,4548204","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 411, Length: 88" "19:13:28,4548463","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 499, Length: 71" "19:13:28,4548698","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 570, Length: 74" "19:13:28,4548925","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 644, Length: 76" "19:13:28,4549147","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 720, Length: 73" "19:13:28,4549394","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 793, Length: 74" "19:13:28,4549618","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 867, Length: 72" "19:13:28,4549839","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 939, Length: 72" "19:13:28,4550057","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 011, Length: 72" "19:13:28,4550272","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 083, Length: 71" "19:13:28,4550510","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 154, Length: 75" "19:13:28,4550731","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 229, Length: 75" "19:13:28,4550952","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 304, Length: 74" "19:13:28,4551199","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 378, Length: 73" "19:13:28,4551421","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 451, Length: 74" "19:13:28,4551677","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 525, Length: 72" "19:13:28,4551905","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 597, Length: 72" "19:13:28,4552120","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 669, Length: 73" "19:13:28,4552341","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 742, Length: 75" "19:13:28,4552562","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 817, Length: 82" "19:13:28,4552780","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 899, Length: 73" "19:13:28,4553024","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 972, Length: 73" "19:13:28,4553249","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 045, Length: 81" "19:13:28,4553470","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 126, Length: 74" "19:13:28,4553685","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 200, Length: 73" "19:13:28,4553903","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 273, Length: 80" "19:13:28,4554124","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 353, Length: 74" "19:13:28,4554342","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 427, Length: 73" "19:13:28,4554557","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 500, Length: 74" "19:13:28,4554801","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 574, Length: 74" "19:13:28,4555048","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 648, Length: 69" "19:13:28,4555282","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 717, Length: 74" "19:13:28,4555516","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 791, Length: 74" "19:13:28,4555747","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 865, Length: 72" "19:13:28,4555981","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 937, Length: 69" "19:13:28,4556241","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 006, Length: 72" "19:13:28,4556475","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 078, Length: 71" "19:13:28,4556783","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 149, Length: 71" "19:13:28,4557024","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 220, Length: 73" "19:13:28,4557264","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 293, Length: 73" "19:13:28,4557498","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 366, Length: 85" "19:13:28,4557752","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 451, Length: 71" "19:13:28,4557989","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 522, Length: 71" "19:13:28,4558220","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 593, Length: 75" "19:13:28,4558486","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 668, Length: 61" "19:13:28,4559612","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4560279","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4560584","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4560686","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4560850","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4561155","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4562014","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4562675","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4562947","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4563041","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4563194","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4563499","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4564333","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4564965","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4565237","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4565327","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4565484","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4565786","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4566572","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4567213","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4567476","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4567563","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4567717","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4568028","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4568814","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4569433","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4569699","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4569789","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4569943","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4570228","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4571004","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4571665","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4571928","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4572014","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4572168","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4572447","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4573230","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4573942","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4574635","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4575254","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4575523","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4575613","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4575767","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4576059","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4576854","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4577470","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4577730","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4577816","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4577970","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4578253","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4579035","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4579661","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4579940","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4580029","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4580183","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4580469","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4581242","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4581877","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4582137","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4582223","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4582377","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4582656","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4583869","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4584500","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4584763","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4584853","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4585007","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4585293","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4586069","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4586755","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4587018","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4587108","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4587262","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4587560","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4588362","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4588981","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4589237","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4589327","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4589478","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4589770","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4590543","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4591152","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4591402","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4591489","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4591678","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4591970","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4592740","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4593346","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4593599","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4593686","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4593837","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4594119","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4594882","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4595492","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4595745","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4595832","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4595982","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4596258","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4597057","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4597750","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4598442","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4599058","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4599318","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4599405","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4599558","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4599844","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4600610","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4601217","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4601473","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4601560","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4601733","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4602012","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4602785","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4603404","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4603670","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4603757","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4603911","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4604190","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4604956","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4605566","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4605822","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4605909","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4606060","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4606355","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4607634","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4608263","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4608526","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4608629","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4608783","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4609068","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4609879","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4610534","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4610790","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4610877","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4611028","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4611307","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4612112","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4612724","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4612978","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4613064","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4613215","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4613504","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4614270","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4614880","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4615133","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4615220","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4615370","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4615656","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4616416","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4617051","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4617301","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4617388","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4617538","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4617817","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4618574","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4619222","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4619472","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4619559","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4619707","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4619982","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4620749","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4621439","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4622144","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4622757","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4623013","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4623100","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4623251","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4623533","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4624303","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4624909","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4625162","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4625249","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4625399","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4625701","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4626480","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4627115","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4627375","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4627462","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4627616","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4627895","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4628661","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4629271","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4629524","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4629611","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4629761","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4630037","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4631169","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4631811","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4632071","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4632157","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4632308","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4632593","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4633360","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4633973","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4634226","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4634312","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4634463","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4634739","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4635525","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4636137","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4636394","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4636493","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4636667","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4636962","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4637728","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4638338","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4638588","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4638671","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4638822","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4639107","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4639867","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4640480","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4640730","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4640817","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4640968","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4641253","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4642029","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4642635","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4642886","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4642972","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4643123","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4643415","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4644191","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4644887","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4645573","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4646189","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4646446","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4646535","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4646709","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4646994","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4647761","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4648367","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4648617","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4648704","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4648857","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4649133","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4649906","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4650519","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4650775","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4650862","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4651016","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4651292","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4652148","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4652758","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4653017","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4653104","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4653258","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4653534","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4654916","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4655541","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4655801","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4655891","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4656045","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4656327","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4657116","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4657729","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4657982","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4658072","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4658223","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4658499","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4659278","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4659890","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4660141","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4660227","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4660381","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4660667","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4661424","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4662059","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4662312","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4662399","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4662549","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4662851","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4663621","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4664249","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4664503","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4664589","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4664743","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4665022","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4665779","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4666385","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4666655","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4666741","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4666895","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4667174","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4667941","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4668637","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4669329","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4669942","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4670195","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4670282","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4670436","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4670718","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4671485","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4672136","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4672392","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4672482","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4672633","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4672912","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4673685","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4674301","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4674557","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4674647","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4674798","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4675077","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4675917","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4676530","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4676806","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4676895","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4677046","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4677325","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4679830","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4680228","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Name: \Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe" "19:13:28,4681456","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4682123","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4682402","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4682495","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4682656","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4682957","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4683743","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4684365","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4684628","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4684718","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4684869","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4685180","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4686027","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4686671","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4686941","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4687030","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4687184","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4687479","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4688246","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4688862","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4689115","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4689205","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4689359","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4689644","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4690408","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4691017","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4691267","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4691357","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4691511","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4691848","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4692611","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4693220","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4693477","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4693573","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4693727","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4694016","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4694991","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4695690","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4696376","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4697015","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4697278","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4697367","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4697521","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4697820","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4698583","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4699189","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4699449","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4699536","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4699690","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4699978","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4700754","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4701367","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4701649","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4701739","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4701893","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4702182","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4702948","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4703554","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4703811","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4703897","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4704048","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4704353","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4705892","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4705979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4706152","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","Desired Access: Read" "19:13:28,4706354","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4706746","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4706829","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}","SUCCESS","Desired Access: Read" "19:13:28,4706996","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","" "19:13:28,4707082","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4" "19:13:28,4707159","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name","SUCCESS","Type: REG_SZ, Length: 16, Data: AppData" "19:13:28,4707236","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder","NAME NOT FOUND","Length: 144" "19:13:28,4707304","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description","NAME NOT FOUND","Length: 144" "19:13:28,4707358","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath","SUCCESS","Type: REG_SZ, Length: 32, Data: AppData\Roaming" "19:13:28,4707438","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName","NAME NOT FOUND","Length: 144" "19:13:28,4707496","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip","NAME NOT FOUND","Length: 144" "19:13:28,4707551","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName","NAME NOT FOUND","Length: 144" "19:13:28,4707608","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon","NAME NOT FOUND","Length: 144" "19:13:28,4707660","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security","NAME NOT FOUND","Length: 144" "19:13:28,4707714","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource","NAME NOT FOUND","Length: 144" "19:13:28,4707769","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType","NAME NOT FOUND","Length: 144" "19:13:28,4707826","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly","NAME NOT FOUND","Length: 144" "19:13:28,4707881","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable","NAME NOT FOUND","Length: 144" "19:13:28,4707935","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate","NAME NOT FOUND","Length: 144" "19:13:28,4707990","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream","NAME NOT FOUND","Length: 144" "19:13:28,4708044","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath","NAME NOT FOUND","Length: 144" "19:13:28,4708099","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\DefinitionFlags","NAME NOT FOUND","Length: 144" "19:13:28,4708150","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes","NAME NOT FOUND","Length: 144" "19:13:28,4708205","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID","NAME NOT FOUND","Length: 144" "19:13:28,4708259","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler","NAME NOT FOUND","Length: 144" "19:13:28,4708372","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4708449","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag","NAME NOT FOUND","Desired Access: Read" "19:13:28,4708606","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}","SUCCESS","" "19:13:28,4708824","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4708882","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4708991","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer","SUCCESS","Desired Access: Query Value" "19:13:28,4709112","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4709202","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4709270","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1","SUCCESS","Desired Access: Query Value" "19:13:28,4709392","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4709456","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4709545","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1","SUCCESS","" "19:13:28,4709683","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,4709805","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4709863","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4709956","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","Desired Access: Read" "19:13:28,4710059","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4710126","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,4710222","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData","SUCCESS","Type: REG_EXPAND_SZ, Length: 60, Data: %USERPROFILE%\AppData\Roaming" "19:13:28,4710694","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read" "19:13:28,4710800","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Read" "19:13:28,4710918","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4710976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\hu-HU","NAME NOT FOUND","Length: 532" "19:13:28,4711043","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","" "19:13:28,4711136","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read" "19:13:28,4711213","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","Desired Access: Read" "19:13:28,4711306","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4711361","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\hu-HU","NAME NOT FOUND","Length: 532" "19:13:28,4711422","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","" "19:13:28,4711556","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\000602xx","SUCCESS","Type: REG_SZ, Length: 26, Data: kernel32.dll" "19:13:28,4712384","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4713057","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4713349","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4713449","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4713628","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4713949","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4714780","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4715415","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4715691","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4715784","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4715941","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4716242","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4717083","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4717714","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4717984","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4718077","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4718234","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4718532","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4719318","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4719943","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4720210","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4720299","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4720453","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4720752","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4721531","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4722172","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4722432","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4722522","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4722679","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4722968","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4723744","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4724360","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4724616","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4724706","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4724860","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4725146","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4725925","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4726643","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4727378","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4727990","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4728257","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4728346","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4728500","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4728799","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4729578","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4730194","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4730457","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4730547","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4730701","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4731012","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4731830","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4732830","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4733109","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4733202","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4733356","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4733651","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4734434","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4735050","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4735316","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4735402","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4735556","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4735845","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4737115","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4737343","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4737433","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","AllocationSize: 3 371 008, EndOfFile: 3 368 788, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4737587","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4737792","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","" "19:13:28,4738170","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","REPARSE","Desired Access: Read" "19:13:28,4738270","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","Desired Access: Read" "19:13:28,4738392","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4738465","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\hu-HU","NAME NOT FOUND","Length: 90" "19:13:28,4738568","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\hu","SUCCESS","Type: REG_SZ, Length: 78, Data: {00000004-57EE-1E5C-00B4-D0000BB1E11E}" "19:13:28,4739107","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders","SUCCESS","" "19:13:28,4739351","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4739412","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4739533","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Explorer","REPARSE","Desired Access: Query Value" "19:13:28,4739636","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer","SUCCESS","Desired Access: Query Value" "19:13:28,4739752","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4739812","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer\DisableKnownFolders","NAME NOT FOUND","Length: 144" "19:13:28,4739896","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer","SUCCESS","" "19:13:28,4739979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4740034","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,4740136","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Explorer","SUCCESS","Desired Access: Query Value" "19:13:28,4740236","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\Windows\Explorer","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4740297","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\Explorer\DisableKnownFolders","NAME NOT FOUND","Length: 144" "19:13:28,4740377","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\Windows\Explorer","SUCCESS","" "19:13:28,4741458","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4741522","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4741666","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","Desired Access: Read" "19:13:28,4741775","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4741856","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4741926","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}","SUCCESS","Desired Access: Read" "19:13:28,4742051","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","" "19:13:28,4742122","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2" "19:13:28,4742189","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name","SUCCESS","Type: REG_SZ, Length: 16, Data: Profile" "19:13:28,4742260","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder","NAME NOT FOUND","Length: 144" "19:13:28,4742321","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description","NAME NOT FOUND","Length: 144" "19:13:28,4742375","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath","NAME NOT FOUND","Length: 144" "19:13:28,4742430","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName","NAME NOT FOUND","Length: 144" "19:13:28,4742481","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip","NAME NOT FOUND","Length: 144" "19:13:28,4742535","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName","NAME NOT FOUND","Length: 144" "19:13:28,4742590","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon","NAME NOT FOUND","Length: 144" "19:13:28,4742644","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security","NAME NOT FOUND","Length: 144" "19:13:28,4742699","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource","NAME NOT FOUND","Length: 144" "19:13:28,4742750","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType","NAME NOT FOUND","Length: 144" "19:13:28,4742805","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly","NAME NOT FOUND","Length: 144" "19:13:28,4742859","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable","NAME NOT FOUND","Length: 144" "19:13:28,4742911","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate","NAME NOT FOUND","Length: 144" "19:13:28,4742965","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream","NAME NOT FOUND","Length: 144" "19:13:28,4743020","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath","NAME NOT FOUND","Length: 144" "19:13:28,4743074","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\DefinitionFlags","NAME NOT FOUND","Length: 144" "19:13:28,4743129","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes","NAME NOT FOUND","Length: 144" "19:13:28,4743183","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID","NAME NOT FOUND","Length: 144" "19:13:28,4743235","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler","NAME NOT FOUND","Length: 144" "19:13:28,4743324","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,4743395","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag","NAME NOT FOUND","Desired Access: Read" "19:13:28,4743488","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}","SUCCESS","" "19:13:28,4743838","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4743899","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4744020","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","REPARSE","Desired Access: Read" "19:13:28,4744136","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","SUCCESS","Desired Access: Read" "19:13:28,4744232","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4744293","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 46, Data: C:\Users\Administrator" "19:13:28,4744364","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 46, Data: C:\Users\Administrator" "19:13:28,4744441","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","SUCCESS","" "19:13:28,4745377","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:28,4746086","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator","SUCCESS","CreationTime: 2020. 01. 09. 4:53:33, LastAccessTime: 2021. 04. 14. 15:44:50, LastWriteTime: 2021. 04. 14. 15:44:50, ChangeTime: 2021. 04. 14. 15:44:50, AllocationSize: 20 480, EndOfFile: 20 480, FileAttributes: DNCI" "19:13:28,4746262","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4746323","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4746445","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4746567","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4746622","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4746750","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4747465","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:28,4748103","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming","SUCCESS","CreationTime: 2020. 01. 09. 4:53:34, LastAccessTime: 2021. 04. 13. 16:48:14, LastWriteTime: 2021. 04. 13. 16:48:14, ChangeTime: 2021. 04. 13. 16:48:14, AllocationSize: 12 288, EndOfFile: 12 288, FileAttributes: DANCI" "19:13:28,4748851","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat","SUCCESS","CreationTime: 2021. 04. 12. 10:49:55, LastAccessTime: 2021. 04. 12. 10:49:55, LastWriteTime: 2021. 04. 12. 10:49:55, ChangeTime: 2021. 04. 12. 10:49:55, AllocationSize: 0, EndOfFile: 0, FileAttributes: DNCI" "19:13:28,4749707","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten" "19:13:28,4752962","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 0, Length: 84, Priority: Normal" "19:13:28,4755063","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Hardware\DeviceMap\VIDEO","SUCCESS","Desired Access: Read, Maximum Allowed" "19:13:28,4755278","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\HARDWARE\DEVICEMAP\VIDEO\MaxObjectNumber","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4" "19:13:28,4755419","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\HARDWARE\DEVICEMAP\VIDEO","SUCCESS","" "19:13:28,4755573","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Hardware\DeviceMap\Video","SUCCESS","Desired Access: Read" "19:13:28,4755692","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\HARDWARE\DEVICEMAP\VIDEO\\Device\Video0","SUCCESS","Type: REG_SZ, Length: 202, Data: \Registry\Machine\System\CurrentControlSet\Control\Video\{DC1F5717-98A5-11EB-A77F-C4EF73791CDA}\0000" "19:13:28,4755826","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\CONTROL\VIDEO\{DC1F5717-98A5-11EB-A77F-C4EF73791CDA}\0000","REPARSE","Desired Access: Read" "19:13:28,4755945","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\CONTROL\VIDEO\{DC1F5717-98A5-11EB-A77F-C4EF73791CDA}\0000","REPARSE","Desired Access: Read" "19:13:28,4756154","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000","SUCCESS","Desired Access: Read" "19:13:28,4756279","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\HARDWARE\DEVICEMAP\VIDEO","SUCCESS","" "19:13:28,4756452","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000\PruningMode","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,4756615","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000","SUCCESS","" "19:13:28,4756837","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Enum\PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1\4&1ddda1e7&0&0008","SUCCESS","Desired Access: Query Value, Maximum Allowed" "19:13:28,4756997","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Enum\PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1\4&1ddda1e7&0&0008\HardwareID","BUFFER OVERFLOW","Length: 268" "19:13:28,4757119","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Enum\PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1\4&1ddda1e7&0&0008","SUCCESS","" "19:13:28,4757257","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Enum\PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1\4&1ddda1e7&0&0008","SUCCESS","Desired Access: Query Value, Maximum Allowed" "19:13:28,4757372","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Enum\PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1\4&1ddda1e7&0&0008\HardwareID","SUCCESS","Type: REG_MULTI_SZ, Length: 292, Data: PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1, PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458, PCI\VEN_10DE&DEV_1C81&CC_030000, PCI\VEN_10DE&DEV_1C81&CC_0300" "19:13:28,4757481","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Enum\PCI\VEN_10DE&DEV_1C81&SUBSYS_37651458&REV_A1\4&1ddda1e7&0&0008","SUCCESS","" "19:13:28,4757587","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Hardware\DeviceMap\Video","SUCCESS","Desired Access: Read" "19:13:28,4757693","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\HARDWARE\DEVICEMAP\VIDEO\\Device\Video0","SUCCESS","Type: REG_SZ, Length: 202, Data: \Registry\Machine\System\CurrentControlSet\Control\Video\{DC1F5717-98A5-11EB-A77F-C4EF73791CDA}\0000" "19:13:28,4757792","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\HARDWARE\DEVICEMAP\VIDEO","SUCCESS","" "19:13:28,4759476","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:25, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:25, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 475 136, EndOfFile: 472 576, FileAttributes: A" "19:13:28,4760211","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4760560","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\uxtheme.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4760814","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4761247","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","Image Base: 0x73c40000, Image Size: 0x79000" "19:13:28,4762898","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","" "19:13:28,4763848","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4764162","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\uxtheme.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4764294","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","Information: Owner" "19:13:28,4764425","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","" "19:13:28,4765637","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4767071","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4767812","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4768139","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4768264","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4768476","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4768851","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4769743","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4770442","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4770750","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4770865","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4771074","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4771414","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4772610","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4773421","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4773733","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4773845","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4774063","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4774429","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4775388","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4776122","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4776443","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4776571","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4776805","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4777187","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4778082","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4778752","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4779047","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4779162","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4779365","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4779721","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4780635","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4781289","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4781578","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4781699","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4781895","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4782235","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4783088","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4783835","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4784560","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4785205","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4785503","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4785628","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4785827","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4786174","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4787020","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4787659","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4787944","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4788056","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4788252","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4788589","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4789442","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4790093","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4790391","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4790503","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4790702","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4791042","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4791886","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4792527","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4792816","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4792928","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4793124","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4793480","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4796742","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read" "19:13:28,4796876","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Read" "19:13:28,4797011","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4797088","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532" "19:13:28,4797178","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","" "19:13:28,4797280","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read" "19:13:28,4797361","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","Desired Access: Read" "19:13:28,4797450","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4797508","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532" "19:13:28,4797575","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","" "19:13:28,4798490","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4799182","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4799490","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4799593","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4799760","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4800074","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4800914","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,4801562","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4801867","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4801963","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4802120","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4802438","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,4803288","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4803926","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4804202","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4804295","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4804452","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4804763","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4805565","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,4806197","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4806466","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4806556","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4806735","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4807034","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,4807826","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4808448","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4808711","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4808798","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4808955","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4809243","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4810029","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,4810645","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4810908","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4810998","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4811152","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4811437","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,4812242","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4812954","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,4813666","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4814295","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4814568","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4814657","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4814815","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4815103","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4815883","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,4816505","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4816819","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4816909","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4817066","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4817348","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,4818144","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4818769","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4819032","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4819122","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4819279","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4819564","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4820395","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,4821014","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4821280","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4821370","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,4821524","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4821842","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,4822672","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 3932" "19:13:28,4823012","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\785e3ea5-a921-427c-8edb-0583d49c7636","NAME NOT FOUND","Length: 524" "19:13:28,4824828","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\msctf.dll","SUCCESS","Image Base: 0x73d40000, Image Size: 0x144000" "19:13:28,4827538","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\msctf.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4827894","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msctf.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4828035","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msctf.dll","SUCCESS","Information: Owner" "19:13:28,4828160","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\msctf.dll","SUCCESS","" "19:13:28,4829427","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4830488","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\DWrite.dll","NAME NOT FOUND","" "19:13:28,4832217","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 20:11:35, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 2 580 480, EndOfFile: 2 577 408, FileAttributes: A" "19:13:28,4832936","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4833256","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\DWrite.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,4833462","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4833792","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","Image Base: 0x731f0000, Image Size: 0x280000" "19:13:28,4834478","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","" "19:13:28,4835617","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4835893","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\DWrite.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4835999","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","Information: Owner" "19:13:28,4836092","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","" "19:13:28,4837150","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4838058","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\364e2beb-6efc-47dc-b8b1-49aae1d83922","NAME NOT FOUND","Length: 524" "19:13:28,4838754","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4838827","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4838978","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\DirectWrite","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,4839703","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4839764","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4839870","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\FontCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,4839972","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\FontCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,4840142","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\FontCache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4840210","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\FontCache\Parameters\ClientCacheSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4194304" "19:13:28,4840312","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\FontCache\Parameters","SUCCESS","" "19:13:28,4841849","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,4841913","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,4842028","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Avalon.Graphics","SUCCESS","Desired Access: Read" "19:13:28,4842169","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Avalon.Graphics","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4842233","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Avalon.Graphics\InputAssertEnabled","NAME NOT FOUND","Length: 144" "19:13:28,4842317","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Avalon.Graphics","SUCCESS","" "19:13:28,4842917","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4843006","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,4843109","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,4843170","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:28,4843257","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:28,4853558","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4853825","EasyAntiCheat_launcher.exe","6076","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\hu*.cfg","NO SUCH FILE","FileInformationClass: FileBothDirectoryInformation, Filter: hu*.cfg" "19:13:28,4854011","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization","SUCCESS","" "19:13:28,4854674","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4854909","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","AllocationSize: 65 536, EndOfFile: 6 175, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,4855063","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","Offset: 0, Length: 6 175, Priority: Normal" "19:13:28,4855338","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","" "19:13:28,4861185","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 84, Length: 42" "19:13:28,4861596","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 126, Length: 132" "19:13:28,4862298","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\Settings.json","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4862696","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\Settings.json","SUCCESS","Offset: 0, Length: 339, Priority: Normal" "19:13:28,4862972","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\Settings.json","END OF FILE","Offset: 339, Length: 4 096" "19:13:28,4864011","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\Settings.json","SUCCESS","" "19:13:28,4869332","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 126 976, EndOfFile: 126 872, FileAttributes: A" "19:13:28,4870127","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4870490","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dwmapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,4870749","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,4871141","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","Image Base: 0x73c10000, Image Size: 0x23000" "19:13:28,4871878","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","" "19:13:28,4873273","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4873668","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dwmapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,4873822","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","Information: Owner" "19:13:28,4873957","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","" "19:13:28,4875166","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,4876433","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,4876696","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","AllocationSize: 458 752, EndOfFile: 410 334, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,4876933","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 0, Length: 4 096, Priority: Normal" "19:13:28,4879403","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 4 096, Length: 4 096" "19:13:28,4881840","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 8 192, Length: 4 096" "19:13:28,4884258","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 12 288, Length: 4 096" "19:13:28,4886686","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 16 384, Length: 4 096" "19:13:28,4889108","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 20 480, Length: 4 096" "19:13:28,4891523","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 24 576, Length: 4 096" "19:13:28,4893948","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 28 672, Length: 4 096" "19:13:28,4896347","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 32 768, Length: 4 096" "19:13:28,4898736","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 36 864, Length: 4 096" "19:13:28,4901151","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 40 960, Length: 4 096" "19:13:28,4903540","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 45 056, Length: 4 096" "19:13:28,4905956","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 49 152, Length: 4 096" "19:13:28,4908380","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 53 248, Length: 4 096" "19:13:28,4910795","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 57 344, Length: 4 096" "19:13:28,4913188","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 61 440, Length: 4 096" "19:13:28,4915606","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 65 536, Length: 4 096" "19:13:28,4918018","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 69 632, Length: 4 096" "19:13:28,4920433","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 73 728, Length: 4 096" "19:13:28,4922835","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 77 824, Length: 4 096" "19:13:28,4925267","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 81 920, Length: 4 096" "19:13:28,4927688","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 86 016, Length: 4 096" "19:13:28,4930100","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 90 112, Length: 4 096" "19:13:28,4932509","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 94 208, Length: 4 096" "19:13:28,4934924","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 98 304, Length: 4 096" "19:13:28,4937345","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 102 400, Length: 4 096" "19:13:28,4939654","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 106 496, Length: 4 096" "19:13:28,4942060","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 110 592, Length: 4 096" "19:13:28,4944478","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 114 688, Length: 4 096" "19:13:28,4946896","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 118 784, Length: 4 096" "19:13:28,4949315","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 122 880, Length: 4 096" "19:13:28,4951739","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 126 976, Length: 4 096" "19:13:28,4954151","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 131 072, Length: 4 096" "19:13:28,4956557","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 135 168, Length: 4 096" "19:13:28,4958975","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 139 264, Length: 4 096" "19:13:28,4961393","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 143 360, Length: 4 096" "19:13:28,4963776","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 147 456, Length: 4 096" "19:13:28,4966191","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 151 552, Length: 4 096" "19:13:28,4968610","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 155 648, Length: 4 096" "19:13:28,4970999","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 159 744, Length: 4 096" "19:13:28,4973424","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 163 840, Length: 4 096" "19:13:28,4975845","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 167 936, Length: 4 096" "19:13:28,4978238","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 172 032, Length: 4 096" "19:13:28,4980653","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 176 128, Length: 4 096" "19:13:28,4983036","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 180 224, Length: 4 096" "19:13:28,4985454","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 184 320, Length: 4 096" "19:13:28,4987850","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 188 416, Length: 4 096" "19:13:28,4990265","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 192 512, Length: 4 096" "19:13:28,4992667","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 196 608, Length: 4 096" "19:13:28,4995082","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 200 704, Length: 4 096" "19:13:28,4997485","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 204 800, Length: 4 096" "19:13:28,4999900","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 208 896, Length: 4 096" "19:13:28,5002308","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 212 992, Length: 4 096" "19:13:28,5004723","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 217 088, Length: 4 096" "19:13:28,5007235","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 221 184, Length: 4 096" "19:13:28,5009653","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 225 280, Length: 4 096" "19:13:28,5012071","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 229 376, Length: 4 096" "19:13:28,5014486","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 233 472, Length: 4 096" "19:13:28,5016905","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 237 568, Length: 4 096" "19:13:28,5019320","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 241 664, Length: 4 096" "19:13:28,5021738","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 245 760, Length: 4 096" "19:13:28,5024121","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 249 856, Length: 4 096" "19:13:28,5026533","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 253 952, Length: 4 096" "19:13:28,5028942","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 258 048, Length: 4 096" "19:13:28,5031341","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 262 144, Length: 4 096" "19:13:28,5033781","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 266 240, Length: 4 096" "19:13:28,5036209","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 270 336, Length: 4 096" "19:13:28,5038634","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 274 432, Length: 4 096" "19:13:28,5041049","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 278 528, Length: 4 096" "19:13:28,5043471","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 282 624, Length: 4 096" "19:13:28,5045882","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 286 720, Length: 4 096" "19:13:28,5048285","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 290 816, Length: 4 096" "19:13:28,5050700","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 294 912, Length: 4 096" "19:13:28,5053099","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 299 008, Length: 4 096" "19:13:28,5055495","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 303 104, Length: 4 096" "19:13:28,5057906","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 307 200, Length: 4 096" "19:13:28,5060299","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 311 296, Length: 4 096" "19:13:28,5062714","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 315 392, Length: 4 096" "19:13:28,5065107","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 319 488, Length: 4 096" "19:13:28,5067515","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 323 584, Length: 4 096" "19:13:28,5069911","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 327 680, Length: 4 096" "19:13:28,5072323","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 331 776, Length: 4 096" "19:13:28,5074738","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 335 872, Length: 4 096" "19:13:28,5077160","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 339 968, Length: 4 096" "19:13:28,5079575","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 344 064, Length: 4 096" "19:13:28,5081999","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 348 160, Length: 4 096" "19:13:28,5084415","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 352 256, Length: 4 096" "19:13:28,5086727","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 356 352, Length: 4 096" "19:13:28,5089145","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 360 448, Length: 4 096" "19:13:28,5091560","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 364 544, Length: 4 096" "19:13:28,5093985","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 368 640, Length: 4 096" "19:13:28,5096400","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 372 736, Length: 4 096" "19:13:28,5098783","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 376 832, Length: 4 096" "19:13:28,5101198","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 380 928, Length: 4 096" "19:13:28,5103588","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 385 024, Length: 4 096" "19:13:28,5106006","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 389 120, Length: 4 096" "19:13:28,5108395","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 393 216, Length: 4 096" "19:13:28,5110705","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 397 312, Length: 4 096" "19:13:28,5113104","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 401 408, Length: 4 096" "19:13:28,5115519","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 405 504, Length: 4 096" "19:13:28,5117943","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","Offset: 409 600, Length: 734" "19:13:28,5118437","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","END OF FILE","Offset: 410 334, Length: 4 096" "19:13:28,5124396","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WindowsCodecs.dll","NAME NOT FOUND","" "19:13:28,5125256","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 1 507 328, EndOfFile: 1 503 600, FileAttributes: A" "19:13:28,5125997","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5126260","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\WindowsCodecs.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5129108","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5129528","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","Image Base: 0x734c0000, Image Size: 0x16e000" "19:13:28,5131016","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","" "19:13:28,5131991","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5132209","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\WindowsCodecs.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5132318","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","Information: Owner" "19:13:28,5132411","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","" "19:13:28,5133518","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,5134243","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\7c29709d-3c02-47fb-8a39-d8287522fadb","NAME NOT FOUND","Length: 524" "19:13:28,5135359","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5136032","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5136372","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5136475","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5136648","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5137023","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5137873","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5138508","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5138781","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5138874","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5139031","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5139355","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5140343","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5141029","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5141318","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5141510","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5141751","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5142117","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5143220","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5143929","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5144230","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5144326","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5144484","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5144791","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5145619","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5146260","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5146536","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5146629","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5146799","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5147107","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5147909","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5148531","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5148797","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5148887","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5149041","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5149336","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5150138","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5150866","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5151568","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5152213","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5152492","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5152585","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5152742","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5153050","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5153833","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5154452","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5154715","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5154805","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5154958","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5155257","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5156055","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5156694","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5157005","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5157098","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5157252","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5157550","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5158326","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5158942","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5159202","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5159292","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5159442","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5159753","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5160876","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,5161036","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Classes","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5161139","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: Name" "19:13:28,5161238","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: HandleTags, HandleTags: 0x1" "19:13:28,5161328","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: HandleTags, HandleTags: 0x1" "19:13:28,5161386","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: Name" "19:13:28,5161517","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\WOW6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance","NAME NOT FOUND","Desired Access: Read" "19:13:28,5161713","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCR\WOW6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance","SUCCESS","Desired Access: Read" "19:13:28,5161915","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCR\WOW6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5161982","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: Name" "19:13:28,5162072","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: HandleTags, HandleTags: 0x1" "19:13:28,5162149","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: HandleTags, HandleTags: 0x1" "19:13:28,5162201","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Classes","SUCCESS","Query: Name" "19:13:28,5162322","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\WOW6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled","NAME NOT FOUND","Desired Access: Read" "19:13:28,5162460","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCR\WOW6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled","NAME NOT FOUND","Desired Access: Read" "19:13:28,5162605","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCR\WOW6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance","SUCCESS","" "19:13:28,5163692","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Launcher\SplashScreen.png","SUCCESS","" "19:13:28,5167438","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,5167544","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,5167666","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5167730","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:28,5167823","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:28,5284927","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,5285116","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,5285283","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5285389","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:28,5285527","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:28,5286652","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "19:13:28,5287698","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe.Local","NAME NOT FOUND","" "19:13:28,5288811","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5289734","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:23, LastAccessTime: 2021. 02. 13. 21:58:53, LastWriteTime: 2017. 09. 29. 15:42:23, ChangeTime: 2020. 01. 09. 4:44:11, AllocationSize: 2 154 496, EndOfFile: 2 150 808, FileAttributes: A" "19:13:28,5290434","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5290697","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5290940","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5291357","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","Image Base: 0x72dd0000, Image Size: 0x211000" "19:13:28,5293471","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","" "19:13:28,5295193","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,5296556","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\WindowsShell.Manifest","SUCCESS","Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5296810","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\WindowsShell.Manifest","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5296916","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\WindowsShell.Manifest","SUCCESS","AllocationSize: 4 096, EndOfFile: 670, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5297098","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\WindowsShell.Manifest","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5297419","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","Desired Access: Read" "19:13:28,5297563","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5297634","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20" "19:13:28,5297721","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","" "19:13:28,5297842","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\WindowsShell.Manifest","SUCCESS","AllocationSize: 4 096, EndOfFile: 670, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5297955","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\WindowsShell.Manifest","SUCCESS","CreationTime: 2017. 09. 29. 15:41:58, LastAccessTime: 2021. 02. 13. 21:58:53, LastWriteTime: 2017. 09. 29. 15:41:58, ChangeTime: 2020. 01. 09. 4:40:35, FileAttributes: RHA" "19:13:28,5298535","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\WindowsShell.Manifest","SUCCESS","" "19:13:28,5299863","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5300537","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5300867","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5300963","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5301127","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5301502","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5302490","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5303128","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5303404","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5303494","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5303651","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5303984","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5304828","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5305466","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5305745","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5305835","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5305992","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5306332","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5307163","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5307785","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5308051","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5308141","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5308295","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5308619","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5309401","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5310027","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5310293","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5310383","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5310540","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5310870","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5311637","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5312326","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5312583","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5312673","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5312824","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5313141","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5313933","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5314649","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5315345","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5315964","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5316239","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5316348","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5316512","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5316887","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5317686","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5318327","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5318593","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5318683","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5318840","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5319190","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5319995","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5320637","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5320919","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5321009","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5321175","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5321512","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5322311","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5322939","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5323209","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5323299","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5323459","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5323940","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5335464","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","CreationTime: 2021. 04. 12. 12:13:17, LastAccessTime: 2021. 04. 12. 12:13:17, LastWriteTime: 2021. 04. 12. 12:13:17, ChangeTime: 2021. 04. 12. 12:13:24, AllocationSize: 720 896, EndOfFile: 683 120, FileAttributes: ANCI" "19:13:28,5335967","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5336195","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5338132","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5338501","EasyAntiCheat_launcher.exe","6076","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","Image Base: 0x724d0000, Image Size: 0xac000" "19:13:28,5339101","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ws2_32.dll","SUCCESS","Image Base: 0x77240000, Image Size: 0x66000" "19:13:28,5339960","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","Image Base: 0x74c00000, Image Size: 0x182000" "19:13:28,5340807","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Image Base: 0x73ff0000, Image Size: 0xe000" "19:13:28,5341878","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","" "19:13:28,5342860","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ws2_32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5343190","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ws2_32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5343306","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ws2_32.dll","SUCCESS","Information: Owner" "19:13:28,5343402","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ws2_32.dll","SUCCESS","" "19:13:28,5344415","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5344691","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msasn1.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5344790","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Information: Owner" "19:13:28,5344880","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","" "19:13:28,5345746","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5346012","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\crypt32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5346109","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","Information: Owner" "19:13:28,5346198","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","" "19:13:28,5347016","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5347196","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5347279","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","Information: Owner" "19:13:28,5347363","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll","SUCCESS","" "19:13:28,5348242","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\d0f1a5c6-fc43-48ae-99bf-efb1c38be9d1","NAME NOT FOUND","Length: 524" "19:13:28,5349441","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,5350862","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5351513","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5351834","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5351949","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5352122","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5352494","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5353315","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5353957","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5354233","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5354332","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5354496","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5354842","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5355689","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5356391","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5356670","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5356786","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5356952","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5357289","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5358264","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5359172","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5359499","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5359608","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5359784","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5360144","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5361045","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5361709","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5362004","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5362110","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5362273","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5362626","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5363518","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5364162","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5364432","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5364522","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5364685","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5365019","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5365840","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5366590","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5367363","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5368152","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5368451","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5368547","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5368710","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5369060","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5369926","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5370599","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5370869","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5370968","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5371135","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5371485","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5372421","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5373079","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5373358","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5373451","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5373624","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5373967","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5374775","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5375532","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5375853","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5375956","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5376129","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5376469","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5377713","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5378419","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5378711","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5378804","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5378964","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5379317","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5380205","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5380837","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5381106","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5381196","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5381353","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5381681","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5382502","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5383121","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5383384","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5383473","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5383643","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5383967","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5384740","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5385359","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5385616","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5385706","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5385860","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5386184","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5386963","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5387579","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5387835","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5387922","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5388076","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5388397","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5389160","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5389772","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5390026","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5390112","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5390266","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5390581","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5391350","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5392104","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5392791","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5393413","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5393676","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5393766","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5393923","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5394240","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5395013","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5395632","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5395895","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5395985","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5396142","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5396453","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5397239","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5397864","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5398124","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5398214","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5398371","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5398714","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5399503","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5400119","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5400382","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5400472","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5400629","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5400947","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5402204","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5402839","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5403102","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5403192","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5403349","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5403670","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5404443","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5405065","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5405325","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5405414","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5405571","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5405889","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5406678","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5407316","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5407576","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5407666","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5407820","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5408137","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5408897","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5409513","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5409767","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5409856","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5410014","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5410331","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5411094","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5411745","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5412005","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5412095","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5412249","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5412567","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5413330","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5413936","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5414189","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5414279","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5414433","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5414747","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5415546","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5416242","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5416944","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5417557","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5417817","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5417907","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5418064","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5418407","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5419190","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5419799","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5420059","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5420145","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5420302","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5420617","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5421390","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5422015","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5422281","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5422371","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5422528","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5422846","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5423616","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5424222","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5424482","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5424571","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5424729","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5425046","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5426188","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5426820","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5427083","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5427172","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5427330","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5427657","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5428430","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5429046","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5429305","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5429392","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5429549","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5429883","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5430720","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5431339","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5431595","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5431685","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5431849","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5432169","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5432930","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5433536","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5433786","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5433876","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5434026","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5434344","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5435101","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5435707","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5435960","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5436047","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5436204","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5436547","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5437330","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5437936","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5438189","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5438276","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5438430","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5438748","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5439514","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5440210","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5440893","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5441503","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5441772","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5441865","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5442019","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5442333","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5443097","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5443703","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5443959","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5444052","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5444206","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5444521","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5445294","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5445909","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5446169","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5446259","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5446413","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5446737","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5447503","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5448113","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5448369","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5448459","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5448613","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5448927","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5450265","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5450890","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5451150","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5451243","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5451400","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5451731","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5452500","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5453126","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5453385","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5453475","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5453629","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5453950","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5454736","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5455345","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5455602","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5455692","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5455845","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5456192","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5457007","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5457613","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5457872","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5457959","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5458116","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5458434","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5459226","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5459835","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5460089","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5460178","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5460332","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5460647","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5461404","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5462023","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5462273","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5462363","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5462517","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5462831","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5463601","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5464297","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5464986","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5465596","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5465855","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5465942","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5466099","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5466417","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5467196","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5467805","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5468062","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5468152","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5468306","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5468617","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5469393","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5470006","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5470265","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5470358","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5470512","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5470830","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5471593","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5472215","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5472475","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5472562","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5472719","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5473036","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5474816","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,5476523","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5477167","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5477434","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5477527","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5477684","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5478040","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5478829","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5479473","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5479733","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5479820","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5479977","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5480298","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5481100","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5481715","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5481985","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5482075","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5482228","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5482549","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5483348","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5483957","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5484211","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5484297","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5484451","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5484765","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5485526","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5486132","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5486385","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5486472","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5486626","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5486946","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5487710","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5488313","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5488563","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5488649","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5488800","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5489108","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5489871","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5490561","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5491241","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5491866","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5492129","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5492216","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5492370","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5492687","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5493454","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5494057","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5494310","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5494397","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5494551","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5494862","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5495638","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5496251","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5496510","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5496600","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5496761","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5497107","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5497918","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5498531","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5498788","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5498874","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5499025","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5499339","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5500298","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 258, Length: 185" "19:13:28,5500959","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5501187","EasyAntiCheat_launcher.exe","6076","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\hu*.cfg","NO SUCH FILE","FileInformationClass: FileBothDirectoryInformation, Filter: hu*.cfg" "19:13:28,5501337","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization","SUCCESS","" "19:13:28,5501956","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5502171","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","AllocationSize: 65 536, EndOfFile: 6 175, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,5502277","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","Offset: 0, Length: 6 175, Priority: Normal" "19:13:28,5502447","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","" "19:13:28,5506767","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5507001","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5507187","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5507335","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:28,5508018","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe.eac","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "19:13:28,5508900","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5509567","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5509850","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5509946","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5510109","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5510459","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5511270","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5511925","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5512194","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5512287","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5512444","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5512775","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5513592","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5514218","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5514484","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5514574","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5514731","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5515061","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5515841","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5516456","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5516716","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5516816","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5516973","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5517297","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5518067","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5518673","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5518929","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5519019","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5519173","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5519494","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5520254","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5520863","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5521117","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5521206","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5521360","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5521684","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5522477","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5523166","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5523859","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5524462","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5524728","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5524818","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5524975","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5525321","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5526110","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5526720","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5526992","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5527079","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5527236","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5527554","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5528330","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5528942","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5529202","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5529292","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5529446","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5529763","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5530533","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5531143","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5531406","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5531492","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5531646","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5531973","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5533163","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:28,5533840","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator","SUCCESS","CreationTime: 2020. 01. 09. 4:53:33, LastAccessTime: 2021. 04. 14. 15:44:50, LastWriteTime: 2021. 04. 14. 15:44:50, ChangeTime: 2021. 04. 14. 15:44:50, AllocationSize: 20 480, EndOfFile: 20 480, FileAttributes: DNCI" "19:13:28,5534501","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:28,5535110","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming","SUCCESS","CreationTime: 2020. 01. 09. 4:53:34, LastAccessTime: 2021. 04. 13. 16:48:14, LastWriteTime: 2021. 04. 13. 16:48:14, ChangeTime: 2021. 04. 13. 16:48:14, AllocationSize: 12 288, EndOfFile: 12 288, FileAttributes: DANCI" "19:13:28,5535771","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat","SUCCESS","CreationTime: 2021. 04. 12. 10:49:55, LastAccessTime: 2021. 04. 12. 10:49:55, LastWriteTime: 2021. 04. 12. 10:49:55, ChangeTime: 2021. 04. 12. 10:49:55, AllocationSize: 0, EndOfFile: 0, FileAttributes: DNCI" "19:13:28,5536460","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154","SUCCESS","CreationTime: 2021. 04. 12. 10:49:55, LastAccessTime: 2021. 04. 14. 19:11:46, LastWriteTime: 2021. 04. 14. 19:11:46, ChangeTime: 2021. 04. 14. 19:11:46, AllocationSize: 0, EndOfFile: 0, FileAttributes: DNCI" "19:13:28,5537301","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5537916","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5538189","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5538282","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5538442","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5538779","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5539571","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5540184","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5540447","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5540537","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5540694","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5541018","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5541823","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5542439","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5542698","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5542788","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5542939","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5543263","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5544029","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5544636","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5544892","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5544982","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5545136","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5545457","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5546217","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5546829","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5547089","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5547176","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5547330","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5547676","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5548446","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5549055","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5549309","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5549398","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5549552","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5549870","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5550640","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5551326","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5552022","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5552660","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5552926","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5553016","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5553173","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5553497","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5554261","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5554867","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5555127","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5555216","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5555370","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5555691","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5556496","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5557125","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5557394","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5557484","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5557641","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5557962","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5558725","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5559334","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5559594","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5559681","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5559835","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5560149","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5561451","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten" "19:13:28,5563074","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5563709","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5563979","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5564068","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5564229","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5564559","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5565339","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5565974","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5566233","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5566323","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5566477","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5566804","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5567606","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5568219","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5568482","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5568568","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5568722","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5569059","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5569835","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5570444","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5570701","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5570791","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5570942","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5571259","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5572035","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5572648","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5572901","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5572988","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5573142","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5573459","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5574258","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5574864","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5575114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5575204","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5575355","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5575666","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5576436","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5577148","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5577834","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5578447","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5578706","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5578793","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5578947","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5579261","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5580021","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5580631","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5580887","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5580974","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5581128","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5581449","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5582234","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5582844","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5583104","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5583190","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5583344","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5583662","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5584422","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5585028","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5585285","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5585374","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5585525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5585836","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5586949","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:28,5587578","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator","SUCCESS","CreationTime: 2020. 01. 09. 4:53:33, LastAccessTime: 2021. 04. 14. 15:44:50, LastWriteTime: 2021. 04. 14. 15:44:50, ChangeTime: 2021. 04. 14. 15:44:50, AllocationSize: 20 480, EndOfFile: 20 480, FileAttributes: DNCI" "19:13:28,5588219","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:28,5588825","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming","SUCCESS","CreationTime: 2020. 01. 09. 4:53:34, LastAccessTime: 2021. 04. 13. 16:48:14, LastWriteTime: 2021. 04. 13. 16:48:14, ChangeTime: 2021. 04. 13. 16:48:14, AllocationSize: 12 288, EndOfFile: 12 288, FileAttributes: DANCI" "19:13:28,5589473","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat","SUCCESS","CreationTime: 2021. 04. 12. 10:49:55, LastAccessTime: 2021. 04. 12. 10:49:55, LastWriteTime: 2021. 04. 12. 10:49:55, ChangeTime: 2021. 04. 12. 10:49:55, AllocationSize: 0, EndOfFile: 0, FileAttributes: DNCI" "19:13:28,5590099","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154","SUCCESS","CreationTime: 2021. 04. 12. 10:49:55, LastAccessTime: 2021. 04. 14. 19:11:46, LastWriteTime: 2021. 04. 14. 19:11:46, ChangeTime: 2021. 04. 14. 19:11:46, AllocationSize: 0, EndOfFile: 0, FileAttributes: DNCI" "19:13:28,5590872","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5591109","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","CreationTime: 2021. 04. 14. 19:11:46, LastAccessTime: 2021. 04. 14. 19:11:46, LastWriteTime: 2021. 04. 14. 19:11:46, ChangeTime: 2021. 04. 14. 19:11:46, FileAttributes: ANCI" "19:13:28,5591247","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","" "19:13:28,5592052","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5592350","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Offset: 0, Length: 88, Priority: Normal" "19:13:28,5592610","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","END OF FILE","Offset: 88, Length: 4 096" "19:13:28,5592732","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","" "19:13:28,5593364","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5593553","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,5605211","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Offset: 0, Length: 4 563 888, Priority: Normal" "19:13:28,5618560","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","" "19:13:28,5620148","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 69 632, EndOfFile: 68 264, FileAttributes: A" "19:13:28,5620885","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5621286","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5621543","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5622082","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Image Base: 0x71fe0000, Image Size: 0x13000" "19:13:28,5622835","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","" "19:13:28,5623826","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5624112","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cryptsp.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5624227","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Information: Owner" "19:13:28,5624320","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","" "19:13:28,5625193","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5625276","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5625446","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","Desired Access: Read" "19:13:28,5625651","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5625741","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,5625840","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,5625933","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,5626001","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,5626100","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","" "19:13:28,5626196","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5626254","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5626376","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,5626492","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5626569","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5626646","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,5626713","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,5626793","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,5626860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,5627681","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:11:35, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:35, AllocationSize: 188 416, EndOfFile: 184 984, FileAttributes: A" "19:13:28,5628339","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5628637","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5628826","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5629173","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Image Base: 0x70790000, Image Size: 0x2f000" "19:13:28,5630244","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","" "19:13:28,5631088","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5631363","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\rsaenh.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5631466","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Information: Owner" "19:13:28,5631556","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","" "19:13:28,5632739","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5633390","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5633679","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5633785","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5633961","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5634369","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5635174","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5635802","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5636068","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5636158","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5636315","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5636627","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5637534","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5638169","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5638442","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5638532","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5638689","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5639010","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5639786","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5640401","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5640658","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5640745","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5640902","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5641203","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5641979","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5642595","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5642858","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5642945","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5643102","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5643413","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5644180","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5644786","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5645036","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5645123","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5645277","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5645575","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5646354","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5647085","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5647781","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5648397","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5648663","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5648753","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5648926","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5649241","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5650216","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5651220","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5651566","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5651678","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5651906","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5652368","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5653436","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5654154","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5654478","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5654594","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5654773","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5655104","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5655995","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5656688","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5657012","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5657108","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5657278","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5657596","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5658410","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5658507","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Policies\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,5658641","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5658718","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems","NAME NOT FOUND","Length: 144" "19:13:28,5658789","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds","NAME NOT FOUND","Length: 144" "19:13:28,5658853","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds","NAME NOT FOUND","Length: 144" "19:13:28,5658936","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Cryptography","SUCCESS","" "19:13:28,5659113","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5659238","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,5659360","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5659456","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,5659542","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,5659619","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,5659680","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,5659815","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,5659924","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5659988","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5660110","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,5660556","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","" "19:13:28,5660851","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:28,5660992","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:28,5661149","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:28,5661246","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:28,5661345","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:28,5661464","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:28,5662522","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5663202","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5663500","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5663603","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5663770","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5664119","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5664947","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5665585","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5665858","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5665967","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5666127","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5666438","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5667269","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5667901","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5668170","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5668260","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5668417","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5668722","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5669495","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5670117","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5670377","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5670466","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5670620","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5670925","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5671698","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5672381","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5672644","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5672734","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5672888","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5673189","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5673956","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5674562","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5674816","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5674905","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5675056","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5675354","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5676130","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5676833","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5677526","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5678135","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5678398","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5678488","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5678645","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5678946","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5679713","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5680322","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5680582","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5680672","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5680826","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5681124","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5681916","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5682539","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5682802","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5682891","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5683049","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5683360","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5684139","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5684755","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5685018","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5685108","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5685262","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5685560","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5831683","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5832402","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5832754","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5832867","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5833043","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5833450","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5834249","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5834874","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5835141","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5835230","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5835384","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5835712","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5836529","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5837171","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5837453","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5837543","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5837697","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5838021","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5838790","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5839403","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5839660","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5839746","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5839897","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5840211","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5840978","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5841600","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5841873","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5841959","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5842120","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5842440","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5843204","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5843813","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5844066","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5844153","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5844304","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5844615","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5845394","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5846180","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5846886","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5847505","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5847771","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5847861","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5848018","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5848358","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5849134","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5849747","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5850006","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5850093","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5850250","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5850561","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5851344","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5851976","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5852245","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5852332","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5852489","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5852806","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5853576","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5854185","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5854442","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5854529","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5854683","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5855006","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5856216","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 0, Length: 43, Priority: Normal" "19:13:28,5857489","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5857710","EasyAntiCheat_launcher.exe","6076","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\EasyAntiCheat_x86.dll.debug","NO SUCH FILE","FileInformationClass: FileBothDirectoryInformation, Filter: EasyAntiCheat_x86.dll.debug" "19:13:28,5857858","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat","SUCCESS","" "19:13:28,5858448","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 5004" "19:13:28,5859590","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 443, Length: 40" "19:13:28,5860568","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\secur32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 24 576, EndOfFile: 23 040, FileAttributes: A" "19:13:28,5861299","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\secur32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5861620","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\secur32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5861864","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\secur32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5862277","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\secur32.dll","SUCCESS","Image Base: 0x73170000, Image Size: 0xa000" "19:13:28,5863188","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\secur32.dll","SUCCESS","" "19:13:28,5864096","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\secur32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5864401","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\secur32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5864516","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\secur32.dll","SUCCESS","Information: Owner" "19:13:28,5864612","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\secur32.dll","SUCCESS","" "19:13:28,5866511","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5867547","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5867919","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5868060","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5868236","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5868708","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5869757","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5870469","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5870780","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5870882","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5871056","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5871386","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5871922","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5872050","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5872258","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\Compatibility\EasyAntiCheat_launcher.exe","NAME NOT FOUND","Desired Access: Read" "19:13:28,5872290","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5873221","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5873480","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\rpcss.dll","NAME NOT FOUND","" "19:13:28,5873525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5873621","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5873782","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5874186","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5875132","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5875867","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5876171","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5876274","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5876444","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5876813","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5877663","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5877724","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5877852","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5878041","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\Compatibility\EasyAntiCheat_launcher.exe","NAME NOT FOUND","Desired Access: Read" "19:13:28,5878307","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5878580","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5878715","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5878933","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5879285","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5880161","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5880828","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5881114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5881210","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5881367","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5881701","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5881992","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:10, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:10, ChangeTime: 2020. 01. 09. 4:43:38, AllocationSize: 483 328, EndOfFile: 480 912, FileAttributes: A" "19:13:28,5882660","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5883096","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5883388","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\TextInputFramework.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5883442","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5883686","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5884173","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5884199","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","Image Base: 0x72c60000, Image Size: 0x77000" "19:13:28,5884850","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5885142","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5885190","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","" "19:13:28,5885235","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5885411","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5885748","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5885909","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:20, AllocationSize: 569 344, EndOfFile: 566 664, FileAttributes: A" "19:13:28,5885957","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:10, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:10, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 2 314 240, EndOfFile: 2 313 472, FileAttributes: A" "19:13:28,5886935","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5887147","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5887195","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5887451","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\CoreUIComponents.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5887464","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\CoreMessaging.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5887656","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5887669","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5887701","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5888086","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","Image Base: 0x72990000, Image Size: 0x234000" "19:13:28,5888099","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","Image Base: 0x72bd0000, Image Size: 0x8c000" "19:13:28,5888115","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5888211","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5888410","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5888830","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5889042","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","" "19:13:28,5889469","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","" "19:13:28,5889818","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5890126","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 155 648, EndOfFile: 152 440, FileAttributes: A" "19:13:28,5891063","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:44, AllocationSize: 835 584, EndOfFile: 832 648, FileAttributes: A" "19:13:28,5891143","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5891156","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:44, AllocationSize: 835 584, EndOfFile: 832 648, FileAttributes: A" "19:13:28,5891566","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5891633","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5891678","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5891996","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ntmarta.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5892054","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5892182","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5892329","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5892439","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5892515","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","Image Base: 0x72960000, Image Size: 0x28000" "19:13:28,5892730","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5892939","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5892945","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5893202","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","" "19:13:28,5893263","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Image Base: 0x72890000, Image Size: 0xcb000" "19:13:28,5893391","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\WinTypes.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5893590","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5893940","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","" "19:13:28,5893962","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Image Base: 0x7470000, Image Size: 0xcb000" "19:13:28,5894023","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5894138","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:44, AllocationSize: 835 584, EndOfFile: 832 648, FileAttributes: A" "19:13:28,5894235","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","" "19:13:28,5894716","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5895014","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5895107","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5895267","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5895617","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5896621","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5897028","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ntmarta.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5897188","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","Information: Owner" "19:13:28,5897336","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","" "19:13:28,5898503","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5898750","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\CoreMessaging.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5898885","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","Information: Owner" "19:13:28,5899010","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","" "19:13:28,5900223","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5900540","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\WinTypes.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5900672","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Information: Owner" "19:13:28,5900819","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","" "19:13:28,5901906","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5902137","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\CoreUIComponents.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5902262","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","Information: Owner" "19:13:28,5902532","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","" "19:13:28,5903853","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5904123","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\TextInputFramework.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5904270","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","Information: Owner" "19:13:28,5904408","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","" "19:13:28,5905306","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5905380","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5905495","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","REPARSE","Desired Access: All Access" "19:13:28,5905608","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Desired Access: All Access" "19:13:28,5905745","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5905822","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 2.0" "19:13:28,5905829","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\4e7add1a-6945-435a-82b6-612688ba9f57","NAME NOT FOUND","Length: 524" "19:13:28,5905909","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 2.0" "19:13:28,5906018","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5906089","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","Desired Access: Read" "19:13:28,5906294","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5906364","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\26797D1D-0AA2F79D","NAME NOT FOUND","Desired Access: Read" "19:13:28,5906470","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5906534","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\26797D1D","NAME NOT FOUND","Desired Access: Read" "19:13:28,5906634","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","" "19:13:28,5906727","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout","SUCCESS","Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll" "19:13:28,5906871","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout","SUCCESS","Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll" "19:13:28,5907048","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5907166","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,5907202","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,5907323","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 10" "19:13:28,5907577","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 10" "19:13:28,5907699","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5907772","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000A","NAME NOT FOUND","Desired Access: Read" "19:13:28,5907859","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1013" "19:13:28,5907926","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries","SUCCESS","Type: REG_DWORD, Length: 4, Data: 12" "19:13:28,5907994","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\3720dda7-caea-4af3-a138-375aafc3f1d6","NAME NOT FOUND","Length: 524" "19:13:28,5908013","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5908084","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,5908234","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5908305","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001","SUCCESS","Desired Access: Read" "19:13:28,5908446","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5908513","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5908642","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001","SUCCESS","" "19:13:28,5908744","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5908815","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002","SUCCESS","Desired Access: Read" "19:13:28,5908934","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5908998","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5909087","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002","SUCCESS","" "19:13:28,5909136","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,5909174","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5909241","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003","SUCCESS","Desired Access: Read" "19:13:28,5909357","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5909415","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5909498","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003","SUCCESS","" "19:13:28,5909591","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5909668","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\ebadf775-48aa-4bf3-8f8e-ec68d113c98e","NAME NOT FOUND","Length: 524" "19:13:28,5909729","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004","SUCCESS","Desired Access: Read" "19:13:28,5909902","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5909969","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5910072","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004","SUCCESS","" "19:13:28,5910194","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5910268","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005","SUCCESS","Desired Access: Read" "19:13:28,5910390","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5910495","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5910604","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005","SUCCESS","" "19:13:28,5910698","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5910768","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006","SUCCESS","Desired Access: Read" "19:13:28,5910887","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5910954","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5911041","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006","SUCCESS","" "19:13:28,5911130","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5911233","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007","SUCCESS","Desired Access: Read" "19:13:28,5911422","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5911486","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5911576","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007","SUCCESS","" "19:13:28,5911666","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5911733","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008","SUCCESS","Desired Access: Read" "19:13:28,5911865","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5911923","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5912003","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008","SUCCESS","" "19:13:28,5912099","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5912131","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5912208","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009","SUCCESS","Desired Access: Read" "19:13:28,5912263","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5912333","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5912401","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5912445","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\","SUCCESS","Desired Access: Read" "19:13:28,5912484","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009","SUCCESS","" "19:13:28,5912580","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5912641","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5912648","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010","SUCCESS","Desired Access: Read" "19:13:28,5912753","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF\EnableAnchorContext","NAME NOT FOUND","Length: 144" "19:13:28,5912769","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5912846","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5912930","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010","SUCCESS","" "19:13:28,5912991","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\CTF","SUCCESS","" "19:13:28,5913016","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5913084","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011","SUCCESS","Desired Access: Read" "19:13:28,5913199","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5913267","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5913347","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011","SUCCESS","" "19:13:28,5913459","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5913523","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012","SUCCESS","Desired Access: Read" "19:13:28,5913642","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:28,5913712","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:28,5913796","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012","SUCCESS","" "19:13:28,5913863","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries","SUCCESS","" "19:13:28,5914059","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5914129","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,5914222","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 20" "19:13:28,5914370","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 20" "19:13:28,5914469","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5914533","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\00000014","NAME NOT FOUND","Desired Access: Read" "19:13:28,5914607","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries","SUCCESS","Type: REG_DWORD, Length: 4, Data: 6" "19:13:28,5914710","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5914774","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,5915034","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5915114","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001","SUCCESS","Desired Access: Read" "19:13:28,5915255","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll" "19:13:28,5915329","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll" "19:13:28,5915512","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:28,5915598","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:28,5915682","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:28,5915746","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:28,5915823","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: A2 CB 4A 96 BC B2 EB 40 8C 6A A6 DB 40 16 1C AE" "19:13:28,5915903","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:28,5916002","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 37" "19:13:28,5916127","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5916195","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5916262","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5916346","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5916435","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5916522","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001","SUCCESS","" "19:13:28,5916634","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5916708","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002","SUCCESS","Desired Access: Read" "19:13:28,5916862","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:28,5916939","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:28,5917022","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:28,5917086","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:28,5917167","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:28,5917228","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:28,5917295","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: CE 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D" "19:13:28,5917369","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:28,5917433","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 39" "19:13:28,5917500","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5917564","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5917628","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5917702","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5917805","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5917965","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002","SUCCESS","" "19:13:28,5918119","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5918212","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003","SUCCESS","Desired Access: Read" "19:13:28,5918369","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:28,5918510","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:28,5918542","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5918677","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:28,5918754","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:28,5918834","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:28,5918899","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:28,5918969","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: CD 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D" "19:13:28,5919043","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:28,5919113","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 38" "19:13:28,5919181","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5919248","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5919312","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5919360","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5919402","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5919479","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5919569","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003","SUCCESS","" "19:13:28,5919684","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5919777","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004","SUCCESS","Desired Access: Read" "19:13:28,5919845","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5919976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll" "19:13:28,5920002","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5920047","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll" "19:13:28,5920127","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:28,5920194","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:28,5920268","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5920271","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:28,5920335","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:28,5920406","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: 3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83" "19:13:28,5920480","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:28,5920553","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 15" "19:13:28,5920624","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5920688","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5920739","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5920752","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5920826","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5920900","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5920983","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004","SUCCESS","" "19:13:28,5921092","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5921166","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005","SUCCESS","Desired Access: Read" "19:13:28,5921291","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll" "19:13:28,5921355","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll" "19:13:28,5921435","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:28,5921500","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:28,5921573","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:28,5921634","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:28,5921705","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: 40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B" "19:13:28,5921779","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:28,5921820","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5921856","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 12" "19:13:28,5921920","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5921984","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5922048","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5922119","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5922192","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5922269","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005","SUCCESS","" "19:13:28,5922369","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,5922439","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006","SUCCESS","Desired Access: Read" "19:13:28,5922561","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll" "19:13:28,5922625","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll" "19:13:28,5922702","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:28,5922709","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5922770","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:28,5922843","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:28,5922908","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:28,5922975","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: EE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC" "19:13:28,5923036","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5923049","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:28,5923171","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5923174","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 32" "19:13:28,5923315","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,5923389","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5923408","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5923459","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,5923591","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5923751","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:28,5923847","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006","SUCCESS","" "19:13:28,5923921","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries","SUCCESS","" "19:13:28,5923966","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5923998","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","" "19:13:28,5924139","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,5924197","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,5924306","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock2\Parameters","REPARSE","Desired Access: Query Value" "19:13:28,5924405","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock2\Parameters","SUCCESS","Desired Access: Query Value" "19:13:28,5924511","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,5924575","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets","NAME NOT FOUND","Length: 144" "19:13:28,5924649","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32SpinCount","NAME NOT FOUND","Length: 144" "19:13:28,5924723","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","" "19:13:28,5925031","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5925768","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5925990","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 43, Length: 172" "19:13:28,5926185","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5926333","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5926574","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5926997","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5927327","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 168" "19:13:28,5927577","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 215, Length: 46" "19:13:28,5927924","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5928671","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5928703","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 483, Length: 31" "19:13:28,5929037","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5929056","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 261, Length: 46" "19:13:28,5929171","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5929399","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5929797","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 514, Length: 31" "19:13:28,5929822","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5930143","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 307, Length: 46" "19:13:28,5930743","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5931032","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 545, Length: 31" "19:13:28,5931384","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 353, Length: 46" "19:13:28,5931429","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5931753","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5931891","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5932119","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 576, Length: 31" "19:13:28,5932132","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5932430","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 399, Length: 46" "19:13:28,5932536","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5933110","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 607, Length: 31" "19:13:28,5933392","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 445, Length: 46" "19:13:28,5933418","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5934088","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 638, Length: 31" "19:13:28,5934143","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5934374","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 491, Length: 46" "19:13:28,5934451","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5934579","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5934803","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5935150","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 669, Length: 31" "19:13:28,5935198","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5935435","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 537, Length: 46" "19:13:28,5936109","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 700, Length: 31" "19:13:28,5936218","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5936381","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 583, Length: 46" "19:13:28,5937013","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 731, Length: 31" "19:13:28,5937251","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5937279","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 629, Length: 46" "19:13:28,5937892","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 762, Length: 31" "19:13:28,5938152","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5938158","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 675, Length: 46" "19:13:28,5938764","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 793, Length: 31" "19:13:28,5938883","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5939037","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 721, Length: 46" "19:13:28,5939274","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5939483","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5939643","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 824, Length: 31" "19:13:28,5939826","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5939916","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 767, Length: 46" "19:13:28,5940304","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5940532","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 855, Length: 31" "19:13:28,5940801","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 813, Length: 46" "19:13:28,5941407","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 886, Length: 31" "19:13:28,5941523","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5941677","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 859, Length: 46" "19:13:28,5942289","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 917, Length: 31" "19:13:28,5942347","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5942565","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 905, Length: 46" "19:13:28,5942703","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5942841","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5943075","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5943168","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 948, Length: 31" "19:13:28,5943444","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 951, Length: 46" "19:13:28,5943479","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5944047","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 979, Length: 31" "19:13:28,5944313","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 997, Length: 46" "19:13:28,5944448","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5944916","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 010, Length: 31" "19:13:28,5945156","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5945179","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 043, Length: 46" "19:13:28,5945500","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5945631","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5945772","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 041, Length: 31" "19:13:28,5945865","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5946035","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 089, Length: 46" "19:13:28,5946269","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5947199","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5947828","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 072, Length: 31" "19:13:28,5947886","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5948203","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5948223","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 135, Length: 46" "19:13:28,5948332","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5948553","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5948944","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5949034","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 103, Length: 31" "19:13:28,5949371","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 181, Length: 46" "19:13:28,5950304","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5950862","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 134, Length: 31" "19:13:28,5950974","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5951228","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 227, Length: 46" "19:13:28,5951266","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5951366","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5951529","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5951949","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5952042","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 165, Length: 31" "19:13:28,5952344","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 273, Length: 46" "19:13:28,5952787","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5953033","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 196, Length: 31" "19:13:28,5953316","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 319, Length: 46" "19:13:28,5953592","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5953896","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5953970","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 227, Length: 31" "19:13:28,5953999","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5954159","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5954348","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 365, Length: 46" "19:13:28,5954528","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5955192","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 258, Length: 31" "19:13:28,5955429","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5955692","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 411, Length: 46" "19:13:28,5956096","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5956385","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5956430","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 289, Length: 31" "19:13:28,5956481","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5956635","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5956731","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 457, Length: 46" "19:13:28,5957017","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5957915","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 320, Length: 31" "19:13:28,5958287","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5958396","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 503, Length: 46" "19:13:28,5959041","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 351, Length: 31" "19:13:28,5959105","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5959387","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5959483","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 549, Length: 46" "19:13:28,5959512","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5959743","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5960218","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5960606","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 382, Length: 31" "19:13:28,5961113","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 595, Length: 46" "19:13:28,5961613","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5961882","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 413, Length: 31" "19:13:28,5962373","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5962707","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5962809","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5963008","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5963505","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5964602","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5965282","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5965571","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5965664","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5965920","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5966366","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5967469","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5968547","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,5969894","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5970667","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5971062","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5971164","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5971363","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5971988","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5972880","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,5973752","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5974057","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5974160","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5974365","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5974715","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,5975837","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5976700","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5977046","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5977149","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5977319","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5977697","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5978740","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,5979442","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5979747","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5979846","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5980007","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5980363","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,5982111","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5982255","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:12, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 335 872, EndOfFile: 334 744, FileAttributes: A" "19:13:28,5983031","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5983047","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5983403","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\mswsock.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,5983493","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5983608","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5983647","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5983900","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5984032","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","Image Base: 0x72ff0000, Image Size: 0x55000" "19:13:28,5984555","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5985523","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,5985693","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","" "19:13:28,5986412","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5986630","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5986774","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5986934","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5986970","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\mswsock.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,5987127","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","Information: Owner" "19:13:28,5987217","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5987233","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","" "19:13:28,5987672","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,5988663","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5989372","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5989693","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5989821","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5990049","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5990472","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5991370","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,5992104","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5992406","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5992531","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5992756","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5993172","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,5994048","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5994722","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5995030","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5995151","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5995379","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5995790","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5996659","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,5997345","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,5997640","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,5997765","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,5997987","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,5998384","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,5999270","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6000042","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6000790","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6001460","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6001806","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6001935","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6002159","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6002592","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6003631","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6004315","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6004626","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6004751","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6004975","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6005379","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6006271","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6007140","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6007458","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6007586","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6007817","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6008224","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6009116","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6009985","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6010331","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6010473","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6010710","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6011152","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6011993","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6012108","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6012301","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Rpc","REPARSE","Desired Access: Read" "19:13:28,6012371","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6012593","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","Desired Access: Read" "19:13:28,6012746","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6012862","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize","NAME NOT FOUND","Length: 144" "19:13:28,6013013","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","" "19:13:28,6013019","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6013314","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6013407","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","REPARSE","Desired Access: Read" "19:13:28,6013414","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6013558","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","Desired Access: Read" "19:13:28,6013593","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6013702","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6013795","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName","SUCCESS","Type: REG_SZ, Length: 18, Data: DEVLA-PC" "19:13:28,6013940","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","" "19:13:28,6013965","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6014071","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:28,6014199","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6014286","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\OOBEInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6014395","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,6014514","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:28,6014623","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6014709","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6014783","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6014815","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,6014963","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6015069","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EasyAntiCheat_launcher.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,6015415","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6015588","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6015681","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6015742","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6015841","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6015880","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\Rpc","REPARSE","Desired Access: Read" "19:13:28,6015999","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6016015","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc","NAME NOT FOUND","Desired Access: Read" "19:13:28,6016367","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6016493","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6016586","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6016720","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Rpc","REPARSE","Desired Access: Query Value" "19:13:28,6016849","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","Desired Access: Query Value" "19:13:28,6016967","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6017060","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow","NAME NOT FOUND","Length: 144" "19:13:28,6017176","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","" "19:13:28,6017221","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6017259","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 641, Length: 46" "19:13:28,6017926","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6018196","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6018285","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6018324","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 444, Length: 31" "19:13:28,6018478","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6018815","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6019607","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6020242","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6020508","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6020595","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6020749","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6021117","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6022054","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6022301","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\user32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 531 904, EndOfFile: 1 528 904, FileAttributes: A" "19:13:28,6022689","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6022949","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6023039","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6023189","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6023513","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6024286","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6024892","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6025146","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6025236","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6025386","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6025704","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6026490","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6027205","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6027898","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6028510","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6028773","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6028863","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6029017","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6029338","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6030111","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6030736","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6030996","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6031082","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6031236","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6031554","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6032343","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6032959","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6033222","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6033311","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6033462","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6033789","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6034566","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6035178","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6035438","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6035525","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6035675","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6036006","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6037410","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6037436","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:09:43, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 598 016, EndOfFile: 597 160, FileAttributes: A" "19:13:28,6038225","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6038247","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6038510","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dnsapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6038597","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6038745","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6038754","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6039011","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6039168","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","Image Base: 0x6dfb0000, Image Size: 0x94000" "19:13:28,6039521","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6040185","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\nsi.dll","SUCCESS","Image Base: 0x74000000, Image Size: 0x7000" "19:13:28,6040486","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6040714","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","" "19:13:28,6041224","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6041593","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6041724","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6041952","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\nsi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6041990","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6042109","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 687, Length: 46" "19:13:28,6042241","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\nsi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,6042359","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\nsi.dll","SUCCESS","Information: Owner" "19:13:28,6042455","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\nsi.dll","SUCCESS","" "19:13:28,6042513","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6042988","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 475, Length: 31" "19:13:28,6043459","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6043690","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6043726","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dnsapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,6043825","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","Information: Owner" "19:13:28,6043915","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","" "19:13:28,6044444","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6044787","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6044887","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\9ca335ed-c0a6-4b4d-b084-9c9b5143aff0","NAME NOT FOUND","Length: 524" "19:13:28,6044925","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6045156","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6045621","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6046185","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6046253","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6046381","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6046490","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6046564","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6046625","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6046708","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6046763","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6046872","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6046955","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6047074","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6047148","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6047231","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6047305","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6047343","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6047440","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6047539","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6047629","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6047658","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6047796","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6047837","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6047940","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6048010","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6048026","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6048071","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6048177","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6048245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6048382","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6048469","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6048482","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6048626","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6048706","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6048761","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6048854","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6048931","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6049018","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6049088","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6049139","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6049245","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6049332","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6049422","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6049483","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6049547","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6049556","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6049633","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6049697","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6049755","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6049887","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6049973","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6050076","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6050163","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6050262","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6050281","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6050381","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6050438","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6050531","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6050579","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6050608","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6050695","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6050721","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6050769","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6050823","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6050935","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6051019","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6051025","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6051128","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6051195","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6051320","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6051375","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6051494","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\System\DNSClient","REPARSE","Desired Access: Query Value" "19:13:28,6051574","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\System\DNSClient","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,6051622","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6051667","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6051753","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6051875","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6051943","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6052003","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6052238","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6052324","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6052427","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6052507","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6052597","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6052667","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6052671","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6052725","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6052809","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6052882","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6052959","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6053027","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6053078","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6053171","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6053254","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6053347","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6053415","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6053447","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6053488","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6053565","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6053626","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6053684","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6053758","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6053787","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6053812","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6053905","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6053928","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6054008","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6054095","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6054165","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6054172","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6054223","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6054310","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6054386","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6054483","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6054553","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6054608","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6054611","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6054704","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6054781","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6054861","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6054919","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6054993","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6055044","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6055140","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\System\DNSClient","REPARSE","Desired Access: Query Value" "19:13:28,6055214","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\System\DNSClient","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,6055291","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6055355","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6055432","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6055493","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6055548","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6055554","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6055641","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6055711","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6055804","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6055884","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6055971","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6056074","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6056131","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6056215","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6056298","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6056353","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6056378","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6056449","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6056500","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6056596","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6056670","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6056747","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6056805","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6056994","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6057077","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6057135","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6057145","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6057212","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6057315","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6057369","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6057462","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6057539","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6057623","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6057693","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6057744","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6057831","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6057902","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6057959","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6057979","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6058046","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6058097","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6058190","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6058264","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6058328","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6058344","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6058434","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6058476","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6058485","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6058569","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","REPARSE","Desired Access: Query Value" "19:13:28,6058646","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,6058707","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6058768","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6058870","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6058989","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6059079","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:28,6059149","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:28,6059178","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6059207","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6059274","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:28,6059329","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:28,6059406","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:28,6059460","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:28,6059515","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:28,6059576","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:28,6059627","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:28,6059678","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:28,6059736","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:28,6059791","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:28,6059842","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:28,6059897","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:28,6059948","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:28,6060002","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:28,6060054","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:28,6060105","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:28,6060160","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6060214","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6060265","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:28,6060285","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6060320","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:28,6060371","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:28,6060426","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:28,6060480","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns","NAME NOT FOUND","Length: 144" "19:13:28,6060532","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseEdns","NAME NOT FOUND","Length: 144" "19:13:28,6060586","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:28,6060637","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:28,6060692","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:28,6060743","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:28,6060795","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6060846","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6060900","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:28,6060952","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:28,6061003","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:28,6061054","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:28,6061086","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6061109","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:28,6061163","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:28,6061218","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartNameResolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6061276","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:28,6061327","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:28,6061382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:28,6061407","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6061436","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:28,6061494","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:28,6061535","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6061548","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:28,6061616","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:28,6061673","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:28,6061728","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:28,6061766","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6061782","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:28,6061847","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:28,6061901","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:28,6061956","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:28,6062010","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:28,6062081","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:28,6062154","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:28,6062212","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6062219","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6062273","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6062344","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:28,6062408","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:28,6062472","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:28,6062527","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6062578","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6062632","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6062697","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:28,6062748","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:28,6062802","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableReverseAddressRegistrations","NAME NOT FOUND","Length: 144" "19:13:28,6062863","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:28,6062915","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:28,6062969","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableWanDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:28,6063027","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:28,6063078","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:28,6063133","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationTTL","NAME NOT FOUND","Length: 144" "19:13:28,6063194","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6063210","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:28,6063271","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:28,6063325","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:28,6063386","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6063437","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6063492","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:28,6063550","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:28,6063601","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:28,6063652","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:28,6063710","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:28,6063771","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:28,6063829","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:28,6063883","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:28,6063902","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6063938","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:28,6063989","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:28,6064044","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:28,6064098","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:28,6064149","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6064204","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6064233","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6064258","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6064313","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6064364","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:28,6064368","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6064419","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:28,6064473","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:28,6064525","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:28,6064579","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:28,6064608","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6064634","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:28,6064688","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:28,6064743","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:28,6064794","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6064845","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6064916","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6064967","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6065022","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6065054","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6065076","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6065128","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:28,6065182","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:28,6065237","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsTest","NAME NOT FOUND","Length: 144" "19:13:28,6065291","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseCompartments","NAME NOT FOUND","Length: 144" "19:13:28,6065346","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\CacheAllCompartments","NAME NOT FOUND","Length: 144" "19:13:28,6065397","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseNewRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6065448","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6065503","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistrationOnly","NAME NOT FOUND","Length: 144" "19:13:28,6065554","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\NewDhcpSrvRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6065609","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessPreferLocal","NAME NOT FOUND","Length: 144" "19:13:28,6065660","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:28,6065711","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:28,6065766","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:28,6065817","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:28,6065869","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ShortnameProxyDefault","NAME NOT FOUND","Length: 144" "19:13:28,6065926","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength","NAME NOT FOUND","Length: 144" "19:13:28,6065958","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6065984","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval","NAME NOT FOUND","Length: 144" "19:13:28,6066064","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6066122","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6066215","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Query Value" "19:13:28,6066301","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6066359","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6066443","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,6066510","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6066574","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6066635","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6066645","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6066702","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6066776","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6066844","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6066904","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6066997","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6067119","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 733, Length: 46" "19:13:28,6067145","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6067411","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6067854","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6068293","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 506, Length: 31" "19:13:28,6068309","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6068373","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6068476","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:28,6068569","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6068627","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6068710","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,6070628","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6070692","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6070792","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","REPARSE","Desired Access: Query Value" "19:13:28,6070881","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","SUCCESS","Desired Access: Query Value" "19:13:28,6070984","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6071045","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\SQMServiceList\SQMServiceList","SUCCESS","Type: REG_SZ, Length: 54, Data: netprofm,netman,dcomlaunch" "19:13:28,6071144","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","SUCCESS","" "19:13:28,6071385","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6072136","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6072472","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6072607","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6072841","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6073290","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6074185","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6074855","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6075163","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6075192","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6075256","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6075288","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6075381","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:13:28,6075477","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:13:28,6075513","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6075590","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6075644","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6075734","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:13:28,6075827","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:13:28,6075933","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6076446","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6076507","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6076597","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:28,6076687","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6076748","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6076844","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,6076879","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6077556","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6077861","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6077989","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6078229","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6078656","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6079596","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6080260","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6080567","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6080696","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6080917","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6081273","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6081337","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6081344","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6081498","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:28,6081626","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,6081745","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6081841","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6081898","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6081995","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:28,6082075","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6082158","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6082229","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6082283","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6082306","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6082396","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\DnsClient","REPARSE","Desired Access: Read" "19:13:28,6082479","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:28,6082566","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6082636","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6082691","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6082777","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","REPARSE","Desired Access: Query Value" "19:13:28,6082851","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,6082950","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6082983","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6083011","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6083072","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6083136","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:28,6083191","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:28,6083246","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6083287","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6083310","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:28,6083364","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:28,6083412","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6083419","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:28,6083473","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:28,6083528","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:28,6083589","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:28,6083640","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6083643","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:28,6083698","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:28,6083759","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:28,6083810","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:28,6083865","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:28,6083932","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:28,6083986","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:28,6084041","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:28,6084063","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6084095","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:28,6084150","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:28,6084204","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6084259","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6084310","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:28,6084365","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:28,6084416","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:28,6084471","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:28,6084522","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns","NAME NOT FOUND","Length: 144" "19:13:28,6084577","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseEdns","NAME NOT FOUND","Length: 144" "19:13:28,6084631","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:28,6084682","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:28,6084737","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:28,6084791","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:28,6084843","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6084897","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:28,6084929","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6084952","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:28,6085003","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:28,6085058","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:28,6085109","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:28,6085163","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:28,6085215","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:28,6085269","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartNameResolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6085327","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:28,6085378","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:28,6085433","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:28,6085484","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:28,6085539","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:28,6085593","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6085616","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:28,6085680","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:28,6085734","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:28,6085789","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:28,6085840","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:28,6085895","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:28,6085904","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6085975","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:28,6086029","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:28,6086039","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6086103","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:28,6086158","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:28,6086235","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:28,6086283","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6086312","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6086373","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6086427","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:28,6086488","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:28,6086549","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:28,6086610","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6086664","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6086722","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6086735","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6086802","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:28,6086863","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:28,6086921","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableReverseAddressRegistrations","NAME NOT FOUND","Length: 144" "19:13:28,6086985","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:28,6087037","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:28,6087091","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableWanDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:28,6087149","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:28,6087200","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:28,6087258","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationTTL","NAME NOT FOUND","Length: 144" "19:13:28,6087316","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:28,6087367","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:28,6087421","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:28,6087482","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6087537","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6087591","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:28,6087630","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6087649","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:28,6087704","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:28,6087755","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:28,6087813","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:28,6087867","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:28,6087922","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:28,6087976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:28,6088031","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:28,6088082","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:28,6088137","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:28,6088188","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:28,6088242","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6088294","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6088348","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6088400","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6088416","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:28,6088480","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:28,6088534","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:28,6088586","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:28,6088640","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:28,6088695","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:28,6088746","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:28,6088797","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:28,6088852","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:28,6088903","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6088954","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6089009","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6089060","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6089115","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6089153","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6089166","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:28,6089221","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:28,6089272","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:28,6089326","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsTest","NAME NOT FOUND","Length: 144" "19:13:28,6089381","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseCompartments","NAME NOT FOUND","Length: 144" "19:13:28,6089432","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\CacheAllCompartments","NAME NOT FOUND","Length: 144" "19:13:28,6089487","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseNewRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6089538","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6089593","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistrationOnly","NAME NOT FOUND","Length: 144" "19:13:28,6089644","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\NewDhcpSrvRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6089699","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessPreferLocal","NAME NOT FOUND","Length: 144" "19:13:28,6089750","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:28,6089804","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:28,6089817","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6089859","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:28,6089910","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:28,6089965","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ShortnameProxyDefault","NAME NOT FOUND","Length: 144" "19:13:28,6090019","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength","NAME NOT FOUND","Length: 144" "19:13:28,6090077","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval","NAME NOT FOUND","Length: 144" "19:13:28,6090132","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6090167","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6090225","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6090260","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6090321","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Query Value" "19:13:28,6090414","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6090471","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6090484","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6090568","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,6090641","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6090706","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6090786","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6090847","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:28,6090943","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6090972","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6091142","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6091238","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6091376","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\System\DNSClient","REPARSE","Desired Access: Query Value" "19:13:28,6091482","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\System\DNSClient","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,6091584","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6091665","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6091732","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6091799","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:28,6091902","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6091905","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6091963","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6092024","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6092207","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 779, Length: 46" "19:13:28,6092579","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6092880","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6093002","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6093227","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6093246","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 537, Length: 31" "19:13:28,6093627","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6094509","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6095173","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6095484","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6095606","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6095828","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6096222","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6097107","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6097762","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6098063","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6098185","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6098406","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6098794","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6100183","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6100902","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6101094","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","Desired Access: Read" "19:13:28,6101216","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6101286","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6101318","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6101395","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm","NAME NOT FOUND","Length: 20" "19:13:28,6101492","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6101517","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","" "19:13:28,6101893","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6102749","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6103390","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6103663","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6103756","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6103913","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6104253","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6105090","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6105725","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6105995","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6106088","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6106245","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6106575","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6107383","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6108012","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6108275","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6108365","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6108519","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6108856","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6109638","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6110260","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6110523","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6110613","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6110767","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6111097","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6111944","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6112560","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6112820","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6112910","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6113080","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6113400","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6114244","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6114956","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6115652","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6116268","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6116537","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6116627","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6116781","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6117069","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 825, Length: 46" "19:13:28,6117162","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6117842","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 568, Length: 31" "19:13:28,6117955","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6118570","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6118833","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6118920","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6119077","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6119398","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6120180","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6120799","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6121066","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6121155","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6121309","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6121633","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6122429","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6123045","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6123308","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6123394","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6123548","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6123862","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6125171","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6125905","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6126322","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6126460","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6126521","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 21:50:19, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 61 440, EndOfFile: 57 856, FileAttributes: A" "19:13:28,6126698","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6127217","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6127240","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6127490","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6127685","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6128058","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","Image Base: 0x72db0000, Image Size: 0x13000" "19:13:28,6128311","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6128747","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","" "19:13:28,6129023","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6129363","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6129491","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6129719","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6129773","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6130001","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,6130123","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","Information: Owner" "19:13:28,6130171","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6130222","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","" "19:13:28,6131159","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6131861","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6132176","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6132301","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6132538","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6132965","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6133131","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6133205","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6133333","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6133452","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6133596","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6133667","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6133760","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6133856","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6133914","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6133949","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6134013","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6134097","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6134219","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6134273","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6134366","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6134446","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6134581","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6134655","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6134690","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6134738","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6135062","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6135190","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6135418","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6135627","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 21:50:19, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 65 536, EndOfFile: 62 976, FileAttributes: A" "19:13:28,6135848","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6136477","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6136778","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6136788","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6137006","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6137314","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","Image Base: 0x73150000, Image Size: 0x14000" "19:13:28,6137522","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6137849","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6137978","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6137987","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","" "19:13:28,6138205","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6138645","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6139171","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6139507","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dhcpcsvc.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,6139629","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6139645","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","Information: Owner" "19:13:28,6139806","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","" "19:13:28,6140402","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6140713","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6140842","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6141069","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6141509","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6142279","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6142349","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6142471","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read" "19:13:28,6142577","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Desired Access: Read" "19:13:28,6142593","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6142705","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6142946","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6143026","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055b14ee-328a-11ea-a2f1-806e6f6e6963}","SUCCESS","Desired Access: Query Value" "19:13:28,6143138","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\EnableDhcp","NAME NOT FOUND","Length: 144" "19:13:28,6143231","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","" "19:13:28,6143292","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:28,6143385","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6143414","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6143443","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6143539","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read" "19:13:28,6143626","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Desired Access: Read" "19:13:28,6143719","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6143917","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6143991","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","Desired Access: Query Value" "19:13:28,6144091","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\EnableDhcp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6144209","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6144229","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","" "19:13:28,6144341","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6144459","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6144520","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6144633","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6144726","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6144832","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6144953","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpRACoexistenceEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6144966","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6145034","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6145200","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6145255","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6145351","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6145358","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6145447","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6145483","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6145553","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6145643","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6145714","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6145746","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6145839","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6145896","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6146025","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6146121","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6146259","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6146307","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6146333","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6146432","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6146519","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6146576","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6146669","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6146749","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6146842","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6146913","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6146984","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6147051","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6147118","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:28,6147199","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6147237","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6147279","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6147333","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6147426","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6147506","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6147593","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6147686","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Dhcpv6Domain","NAME NOT FOUND","Length: 144" "19:13:28,6147763","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6147846","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6147904","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6147920","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6148020","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6148100","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6148190","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6148228","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6148263","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","NAME NOT FOUND","Length: 144" "19:13:28,6148327","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6148353","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6148401","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6148481","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6148546","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6148635","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6148655","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6148712","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6148799","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6148860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6148924","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6149004","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6149065","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6149139","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6149155","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6149296","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6149354","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6149444","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6149524","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6149607","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6149668","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6149726","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6149790","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6149848","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6149921","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6150075","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6150130","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6150249","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6150310","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6150329","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6150598","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6150659","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6150752","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6150829","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6150938","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6151057","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6151063","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6151233","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6151342","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:28,6151410","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6151464","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6151548","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6151551","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6151647","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:28,6151750","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6151791","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6151814","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6151926","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6152016","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:28,6152131","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6152211","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6152247","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6152285","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6152353","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\Domain","NAME NOT FOUND","Length: 144" "19:13:28,6152414","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:28,6152491","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:28,6152577","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6152635","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6152734","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6152818","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6152946","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6153000","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6153087","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6153167","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6153203","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6153276","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6153331","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6153417","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6153494","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:28,6153587","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6153652","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6153716","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6153780","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6153841","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6153908","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6153918","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:28,6154030","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6154085","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6154174","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6154229","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6154258","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:28,6154344","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6154357","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6154408","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6154469","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:28,6154530","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6154588","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6154614","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:28,6154723","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:28,6154899","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6154957","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6155050","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6155053","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6155130","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6155223","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6155294","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DhcpRACoexistenceEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6155371","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6155518","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6155573","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6155672","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6155749","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6155832","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6155897","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6155970","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6156047","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6156099","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6156185","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6156262","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6156346","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6156407","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6156490","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6156564","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6156618","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6156705","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6156779","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6156872","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6156936","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegistrationEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6156958","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","Desired Access: Read" "19:13:28,6157016","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegisterAdapterName","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6157122","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6157163","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6157189","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:28,6157276","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6157292","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm","NAME NOT FOUND","Length: 20" "19:13:28,6157362","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6157417","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6157423","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","" "19:13:28,6157507","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6157587","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6157667","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6157728","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\NameServer","SUCCESS","Type: REG_SZ, Length: 32, Data: 1.1.1.1,1.1.0.0" "19:13:28,6157792","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\NameServer","SUCCESS","Type: REG_SZ, Length: 32, Data: 1.1.1.1,1.1.0.0" "19:13:28,6157866","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6158979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6159040","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6159142","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:28,6159226","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:28,6159312","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6159373","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6159441","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6159498","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6159556","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:28,6159614","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6159675","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6159739","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6159797","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:28,6159813","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","Desired Access: Read" "19:13:28,6159858","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6159922","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6159983","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6159989","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6160092","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:28,6160140","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm","NAME NOT FOUND","Length: 20" "19:13:28,6160169","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:28,6160265","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","" "19:13:28,6160316","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6160374","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6160467","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\","REPARSE","Desired Access: Read" "19:13:28,6160547","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Desired Access: Read" "19:13:28,6160650","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6160727","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6160733","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","Desired Access: Read" "19:13:28,6160801","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6160874","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6160884","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","" "19:13:28,6160971","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM\DeviceForm","NAME NOT FOUND","Length: 20" "19:13:28,6161083","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\OEM","SUCCESS","" "19:13:28,6161378","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6161439","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6161464","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6161535","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:28,6161567","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6161622","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:28,6161711","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6161724","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Input","REPARSE","Desired Access: Read" "19:13:28,6161769","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6161849","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6161913","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegistrationEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6161949","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Input","SUCCESS","Desired Access: Read" "19:13:28,6161978","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegisterAdapterName","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6162058","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6162122","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:28,6162170","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Input","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6162180","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6162276","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6162321","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Input\ResyncResetTime","NAME NOT FOUND","Length: 144" "19:13:28,6162340","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6162439","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:28,6162465","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Input\MaxResyncAttempts","NAME NOT FOUND","Length: 144" "19:13:28,6162520","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:28,6162587","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Input","SUCCESS","" "19:13:28,6162622","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6162680","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6162770","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\","REPARSE","Desired Access: Read" "19:13:28,6162850","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Desired Access: Read" "19:13:28,6162933","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6163004","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6163068","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","NAME NOT FOUND","Desired Access: Read" "19:13:28,6163148","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","" "19:13:28,6163543","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6163597","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6163690","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:28,6163770","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:28,6163860","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6163918","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6163976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:28,6164030","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:28,6164082","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:28,6164136","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:28,6164197","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:28,6164255","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:28,6164306","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:28,6164357","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:28,6164412","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\Domain","NAME NOT FOUND","Length: 144" "19:13:28,6164463","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:28,6164531","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:28,6164909","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList","NAME NOT FOUND","Length: 144" "19:13:28,6164973","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\SearchList","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6165041","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\SearchList","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:28,6165172","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:28,6165233","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:28,6165297","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:28,6166304","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 21:50:12, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 28 672, EndOfFile: 28 440, FileAttributes: A" "19:13:28,6167048","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6167395","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6167606","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6167985","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","Image Base: 0x6dfa0000, Image Size: 0x8000" "19:13:28,6168613","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","" "19:13:28,6169605","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6169893","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winnsi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,6170002","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","Information: Owner" "19:13:28,6170095","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","" "19:13:28,6171869","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 196" "19:13:28,6172324","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6173094","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6173229","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 1524" "19:13:28,6173463","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6173604","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6173845","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6174261","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6175201","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6175971","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6176288","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6176414","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6176446","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 2664" "19:13:28,6176635","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6177049","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6177969","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6178675","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6178995","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6179005","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6179120","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6179258","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 0, Length: 2, Priority: Normal" "19:13:28,6179348","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6179711","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2, Length: 998" "19:13:28,6179756","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6179884","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 000, Length: 962" "19:13:28,6180022","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 962, Length: 963" "19:13:28,6180160","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2 925, Length: 979" "19:13:28,6180528","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 3 904, Length: 995" "19:13:28,6180714","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6180917","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 4 899, Length: 995" "19:13:28,6181333","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 5 894, Length: 986" "19:13:28,6181401","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6181706","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6181741","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 6 880, Length: 980" "19:13:28,6181840","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6182062","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6182155","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 7 860, Length: 976" "19:13:28,6182443","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6182568","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 8 836, Length: 989" "19:13:28,6182754","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 9 825, Length: 968" "19:13:28,6182928","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 10 793, Length: 980" "19:13:28,6183091","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 11 773, Length: 961" "19:13:28,6183306","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 12 734, Length: 985" "19:13:28,6183312","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6183684","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 13 719, Length: 986" "19:13:28,6183996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6184060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 14 705, Length: 970" "19:13:28,6184300","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6184422","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6184464","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 15 675, Length: 987" "19:13:28,6184643","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6184878","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 16 662, Length: 982" "19:13:28,6185028","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6185275","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 17 644, Length: 992" "19:13:28,6185673","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 18 636, Length: 985" "19:13:28,6185885","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6186039","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 19 621, Length: 999" "19:13:28,6186446","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 20 620, Length: 1 000" "19:13:28,6186542","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6186847","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 21 620, Length: 982" "19:13:28,6186850","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6186972","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6187187","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6187222","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 22 602, Length: 972" "19:13:28,6187565","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6187601","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 23 574, Length: 995" "19:13:28,6187960","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 24 569, Length: 974" "19:13:28,6188351","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 25 543, Length: 997" "19:13:28,6188428","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6188739","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 26 540, Length: 999" "19:13:28,6189063","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 27 539, Length: 960" "19:13:28,6189188","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6189387","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 28 499, Length: 960" "19:13:28,6189724","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 29 459, Length: 987" "19:13:28,6189923","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6190115","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 30 446, Length: 974" "19:13:28,6190506","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 31 420, Length: 994" "19:13:28,6190590","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6190894","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6190901","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 32 414, Length: 987" "19:13:28,6191019","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6191244","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6191279","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 33 401, Length: 998" "19:13:28,6191622","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6191690","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 34 399, Length: 982" "19:13:28,6192193","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 35 381, Length: 992" "19:13:28,6192642","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 36 373, Length: 989" "19:13:28,6192687","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6193056","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 37 362, Length: 971" "19:13:28,6193425","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6193444","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 38 333, Length: 973" "19:13:28,6193771","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6193871","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 39 306, Length: 1 000" "19:13:28,6193912","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6194153","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6194284","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 40 306, Length: 1 000" "19:13:28,6194567","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6194692","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 41 306, Length: 991" "19:13:28,6195073","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 42 297, Length: 996" "19:13:28,6195458","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 43 293, Length: 992" "19:13:28,6195503","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6195850","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 44 285, Length: 990" "19:13:28,6196193","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6196238","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 45 275, Length: 976" "19:13:28,6196530","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6196639","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 46 251, Length: 993" "19:13:28,6196661","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6196895","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6197043","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 47 244, Length: 976" "19:13:28,6197296","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6197447","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 48 220, Length: 981" "19:13:28,6197845","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 49 201, Length: 996" "19:13:28,6198181","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6198239","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 50 197, Length: 990" "19:13:28,6198624","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 51 187, Length: 1 000" "19:13:28,6198848","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6199006","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 52 187, Length: 987" "19:13:28,6199156","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6199281","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6199368","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 53 174, Length: 981" "19:13:28,6199499","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6199746","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 54 155, Length: 1 000" "19:13:28,6199881","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6200106","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 55 155, Length: 998" "19:13:28,6200468","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 56 153, Length: 977" "19:13:28,6200843","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 57 130, Length: 971" "19:13:28,6201241","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 58 101, Length: 986" "19:13:28,6201619","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 59 087, Length: 987" "19:13:28,6202014","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 60 074, Length: 998" "19:13:28,6202412","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 61 072, Length: 1 000" "19:13:28,6202809","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 62 072, Length: 990" "19:13:28,6203403","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 63 062, Length: 997" "19:13:28,6203945","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 64 059, Length: 982" "19:13:28,6204368","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 65 041, Length: 1 000" "19:13:28,6204772","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 66 041, Length: 983" "19:13:28,6205170","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 67 024, Length: 996" "19:13:28,6205539","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 020, Length: 966" "19:13:28,6205953","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 986, Length: 986" "19:13:28,6206369","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 69 972, Length: 997" "19:13:28,6206754","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 70 969, Length: 981" "19:13:28,6207290","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 71 950, Length: 989" "19:13:28,6207688","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 72 939, Length: 992" "19:13:28,6208108","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 73 931, Length: 983" "19:13:28,6208502","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 74 914, Length: 975" "19:13:28,6208890","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 75 889, Length: 987" "19:13:28,6209285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 76 876, Length: 981" "19:13:28,6210770","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 77 857, Length: 973" "19:13:28,6211742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 78 830, Length: 988" "19:13:28,6212191","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 79 818, Length: 982" "19:13:28,6213069","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 80 800, Length: 988" "19:13:28,6213502","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 81 788, Length: 993" "19:13:28,6213939","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 82 781, Length: 991" "19:13:28,6214330","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 83 772, Length: 986" "19:13:28,6214737","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 84 758, Length: 1 000" "19:13:28,6215154","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 85 758, Length: 996" "19:13:28,6215574","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 86 754, Length: 990" "19:13:28,6215975","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 87 744, Length: 996" "19:13:28,6216421","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 88 740, Length: 986" "19:13:28,6216803","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 89 726, Length: 959" "19:13:28,6217213","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 90 685, Length: 933" "19:13:28,6217928","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 91 618, Length: 1 000" "19:13:28,6218416","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 92 618, Length: 992" "19:13:28,6218807","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 93 610, Length: 989" "19:13:28,6219215","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 94 599, Length: 979" "19:13:28,6219606","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 95 578, Length: 974" "19:13:28,6219994","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 96 552, Length: 979" "19:13:28,6220372","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 97 531, Length: 987" "19:13:28,6220764","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 98 518, Length: 999" "19:13:28,6221133","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 99 517, Length: 991" "19:13:28,6221517","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 100 508, Length: 998" "19:13:28,6221918","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 101 506, Length: 971" "19:13:28,6222335","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 871, Length: 46" "19:13:28,6222634","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 102 477, Length: 990" "19:13:28,6223025","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 103 467, Length: 1 000" "19:13:28,6223288","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,6223419","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 104 467, Length: 986" "19:13:28,6223487","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 599, Length: 31" "19:13:28,6223560","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6223673","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,6223820","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 105 453, Length: 994" "19:13:28,6223833","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS","Desired Access: Read" "19:13:28,6224009","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6224151","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,6224202","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 106 447, Length: 988" "19:13:28,6224276","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","NO MORE ENTRIES","Index: 0, Length: 288" "19:13:28,6224401","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS","" "19:13:28,6224593","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 107 435, Length: 992" "19:13:28,6224975","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 108 427, Length: 992" "19:13:28,6225357","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 109 419, Length: 992" "19:13:28,6225725","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 110 411, Length: 978" "19:13:28,6226097","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 111 389, Length: 996" "19:13:28,6226460","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 112 385, Length: 986" "19:13:28,6227031","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 113 371, Length: 991" "19:13:28,6227396","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 114 362, Length: 981" "19:13:28,6227781","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 115 343, Length: 997" "19:13:28,6228153","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 116 340, Length: 998" "19:13:28,6228541","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 117 338, Length: 997" "19:13:28,6228907","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 118 335, Length: 997" "19:13:28,6229301","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 119 332, Length: 987" "19:13:28,6229677","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 120 319, Length: 986" "19:13:28,6230042","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 121 305, Length: 965" "19:13:28,6230424","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 122 270, Length: 1 000" "19:13:28,6230812","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 123 270, Length: 992" "19:13:28,6231178","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 124 262, Length: 994" "19:13:28,6231543","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 125 256, Length: 992" "19:13:28,6231922","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 126 248, Length: 969" "19:13:28,6232300","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 127 217, Length: 962" "19:13:28,6232675","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 128 179, Length: 999" "19:13:28,6233051","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 129 178, Length: 1 000" "19:13:28,6233413","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 130 178, Length: 972" "19:13:28,6233795","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 131 150, Length: 981" "19:13:28,6234160","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 132 131, Length: 979" "19:13:28,6234536","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 133 110, Length: 996" "19:13:28,6234911","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 134 106, Length: 973" "19:13:28,6235286","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 135 079, Length: 981" "19:13:28,6235678","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 136 060, Length: 1 000" "19:13:28,6235838","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 137 060, Length: 986" "19:13:28,6236264","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 138 046, Length: 977" "19:13:28,6236678","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 139 023, Length: 999" "19:13:28,6237092","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 140 022, Length: 983" "19:13:28,6237509","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 005, Length: 977" "19:13:28,6237910","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 982, Length: 988" "19:13:28,6238317","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 142 970, Length: 982" "19:13:28,6238734","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 143 952, Length: 972" "19:13:28,6239138","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 144 924, Length: 984" "19:13:28,6239545","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 145 908, Length: 994" "19:13:28,6239956","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 146 902, Length: 978" "19:13:28,6240363","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 147 880, Length: 981" "19:13:28,6240780","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 148 861, Length: 996" "19:13:28,6241178","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 149 857, Length: 986" "19:13:28,6241572","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 150 843, Length: 990" "19:13:28,6241977","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 151 833, Length: 984" "19:13:28,6242361","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 152 817, Length: 1 000" "19:13:28,6242743","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 153 817, Length: 990" "19:13:28,6243166","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 154 807, Length: 980" "19:13:28,6243590","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 155 787, Length: 982" "19:13:28,6244010","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 156 769, Length: 1 000" "19:13:28,6244401","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 157 769, Length: 994" "19:13:28,6244498","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6244603","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6244805","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer","REPARSE","Desired Access: Query Value" "19:13:28,6244815","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 158 763, Length: 995" "19:13:28,6245059","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","Desired Access: Query Value" "19:13:28,6245210","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6245222","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 159 758, Length: 984" "19:13:28,6245303","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations","NAME NOT FOUND","Length: 144" "19:13:28,6245431","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","" "19:13:28,6245543","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6245617","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,6245668","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 160 742, Length: 999" "19:13:28,6245761","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","Desired Access: Query Value" "19:13:28,6245893","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6245973","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations","NAME NOT FOUND","Length: 144" "19:13:28,6246075","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","" "19:13:28,6246197","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 161 741, Length: 973" "19:13:28,6246637","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 162 714, Length: 999" "19:13:28,6247060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 163 713, Length: 989" "19:13:28,6247493","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 164 702, Length: 984" "19:13:28,6247894","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 165 686, Length: 989" "19:13:28,6248288","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 166 675, Length: 982" "19:13:28,6248356","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","REPARSE","Desired Access: Read" "19:13:28,6248484","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","SUCCESS","Desired Access: Read" "19:13:28,6248619","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6248680","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 167 657, Length: 987" "19:13:28,6248738","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","REPARSE","Desired Access: Read" "19:13:28,6248885","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","SUCCESS","Desired Access: Read" "19:13:28,6249001","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6249097","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 168 644, Length: 1 000" "19:13:28,6249113","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","REPARSE","Desired Access: Read" "19:13:28,6249209","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","SUCCESS","Desired Access: Read" "19:13:28,6249318","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6249405","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Locale\0000040E","SUCCESS","Type: REG_SZ, Length: 4, Data: 2" "19:13:28,6249488","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 169 644, Length: 971" "19:13:28,6249543","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Language Groups\2","SUCCESS","Type: REG_SZ, Length: 4, Data: 1" "19:13:28,6249924","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 170 615, Length: 985" "19:13:28,6250322","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 171 600, Length: 993" "19:13:28,6250729","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 172 593, Length: 997" "19:13:28,6251127","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 173 590, Length: 988" "19:13:28,6251518","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 174 578, Length: 988" "19:13:28,6251929","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 175 566, Length: 994" "19:13:28,6252333","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 176 560, Length: 991" "19:13:28,6252718","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 177 551, Length: 987" "19:13:28,6253112","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 178 538, Length: 998" "19:13:28,6253504","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 179 536, Length: 983" "19:13:28,6253901","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 180 519, Length: 998" "19:13:28,6254299","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 181 517, Length: 981" "19:13:28,6254700","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 182 498, Length: 999" "19:13:28,6255104","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 183 497, Length: 1 000" "19:13:28,6255521","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 184 497, Length: 997" "19:13:28,6255906","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 185 494, Length: 991" "19:13:28,6256294","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 186 485, Length: 975" "19:13:28,6256688","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 187 460, Length: 988" "19:13:28,6257105","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 188 448, Length: 985" "19:13:28,6257500","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 189 433, Length: 993" "19:13:28,6257885","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 190 426, Length: 976" "19:13:28,6258286","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 191 402, Length: 995" "19:13:28,6258651","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 192 397, Length: 969" "19:13:28,6259039","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 193 366, Length: 987" "19:13:28,6259424","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 194 353, Length: 993" "19:13:28,6259806","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 195 346, Length: 997" "19:13:28,6260184","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 196 343, Length: 975" "19:13:28,6260576","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 197 318, Length: 975" "19:13:28,6261009","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 198 293, Length: 986" "19:13:28,6261528","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 199 279, Length: 990" "19:13:28,6262118","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 200 269, Length: 997" "19:13:28,6262567","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 201 266, Length: 987" "19:13:28,6263003","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 202 253, Length: 987" "19:13:28,6263408","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 203 240, Length: 977" "19:13:28,6263802","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 204 217, Length: 978" "19:13:28,6264213","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 205 195, Length: 978" "19:13:28,6264617","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 206 173, Length: 990" "19:13:28,6265030","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 207 163, Length: 995" "19:13:28,6265431","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 208 158, Length: 1 000" "19:13:28,6265839","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 209 158, Length: 989" "19:13:28,6266211","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 210 147, Length: 966" "19:13:28,6266602","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 211 113, Length: 994" "19:13:28,6267022","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 212 107, Length: 986" "19:13:28,6267381","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 917, Length: 46" "19:13:28,6267446","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 213 093, Length: 978" "19:13:28,6267875","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 214 071, Length: 999" "19:13:28,6268276","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 215 070, Length: 984" "19:13:28,6268520","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 630, Length: 31" "19:13:28,6268671","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 216 054, Length: 986" "19:13:28,6269065","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 217 040, Length: 1 000" "19:13:28,6269463","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 218 040, Length: 978" "19:13:28,6269857","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 018, Length: 971" "19:13:28,6270262","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 989, Length: 982" "19:13:28,6270678","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 220 971, Length: 1 000" "19:13:28,6271089","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 221 971, Length: 990" "19:13:28,6271500","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 222 961, Length: 990" "19:13:28,6271929","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 223 951, Length: 996" "19:13:28,6272324","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 224 947, Length: 976" "19:13:28,6272744","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 225 923, Length: 980" "19:13:28,6273142","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 226 903, Length: 998" "19:13:28,6273549","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 227 901, Length: 997" "19:13:28,6273950","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 228 898, Length: 998" "19:13:28,6274360","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 229 896, Length: 986" "19:13:28,6274771","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 230 882, Length: 996" "19:13:28,6275178","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 231 878, Length: 984" "19:13:28,6275595","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 232 862, Length: 1 000" "19:13:28,6275993","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 233 862, Length: 994" "19:13:28,6276387","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 234 856, Length: 981" "19:13:28,6276782","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 235 837, Length: 989" "19:13:28,6277196","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 236 826, Length: 999" "19:13:28,6277468","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6277629","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 237 825, Length: 974" "19:13:28,6277638","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0","SUCCESS","Desired Access: Query Value" "19:13:28,6277863","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6277962","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable","NAME NOT FOUND","Length: 144" "19:13:28,6278074","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath","SUCCESS","Type: REG_SZ, Length: 66, Data: C:\Windows\Fonts\staticcache.dat" "19:13:28,6278126","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 238 799, Length: 990" "19:13:28,6278216","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0","SUCCESS","" "19:13:28,6278559","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 239 789, Length: 986" "19:13:28,6278972","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 240 775, Length: 992" "19:13:28,6279139","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6279393","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 241 767, Length: 998" "19:13:28,6279428","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","AllocationSize: 18 612 224, EndOfFile: 18 612 224, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6279559","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","Offset: 0, Length: 60, Priority: Normal" "19:13:28,6279806","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\Fonts\StaticCache.dat","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:28,6279848","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 242 765, Length: 994" "19:13:28,6279976","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","AllocationSize: 18 612 224, EndOfFile: 18 612 224, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6280178","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\Fonts\StaticCache.dat","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6280425","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 243 759, Length: 976" "19:13:28,6280855","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 244 735, Length: 979" "19:13:28,6281272","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 245 714, Length: 982" "19:13:28,6281506","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6281612","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Desired Access: Query Value" "19:13:28,6281708","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 246 696, Length: 1 000" "19:13:28,6281756","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6281904","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1","NAME NOT FOUND","Length: 144" "19:13:28,6281997","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2","SUCCESS","Type: REG_SZ, Length: 24, Data: SimSun-ExtB" "19:13:28,6282077","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2","SUCCESS","Type: REG_SZ, Length: 24, Data: SimSun-ExtB" "19:13:28,6282138","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 247 696, Length: 985" "19:13:28,6282167","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3","NAME NOT FOUND","Length: 144" "19:13:28,6282244","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4","NAME NOT FOUND","Length: 144" "19:13:28,6282321","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5","NAME NOT FOUND","Length: 144" "19:13:28,6282398","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6","NAME NOT FOUND","Length: 144" "19:13:28,6282475","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7","NAME NOT FOUND","Length: 144" "19:13:28,6282545","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 248 681, Length: 978" "19:13:28,6282549","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8","NAME NOT FOUND","Length: 144" "19:13:28,6282626","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9","NAME NOT FOUND","Length: 144" "19:13:28,6282703","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10","NAME NOT FOUND","Length: 144" "19:13:28,6282786","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11","NAME NOT FOUND","Length: 144" "19:13:28,6282866","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12","NAME NOT FOUND","Length: 144" "19:13:28,6282946","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13","NAME NOT FOUND","Length: 144" "19:13:28,6282949","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 249 659, Length: 993" "19:13:28,6283026","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14","NAME NOT FOUND","Length: 144" "19:13:28,6283103","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15","NAME NOT FOUND","Length: 144" "19:13:28,6283184","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16","NAME NOT FOUND","Length: 144" "19:13:28,6283289","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","" "19:13:28,6283354","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 250 652, Length: 983" "19:13:28,6283482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6283578","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:28,6283700","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6283745","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 251 635, Length: 993" "19:13:28,6283809","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Query: Cached, SubKeys: 4, Values: 1" "19:13:28,6283937","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Index: 0, Name: MingLiU" "19:13:28,6284030","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Index: 1, Name: MingLiU_HKSCS" "19:13:28,6284117","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Index: 2, Name: PMingLiU" "19:13:28,6284152","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 252 628, Length: 989" "19:13:28,6284200","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Index: 3, Name: SimSun" "19:13:28,6284534","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 253 617, Length: 980" "19:13:28,6284928","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 254 597, Length: 990" "19:13:28,6285349","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 255 587, Length: 988" "19:13:28,6285432","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,6285535","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\System","NAME NOT FOUND","Desired Access: Query Value" "19:13:28,6285666","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback","SUCCESS","" "19:13:28,6285743","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 256 575, Length: 998" "19:13:28,6286134","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 257 573, Length: 979" "19:13:28,6286545","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 258 552, Length: 984" "19:13:28,6286955","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 259 536, Length: 996" "19:13:28,6287603","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 260 532, Length: 996" "19:13:28,6288043","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 261 528, Length: 998" "19:13:28,6288508","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 262 526, Length: 972" "19:13:28,6288931","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 263 498, Length: 974" "19:13:28,6289335","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 264 472, Length: 993" "19:13:28,6289739","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 265 465, Length: 970" "19:13:28,6290140","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 266 435, Length: 993" "19:13:28,6290531","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 267 428, Length: 974" "19:13:28,6290929","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 268 402, Length: 998" "19:13:28,6291324","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 269 400, Length: 981" "19:13:28,6291731","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 270 381, Length: 969" "19:13:28,6292270","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 271 350, Length: 1 000" "19:13:28,6293059","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 272 350, Length: 1 000" "19:13:28,6293697","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 273 350, Length: 1 000" "19:13:28,6294104","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 274 350, Length: 973" "19:13:28,6294528","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 275 323, Length: 992" "19:13:28,6294932","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 276 315, Length: 979" "19:13:28,6295352","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 277 294, Length: 983" "19:13:28,6295753","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 278 277, Length: 984" "19:13:28,6296154","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 279 261, Length: 981" "19:13:28,6296580","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 280 242, Length: 989" "19:13:28,6296988","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 281 231, Length: 988" "19:13:28,6297385","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 282 219, Length: 984" "19:13:28,6297786","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 283 203, Length: 1 000" "19:13:28,6298187","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 284 203, Length: 1 000" "19:13:28,6298588","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 285 203, Length: 1 000" "19:13:28,6298995","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 286 203, Length: 986" "19:13:28,6299396","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 287 189, Length: 980" "19:13:28,6299807","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 288 169, Length: 993" "19:13:28,6300195","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 289 162, Length: 992" "19:13:28,6300586","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 290 154, Length: 985" "19:13:28,6300997","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 291 139, Length: 980" "19:13:28,6301401","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 292 119, Length: 990" "19:13:28,6301811","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 293 109, Length: 978" "19:13:28,6302225","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 294 087, Length: 988" "19:13:28,6302620","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 295 075, Length: 978" "19:13:28,6303065","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 296 053, Length: 993" "19:13:28,6303890","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 297 046, Length: 1 000" "19:13:28,6304332","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 298 046, Length: 984" "19:13:28,6304887","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 299 030, Length: 976" "19:13:28,6305362","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 006, Length: 988" "19:13:28,6305785","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 994, Length: 989" "19:13:28,6306221","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 301 983, Length: 997" "19:13:28,6306696","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 302 980, Length: 985" "19:13:28,6307225","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 303 965, Length: 990" "19:13:28,6307613","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 304 955, Length: 990" "19:13:28,6308037","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 305 945, Length: 974" "19:13:28,6308470","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 306 919, Length: 1 000" "19:13:28,6308916","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 307 919, Length: 995" "19:13:28,6309316","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 308 914, Length: 996" "19:13:28,6309724","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 309 910, Length: 998" "19:13:28,6310134","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 310 908, Length: 993" "19:13:28,6310548","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 311 901, Length: 986" "19:13:28,6310936","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 312 887, Length: 976" "19:13:28,6311353","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 313 863, Length: 991" "19:13:28,6311764","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 314 854, Length: 990" "19:13:28,6312315","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 1 963, Length: 46" "19:13:28,6312511","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 315 844, Length: 990" "19:13:28,6312941","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 316 834, Length: 985" "19:13:28,6313345","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 317 819, Length: 986" "19:13:28,6313377","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 661, Length: 31" "19:13:28,6313736","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 318 805, Length: 979" "19:13:28,6314143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 319 784, Length: 998" "19:13:28,6314554","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 320 782, Length: 976" "19:13:28,6314961","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 321 758, Length: 992" "19:13:28,6315369","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 322 750, Length: 983" "19:13:28,6315786","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 323 733, Length: 990" "19:13:28,6316186","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 324 723, Length: 977" "19:13:28,6316578","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 325 700, Length: 981" "19:13:28,6316998","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 326 681, Length: 999" "19:13:28,6317402","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 327 680, Length: 985" "19:13:28,6317822","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 328 665, Length: 996" "19:13:28,6318233","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 329 661, Length: 1 000" "19:13:28,6318672","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 330 661, Length: 999" "19:13:28,6319086","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 331 660, Length: 988" "19:13:28,6319500","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 332 648, Length: 983" "19:13:28,6319894","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 333 631, Length: 974" "19:13:28,6320282","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 334 605, Length: 976" "19:13:28,6320680","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 335 581, Length: 989" "19:13:28,6321100","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 336 570, Length: 990" "19:13:28,6321504","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 337 560, Length: 992" "19:13:28,6321905","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 338 552, Length: 990" "19:13:28,6322348","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 339 542, Length: 978" "19:13:28,6322745","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 340 520, Length: 971" "19:13:28,6323143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 341 491, Length: 982" "19:13:28,6323550","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 342 473, Length: 997" "19:13:28,6323938","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 343 470, Length: 991" "19:13:28,6324346","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 344 461, Length: 985" "19:13:28,6324753","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 345 446, Length: 998" "19:13:28,6325154","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 346 444, Length: 976" "19:13:28,6325548","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 347 420, Length: 981" "19:13:28,6325959","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 348 401, Length: 990" "19:13:28,6326350","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 349 391, Length: 979" "19:13:28,6326742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 350 370, Length: 997" "19:13:28,6327210","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 351 367, Length: 997" "19:13:28,6327620","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 352 364, Length: 982" "19:13:28,6328008","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 353 346, Length: 981" "19:13:28,6328400","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 354 327, Length: 1 000" "19:13:28,6328781","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 355 327, Length: 1 000" "19:13:28,6329166","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 356 327, Length: 986" "19:13:28,6329667","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 357 313, Length: 986" "19:13:28,6330084","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 358 299, Length: 975" "19:13:28,6330465","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 359 274, Length: 1 000" "19:13:28,6330850","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 360 274, Length: 998" "19:13:28,6331245","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 361 272, Length: 994" "19:13:28,6331629","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 362 266, Length: 989" "19:13:28,6332014","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 363 255, Length: 995" "19:13:28,6332396","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 364 250, Length: 980" "19:13:28,6332787","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 365 230, Length: 990" "19:13:28,6333182","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 366 220, Length: 992" "19:13:28,6333560","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 367 212, Length: 977" "19:13:28,6333952","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 368 189, Length: 992" "19:13:28,6334327","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 369 181, Length: 972" "19:13:28,6334702","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 370 153, Length: 979" "19:13:28,6335087","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 371 132, Length: 983" "19:13:28,6335469","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 372 115, Length: 994" "19:13:28,6335853","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 373 109, Length: 996" "19:13:28,6336235","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 374 105, Length: 984" "19:13:28,6336620","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 375 089, Length: 972" "19:13:28,6337014","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 376 061, Length: 991" "19:13:28,6337473","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 377 052, Length: 1 000" "19:13:28,6337989","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 378 052, Length: 976" "19:13:28,6338435","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 379 028, Length: 996" "19:13:28,6338830","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 380 024, Length: 998" "19:13:28,6339272","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 381 022, Length: 984" "19:13:28,6339686","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 382 006, Length: 999" "19:13:28,6340138","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 005, Length: 988" "19:13:28,6340517","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 993, Length: 988" "19:13:28,6340914","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 384 981, Length: 996" "19:13:28,6341357","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 385 977, Length: 976" "19:13:28,6341729","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 386 953, Length: 983" "19:13:28,6342104","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 387 936, Length: 986" "19:13:28,6342691","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 388 922, Length: 1 000" "19:13:28,6343169","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 389 922, Length: 971" "19:13:28,6343586","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 390 893, Length: 999" "19:13:28,6343997","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 391 892, Length: 999" "19:13:28,6344391","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 392 891, Length: 994" "19:13:28,6344786","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 393 885, Length: 994" "19:13:28,6345174","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 394 879, Length: 986" "19:13:28,6345543","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 395 865, Length: 1 000" "19:13:28,6346040","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 396 865, Length: 999" "19:13:28,6346473","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 397 864, Length: 996" "19:13:28,6346909","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 398 860, Length: 974" "19:13:28,6347451","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 399 834, Length: 991" "19:13:28,6347910","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 400 825, Length: 985" "19:13:28,6348314","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 401 810, Length: 968" "19:13:28,6348692","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 402 778, Length: 994" "19:13:28,6349055","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 403 772, Length: 992" "19:13:28,6349414","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 404 764, Length: 992" "19:13:28,6350065","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 405 756, Length: 980" "19:13:28,6350671","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 406 736, Length: 986" "19:13:28,6351694","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 407 722, Length: 990" "19:13:28,6352175","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 408 712, Length: 1 000" "19:13:28,6352647","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 409 712, Length: 998" "19:13:28,6353044","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 410 710, Length: 985" "19:13:28,6353442","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 411 695, Length: 979" "19:13:28,6353811","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 412 674, Length: 977" "19:13:28,6354292","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 413 651, Length: 983" "19:13:28,6354815","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 414 634, Length: 973" "19:13:28,6355379","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 415 607, Length: 976" "19:13:28,6355835","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 416 583, Length: 995" "19:13:28,6356245","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 417 578, Length: 978" "19:13:28,6356643","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 418 556, Length: 963" "19:13:28,6357086","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 419 519, Length: 1 000" "19:13:28,6357490","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 420 519, Length: 982" "19:13:28,6357887","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 421 501, Length: 991" "19:13:28,6358282","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 422 492, Length: 979" "19:13:28,6358644","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 423 471, Length: 992" "19:13:28,6359029","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 424 463, Length: 997" "19:13:28,6359424","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 425 460, Length: 988" "19:13:28,6359841","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 426 448, Length: 986" "19:13:28,6360229","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 427 434, Length: 991" "19:13:28,6360623","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 428 425, Length: 987" "19:13:28,6361021","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 429 412, Length: 967" "19:13:28,6361419","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 430 379, Length: 980" "19:13:28,6361810","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 431 359, Length: 971" "19:13:28,6362227","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 432 330, Length: 983" "19:13:28,6362644","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 433 313, Length: 980" "19:13:28,6363048","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 434 293, Length: 988" "19:13:28,6363224","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 435 281, Length: 980" "19:13:28,6363359","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 436 261, Length: 974" "19:13:28,6363612","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 437 235, Length: 989" "19:13:28,6363984","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 438 224, Length: 981" "19:13:28,6364376","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 439 205, Length: 301" "19:13:28,6364603","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","" "19:13:28,6366637","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6367423","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6367811","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6367939","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6368135","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6368638","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6369511","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6370248","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6370530","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6370630","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6370793","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6371111","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6371974","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6372638","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6372923","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6373016","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6373183","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6373523","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6374321","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6374982","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6375296","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6375393","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6375553","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6375912","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6377272","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6378010","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6378340","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6378449","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6378632","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6379001","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6379880","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6380563","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6380855","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6380951","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6381111","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6381448","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6382349","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6383122","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6383853","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6384511","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6384809","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6384905","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6385066","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6385707","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6386817","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6387478","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6387760","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6387856","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6388186","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6388542","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6389508","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6390220","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6390537","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6390666","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6390964","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6391358","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6392337","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6393033","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6393344","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6393446","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6393616","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6393963","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6394809","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6394886","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6395005","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters","REPARSE","Desired Access: Read" "19:13:28,6395117","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Parameters","SUCCESS","Desired Access: Read" "19:13:28,6395291","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Winsock\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6395406","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports","SUCCESS","Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda" "19:13:28,6395489","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports","SUCCESS","Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda" "19:13:28,6395582","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Parameters","SUCCESS","" "19:13:28,6395704","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6395791","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6395903","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,6395987","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,6396131","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6396237","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00" "19:13:28,6396320","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00" "19:13:28,6396413","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","SUCCESS","" "19:13:28,6396522","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6396657","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6396779","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,6396885","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,6397042","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6397128","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping","BUFFER OVERFLOW","Length: 144" "19:13:28,6397218","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping","BUFFER OVERFLOW","Length: 144" "19:13:28,6397289","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 152, Data: 0C 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00" "19:13:28,6397375","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","SUCCESS","" "19:13:28,6397472","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6397526","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6397622","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read" "19:13:28,6397706","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Desired Access: Read" "19:13:28,6397844","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6397962","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6398039","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched","SUCCESS","Desired Access: Read" "19:13:28,6398168","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched\WinSock 2.0 Provider ID","SUCCESS","Type: REG_BINARY, Length: 16, Data: E0 A9 60 9D 7A 33 D0 11 BD 88 00 00 C0 82 E6 9A" "19:13:28,6398254","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched","SUCCESS","" "19:13:28,6398321","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","" "19:13:28,6398411","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6398469","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6398565","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,6398684","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,6398860","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6398950","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00" "19:13:28,6399043","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00" "19:13:28,6399133","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","" "19:13:28,6399236","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6399293","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6399399","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,6399521","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,6399665","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6399742","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00" "19:13:28,6399826","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00" "19:13:28,6399912","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","SUCCESS","" "19:13:28,6400002","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6400098","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6400230","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read" "19:13:28,6400326","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Desired Access: Read" "19:13:28,6400432","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6400528","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,6400605","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip6","SUCCESS","Desired Access: Read" "19:13:28,6400727","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip6\WinSock 2.0 Provider ID","SUCCESS","Type: REG_BINARY, Length: 16, Data: C0 B0 EA F9 D4 26 D0 11 BB BF 00 AA 00 6C 34 E4" "19:13:28,6400820","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip6","SUCCESS","" "19:13:28,6400887","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","" "19:13:28,6401006","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6401064","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6401166","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,6401256","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,6401352","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6401423","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\MinSockaddrLength","SUCCESS","Type: REG_DWORD, Length: 4, Data: 28" "19:13:28,6401509","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\MaxSockaddrLength","SUCCESS","Type: REG_DWORD, Length: 4, Data: 28" "19:13:28,6401583","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock\UseDelayedAcceptance","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,6401689","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock","SUCCESS","" "19:13:28,6467435","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 009, Length: 46" "19:13:28,6469074","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 692, Length: 31" "19:13:28,6672761","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","CreationTime: 2017. 09. 29. 15:42:11, LastAccessTime: 2021. 02. 13. 21:50:18, LastWriteTime: 2017. 09. 29. 15:42:11, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 303 104, EndOfFile: 300 544, FileAttributes: A" "19:13:28,6673586","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6673967","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\FWPUCLNT.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6674221","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6674650","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","Image Base: 0x6df50000, Image Size: 0x4e000" "19:13:28,6676055","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","" "19:13:28,6677008","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6677312","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","BUFFER OVERFLOW","Information: Owner" "19:13:28,6677457","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","Information: Owner" "19:13:28,6677566","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","" "19:13:28,6678996","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6679702","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6680045","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6680157","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6680340","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6680741","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6681584","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6682258","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6682537","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6682633","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6682794","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6683102","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6683955","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6684606","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6684894","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6684991","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6685154","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6685488","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6686293","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6686937","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6687210","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6687303","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6687457","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6687765","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6688567","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6689208","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6689542","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6689638","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6689801","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6690116","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6690956","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6691582","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6691915","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6692011","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6692168","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6692470","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6693304","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6694038","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6694741","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6695369","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6695652","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6695745","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6695908","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6696222","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6697040","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6697746","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6698012","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6698118","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6698310","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6698650","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6699503","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6700167","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6700466","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6700559","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6700719","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6701062","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6701858","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6702502","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6702775","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6702865","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6703022","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6703314","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6706406","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6706505","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6706675","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","REPARSE","Desired Access: All Access" "19:13:28,6706803","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Desired Access: All Access" "19:13:28,6706951","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6707053","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 2.0" "19:13:28,6707146","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 2.0" "19:13:28,6707220","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL","SUCCESS","Type: REG_SZ, Length: 66, Data: C:\Windows\System32\rasadhlp.dll" "19:13:28,6707281","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AutodialDLL","SUCCESS","Type: REG_SZ, Length: 66, Data: C:\Windows\System32\rasadhlp.dll" "19:13:28,6707368","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","" "19:13:28,6708208","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:23, LastAccessTime: 2021. 02. 13. 20:10:32, LastWriteTime: 2017. 09. 29. 15:42:23, ChangeTime: 2020. 01. 09. 4:43:34, AllocationSize: 16 384, EndOfFile: 12 800, FileAttributes: A" "19:13:28,6708882","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6709193","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\rasadhlp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6709388","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6709815","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","Image Base: 0x6e2a0000, Image Size: 0x8000" "19:13:28,6710674","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","" "19:13:28,6711691","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6712041","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\rasadhlp.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,6712150","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","Information: Owner" "19:13:28,6712249","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","" "19:13:28,6713340","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6714145","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6714449","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6714552","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6714722","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6715136","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6716034","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6716691","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6717009","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6717127","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6717288","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6717679","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6718731","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6719437","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6719748","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6719854","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6720030","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6720376","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6721223","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6721868","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6722160","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6722259","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6722419","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6722743","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6723590","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6724267","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6724546","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6724652","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6724822","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6725142","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6725954","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6726586","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6726852","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6726955","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6727115","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6727439","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6728401","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6729161","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6729867","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6730524","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6730803","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6730899","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6731060","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6731406","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6732211","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6733061","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6733414","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6733520","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6733709","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6734084","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6735014","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6735714","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6736038","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6736159","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6736368","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6736705","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6737715","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6738975","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6739582","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6739681","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6739992","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6740435","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6744004","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 168, User Time: 0.0156250, Kernel Time: 0.0468750" "19:13:28,6972295","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6972372","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6972542","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","Desired Access: Read" "19:13:28,6972709","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6972821","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,6972968","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,6973068","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,6973138","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,6973273","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","" "19:13:28,6973379","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,6973437","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,6973558","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,6973667","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,6973738","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,6973812","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,6973873","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,6973940","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,6974001","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,6975185","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6976057","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6976551","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6976682","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6976878","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6977285","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6978334","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,6979129","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6979425","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6979527","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6979691","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6980015","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,6980900","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6981564","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6981865","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6981974","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6982138","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6982475","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6983360","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,6984014","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6984284","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6984380","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6984588","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6984928","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,6985794","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6986474","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6986763","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6986859","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6987109","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6987475","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6988415","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,6989091","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6989402","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6989505","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6989675","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6989986","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,6990833","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6991577","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,6992430","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6993251","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6993549","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6993639","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6993844","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6994226","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6995153","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,6995884","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6996173","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6996269","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6996436","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6996744","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,6997571","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,6998210","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,6998495","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,6998591","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,6998755","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,6999069","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,6999855","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7000891","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7001176","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7001269","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7001532","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7001975","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7002899","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7002985","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,7003097","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7003171","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7003245","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7003325","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7003402","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7003514","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,7003623","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7003681","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7003819","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,7004092","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","" "19:13:28,7004226","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7004287","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7004441","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","Desired Access: Read" "19:13:28,7004582","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7004666","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7004733","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7004804","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7004861","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7004945","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","" "19:13:28,7005041","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7005102","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7005227","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,7005330","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7005391","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,7005458","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7005516","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7005580","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7005638","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7006584","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7007758","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7008117","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7008300","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7008521","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7008893","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7009765","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7010420","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7010708","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7010897","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7011119","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7011465","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7012469","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7013175","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7013479","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7013579","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7013742","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7014079","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7014948","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7015599","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7015875","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7015971","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7016241","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7016658","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7017723","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7018431","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7018749","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7018852","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7019102","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7019445","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7020340","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7020984","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7021305","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7021408","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7021591","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7021943","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7022784","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7023525","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7024230","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7024862","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7025154","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7025250","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7025430","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7025747","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7026552","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7027190","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7027460","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7027553","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7027713","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7028011","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7028849","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7029512","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7029808","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7029897","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7030055","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7030362","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7031167","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7031783","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7032075","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7032165","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7032322","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7032617","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7033531","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7033621","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,7033743","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7033823","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7033922","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7034012","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7034089","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7034211","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,7034330","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7034391","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7034554","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,7034849","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","" "19:13:28,7034994","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7035055","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7035247","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","Desired Access: Read" "19:13:28,7035375","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7035459","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7035536","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7035613","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7035674","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7035776","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","" "19:13:28,7035885","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7035946","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7036068","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,7036174","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7036238","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,7036318","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7036382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7036463","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7036524","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7037434","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7038134","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7038445","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7038589","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7038765","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7039093","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7040036","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7040687","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7040969","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7041062","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7041219","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7041521","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7042361","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7042996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7043265","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7043355","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7043525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7043839","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7044619","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7045257","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7045616","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7045728","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7045905","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7046232","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7047047","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7047723","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7047996","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7048086","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7048240","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7048564","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7049410","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7050020","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7050280","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7050369","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7050527","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7050818","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7051633","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7052342","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7053031","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7053644","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7053910","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7054000","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7054157","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7054500","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7055398","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7056069","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7056380","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7056492","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7056704","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7057047","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7057881","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7058525","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7058804","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7058901","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7059061","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7059379","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7060241","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7060867","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7061139","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7061229","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7061531","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7061887","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7062689","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7062791","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,7062903","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7062977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7063064","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7063141","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7063211","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7063327","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,7063452","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7063545","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7063673","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,7063904","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","" "19:13:28,7064032","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7064096","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7064212","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","Desired Access: Read" "19:13:28,7064321","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7064392","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7064462","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7064533","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7064594","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:28,7064680","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","" "19:13:28,7064764","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7064821","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7064937","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,7065036","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7065100","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,7065168","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7065238","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7065299","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7065363","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,7066181","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7066855","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7067166","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7067268","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7067438","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7067762","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7068603","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7069251","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7069552","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7069677","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7069847","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7070165","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7071149","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7071842","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7072150","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7072246","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7072432","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7072779","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7073619","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7074286","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7074559","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7074703","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7074867","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7075258","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7076114","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7076759","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7077047","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7077140","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7077298","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7077609","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7078420","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7079055","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7079337","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7079430","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7079610","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7079956","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7080797","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7081557","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7082269","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7082891","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7083167","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7083260","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7083424","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7083728","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7084629","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7085274","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7085556","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7085653","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7085813","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7086137","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7086996","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7087619","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7087891","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7087984","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7088145","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7088456","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7089242","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7089870","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7090136","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7090226","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7090386","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7090682","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7091419","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7091512","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,7091608","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7091692","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7091759","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7091875","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7091955","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,7092093","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,7092205","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7092266","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7092391","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,7092593","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","" "19:13:28,7093642","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7094319","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7094614","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7094742","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7094912","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7095239","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7096060","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7096698","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7096981","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7097077","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7097234","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7097536","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7098357","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7098988","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7099255","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7099348","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7099543","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7099906","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7100743","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7101378","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7101654","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7101747","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7101907","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7102221","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7103010","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7103633","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7103896","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7103982","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7104136","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7104431","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7105207","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7105817","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7106076","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7106166","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7106327","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7106635","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7107478","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7108180","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7108873","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7109489","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7109758","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7109848","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7110012","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7110310","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7111077","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7111728","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7111997","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7112087","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7112244","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7112536","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7113318","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7113934","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7114204","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7114294","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7114451","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7114743","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7115512","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7116125","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7116388","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7116474","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7116628","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7116914","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7117542","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7117610","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7117728","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters","REPARSE","Desired Access: Read" "19:13:28,7117847","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Parameters","SUCCESS","Desired Access: Read" "19:13:28,7117972","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Winsock\Parameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7118036","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports","SUCCESS","Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda" "19:13:28,7118113","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Parameters\Transports","SUCCESS","Type: REG_MULTI_SZ, Length: 64, Data: vmbus, Psched, Tcpip, Tcpip6, irda" "19:13:28,7118200","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Parameters","SUCCESS","" "19:13:28,7118290","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7118347","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7118444","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,7118527","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,7118652","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7118723","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00" "19:13:28,7118800","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 44, Data: 03 00 00 00 03 00 00 00 22 00 00 00 01 00 00 00" "19:13:28,7118883","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\vmbus\Parameters\Winsock","SUCCESS","" "19:13:28,7118966","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7119021","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7119114","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,7119194","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,7119294","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7119361","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping","BUFFER OVERFLOW","Length: 144" "19:13:28,7119438","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping","BUFFER OVERFLOW","Length: 144" "19:13:28,7119499","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 152, Data: 0C 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00" "19:13:28,7119579","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Psched\Parameters\Winsock","SUCCESS","" "19:13:28,7119659","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7119714","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7119807","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read" "19:13:28,7119890","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Desired Access: Read" "19:13:28,7119990","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7120079","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,7120147","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched","SUCCESS","Desired Access: Read" "19:13:28,7120230","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched\WinSock 2.0 Provider ID","SUCCESS","Type: REG_BINARY, Length: 16, Data: E0 A9 60 9D 7A 33 D0 11 BD 88 00 00 C0 82 E6 9A" "19:13:28,7120310","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Psched","SUCCESS","" "19:13:28,7120371","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","" "19:13:28,7120451","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7120506","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7120596","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,7120673","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,7120779","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7120846","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00" "19:13:28,7120923","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\Mapping","SUCCESS","Type: REG_BINARY, Length: 104, Data: 08 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00" "19:13:28,7121003","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","" "19:13:28,7121077","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7121128","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7121218","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers","REPARSE","Desired Access: Read" "19:13:28,7121298","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Desired Access: Read" "19:13:28,7121378","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7121452","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,7121516","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip","SUCCESS","Desired Access: Read" "19:13:28,7121629","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip\WinSock 2.0 Provider ID","SUCCESS","Type: REG_BINARY, Length: 16, Data: A0 1A 0F E7 8B AB CF 11 8C A3 00 80 5F 48 A1 92" "19:13:28,7121706","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers\Tcpip","SUCCESS","" "19:13:28,7121766","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers","SUCCESS","" "19:13:28,7121863","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7121924","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7122023","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","REPARSE","Desired Access: Read" "19:13:28,7122103","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","Desired Access: Read" "19:13:28,7122187","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7122251","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\MinSockaddrLength","SUCCESS","Type: REG_DWORD, Length: 4, Data: 16" "19:13:28,7122325","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\MaxSockaddrLength","SUCCESS","Type: REG_DWORD, Length: 4, Data: 16" "19:13:28,7122389","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock\UseDelayedAcceptance","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,7122498","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock","SUCCESS","" "19:13:28,7123851","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 6300" "19:13:28,7124775","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 055, Length: 46" "19:13:28,7125878","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 723, Length: 31" "19:13:28,7126295","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 101, Length: 46" "19:13:28,7126988","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 754, Length: 31" "19:13:28,7127331","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 147, Length: 46" "19:13:28,7127985","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 785, Length: 31" "19:13:28,7364220","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 193, Length: 46" "19:13:28,7365346","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 816, Length: 31" "19:13:28,7367578","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7367662","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7367790","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Hvsi","REPARSE","Desired Access: Read" "19:13:28,7367908","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Hvsi","NAME NOT FOUND","Desired Access: Read" "19:13:28,7369037","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7369798","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7370192","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7370317","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7370513","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7370975","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7371853","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7372521","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7372803","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7372899","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7373063","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7373370","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7374224","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7374878","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7375160","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7375253","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7375449","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7375782","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7376629","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7377277","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7377566","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7377694","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7377857","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7378194","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7378999","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7379637","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7379926","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7380045","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7380208","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7380603","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7381700","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7382425","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7382739","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7382845","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7383028","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7383368","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7384221","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7384974","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7385783","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7386430","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7386758","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7386854","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7387030","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7387364","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7388204","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7388990","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7389295","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7389397","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7389619","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7389978","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7390837","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7391492","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7391819","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7391915","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7392091","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7392412","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7393230","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7393862","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7394134","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7394227","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7394388","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7394699","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7399170","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7399253","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7399372","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SecurityProviders","REPARSE","Desired Access: Read" "19:13:28,7399484","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SecurityProviders","SUCCESS","Desired Access: Read" "19:13:28,7399632","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\SecurityProviders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7399718","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\SecurityProviders\SecurityProviders","SUCCESS","Type: REG_SZ, Length: 24, Data: credssp.dll" "19:13:28,7399805","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\SecurityProviders\SecurityProviders","SUCCESS","Type: REG_SZ, Length: 24, Data: credssp.dll" "19:13:28,7399911","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\SecurityProviders","SUCCESS","" "19:13:28,7400023","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7400084","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7400183","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache","REPARSE","Desired Access: Read" "19:13:28,7400267","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache","SUCCESS","Desired Access: Read" "19:13:28,7400376","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7400462","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,7400533","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll","SUCCESS","Desired Access: Read" "19:13:28,7400671","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Name","SUCCESS","Type: REG_SZ, Length: 16, Data: CREDSSP" "19:13:28,7400735","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Name","SUCCESS","Type: REG_SZ, Length: 16, Data: CREDSSP" "19:13:28,7400799","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Comment","SUCCESS","Type: REG_SZ, Length: 72, Data: Microsoft CredSSP Security Provider" "19:13:28,7400860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Comment","SUCCESS","Type: REG_SZ, Length: 72, Data: Microsoft CredSSP Security Provider" "19:13:28,7400921","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Capabilities","SUCCESS","Type: REG_DWORD, Length: 4, Data: 8455987" "19:13:28,7400982","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\RpcId","SUCCESS","Type: REG_DWORD, Length: 4, Data: 65535" "19:13:28,7401040","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:28,7401097","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 33" "19:13:28,7401158","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\TokenSize","SUCCESS","Type: REG_DWORD, Length: 4, Data: 73032" "19:13:28,7401245","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache","SUCCESS","" "19:13:28,7401312","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll","SUCCESS","" "19:13:28,7401424","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7401482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7401649","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles","REPARSE","Desired Access: Read" "19:13:28,7401745","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles","SUCCESS","Desired Access: Read" "19:13:28,7401999","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7402104","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles","SUCCESS","Index: 0, Name: GSSAPI, Type: REG_SZ, Length: 18, Data: Kerberos" "19:13:28,7402223","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles","NO MORE ENTRIES","Index: 1, Length: 1 040" "19:13:28,7402313","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles","SUCCESS","" "19:13:28,7403448","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\schannel.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 19:44:29, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 409 600, EndOfFile: 406 016, FileAttributes: A" "19:13:28,7404199","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\schannel.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7404645","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\schannel.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7405895","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\schannel.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7406322","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\schannel.dll","SUCCESS","Image Base: 0x736c0000, Image Size: 0x68000" "19:13:28,7408282","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\schannel.dll","SUCCESS","" "19:13:28,7409491","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\schannel.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7409869","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\schannel.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,7409994","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\schannel.dll","SUCCESS","Information: Owner" "19:13:28,7410103","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\schannel.dll","SUCCESS","" "19:13:28,7411322","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,7411864","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","REPARSE","Desired Access: Read" "19:13:28,7411996","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","SUCCESS","Desired Access: Read" "19:13:28,7412172","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7412252","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider\EnableTlsExternalAlgorithms","NAME NOT FOUND","Length: 20" "19:13:28,7412342","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","SUCCESS","" "19:13:28,7413368","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7414064","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7414379","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7414488","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7414664","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7415043","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7415918","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7416954","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7417329","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7417432","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7417596","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7417952","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7418898","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7419562","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7419857","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7419963","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7420190","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7420524","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7421393","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7422278","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7422663","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7422772","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7423035","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7423362","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7424241","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7424895","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7425181","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7425287","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7425460","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7425781","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7426592","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7427355","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7427660","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7427791","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7427955","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7428269","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7429344","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7430158","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,7430925","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7431608","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7431929","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7432057","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7432237","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7432583","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7433468","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,7434116","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7434424","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7434533","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7434732","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7435040","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,7435864","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7436579","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7436858","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7436951","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7437125","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7437513","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7438395","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,7439049","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7439341","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7439440","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7439604","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7439944","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,7440688","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,7440800","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,7440938","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel","REPARSE","Desired Access: Read" "19:13:28,7441057","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,7441188","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,7441268","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\UserContextLockCount","NAME NOT FOUND","Length: 144" "19:13:28,7441339","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\UserContextListCount","NAME NOT FOUND","Length: 144" "19:13:28,7441426","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL","SUCCESS","" "19:13:28,7444909","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 239, Length: 46" "19:13:28,7445996","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 847, Length: 31" "19:13:28,7658474","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 285, Length: 46" "19:13:28,7660469","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 878, Length: 31" "19:13:28,7687471","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 331, Length: 46" "19:13:28,7688344","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 909, Length: 31" "19:13:28,7699111","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 377, Length: 46" "19:13:28,7699855","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 940, Length: 31" "19:13:28,7713191","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 423, Length: 46" "19:13:28,7714021","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 1 971, Length: 31" "19:13:28,7715708","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 469, Length: 46" "19:13:28,7716523","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 002, Length: 31" "19:13:28,7739112","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 515, Length: 46" "19:13:28,7740061","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 033, Length: 31" "19:13:28,7985754","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7986492","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7986893","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7987024","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7987220","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7987579","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7988512","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,7989151","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7989423","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7989516","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7989673","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7989994","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,7990838","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7991492","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7991777","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7991870","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7992031","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7992367","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7993163","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,7993788","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7994051","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7994141","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7994295","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7994593","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,7995369","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7995992","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7996255","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7996344","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7996505","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7996813","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7997608","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,7998224","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,7998481","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,7998567","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,7998721","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,7999007","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,7999792","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8000517","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8001213","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8001842","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8002124","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8002214","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8002371","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8002669","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8003442","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8004048","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8004308","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8004395","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8004545","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8004834","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8005710","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8006335","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8006614","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8006704","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8006861","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8007204","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8007984","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8008603","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8008862","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8008952","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8009103","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8009408","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8010739","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 19:44:29, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:43:30, AllocationSize: 53 248, EndOfFile: 49 664, FileAttributes: A" "19:13:28,8011403","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8011601","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\mskeyprotect.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8036560","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8037026","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","Image Base: 0x736b0000, Image Size: 0x10000" "19:13:28,8037866","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","" "19:13:28,8038472","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:01:20, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 122 880, EndOfFile: 119 416, FileAttributes: A" "19:13:28,8039190","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8039521","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ncrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8041782","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8042109","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","Image Base: 0x734a0000, Image Size: 0x20000" "19:13:28,8042786","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","" "19:13:28,8043450","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:01:20, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 180 224, EndOfFile: 177 704, FileAttributes: A" "19:13:28,8044165","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8044482","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ntasn1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8046243","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8046577","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","Image Base: 0x731c0000, Image Size: 0x2c000" "19:13:28,8047141","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","" "19:13:28,8048225","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8048540","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ntasn1.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,8048655","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","Information: Owner" "19:13:28,8048758","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","" "19:13:28,8049704","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8049973","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ncrypt.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,8050069","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","Information: Owner" "19:13:28,8050163","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","" "19:13:28,8051147","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8051336","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\mskeyprotect.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,8051426","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","Information: Owner" "19:13:28,8051513","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","" "19:13:28,8053075","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8053735","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8054380","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8054499","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8054884","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8055259","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8056186","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8056853","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8057148","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8057241","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8057401","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8057709","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8058575","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8059313","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8059595","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8059688","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8059842","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8060163","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8060958","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8061584","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8061853","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8061943","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8062895","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8063229","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8064072","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8064711","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8064990","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8065080","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8065237","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8065548","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8066337","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8066956","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8067228","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8067318","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8067472","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8067767","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8068569","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8069304","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8070006","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8070635","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8070907","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8070997","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8071154","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8071478","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8072495","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8073274","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8073576","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8073678","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8073851","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8074182","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8075038","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8075715","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8076007","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8076103","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8076266","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8076581","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8077514","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8078310","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8078582","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8078675","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8078896","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8079233","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8080516","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:28,8080693","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:28,8080879","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:28,8080975","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:28,8081074","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:28,8081199","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:28,8082248","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:44:29, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:32, AllocationSize: 106 496, EndOfFile: 104 864, FileAttributes: A" "19:13:28,8082966","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8083172","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ncryptsslp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8083794","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8084153","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","Image Base: 0x731a0000, Image Size: 0x1b000" "19:13:28,8084997","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","" "19:13:28,8085869","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8086074","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ncryptsslp.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,8086180","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","Information: Owner" "19:13:28,8086273","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","" "19:13:28,8086956","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","REPARSE","Desired Access: Read" "19:13:28,8087078","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","SUCCESS","Desired Access: Read" "19:13:28,8087216","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8087296","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider\EnableTlsExternalAlgorithms","NAME NOT FOUND","Length: 20" "19:13:28,8087389","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers\Microsoft SSL Protocol Provider","SUCCESS","" "19:13:28,8088153","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8088817","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8089185","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8089285","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8089455","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8089772","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8090616","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8091466","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8091754","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8091851","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8092014","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8092348","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8093194","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8093913","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8094214","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8094349","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8094519","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8094888","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8095763","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8096504","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8096793","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8096889","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8097056","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8097396","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8098236","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8098878","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8099147","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8099240","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8099394","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8099692","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8100472","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8101081","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8101341","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8101431","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8101585","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8101886","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8102778","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8103554","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8104372","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8105132","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8105408","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8105501","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8105668","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8105972","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8106755","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8107383","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8107640","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8107727","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8107887","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8108176","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8108955","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8109622","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8109885","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8109972","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8110129","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8110414","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8111190","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8111848","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8112121","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8112210","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8112361","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8112650","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8113426","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:28,8113561","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:28,8113705","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:28,8113804","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:28,8113907","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:28,8114026","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:28,8114491","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:28,8114597","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:28,8114715","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:28,8114805","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:28,8114898","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:28,8115004","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:28,8115761","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 561, Length: 46" "19:13:28,8116848","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 064, Length: 31" "19:13:28,8118070","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 607, Length: 46" "19:13:28,8118814","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 095, Length: 31" "19:13:28,8119077","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 653, Length: 46" "19:13:28,8119735","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 126, Length: 31" "19:13:28,8119978","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 699, Length: 46" "19:13:28,8120601","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 157, Length: 31" "19:13:28,8120915","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 745, Length: 46" "19:13:28,8121540","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 188, Length: 31" "19:13:28,8121784","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 791, Length: 46" "19:13:28,8122406","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 219, Length: 31" "19:13:28,8385249","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 837, Length: 46" "19:13:28,8386442","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 250, Length: 31" "19:13:28,8386762","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 883, Length: 46" "19:13:28,8387497","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 281, Length: 31" "19:13:28,8387766","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 929, Length: 46" "19:13:28,8388414","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 312, Length: 31" "19:13:28,8388677","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 2 975, Length: 46" "19:13:28,8389309","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 343, Length: 31" "19:13:28,8389662","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 3 021, Length: 112" "19:13:28,8389816","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 3 133, Length: 41" "19:13:28,8389957","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","Offset: 3 174, Length: 48" "19:13:28,8390598","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 374, Length: 33" "19:13:28,8391644","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8391907","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8404444","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Offset: 0, Length: 4 563 888, Priority: Normal" "19:13:28,8417363","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","" "19:13:28,8418777","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8419028","EasyAntiCheat_launcher.exe","6076","QueryAttributeTagFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Attributes: ANCI, ReparseTag: 0x0" "19:13:28,8419185","EasyAntiCheat_launcher.exe","6076","SetDispositionInformationFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Delete: True" "19:13:28,8419358","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","" "19:13:28,8425570","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8425782","EasyAntiCheat_launcher.exe","6076","QueryAttributeTagFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Attributes: ANCI, ReparseTag: 0x0" "19:13:28,8425910","EasyAntiCheat_launcher.exe","6076","SetDispositionInformationFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Delete: True" "19:13:28,8426045","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","" "19:13:28,8546982","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0, OpenResult: Created" "19:13:28,8547909","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Offset: 0, Length: 4 563 888, Priority: Normal" "19:13:28,8562652","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","" "19:13:28,8564166","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\wintrust.dll","SUCCESS","Image Base: 0x74d90000, Image Size: 0x46000" "19:13:28,8566870","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\wintrust.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8567284","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\wintrust.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,8567406","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\wintrust.dll","SUCCESS","Information: Owner" "19:13:28,8567508","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\wintrust.dll","SUCCESS","" "19:13:28,8568390","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\de5dcaee-6f88-585a-05ee-d8b05b912772","NAME NOT FOUND","Length: 524" "19:13:28,8569061","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8569141","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8569317","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\msasn1","NAME NOT FOUND","Desired Access: Read" "19:13:28,8570279","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8570982","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8571318","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8571437","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8571623","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8572034","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8572961","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8573608","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8573881","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8573974","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8574128","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8574449","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8575295","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8575947","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8576226","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8576312","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8576469","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8576780","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8577608","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8578233","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8578496","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8578583","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8578750","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8579051","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8579843","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8580475","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8580748","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8580838","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8580995","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8581312","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8582265","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8582932","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8583198","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8583291","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8583448","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8583740","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8584613","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8585405","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8586136","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8586768","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8587047","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8587162","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8587323","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8587631","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8588426","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8589045","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8589311","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8589398","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8589545","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8589834","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8590703","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8591338","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8591614","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8591704","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8591855","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8592188","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8592977","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8593596","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8593856","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8593943","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8594090","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8594398","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8595681","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8596310","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8596579","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8596669","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8596819","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8597111","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8597910","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8598526","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8598786","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8598872","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8599023","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8599305","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8600101","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8600723","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8600983","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8601072","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8601220","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8601509","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8602301","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8602913","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8603167","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8603256","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8603401","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8603686","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8604450","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8605065","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8605325","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8605412","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8605556","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8605970","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8606877","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8607580","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8607865","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8607962","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8608125","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8608446","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8609273","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8609995","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8610694","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8611323","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8611605","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8611698","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8611855","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8612166","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8612958","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8613577","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8613844","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8613930","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8614084","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8614376","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8615236","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8615916","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8616185","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8616275","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8616429","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8616717","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8617506","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8618119","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8618382","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8618469","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8618623","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8618911","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8620223","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8620454","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: 4f722c31-2ba4-4db9-66e6-f4f2774da99e, 2: 4f722c31-2ba4-4db9-66e6-f4f2774da99e" "19:13:28,8620759","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp","SUCCESS","" "19:13:28,8621313","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8621394","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8621557","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8621811","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8621894","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8621977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 50, Data: WintrustCertificateTrust" "19:13:28,8622086","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8622186","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8622240","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8622365","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8622503","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8622564","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8622632","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 40, Data: SoftpubAuthenticode" "19:13:28,8622712","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8622792","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8622843","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8622959","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8623090","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8623151","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8623215","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 36, Data: SoftpubInitialize" "19:13:28,8623292","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8623372","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8623424","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8623536","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8623661","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8623716","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8623777","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 38, Data: SoftpubLoadMessage" "19:13:28,8623850","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8623924","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8623979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8624084","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8624219","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8624274","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8624335","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 42, Data: SoftpubLoadSignature" "19:13:28,8624405","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8624482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8624534","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8624643","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8624761","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8624816","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8624873","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 34, Data: SoftpubCheckCert" "19:13:28,8624947","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8625024","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8625076","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8625188","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","NAME NOT FOUND","Desired Access: Read" "19:13:28,8625319","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8625371","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8625470","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8625586","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8625637","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8625698","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 30, Data: SoftpubCleanup" "19:13:28,8625768","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:28,8626131","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8626188","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8626304","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,8626419","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8626487","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 24" "19:13:28,8626554","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8626615","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8626679","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8626737","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8627574","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8628248","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8628543","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8628642","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8628822","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8629139","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8629970","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8630608","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8630881","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8630971","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8631124","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8631423","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8632250","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8632879","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8633145","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8633235","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8633389","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8633687","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8634473","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8635092","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8635352","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8635441","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8635592","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8635903","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8636689","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8637311","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8637574","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8637664","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8637815","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8638107","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8638870","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8639473","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8639726","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8639816","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8639967","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8640252","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8641029","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8641724","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8642424","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8643039","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8643302","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8643389","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8643540","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8643832","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8644598","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8645204","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8645464","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8645551","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8645702","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8645990","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8646763","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8647385","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8647645","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8647735","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8647886","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8648168","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8648931","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8649592","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8649852","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8649938","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8650089","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8650375","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8651096","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8651183","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,8651295","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8651366","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8651439","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8651513","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8651580","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8651693","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,8651799","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8651856","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8651978","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,8652203","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8652257","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8652369","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\DESHashSessionKeyBackward","NAME NOT FOUND","Desired Access: Read" "19:13:28,8652485","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","" "19:13:28,8652738","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8652860","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8652915","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,8653004","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8653136","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8653187","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8653300","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,8653441","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8653514","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8653575","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State","SUCCESS","Type: REG_DWORD, Length: 4, Data: 146432" "19:13:28,8653652","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","" "19:13:28,8653797","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8653851","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,8653941","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8654056","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8654111","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8654201","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Internet Explorer\Security","SUCCESS","Desired Access: Read" "19:13:28,8654297","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Internet Explorer\Security","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8654361","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8654419","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Internet Explorer\Security\Safety Warning Level","SUCCESS","Type: REG_SZ, Length: 12, Data: Query" "19:13:28,8654496","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Internet Explorer\Security","SUCCESS","" "19:13:28,8654592","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8654647","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8654756","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,8654855","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,8655076","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8655134","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,8655221","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8655320","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8655371","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8655461","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,8655561","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8655631","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8655683","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8655788","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,8655878","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,8656231","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8656286","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8656375","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32","REPARSE","Desired Access: Read" "19:13:28,8656468","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","Desired Access: Read" "19:13:28,8656565","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8656622","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\crypt32\DiagLevel","NAME NOT FOUND","Length: 144" "19:13:28,8656680","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\crypt32\DiagMatchAnyMask","NAME NOT FOUND","Length: 144" "19:13:28,8656744","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","" "19:13:28,8656818","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8656869","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8656953","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32","REPARSE","Desired Access: Read" "19:13:28,8657026","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","Desired Access: Read" "19:13:28,8657107","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8657854","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 5700" "19:13:28,8658736","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8659025","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8659137","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8659198","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8659310","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:28,8659461","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8659557","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8659720","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8660147","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8660205","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8660311","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8660416","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8660503","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8660615","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8660683","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8660821","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en-US","NAME NOT FOUND","Length: 90" "19:13:28,8660926","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en","NAME NOT FOUND","Length: 90" "19:13:28,8661096","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8661164","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Desired Access: Read" "19:13:28,8661273","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 0, Name: {000C10F1-0000-0000-C000-000000000046}" "19:13:28,8661379","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8661443","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Desired Access: Read" "19:13:28,8661561","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8661645","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\MSISIP.DLL" "19:13:28,8661712","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: MsiSIPPutSignedDataMsg" "19:13:28,8661847","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","" "19:13:28,8661914","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 1, Name: {06C9E010-38CE-11D4-A2A3-00104BD35090}" "19:13:28,8662014","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8662081","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:28,8662203","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8662267","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8662325","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: PutSignedDataMsg" "19:13:28,8662431","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:28,8662495","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 2, Name: {0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}" "19:13:28,8662594","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8662662","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Desired Access: Read" "19:13:28,8662771","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8662832","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8662892","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: AppxSipPutSignedDataMsg" "19:13:28,8662998","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","" "19:13:28,8663059","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 3, Name: {0F5F58B3-AADE-4B9A-A434-95742D92ECEB}" "19:13:28,8663152","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8663220","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Desired Access: Read" "19:13:28,8663329","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8663390","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8663451","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: AppxBundleSipPutSignedDataMsg" "19:13:28,8663550","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","" "19:13:28,8663611","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 4, Name: {1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}" "19:13:28,8663707","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8663774","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Desired Access: Read" "19:13:28,8663884","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8663944","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8664002","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: PutSignedDataMsg" "19:13:28,8664108","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","" "19:13:28,8664172","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 5, Name: {1A610570-38CE-11D4-A2A3-00104BD35090}" "19:13:28,8664262","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8664329","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:28,8664442","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8664503","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8664560","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: PutSignedDataMsg" "19:13:28,8664660","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:28,8664721","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 6, Name: {5598CFF1-68DB-4340-B57F-1CACF88C9A51}" "19:13:28,8664814","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8664881","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Desired Access: Read" "19:13:28,8664987","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8665048","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8665109","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: P7xSipPutSignedDataMsg" "19:13:28,8665221","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","" "19:13:28,8665282","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 7, Name: {603BCC1F-4B59-4E08-B724-D2C6297EF351}" "19:13:28,8665378","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8665445","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Desired Access: Read" "19:13:28,8665551","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8665619","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 112, Data: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll" "19:13:28,8665676","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 30, Data: PsPutSignature" "19:13:28,8665785","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","" "19:13:28,8665846","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 8, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:28,8665939","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8666007","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8666122","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8666186","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8666244","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:28,8666344","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:28,8666408","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 9, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:28,8666501","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8666571","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:28,8666680","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8666741","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:28,8666802","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EsdSipPutSignature" "19:13:28,8666905","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:28,8666966","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 10, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8667056","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8667123","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8667238","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8667299","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8667357","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:28,8667450","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8667514","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 11, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8667610","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8667675","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8667780","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8667841","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8667896","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:28,8667989","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8668053","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 12, Name: {CF78C6DE-64A2-4799-B506-89ADFF5D16D6}" "19:13:28,8668146","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8668210","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Desired Access: Read" "19:13:28,8668313","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8668377","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8668435","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EappxSipPutSignedDataMsg" "19:13:28,8668534","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","" "19:13:28,8668598","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 13, Name: {D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}" "19:13:28,8668691","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8668759","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Desired Access: Read" "19:13:28,8668861","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8668922","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8668983","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 62, Data: EappxBundleSipPutSignedDataMsg" "19:13:28,8669083","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","" "19:13:28,8669143","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 14, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8669236","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8669304","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8669406","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8669467","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8669525","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:28,8669618","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8669682","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 15, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8669775","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8669839","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8669948","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8670009","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8670067","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:28,8670157","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8670221","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","NO MORE ENTRIES","Index: 16, Length: 288" "19:13:28,8670295","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","" "19:13:28,8670353","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8670414","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8670507","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8670577","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8670693","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8670757","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllPutSignedDataMsg","NAME NOT FOUND","Desired Access: Read" "19:13:28,8670840","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8670901","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8670975","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8671812","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8672524","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8672819","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8672918","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8673082","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8673441","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8674298","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8674939","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8675224","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8675321","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8675475","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8675786","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8676632","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8677280","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8677556","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8677646","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8677800","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8678124","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8678919","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8679545","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8679808","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8679897","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8680048","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8680362","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8681145","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8681793","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8682059","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8682159","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8682316","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8682633","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8683416","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8684032","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8684291","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8684378","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8684529","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8684833","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8685629","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8686338","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8687043","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8687685","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8687957","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8688050","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8688207","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8688512","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8689292","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8689917","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8690180","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8690311","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8690549","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8690902","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8691703","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8692345","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8692624","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8692714","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8692871","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8693201","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8694000","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8694612","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8694879","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8694968","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8695119","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8695408","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8696713","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8697358","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8697624","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8697711","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8697865","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8698160","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8698933","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8699545","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8699802","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8699888","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8700039","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8700315","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8701107","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8701723","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8701976","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8702063","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8702226","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8702534","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8703301","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8703910","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8704164","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8704250","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8704404","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8704690","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8705520","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8706130","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8706383","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8706470","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8706620","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8706909","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8707753","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8708359","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8708606","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8708692","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8708840","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8709129","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8709895","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8710796","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8712175","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8713292","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8713651","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8713760","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8714190","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8714539","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8715527","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8716197","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8716473","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8716563","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8716720","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8717044","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8717872","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8718737","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8719020","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8719110","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8719263","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8719571","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8720354","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8721037","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8721704","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8721823","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8721993","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8722355","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8723459","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 4140" "19:13:28,8723725","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8723815","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8723988","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8724174","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8724286","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8724501","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8724588","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8724812","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8724883","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Desired Access: Read" "19:13:28,8725011","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 0, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:28,8725142","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8725216","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8725332","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8725421","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:28,8725495","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:28,8725707","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:28,8725787","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 1, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:28,8725890","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8725970","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:28,8726069","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8726137","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:28,8726198","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 28, Data: EsdSipGetCaps" "19:13:28,8726310","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:28,8726374","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 2, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8726470","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8726541","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8726627","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8726688","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:28,8726746","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:28,8726855","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8726919","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 3, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8727015","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8727083","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8727182","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8727243","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:28,8727304","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:28,8727404","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8727468","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 4, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8727561","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8727628","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8727715","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8727772","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:28,8727849","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:28,8727955","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8728019","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 5, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8728116","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8728183","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8728270","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8728330","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:28,8728388","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:28,8728484","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8728549","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","NO MORE ENTRIES","Index: 6, Length: 288" "19:13:28,8728622","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","" "19:13:28,8728683","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8728747","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8728866","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8728937","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8729058","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8729123","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetCaps","NAME NOT FOUND","Desired Access: Read" "19:13:28,8729216","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8729280","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8729354","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8730431","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8731153","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8731509","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8731618","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8731794","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8732160","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8733016","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8733667","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8733950","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8734039","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8734197","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8734501","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8735348","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8735996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8736278","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8736368","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8736525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8736849","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8737664","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8738299","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8738565","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8738651","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8738805","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8739113","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8739905","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8740621","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8740890","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8740980","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8741134","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8741471","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8742276","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8742891","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8743154","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8743244","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8743395","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8743687","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8744489","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8745220","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8745922","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8746551","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8746824","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8746910","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8747067","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8747382","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8748167","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8748790","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8749053","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8749139","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8749293","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8749585","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8750380","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8751006","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8751282","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8751371","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8751525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8751817","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8752603","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8753219","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8753479","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8753568","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8753719","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8754005","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8754925","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8755005","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8755162","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8755310","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8755406","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8755538","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8755615","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8755772","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8755842","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Desired Access: Read" "19:13:28,8755948","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 0, Name: {000C10F1-0000-0000-C000-000000000046}" "19:13:28,8756054","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8756121","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Desired Access: Read" "19:13:28,8756224","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8756311","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\MSISIP.DLL" "19:13:28,8756378","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: MsiSIPGetSignedDataMsg" "19:13:28,8756538","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","" "19:13:28,8756609","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 1, Name: {06C9E010-38CE-11D4-A2A3-00104BD35090}" "19:13:28,8756708","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8756779","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:28,8756869","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8756936","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8756994","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: GetSignedDataMsg" "19:13:28,8757109","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:28,8757186","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 2, Name: {0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}" "19:13:28,8757408","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8757478","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Desired Access: Read" "19:13:28,8757568","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8757632","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8757693","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: AppxSipGetSignedDataMsg" "19:13:28,8757825","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","" "19:13:28,8757889","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 3, Name: {0F5F58B3-AADE-4B9A-A434-95742D92ECEB}" "19:13:28,8757988","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8758055","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Desired Access: Read" "19:13:28,8758142","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8758203","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8758261","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: AppxBundleSipGetSignedDataMsg" "19:13:28,8758367","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","" "19:13:28,8758431","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 4, Name: {1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}" "19:13:28,8758524","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8758594","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Desired Access: Read" "19:13:28,8758678","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8758739","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8758800","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: GetSignedDataMsg" "19:13:28,8758899","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","" "19:13:28,8758960","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 5, Name: {1A610570-38CE-11D4-A2A3-00104BD35090}" "19:13:28,8759053","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8759120","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:28,8759204","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8759265","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8759322","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: GetSignedDataMsg" "19:13:28,8759422","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:28,8759486","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 6, Name: {5598CFF1-68DB-4340-B57F-1CACF88C9A51}" "19:13:28,8759579","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8759646","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Desired Access: Read" "19:13:28,8759730","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8759791","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8759848","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: P7xSipGetSignedDataMsg" "19:13:28,8759948","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","" "19:13:28,8760009","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 7, Name: {603BCC1F-4B59-4E08-B724-D2C6297EF351}" "19:13:28,8760102","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8760169","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Desired Access: Read" "19:13:28,8760249","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8760317","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 112, Data: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll" "19:13:28,8760378","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 30, Data: PsGetSignature" "19:13:28,8760487","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","" "19:13:28,8760547","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 8, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:28,8760640","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8760708","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8760791","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8760852","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8760913","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:28,8761006","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:28,8761067","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 9, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:28,8761160","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8761227","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:28,8761314","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8761372","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:28,8761429","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EsdSipGetSignature" "19:13:28,8761526","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:28,8761587","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 10, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8761676","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8761744","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8761827","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8761885","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8761943","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:28,8762036","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8762097","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 11, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8762199","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8762267","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8762350","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8762408","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8762465","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:28,8762558","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8762623","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 12, Name: {CF78C6DE-64A2-4799-B506-89ADFF5D16D6}" "19:13:28,8762712","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8762780","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Desired Access: Read" "19:13:28,8762863","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8762921","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8762982","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EappxSipGetSignedDataMsg" "19:13:28,8763078","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","" "19:13:28,8763139","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 13, Name: {D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}" "19:13:28,8763245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8763312","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Desired Access: Read" "19:13:28,8763399","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8763460","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8763517","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 62, Data: EappxBundleSipGetSignedDataMsg" "19:13:28,8763620","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","" "19:13:28,8763678","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 14, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8763771","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8763838","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8763922","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8763979","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8764037","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:28,8764130","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8764191","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 15, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8764281","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8764348","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8764428","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8764486","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8764544","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:28,8764637","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8764698","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","NO MORE ENTRIES","Index: 16, Length: 288" "19:13:28,8764771","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","" "19:13:28,8764829","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8764890","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8764986","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8765054","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8765166","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8765233","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetSignedDataMsg","NAME NOT FOUND","Desired Access: Read" "19:13:28,8765320","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8765384","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8765455","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8766006","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\imagehlp.dll","SUCCESS","Image Base: 0x74010000, Image Size: 0x19000" "19:13:28,8767985","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\imagehlp.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8768306","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\imagehlp.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,8768421","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\imagehlp.dll","SUCCESS","Information: Owner" "19:13:28,8768521","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\imagehlp.dll","SUCCESS","" "19:13:28,8769829","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8770496","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8770792","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8770894","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8771064","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8771385","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8772219","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8772851","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8773126","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8773219","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8773377","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8773678","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8774515","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8775163","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8775436","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8775529","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8775686","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8776000","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8776799","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8777437","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8777697","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8777787","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8777941","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8778268","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8779050","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8779679","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8779942","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8780032","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8780189","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8780506","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8782030","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8782925","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8783961","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8784256","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8784483","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8785035","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8786456","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8787309","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8788085","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8788759","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8789208","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8789314","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8789487","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8789856","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8790712","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8791357","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8791639","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8791735","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8791905","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8792720","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8793970","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8794795","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8795135","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8795247","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8795436","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8795786","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8796835","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8797617","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8797912","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8798012","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8798191","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8798509","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8799654","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8799772","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8799862","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8800023","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8800472","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8800725","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8800821","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8800905","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8801068","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8801363","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8801437","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8801581","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:28,8806055","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8806110","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8806219","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:28,8806713","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8806771","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8806896","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:28,8807056","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8807133","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 24" "19:13:28,8807223","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8807287","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8807351","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8807409","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:28,8808262","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8808942","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8809247","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8809346","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8809513","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8809830","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8810648","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,8811283","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8811556","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8811646","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8811800","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8812114","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,8812964","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8813605","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8813881","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8813974","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8814128","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8814439","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8815219","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,8815841","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8816104","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8816190","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8816341","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8816639","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,8817428","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8818054","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8818320","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8818410","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8818567","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8818862","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8819632","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,8820244","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8820504","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8820591","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8820742","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8821021","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,8821803","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8822531","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,8823221","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8823840","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8824116","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8824202","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8824359","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8824651","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8825482","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,8826094","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8826357","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8826447","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8826598","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8826880","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,8827663","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8828282","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8828548","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8828635","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8828785","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8829074","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8829831","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,8830440","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8830700","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8830787","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,8830937","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8831236","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,8831970","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8832057","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:28,8832179","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8832252","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8832326","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8832403","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8832474","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:28,8832589","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:28,8832695","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8832753","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8832875","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:28,8833099","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8833154","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8833266","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\DESHashSessionKeyBackward","NAME NOT FOUND","Desired Access: Read" "19:13:28,8833378","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","" "19:13:28,8833869","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8833927","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8834036","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8834138","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8834231","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8834302","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8834433","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8834501","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Desired Access: Read" "19:13:28,8834610","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Index: 0, Name: 1.3.6.1.4.1.311.64.1.1!7" "19:13:28,8834719","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8834786","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Desired Access: Read" "19:13:28,8834911","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Query: Cached, SubKeys: 0, Values: 1" "19:13:28,8834995","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Index: 0, Name: Name, Type: REG_SZ, Length: 78, Data: @%SystemRoot%\system32\dnsapi.dll,-103" "19:13:28,8835117","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8835171","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8835290","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Desired Access: Read" "19:13:28,8835399","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8835463","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name","SUCCESS","Type: REG_SZ, Length: 78, Data: @%SystemRoot%\system32\dnsapi.dll,-103" "19:13:28,8835630","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:28,8835732","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:28,8835845","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8835899","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:28,8835983","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:28,8836140","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8836274","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8836332","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8836432","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","REPARSE","Desired Access: Read/Write" "19:13:28,8836521","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:28,8836634","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8836698","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8836781","EasyAntiCheat_launcher.exe","6076","RegSetValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:28,8837573","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:09:43, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 598 016, EndOfFile: 597 160, FileAttributes: A" "19:13:28,8837727","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\dnsapi.dll,-103","SUCCESS","Type: REG_SZ, Length: 76, Data: Domain Name System (DNS) Server Trust" "19:13:28,8837820","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:28,8837891","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name","SUCCESS","Type: REG_SZ, Length: 78, Data: @%SystemRoot%\system32\dnsapi.dll,-103" "19:13:28,8838032","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:28,8838115","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:28,8838202","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8838256","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:28,8838324","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:28,8838449","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8838564","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8838622","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8838715","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","REPARSE","Desired Access: Read/Write" "19:13:28,8838792","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:28,8838875","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8838936","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8839004","EasyAntiCheat_launcher.exe","6076","RegSetValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:28,8839690","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:09:43, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 598 016, EndOfFile: 597 160, FileAttributes: A" "19:13:28,8839825","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\dnsapi.dll,-103","SUCCESS","Type: REG_SZ, Length: 76, Data: Domain Name System (DNS) Server Trust" "19:13:28,8839911","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:28,8840001","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","" "19:13:28,8840078","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","" "19:13:28,8840149","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Index: 1, Name: 1.3.6.1.4.1.311.80.1!7" "19:13:28,8840264","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8840338","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Desired Access: Read" "19:13:28,8840457","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Query: Cached, SubKeys: 0, Values: 1" "19:13:28,8840572","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Index: 0, Name: Name, Type: REG_SZ, Length: 132, Data: @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124" "19:13:28,8840697","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8840752","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8840870","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Desired Access: Read" "19:13:28,8840973","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8841037","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7\Name","SUCCESS","Type: REG_SZ, Length: 132, Data: @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124" "19:13:28,8841165","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:28,8841249","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:28,8841332","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8841387","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:28,8841454","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:28,8841582","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8841695","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8841749","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8841845","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","REPARSE","Desired Access: Read/Write" "19:13:28,8841922","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:28,8842006","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8842067","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8842131","EasyAntiCheat_launcher.exe","6076","RegSetValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:28,8843138","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:43:19, LastAccessTime: 2021. 02. 13. 20:09:40, LastWriteTime: 2017. 09. 29. 15:43:19, ChangeTime: 2020. 01. 12. 12:29:30, AllocationSize: 434 176, EndOfFile: 431 616, FileAttributes: A" "19:13:28,8843507","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124","SUCCESS","Type: REG_SZ, Length: 40, Data: Document Encryption" "19:13:28,8843613","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:28,8843683","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7\Name","SUCCESS","Type: REG_SZ, Length: 132, Data: @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124" "19:13:28,8843828","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:28,8843921","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:28,8844007","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8844062","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:28,8844129","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:28,8844254","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,8844366","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8844424","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,8844517","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","REPARSE","Desired Access: Read/Write" "19:13:28,8844594","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:28,8844677","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8844738","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,8844803","EasyAntiCheat_launcher.exe","6076","RegSetValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:28,8845479","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:43:19, LastAccessTime: 2021. 02. 13. 20:09:40, LastWriteTime: 2017. 09. 29. 15:43:19, ChangeTime: 2020. 01. 12. 12:29:30, AllocationSize: 434 176, EndOfFile: 431 616, FileAttributes: A" "19:13:28,8845614","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124","SUCCESS","Type: REG_SZ, Length: 40, Data: Document Encryption" "19:13:28,8845701","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:28,8845771","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","" "19:13:28,8845871","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","" "19:13:28,8845941","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8846018","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","" "19:13:28,8846079","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8846134","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8846223","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8846294","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Cryptography\ECCParameters","REPARSE","Desired Access: Read" "19:13:28,8846390","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","SUCCESS","Desired Access: Read" "19:13:28,8846480","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8846538","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","NO MORE ENTRIES","Index: 0, Length: 288" "19:13:28,8846608","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","SUCCESS","" "19:13:28,8848670","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\CMF\Config","REPARSE","Desired Access: Read" "19:13:28,8848754","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","Desired Access: Read" "19:13:28,8848860","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8848921","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CMF\Config\SYSTEM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,8848994","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","" "19:13:28,8849751","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,8850014","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8850114","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","SUCCESS","AllocationSize: 40 960, EndOfFile: 40 448, NumberOfLinks: 4, DeletePending: False, Directory: False" "19:13:28,8850287","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\System32\en-US\crypt32.dll.mui","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8853064","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:28,8853193","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:28,8853331","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:28,8853424","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:28,8853517","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:28,8853632","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:28,8854886","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8854970","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8855120","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8855265","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8855348","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8855473","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8855550","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8855691","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8855762","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Desired Access: Read" "19:13:28,8855858","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Index: 0, Name: #16" "19:13:28,8855961","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8856028","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Desired Access: Read" "19:13:28,8856124","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8856208","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll" "19:13:28,8856275","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore" "19:13:28,8856435","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","" "19:13:28,8856499","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Index: 1, Name: Ldap" "19:13:28,8856596","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8856663","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Desired Access: Read" "19:13:28,8856750","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8856817","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll" "19:13:28,8856878","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore" "19:13:28,8856987","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","" "19:13:28,8857048","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8857125","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","" "19:13:28,8857237","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8857301","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8857401","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8857471","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8857590","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8857654","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv","NAME NOT FOUND","Desired Access: Read" "19:13:28,8857744","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8857808","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8857879","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8858000","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8858058","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8858167","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8858263","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8858328","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8858421","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8858488","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8858594","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8858658","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx","NAME NOT FOUND","Desired Access: Read" "19:13:28,8858745","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8858805","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8858892","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8858956","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8859059","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8859120","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Desired Access: Read" "19:13:28,8859219","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 0, Name: 1.2.840.113549.1.9.16.1.1" "19:13:28,8859312","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8859380","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Desired Access: Read" "19:13:28,8859505","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8859575","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8859636","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EssReceiptDecodeEx" "19:13:28,8859752","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","" "19:13:28,8859813","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 1, Name: 1.2.840.113549.1.9.16.2.1" "19:13:28,8859906","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8859973","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Desired Access: Read" "19:13:28,8860085","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8860153","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8860213","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: EssReceiptRequestDecodeEx" "19:13:28,8860313","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","" "19:13:28,8860371","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 2, Name: 1.2.840.113549.1.9.16.2.11" "19:13:28,8860464","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8860534","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Desired Access: Read" "19:13:28,8860640","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8860707","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8860768","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: EssKeyExchPreferenceDecodeEx" "19:13:28,8860865","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","" "19:13:28,8860922","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 3, Name: 1.2.840.113549.1.9.16.2.12" "19:13:28,8861015","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8861079","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Desired Access: Read" "19:13:28,8861185","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8861249","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8861310","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: EssSignCertificateDecodeEx" "19:13:28,8861403","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","" "19:13:28,8861464","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 4, Name: 1.2.840.113549.1.9.16.2.2" "19:13:28,8861557","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8861621","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Desired Access: Read" "19:13:28,8861721","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8861788","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8861846","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EssSecurityLabelDecodeEx" "19:13:28,8861939","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","" "19:13:28,8862000","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 5, Name: 1.2.840.113549.1.9.16.2.3" "19:13:28,8862090","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8862167","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Desired Access: Read" "19:13:28,8862273","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8862337","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8862394","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: EssMLHistoryDecodeEx" "19:13:28,8862491","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","" "19:13:28,8862548","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 6, Name: 1.2.840.113549.1.9.16.2.4" "19:13:28,8862654","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8862722","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Desired Access: Read" "19:13:28,8862831","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8862898","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:28,8862956","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: EssContentHintDecodeEx" "19:13:28,8863052","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","" "19:13:28,8863113","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","NO MORE ENTRIES","Index: 7, Length: 288" "19:13:28,8863183","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","" "19:13:28,8863241","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8863299","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8863369","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8864037","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8864094","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8864207","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8864306","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8864373","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8864470","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8864537","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8864643","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8864710","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObject","NAME NOT FOUND","Desired Access: Read" "19:13:28,8864797","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8864858","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8864947","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8865015","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8865117","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8865178","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Desired Access: Read" "19:13:28,8865268","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 0, Name: #2000" "19:13:28,8865361","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8865425","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Desired Access: Read" "19:13:28,8865531","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8865602","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8865659","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: WVTAsn1SpcSpAgencyInfoDecode" "19:13:28,8865765","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","" "19:13:28,8865826","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 1, Name: #2001" "19:13:28,8865919","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8865987","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Desired Access: Read" "19:13:28,8866086","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8866153","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8866211","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcMinimalCriteriaInfoDecode" "19:13:28,8866314","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","" "19:13:28,8866371","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 2, Name: #2002" "19:13:28,8866464","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8866532","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Desired Access: Read" "19:13:28,8866631","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8866699","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8866756","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 76, Data: WVTAsn1SpcFinancialCriteriaInfoDecode" "19:13:28,8866859","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","" "19:13:28,8866917","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 3, Name: #2003" "19:13:28,8867010","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8867074","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Desired Access: Read" "19:13:28,8867183","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8867250","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8867308","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcIndirectDataContentDecode" "19:13:28,8867404","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","" "19:13:28,8867465","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 4, Name: #2004" "19:13:28,8867555","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8867619","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Desired Access: Read" "19:13:28,8867718","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8867783","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8867840","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1SpcPeImageDataDecode" "19:13:28,8867937","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","" "19:13:28,8867997","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 5, Name: #2005" "19:13:28,8868087","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8868155","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Desired Access: Read" "19:13:28,8868257","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8868318","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8868376","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:28,8868469","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","" "19:13:28,8868530","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 6, Name: #2006" "19:13:28,8868620","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8868687","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Desired Access: Read" "19:13:28,8868786","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8868847","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8868905","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: WVTAsn1SpcStatementTypeDecode" "19:13:28,8869001","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","" "19:13:28,8869062","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 7, Name: #2007" "19:13:28,8869152","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8869216","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Desired Access: Read" "19:13:28,8869319","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8869383","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8869438","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1SpcSpOpusInfoDecode" "19:13:28,8869534","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","" "19:13:28,8869595","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 8, Name: #2008" "19:13:28,8869688","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8869752","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Desired Access: Read" "19:13:28,8869851","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8869912","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8869970","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:28,8870060","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","" "19:13:28,8870124","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 9, Name: #2009" "19:13:28,8870217","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8870281","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Desired Access: Read" "19:13:28,8870387","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8870448","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8870502","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:28,8870595","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","" "19:13:28,8870656","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 10, Name: #2010" "19:13:28,8870746","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8870813","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Desired Access: Read" "19:13:28,8870910","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8870974","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8871032","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 70, Data: WVTAsn1IntentToSealAttributeDecode" "19:13:28,8871128","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","" "19:13:28,8871186","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 11, Name: #2011" "19:13:28,8871275","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8871343","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Desired Access: Read" "19:13:28,8871445","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8871509","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8871567","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingSignatureAttributeDecode" "19:13:28,8871663","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","" "19:13:28,8871724","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 12, Name: #2012" "19:13:28,8871814","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8871878","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Desired Access: Read" "19:13:28,8871994","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8872061","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8872119","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingTimestampAttributeDecode" "19:13:28,8872225","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","" "19:13:28,8872286","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 13, Name: #2130" "19:13:28,8872375","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8872443","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Desired Access: Read" "19:13:28,8872542","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8872603","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8872661","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: WVTAsn1SpcSigInfoDecode" "19:13:28,8872754","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","" "19:13:28,8872815","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 14, Name: #2221" "19:13:28,8872908","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8872972","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Desired Access: Read" "19:13:28,8873071","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8873132","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8873190","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: WVTAsn1CatNameValueDecode" "19:13:28,8873283","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","" "19:13:28,8873344","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 15, Name: #2222" "19:13:28,8873437","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8873501","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Desired Access: Read" "19:13:28,8873601","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8873665","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8873722","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1CatMemberInfoDecode" "19:13:28,8873815","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","" "19:13:28,8873876","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 16, Name: #2223" "19:13:28,8873969","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8874034","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Desired Access: Read" "19:13:28,8874136","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8874197","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8874255","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1CatMemberInfo2Decode" "19:13:28,8874351","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","" "19:13:28,8874409","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 17, Name: 1.3.6.1.4.1.311.12.2.1" "19:13:28,8874502","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8874569","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Desired Access: Read" "19:13:28,8874672","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8874733","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8874791","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: WVTAsn1CatNameValueDecode" "19:13:28,8874928","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","" "19:13:28,8874993","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 18, Name: 1.3.6.1.4.1.311.12.2.2" "19:13:28,8875086","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8875156","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Desired Access: Read" "19:13:28,8875240","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8875300","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8875358","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1CatMemberInfoDecode" "19:13:28,8875454","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","" "19:13:28,8875515","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 19, Name: 1.3.6.1.4.1.311.12.2.3" "19:13:28,8875605","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8875673","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Desired Access: Read" "19:13:28,8875756","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8875817","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8875871","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1CatMemberInfo2Decode" "19:13:28,8875968","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","" "19:13:28,8876029","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 20, Name: 1.3.6.1.4.1.311.16.1.1" "19:13:28,8876118","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8876186","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Desired Access: Read" "19:13:28,8876266","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8876327","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: cryptdlg.dll" "19:13:28,8876381","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: DecodeAttrSequence" "19:13:28,8876484","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","" "19:13:28,8876545","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 21, Name: 1.3.6.1.4.1.311.16.4" "19:13:28,8876638","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8876702","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Desired Access: Read" "19:13:28,8876789","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8876853","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: cryptdlg.dll" "19:13:28,8876911","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: DecodeRecipientID" "19:13:28,8877004","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","" "19:13:28,8877064","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 22, Name: 1.3.6.1.4.1.311.2.1.10" "19:13:28,8877164","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8877231","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Desired Access: Read" "19:13:28,8877311","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8877372","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8877430","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: WVTAsn1SpcSpAgencyInfoDecode" "19:13:28,8877530","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","" "19:13:28,8877590","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 23, Name: 1.3.6.1.4.1.311.2.1.11" "19:13:28,8877680","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8877748","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Desired Access: Read" "19:13:28,8877831","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8877892","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8877950","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: WVTAsn1SpcStatementTypeDecode" "19:13:28,8878043","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","" "19:13:28,8878104","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 24, Name: 1.3.6.1.4.1.311.2.1.12" "19:13:28,8878193","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8878261","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Desired Access: Read" "19:13:28,8878341","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8878402","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8878460","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1SpcSpOpusInfoDecode" "19:13:28,8878556","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","" "19:13:28,8878617","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 25, Name: 1.3.6.1.4.1.311.2.1.15" "19:13:28,8878707","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8878774","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Desired Access: Read" "19:13:28,8878857","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8878918","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8878979","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1SpcPeImageDataDecode" "19:13:28,8879072","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","" "19:13:28,8879133","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 26, Name: 1.3.6.1.4.1.311.2.1.20" "19:13:28,8879223","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8879287","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Desired Access: Read" "19:13:28,8879370","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8879428","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8879486","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:28,8879579","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","" "19:13:28,8879640","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 27, Name: 1.3.6.1.4.1.311.2.1.25" "19:13:28,8879730","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8879797","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Desired Access: Read" "19:13:28,8879877","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8879935","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8880002","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:28,8880099","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","" "19:13:28,8880163","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 28, Name: 1.3.6.1.4.1.311.2.1.26" "19:13:28,8880252","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8880320","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Desired Access: Read" "19:13:28,8880400","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8880464","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8880522","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcMinimalCriteriaInfoDecode" "19:13:28,8880618","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","" "19:13:28,8880679","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 29, Name: 1.3.6.1.4.1.311.2.1.27" "19:13:28,8880769","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8880836","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Desired Access: Read" "19:13:28,8880916","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8880981","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8881038","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 76, Data: WVTAsn1SpcFinancialCriteriaInfoDecode" "19:13:28,8881134","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","" "19:13:28,8881195","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 30, Name: 1.3.6.1.4.1.311.2.1.28" "19:13:28,8881285","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8881353","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Desired Access: Read" "19:13:28,8881433","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8881490","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8881548","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:28,8881641","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","" "19:13:28,8881702","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 31, Name: 1.3.6.1.4.1.311.2.1.30" "19:13:28,8881795","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8881859","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Desired Access: Read" "19:13:28,8881940","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8881997","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8882055","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: WVTAsn1SpcSigInfoDecode" "19:13:28,8882154","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","" "19:13:28,8882219","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 32, Name: 1.3.6.1.4.1.311.2.1.4" "19:13:28,8882308","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8882376","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Desired Access: Read" "19:13:28,8882459","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8882520","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8882581","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcIndirectDataContentDecode" "19:13:28,8882677","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","" "19:13:28,8882738","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 33, Name: 1.3.6.1.4.1.311.2.4.2" "19:13:28,8882828","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8882892","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Desired Access: Read" "19:13:28,8882972","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8883036","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8883094","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 70, Data: WVTAsn1IntentToSealAttributeDecode" "19:13:28,8883194","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","" "19:13:28,8883251","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 34, Name: 1.3.6.1.4.1.311.2.4.3" "19:13:28,8883341","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8883408","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Desired Access: Read" "19:13:28,8883492","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8883553","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8883614","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingSignatureAttributeDecode" "19:13:28,8883710","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","" "19:13:28,8883768","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 35, Name: 1.3.6.1.4.1.311.2.4.4" "19:13:28,8883857","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8883925","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Desired Access: Read" "19:13:28,8884005","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8884066","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8884127","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingTimestampAttributeDecode" "19:13:28,8884220","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","" "19:13:28,8884281","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","NO MORE ENTRIES","Index: 36, Length: 288" "19:13:28,8884351","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","" "19:13:28,8884409","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8884467","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8884537","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8884730","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8884788","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8884897","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,8884993","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,8885060","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,8885153","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8885221","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,8885330","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8885394","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Desired Access: Read" "19:13:28,8885484","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 0, Name: {000C10F1-0000-0000-C000-000000000046}" "19:13:28,8885580","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8885647","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Desired Access: Read" "19:13:28,8885734","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8885798","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\MSISIP.DLL" "19:13:28,8885859","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: MsiSIPVerifyIndirectData" "19:13:28,8885971","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","" "19:13:28,8886035","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 1, Name: {06C9E010-38CE-11D4-A2A3-00104BD35090}" "19:13:28,8886128","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8886192","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:28,8886273","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8886337","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8886398","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: VerifyIndirectData" "19:13:28,8886500","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:28,8886561","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 2, Name: {0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}" "19:13:28,8886654","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8886718","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Desired Access: Read" "19:13:28,8886805","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8886866","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8886927","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: AppxSipVerifyIndirectData" "19:13:28,8887029","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","" "19:13:28,8887090","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 3, Name: {0F5F58B3-AADE-4B9A-A434-95742D92ECEB}" "19:13:28,8887190","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8887257","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Desired Access: Read" "19:13:28,8887344","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8887405","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8887466","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 64, Data: AppxBundleSipVerifyIndirectData" "19:13:28,8887568","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","" "19:13:28,8887626","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 4, Name: {1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}" "19:13:28,8887719","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8887786","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Desired Access: Read" "19:13:28,8887867","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8887931","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8887988","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: VerifyIndirectData" "19:13:28,8888104","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","" "19:13:28,8888165","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 5, Name: {1A610570-38CE-11D4-A2A3-00104BD35090}" "19:13:28,8888255","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8888322","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:28,8888405","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8888470","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:28,8888527","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: VerifyIndirectData" "19:13:28,8888630","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:28,8888688","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 6, Name: {5598CFF1-68DB-4340-B57F-1CACF88C9A51}" "19:13:28,8888781","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8888848","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Desired Access: Read" "19:13:28,8888928","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8888992","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8889053","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: P7xSipVerifyIndirectData" "19:13:28,8889153","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","" "19:13:28,8889214","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 7, Name: {603BCC1F-4B59-4E08-B724-D2C6297EF351}" "19:13:28,8889303","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8889371","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Desired Access: Read" "19:13:28,8889451","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8889515","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 112, Data: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll" "19:13:28,8889576","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 26, Data: PsVerifyHash" "19:13:28,8889679","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","" "19:13:28,8889740","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 8, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:28,8889829","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8889897","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8889980","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8890041","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8890099","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:28,8890214","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:28,8890275","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 9, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:28,8890368","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8890436","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:28,8890519","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8890583","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:28,8890641","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: EsdSipVerifyHash" "19:13:28,8890740","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:28,8890798","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 10, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8890891","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8890955","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8891039","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8891103","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8891160","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:28,8891257","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8891318","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 11, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:28,8891407","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8891475","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8891558","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8891718","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8891776","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:28,8891876","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8891937","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 12, Name: {CF78C6DE-64A2-4799-B506-89ADFF5D16D6}" "19:13:28,8892033","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8892100","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Desired Access: Read" "19:13:28,8892190","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8892254","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8892315","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: EappxSipVerifyIndirectData" "19:13:28,8892418","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","" "19:13:28,8892479","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 13, Name: {D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}" "19:13:28,8892568","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8892636","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Desired Access: Read" "19:13:28,8892716","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8892780","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:28,8892841","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 66, Data: EappxBundleSipVerifyIndirectData" "19:13:28,8892940","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","" "19:13:28,8893001","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 14, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8893091","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8893159","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8893245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8893303","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8893361","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:28,8893457","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8893518","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 15, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:28,8893611","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8893675","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:28,8893762","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:28,8893819","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:28,8893877","EasyAntiCheat_launcher.exe","6076","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:28,8893970","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:28,8894031","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","NO MORE ENTRIES","Index: 16, Length: 288" "19:13:28,8894101","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","" "19:13:28,8894162","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,8894220","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,8894310","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8894377","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,8894486","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,8894551","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllVerifyIndirectData","NAME NOT FOUND","Desired Access: Read" "19:13:28,8894631","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,8894692","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,8894762","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,8895198","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8895256","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8895372","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:28,8895558","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8895660","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,8895715","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,8895814","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:28,8895968","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,8896087","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,8896257","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,8897508","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Offset: 0, Length: 524 288, Priority: Normal" "19:13:28,9164705","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9165453","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9165854","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9165985","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9166181","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9166546","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9167428","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9168079","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9168362","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9168455","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9168615","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9168917","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9169754","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9170402","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9170684","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9170777","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9170934","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9171248","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9172040","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9172679","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9172945","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9173035","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9173189","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9173548","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9174343","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9175065","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9175331","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9175421","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9175578","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9175880","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9176659","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9177284","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9177544","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9177631","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9177781","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9178093","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9178898","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9179626","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9180325","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9181037","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9181309","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9181399","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9181560","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9181861","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9182650","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9183266","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9183526","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9183612","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9183766","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9184052","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9184844","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9185469","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9185745","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9185832","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9185986","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9186278","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9187047","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9187666","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9187926","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9188013","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9188167","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9188449","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9190556","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9190633","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9190777","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,9190931","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9191018","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,9191143","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9191220","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,9191361","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9191428","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature","NAME NOT FOUND","Desired Access: Read" "19:13:28,9191537","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,9191611","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,9191711","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9191778","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,9191897","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9191964","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature","NAME NOT FOUND","Desired Access: Read" "19:13:28,9192051","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,9192118","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,9192208","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,9192291","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9192349","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9192455","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,9192551","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9192618","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,9192714","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9192782","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,9192891","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9192955","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2","NAME NOT FOUND","Desired Access: Read" "19:13:28,9193048","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,9193112","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,9193202","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9193269","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,9193372","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9193436","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2","NAME NOT FOUND","Desired Access: Read" "19:13:28,9193520","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,9193584","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,9193654","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,9193940","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:28,9194074","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:28,9194219","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:28,9194312","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:28,9194408","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:28,9194527","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:28,9198459","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9198526","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9198648","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:28,9198744","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:28,9198972","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9199026","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9199129","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read" "19:13:28,9199219","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read" "19:13:28,9199325","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9199424","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,9199520","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:28,9199601","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9199668","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","Desired Access: Read" "19:13:28,9199787","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9199860","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9199924","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:28,9200027","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9200085","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertSyncDeltaTime","NAME NOT FOUND","Length: 144" "19:13:28,9200162","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:28,9200232","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9200284","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9200386","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:28,9200466","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:28,9200556","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9200611","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9200707","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\ChainEngine\Config","REPARSE","Desired Access: Read" "19:13:28,9200781","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ChainEngine\Config","NAME NOT FOUND","Desired Access: Read" "19:13:28,9200864","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints","NAME NOT FOUND","Length: 144" "19:13:28,9200922","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints","NAME NOT FOUND","Length: 144" "19:13:28,9200976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions","NAME NOT FOUND","Length: 144" "19:13:28,9201034","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert","NAME NOT FOUND","Length: 144" "19:13:28,9201085","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain","NAME NOT FOUND","Length: 144" "19:13:28,9201137","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount","NAME NOT FOUND","Length: 144" "19:13:28,9201188","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount","NAME NOT FOUND","Length: 144" "19:13:28,9201239","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount","NAME NOT FOUND","Length: 144" "19:13:28,9201291","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds","NAME NOT FOUND","Length: 144" "19:13:28,9201342","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags","NAME NOT FOUND","Length: 144" "19:13:28,9201393","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MinRsaPubKeyBitLength","NAME NOT FOUND","Length: 144" "19:13:28,9201445","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakRsaPubKeyTime","NAME NOT FOUND","Length: 144" "19:13:28,9201496","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime","NAME NOT FOUND","Length: 144" "19:13:28,9201547","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableStrictChecksFlags","NAME NOT FOUND","Length: 144" "19:13:28,9201631","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,9201701","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default","SUCCESS","Desired Access: Read" "19:13:28,9201801","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9201862","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\CI\Config","REPARSE","Desired Access: Read" "19:13:28,9201939","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","Desired Access: Read" "19:13:28,9202025","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9202102","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:28,9202163","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI\Config\Default","SUCCESS","Desired Access: Read" "19:13:28,9202269","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5ThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9202336","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartyFlags","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2291138560" "19:13:28,9202404","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartyAfterTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 00 C0 29 B8 43 9A C9 01" "19:13:28,9202468","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartyAfterTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 00 C0 29 B8 43 9A C9 01" "19:13:28,9202538","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9202596","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9202651","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9202715","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9202782","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9202846","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9202910","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartySha256Allow","BUFFER OVERFLOW","Length: 144" "19:13:28,9202978","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartySha256Allow","BUFFER OVERFLOW","Length: 144" "19:13:28,9203042","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartySha256Allow","SUCCESS","Type: REG_MULTI_SZ, Length: 782, Data: 01A8F438E1A14A904BA530942BEDBD94708CA654B8DF3C4585F17B60DA6690D1, 8421A0182C854C1F4266C95FC8302E217A14C7797FE41F2A87CA6B2734C43F1D, 1AD335187A1DC540738FB2EA82B7366678C2EEDCDAE75FEADD6ECD89779CB983, 4B480E8EE1B8DFF231005E9DC5D8267227684D07A38BA6FECDB288DE53FB0A3E, E059080EF4409BC0D96FBCBDDEEE6C0AFBE871AD3D68BBA6A743C64631F599C9, 26ED148B33F377BA01B68A9A97FEB2391FBED7D51E3F6EB83BEBC2FBA90920B1" "19:13:28,9203129","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9203196","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakMD5ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9203257","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9203318","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakMD5ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9203382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9203481","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1ThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9203542","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1ThirdPartyFlags","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2147745792" "19:13:28,9203606","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1ThirdPartyAfterTime","NAME NOT FOUND","Length: 144" "19:13:28,9203667","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9203722","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9203776","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9203834","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9203895","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9203959","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204023","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204084","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204148","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204209","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204274","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204331","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:28,9204392","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakRSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204450","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakRSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204508","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakRSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204562","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakRSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204623","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204678","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204735","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204790","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204848","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakECDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204905","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakECDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:28,9204963","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakECDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9205018","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakECDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:28,9205091","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default","SUCCESS","" "19:13:28,9205152","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","" "19:13:28,9205207","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI\Config\Default","SUCCESS","" "19:13:28,9205739","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9205797","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9205893","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9206021","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9206076","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9206169","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9206281","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9206528","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9206586","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9206673","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9206782","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9206836","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9206939","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9207029","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9207093","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9207157","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9207587","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9207644","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9207744","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9207850","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9207901","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9207994","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9208077","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9208141","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9208231","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9208295","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:28,9208404","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9208475","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9208571","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 38, Values: 0" "19:13:28,9208632","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 38, Values: 0" "19:13:28,9208693","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: 02D65B95E28370C1570095FA88F923DD937FAD8F" "19:13:28,9208783","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9208850","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F","SUCCESS","Desired Access: Read" "19:13:28,9208943","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9209014","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9209075","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F\Blob","SUCCESS","Type: REG_BINARY, Length: 2 092, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 30 00 37 00" "19:13:28,9209155","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F","SUCCESS","" "19:13:28,9209389","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 1, Name: 06B25927C42A721631C1EFD9431E648FA62E1E39" "19:13:28,9209485","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9209553","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39","SUCCESS","Desired Access: Read" "19:13:28,9209642","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9209710","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9209768","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39\Blob","SUCCESS","Type: REG_BINARY, Length: 1 508, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 42 00 41 00" "19:13:28,9209848","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39","SUCCESS","" "19:13:28,9210031","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 2, Name: 1FB86B1168EC743154062E8C9CC5B171A4B7CCB4" "19:13:28,9210120","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9210188","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4","SUCCESS","Desired Access: Read" "19:13:28,9210274","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9210342","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9210399","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 510, Data: 03 00 00 00 01 00 00 00 14 00 00 00 1F B8 6B 11" "19:13:28,9210480","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4","SUCCESS","" "19:13:28,9210646","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 3, Name: 27AC9369FAF25207BB2627CEFACCBE4EF9C319B8" "19:13:28,9210736","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9210804","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8","SUCCESS","Desired Access: Read" "19:13:28,9210890","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9210957","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9211015","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 570, Data: 03 00 00 00 01 00 00 00 14 00 00 00 27 AC 93 69" "19:13:28,9211092","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8","SUCCESS","" "19:13:28,9211269","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 4, Name: 2F2877C5D778C31E0F29C7E371DF5471BD673173" "19:13:28,9211355","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9211423","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173","SUCCESS","Desired Access: Read" "19:13:28,9211512","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9211576","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9211634","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173\Blob","SUCCESS","Type: REG_BINARY, Length: 1 877, Data: 03 00 00 00 01 00 00 00 14 00 00 00 2F 28 77 C5" "19:13:28,9211714","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173","SUCCESS","" "19:13:28,9211907","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 5, Name: 339CDD57CFD5B141169B615FF31428782D1DA639" "19:13:28,9211997","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9212064","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639","SUCCESS","Desired Access: Read" "19:13:28,9212147","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9212224","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9212282","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639\Blob","SUCCESS","Type: REG_BINARY, Length: 1 898, Data: 03 00 00 00 01 00 00 00 14 00 00 00 33 9C DD 57" "19:13:28,9212362","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639","SUCCESS","" "19:13:28,9212523","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 6, Name: 33E4E80807204C2B6182A3A14B591ACD25B5F0DB" "19:13:28,9212612","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9212680","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB","SUCCESS","Desired Access: Read" "19:13:28,9212763","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9212827","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9212885","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB\Blob","SUCCESS","Type: REG_BINARY, Length: 1 909, Data: 03 00 00 00 01 00 00 00 14 00 00 00 33 E4 E8 08" "19:13:28,9212962","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB","SUCCESS","" "19:13:28,9213122","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 7, Name: 409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875" "19:13:28,9213209","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9213273","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875","SUCCESS","Desired Access: Read" "19:13:28,9213356","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9213421","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9213478","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875\Blob","SUCCESS","Type: REG_BINARY, Length: 1 991, Data: 03 00 00 00 01 00 00 00 14 00 00 00 40 9A A4 A7" "19:13:28,9213559","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875","SUCCESS","" "19:13:28,9213719","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 8, Name: 40CEF3046C916ED7AE557F60E76842828B51DE53" "19:13:28,9213806","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9213873","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53","SUCCESS","Desired Access: Read" "19:13:28,9213956","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9214020","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9214078","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53\Blob","SUCCESS","Type: REG_BINARY, Length: 1 915, Data: 03 00 00 00 01 00 00 00 14 00 00 00 40 CE F3 04" "19:13:28,9214155","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53","SUCCESS","" "19:13:28,9214315","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 9, Name: 440FF68A35E03995AC55E457A67EB1680F9A7CDD" "19:13:28,9214402","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9214469","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD","SUCCESS","Desired Access: Read" "19:13:28,9214553","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9214617","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9214675","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 896, Data: 03 00 00 00 01 00 00 00 14 00 00 00 44 0F F6 8A" "19:13:28,9214752","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD","SUCCESS","" "19:13:28,9214999","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 10, Name: 48504E974C0DAC5B5CD476C8202274B24C8C7172" "19:13:28,9215088","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9215159","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172","SUCCESS","Desired Access: Read" "19:13:28,9215239","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9215307","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9215364","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172\Blob","SUCCESS","Type: REG_BINARY, Length: 1 383, Data: 03 00 00 00 01 00 00 00 14 00 00 00 48 50 4E 97" "19:13:28,9215441","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172","SUCCESS","" "19:13:28,9215614","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 11, Name: 4C27431717565A3A07F3E6D0032C4258949CF9EC" "19:13:28,9215704","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9215775","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC","SUCCESS","Desired Access: Read" "19:13:28,9215858","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9215926","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9215983","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC\Blob","SUCCESS","Type: REG_BINARY, Length: 1 439, Data: 03 00 00 00 01 00 00 00 14 00 00 00 4C 27 43 17" "19:13:28,9216060","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC","SUCCESS","" "19:13:28,9216221","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 12, Name: 6023192FE7B59D2789130A9FE4094F9B5570D4A2" "19:13:28,9216307","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9216375","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2","SUCCESS","Desired Access: Read" "19:13:28,9216455","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9216519","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9216577","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 60 23 19 2F" "19:13:28,9216654","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2","SUCCESS","" "19:13:28,9216814","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 13, Name: 77B99BB2BD7522E17EC099EA7177516F27787CAD" "19:13:28,9216901","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9216968","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD","SUCCESS","Desired Access: Read" "19:13:28,9217051","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9217115","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9217221","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 613, Data: 03 00 00 00 01 00 00 00 14 00 00 00 77 B9 9B B2" "19:13:28,9217305","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD","SUCCESS","" "19:13:28,9217468","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 14, Name: 78892492BAADB0679670F606667544740E416C4C" "19:13:28,9217558","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9217625","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C","SUCCESS","Desired Access: Read" "19:13:28,9217712","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9217776","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9217834","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C\Blob","SUCCESS","Type: REG_BINARY, Length: 2 017, Data: 03 00 00 00 01 00 00 00 14 00 00 00 78 89 24 92" "19:13:28,9217911","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C","SUCCESS","" "19:13:28,9218087","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 15, Name: 7CCC2A87E3949F20572B18482980505FA90CAC3B" "19:13:28,9218174","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9218241","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B","SUCCESS","Desired Access: Read" "19:13:28,9218325","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9218389","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9218482","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 501, Data: 03 00 00 00 01 00 00 00 14 00 00 00 7C CC 2A 87" "19:13:28,9218559","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B","SUCCESS","" "19:13:28,9218719","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 16, Name: 7EDC376DCFD45E6DDF082C160DF6AC21835B95D4" "19:13:28,9218806","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9218876","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4","SUCCESS","Desired Access: Read" "19:13:28,9218956","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9219024","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9219081","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 618, Data: 03 00 00 00 01 00 00 00 14 00 00 00 7E DC 37 6D" "19:13:28,9219158","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4","SUCCESS","" "19:13:28,9219316","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 17, Name: 8BFE3107712B3C886B1C96AAEC89984914DC9B6B" "19:13:28,9219402","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9219470","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B","SUCCESS","Desired Access: Read" "19:13:28,9219553","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9219620","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9219710","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 906, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:28,9219787","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B","SUCCESS","" "19:13:28,9219980","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 18, Name: 902EF2DEEB3C5B13EA4C3D5193629309E231AE55" "19:13:28,9220069","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9220137","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55","SUCCESS","Desired Access: Read" "19:13:28,9220220","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9220287","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9220345","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55\Blob","SUCCESS","Type: REG_BINARY, Length: 1 467, Data: 03 00 00 00 01 00 00 00 14 00 00 00 90 2E F2 DE" "19:13:28,9220422","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55","SUCCESS","" "19:13:28,9220589","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 19, Name: 94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66" "19:13:28,9220675","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9220743","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66","SUCCESS","Desired Access: Read" "19:13:28,9220829","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9220897","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9220987","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66\Blob","SUCCESS","Type: REG_BINARY, Length: 1 845, Data: 03 00 00 00 01 00 00 00 14 00 00 00 94 C9 5D A1" "19:13:28,9221064","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66","SUCCESS","" "19:13:28,9221246","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 20, Name: 98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D" "19:13:28,9221336","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9221404","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D","SUCCESS","Desired Access: Read" "19:13:28,9221490","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9221554","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9221644","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D\Blob","SUCCESS","Type: REG_BINARY, Length: 1 539, Data: 03 00 00 00 01 00 00 00 14 00 00 00 98 C6 A8 DC" "19:13:28,9221721","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D","SUCCESS","" "19:13:28,9221888","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 21, Name: 9E99A48A9960B14926BB7F3B02E22DA2B0AB7280" "19:13:28,9221978","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9222045","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280","SUCCESS","Desired Access: Read" "19:13:28,9222132","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9222202","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9222263","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280\Blob","SUCCESS","Type: REG_BINARY, Length: 1 479, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 42 00 36 00" "19:13:28,9222340","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280","SUCCESS","" "19:13:28,9222500","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 22, Name: A031C46782E6E6C662C2C87C76DA9AA62CCABD8E" "19:13:28,9222590","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9222658","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E","SUCCESS","Desired Access: Read" "19:13:28,9222741","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9222805","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9222892","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 539, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 45 00 44 00" "19:13:28,9222972","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E","SUCCESS","" "19:13:28,9223139","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 23, Name: A0863E7F47091FAFA229848C622F5602BB136C38" "19:13:28,9223232","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9223302","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38","SUCCESS","Desired Access: Read" "19:13:28,9223398","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9223469","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9223524","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38\Blob","SUCCESS","Type: REG_BINARY, Length: 1 968, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A0 86 3E 7F" "19:13:28,9223604","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38","SUCCESS","" "19:13:28,9223787","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 24, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:28,9223876","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9223944","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:28,9224027","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9224094","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9224181","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 867, Data: 04 00 00 00 01 00 00 00 10 00 00 00 18 23 21 7D" "19:13:28,9224261","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:28,9224412","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 25, Name: B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75" "19:13:28,9224502","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9224572","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75","SUCCESS","Desired Access: Read" "19:13:28,9224656","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9224723","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9224781","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75\Blob","SUCCESS","Type: REG_BINARY, Length: 1 708, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 36 00 42 00" "19:13:28,9224858","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75","SUCCESS","" "19:13:28,9225028","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 26, Name: C01B8463C8619676BA102EEBF0C30CDCED9A942B" "19:13:28,9225114","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9225182","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B","SUCCESS","Desired Access: Read" "19:13:28,9225265","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9225332","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9225390","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 333, Data: 03 00 00 00 01 00 00 00 14 00 00 00 C0 1B 84 63" "19:13:28,9225467","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B","SUCCESS","" "19:13:28,9225644","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 27, Name: C2826E266D7405D34EF89762636AE4B36E86CB5E" "19:13:28,9225733","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9225801","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E","SUCCESS","Desired Access: Read" "19:13:28,9225881","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9225977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9226038","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E\Blob","SUCCESS","Type: REG_BINARY, Length: 2 119, Data: 03 00 00 00 01 00 00 00 14 00 00 00 C2 82 6E 26" "19:13:28,9226115","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E","SUCCESS","" "19:13:28,9226320","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 28, Name: C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34" "19:13:28,9226410","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9226477","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34","SUCCESS","Desired Access: Read" "19:13:28,9226561","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9226625","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9226683","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34\Blob","SUCCESS","Type: REG_BINARY, Length: 2 103, Data: 03 00 00 00 01 00 00 00 14 00 00 00 C8 1A 8B D1" "19:13:28,9226763","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34","SUCCESS","" "19:13:28,9226942","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 29, Name: D6AEE31631F7ABC56B9DE8ABECCC4108A626B104" "19:13:28,9227029","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9227100","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104","SUCCESS","Desired Access: Read" "19:13:28,9227193","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9227260","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9227350","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104\Blob","SUCCESS","Type: REG_BINARY, Length: 1 501, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D6 AE E3 16" "19:13:28,9227427","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104","SUCCESS","" "19:13:28,9227606","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 30, Name: DFE83023062B997682708B4EAB8E819AFF5D9775" "19:13:28,9227699","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9227767","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775","SUCCESS","Desired Access: Read" "19:13:28,9227850","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9227918","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9227975","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775\Blob","SUCCESS","Type: REG_BINARY, Length: 1 440, Data: 03 00 00 00 01 00 00 00 14 00 00 00 DF E8 30 23" "19:13:28,9228052","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775","SUCCESS","" "19:13:28,9228283","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 31, Name: E6A3B45B062D509B3382282D196EFE97D5956CCB" "19:13:28,9228373","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9228444","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB","SUCCESS","Desired Access: Read" "19:13:28,9228527","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9228594","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9228649","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB\Blob","SUCCESS","Type: REG_BINARY, Length: 1 508, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 45 00 34 00" "19:13:28,9228729","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB","SUCCESS","" "19:13:28,9228905","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 32, Name: EC4191D1F357BD539483286FA67FD219143D2611" "19:13:28,9228995","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9229063","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611","SUCCESS","Desired Access: Read" "19:13:28,9229143","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9229207","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9229265","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611\Blob","SUCCESS","Type: REG_BINARY, Length: 1 536, Data: 03 00 00 00 01 00 00 00 14 00 00 00 EC 41 91 D1" "19:13:28,9229342","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611","SUCCESS","" "19:13:28,9229518","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 33, Name: F21C12F46CDB6B2E16F09F9419CDFF328437B2D7" "19:13:28,9229605","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9229672","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7","SUCCESS","Desired Access: Read" "19:13:28,9229752","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9229816","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9229877","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 632, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F2 1C 12 F4" "19:13:28,9229954","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7","SUCCESS","" "19:13:28,9230179","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 34, Name: F252E794FE438E35ACE6E53762C0A234A2C52135" "19:13:28,9230268","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9230336","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135","SUCCESS","Desired Access: Read" "19:13:28,9230422","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9230487","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9230544","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135\Blob","SUCCESS","Type: REG_BINARY, Length: 2 172, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:28,9230621","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135","SUCCESS","" "19:13:28,9230801","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 35, Name: F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0" "19:13:28,9230887","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9230958","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","Desired Access: Read" "19:13:28,9231041","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9231106","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9231163","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 750, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F5 AD 0B CC" "19:13:28,9231253","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","" "19:13:28,9231423","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 36, Name: F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6" "19:13:28,9231513","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9231580","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6","SUCCESS","Desired Access: Read" "19:13:28,9231664","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9231731","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9231789","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6\Blob","SUCCESS","Type: REG_BINARY, Length: 1 883, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F5 FB 01 DE" "19:13:28,9231866","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6","SUCCESS","" "19:13:28,9232125","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 37, Name: F695C5B4037AE8EAE51EA943A4F54D750E0DA609" "19:13:28,9232228","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9232299","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609","SUCCESS","Desired Access: Read" "19:13:28,9232385","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9232453","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9232523","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609\Blob","SUCCESS","Type: REG_BINARY, Length: 1 600, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F6 95 C5 B4" "19:13:28,9232600","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609","SUCCESS","" "19:13:28,9232770","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9232854","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9232930","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9233017","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9233075","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9233139","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9233213","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9233277","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9233357","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9233412","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9233476","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9233540","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9233912","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9233973","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9234066","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9234172","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9234226","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9234313","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,9234399","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9234473","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9234528","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9234624","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9234723","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9234804","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9234868","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9234954","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9235012","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9235076","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9235150","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9235217","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9235294","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9235349","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9235410","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9235483","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9235548","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9235625","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9235679","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9235740","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9235801","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9235920","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9235974","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9236086","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\CA\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9236183","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9236295","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9236349","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9236452","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9236532","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9236616","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9236683","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9236808","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9236863","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9236965","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9237045","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9237122","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9237215","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9237280","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:28,9237373","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9237440","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9237530","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:28,9237584","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:28,9237645","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: 109F1CAED645BB78B3EA2B94C0697C740733031C" "19:13:28,9237729","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9237796","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","Desired Access: Read" "19:13:28,9237886","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9237956","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9238014","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 147, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 B6 53 18" "19:13:28,9238097","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","" "19:13:28,9238373","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 1, Name: C415CBF62AF1B513B81ED7B707BDE0A954E2B813" "19:13:28,9238768","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9238864","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","Desired Access: Read" "19:13:28,9238983","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9239066","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9239335","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","SUCCESS","Type: REG_BINARY, Length: 1 091, Data: 04 00 00 00 01 00 00 00 10 00 00 00 E1 3A 7C 82" "19:13:28,9239454","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","" "19:13:28,9239701","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 2, Name: D559A586669B08F46A30A133F8A9ED3D038E2EA8" "19:13:28,9239804","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9239881","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","Desired Access: Read" "19:13:28,9239980","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9240047","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9240163","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 095, Data: 04 00 00 00 01 00 00 00 10 00 00 00 AC D8 0E A2" "19:13:28,9240253","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","" "19:13:28,9240439","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 3, Name: FEE449EE0E3965A5246F000E87FDE2A065FD89D4" "19:13:28,9240548","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9240622","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","Desired Access: Read" "19:13:28,9240711","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9240782","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9240840","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","SUCCESS","Type: REG_BINARY, Length: 566, Data: 19 00 00 00 01 00 00 00 10 00 00 00 ED BC CD D5" "19:13:28,9240917","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","" "19:13:28,9241080","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9241170","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9241247","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9241340","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9241401","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9241459","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Index: 0, Name: A377D1B1C0538833035211F4083D00FECC414DAB" "19:13:28,9241545","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9241613","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","Desired Access: Read" "19:13:28,9241696","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9241760","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9241821","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","SUCCESS","Type: REG_BINARY, Length: 481, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A3 77 D1 B1" "19:13:28,9241901","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","" "19:13:28,9242129","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9242222","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9242296","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9242392","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9242446","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9242514","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9242578","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9242754","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9242818","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9242947","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9243049","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9243162","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9243245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9243316","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9243405","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9243463","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9243534","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9243607","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9243675","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9243752","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9243810","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9243874","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9243944","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9244012","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9244089","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9244143","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9244207","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9244268","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9244384","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9244441","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9244554","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\CA\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9244653","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9244775","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9244829","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9244935","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9245015","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9245102","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9245173","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","" "19:13:28,9245295","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9245352","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9245452","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9245532","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9245612","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9245692","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9245760","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Desired Access: Read" "19:13:28,9245853","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9245920","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9246010","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9246064","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9246132","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","" "19:13:28,9246205","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9246270","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9246353","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9246407","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9246472","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","" "19:13:28,9246542","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9246606","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9247472","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9247556","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9247626","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","" "19:13:28,9247694","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","" "19:13:28,9248297","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9248357","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9248457","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9248576","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9248627","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9248723","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9248839","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9249092","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9249150","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9249236","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9249342","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9249397","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9249490","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9249583","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9249647","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9249708","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9249798","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9249852","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9249958","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9250044","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9250214","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9250269","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9250352","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9250452","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9250506","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9250596","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9250705","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9250779","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9250833","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9250936","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9251016","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9251427","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9251488","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9251574","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9251677","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9251732","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9251825","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9251911","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9251975","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9252062","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9252129","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9252232","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9252299","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9252389","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9252447","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9252511","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9252585","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9252649","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9252729","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9252783","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9252844","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9252915","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9252982","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9253056","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9253111","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9253175","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9253236","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9253550","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9253608","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9253698","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9253797","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9253852","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9253932","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,9254018","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9254092","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9254147","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9254240","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9254329","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9254410","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9254474","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9254564","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9254621","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9254685","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9254759","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9254827","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9254903","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9254958","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9255022","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9255093","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9255157","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9255234","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9255288","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9255353","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9255410","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9255558","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9255612","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9255718","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9255802","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9255914","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9255968","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9256068","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9256148","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9256231","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9256302","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9256382","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9256437","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9256539","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9256616","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9256777","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9256831","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9256914","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9257014","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9257068","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9257158","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9257254","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9257322","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9257376","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9257476","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9257553","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9257694","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9257748","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9257848","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9257925","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9258005","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9258085","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9258149","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9258239","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9258306","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9258393","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9258451","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9258518","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9258592","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9258659","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9258736","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9258791","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9258852","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9258922","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9258990","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9259063","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9259131","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9259198","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:28,9259285","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9259352","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:28,9259442","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9259519","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9259580","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:28,9259663","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:28,9260093","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9260160","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9260369","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9260426","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9260542","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9260625","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9260725","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9260805","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9260872","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9260962","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9261308","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9261395","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9261475","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9261549","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9261632","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9261687","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9261751","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9261825","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9261892","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9261969","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9262024","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9262088","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9262149","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9262280","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9262338","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9262444","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9262527","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9262643","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9262697","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9262797","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9262877","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9262957","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9263028","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:28,9263146","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9263201","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9263300","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9263380","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9263457","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9263537","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9263602","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9263691","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9263759","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9263845","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9263900","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9263967","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9264038","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9264105","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9264182","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9264237","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9264301","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9264371","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9264436","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9264512","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9264567","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9264628","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9264692","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:28,9265183","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9265237","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9265330","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9265436","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9265487","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9265580","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9265674","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9265917","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9265975","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9266062","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9266164","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9266219","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9266309","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9266395","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9266459","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9266523","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:28,9266604","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9266658","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9266761","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:28,9266841","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:28,9267149","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9267216","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9267306","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9267425","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9267479","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9267569","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9267649","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9267781","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9267835","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9267919","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9268021","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9268073","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9268162","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read" "19:13:28,9268255","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9268323","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:28,9268380","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9268464","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9268528","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read" "19:13:28,9268618","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9268685","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9268785","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9268839","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9268903","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:28,9268977","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9269041","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9269121","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9269176","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9269240","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:28,9269311","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9269375","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9269452","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9269506","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9269567","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:28,9269699","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9269753","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9269840","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9270183","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9270241","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9270334","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read" "19:13:28,9270420","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9270516","EasyAntiCheat_launcher.exe","6076","RegQueryKeySecurity","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:28,9270626","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 D0 7F 76 08 98 C6 D5 01" "19:13:28,9270735","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 D0 7F 76 08 98 C6 D5 01" "19:13:28,9270921","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:28,9271036","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9271132","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:28,9271203","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9271338","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9271395","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9271508","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Root\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9271601","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Root\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9271719","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9271774","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9271873","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9271957","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9272040","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9272111","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","" "19:13:28,9272200","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9272255","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9272357","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:28,9272438","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:28,9272604","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9272659","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9272771","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9272851","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9272932","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9273015","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9273082","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Desired Access: Read" "19:13:28,9273172","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9273239","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9273332","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:28,9273390","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:28,9273490","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 0, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:28,9273583","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9273650","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:28,9273762","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9273842","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9273907","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 95 6C C4 8F" "19:13:28,9273993","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:28,9274214","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 1, Name: 18F7C1FCC3090203FD5BAA2F861A754976C8DD25" "19:13:28,9274327","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9274400","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","Desired Access: Read" "19:13:28,9274494","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9274567","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9274628","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","SUCCESS","Type: REG_BINARY, Length: 968, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:28,9274712","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","" "19:13:28,9274869","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 2, Name: 245C97DF7514E7CF2DF8BE72AE957B9E04741E85" "19:13:28,9274959","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9275029","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","Desired Access: Read" "19:13:28,9275116","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9275183","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9275305","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","SUCCESS","Type: REG_BINARY, Length: 907, Data: 19 00 00 00 01 00 00 00 10 00 00 00 7F DF F5 07" "19:13:28,9275385","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","" "19:13:28,9275526","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 3, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:28,9275622","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9275693","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:28,9275776","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9275850","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9275908","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 237, Data: 19 00 00 00 01 00 00 00 10 00 00 00 79 A6 2B 38" "19:13:28,9275985","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:28,9276145","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 4, Name: 3B1EFD3A66EA28B16697394703A72CA340A05BD5" "19:13:28,9276254","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9276328","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","Desired Access: Read" "19:13:28,9276415","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9276485","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9276585","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 835, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:28,9276690","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","" "19:13:28,9276873","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 5, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:28,9276998","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9277072","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:28,9277162","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9277242","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9277300","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 149, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9277377","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:28,9277531","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 6, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:28,9277621","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9277688","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:28,9277775","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9277842","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9277900","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 71 BD 96 83" "19:13:28,9277977","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:28,9278105","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 7, Name: 7D5E3BD28E9429952ADFC4630B770C389E7A64FD" "19:13:28,9278188","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9278259","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","Desired Access: Read" "19:13:28,9278342","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9278410","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9278467","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 134, Data: 19 00 00 00 01 00 00 00 10 00 00 00 78 DD D8 24" "19:13:28,9278544","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","" "19:13:28,9278766","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 8, Name: 7F88CD7223F3C813818C994614A89C99FA3B5247" "19:13:28,9278855","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9278926","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","Desired Access: Read" "19:13:28,9279009","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9279073","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9279134","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","SUCCESS","Type: REG_BINARY, Length: 1 228, Data: 19 00 00 00 01 00 00 00 10 00 00 00 07 D3 4D ED" "19:13:28,9279211","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","" "19:13:28,9279381","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 9, Name: 8F43288AD272F3103B6FB1428485EA3014C0BCFE" "19:13:28,9279468","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9279539","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","Desired Access: Read" "19:13:28,9279625","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9279692","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9279750","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 869, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:28,9279830","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","" "19:13:28,9279991","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 10, Name: 9007A10299C432559B502DB7D6C449757780FDB1" "19:13:28,9280074","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9280142","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","Desired Access: Read" "19:13:28,9280228","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9280292","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9280350","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 D4 65 24 73" "19:13:28,9280427","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","" "19:13:28,9280555","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 11, Name: 92B46C76E13054E104F230517E6E504D43AB10B5" "19:13:28,9280639","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9280709","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","Desired Access: Read" "19:13:28,9280789","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9280854","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9280911","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 255, Data: 09 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:28,9280988","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","" "19:13:28,9281142","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 12, Name: A43489159A520F0D93D032CCAF37E7FE20A8B419" "19:13:28,9281229","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9281296","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","Desired Access: Read" "19:13:28,9281380","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9281444","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9281533","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","SUCCESS","Type: REG_BINARY, Length: 1 310, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9281614","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","" "19:13:28,9281761","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 13, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:28,9281851","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9281922","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:28,9282008","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9282072","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9282130","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 8B 7C EF 92" "19:13:28,9282220","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:28,9282351","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 14, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:28,9282438","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9282505","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:28,9282589","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9282653","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9282743","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 823, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 42 25 E4" "19:13:28,9282823","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:28,9282922","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 15, Name: B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD" "19:13:28,9283009","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9283079","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","Desired Access: Read" "19:13:28,9283163","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9283227","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9283288","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 105, Data: 19 00 00 00 01 00 00 00 10 00 00 00 56 57 7B 94" "19:13:28,9283365","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","" "19:13:28,9283506","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 16, Name: BE36A4562FB2EE05DBB3D32323ADF445084ED656" "19:13:28,9283589","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9283657","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","Desired Access: Read" "19:13:28,9283756","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9283820","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9283878","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","SUCCESS","Type: REG_BINARY, Length: 935, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:28,9283952","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","" "19:13:28,9284093","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 17, Name: CDD4EEAE6000AC7F40C3802C171E30148030C072" "19:13:28,9284179","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9284250","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","Desired Access: Read" "19:13:28,9284337","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9284433","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9284494","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","SUCCESS","Type: REG_BINARY, Length: 1 759, Data: 59 00 00 00 01 00 00 00 12 00 00 00 52 00 53 00" "19:13:28,9284574","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","" "19:13:28,9284725","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 18, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:28,9284815","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9284882","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:28,9284968","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9285036","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9285094","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 071, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9285171","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:28,9285315","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 19, Name: E06A30801D661F606869D9BC0ACC5EE57C7A48A7" "19:13:28,9285401","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9285469","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","Desired Access: Read" "19:13:28,9285552","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9285616","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9285674","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 102, Data: 19 00 00 00 01 00 00 00 10 00 00 00 B7 B9 C2 BF" "19:13:28,9285754","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","" "19:13:28,9285918","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 20, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:28,9286001","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9286072","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:28,9286155","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9286222","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9286309","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 BB AD 3C 3F" "19:13:28,9286389","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:28,9286521","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","" "19:13:28,9286601","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9286678","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9286765","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9286822","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9286886","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","" "19:13:28,9286957","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9287028","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9287108","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9287162","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9287236","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","" "19:13:28,9287300","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","" "19:13:28,9287435","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9287493","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9287608","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9287698","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9287797","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9287881","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9287945","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read" "19:13:28,9288035","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9288102","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9288189","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:28,9288243","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:28,9288301","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 0, Name: 02FAF3E291435468607857694DF5E45B68851868" "19:13:28,9288384","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9288452","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","Desired Access: Read" "19:13:28,9288541","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9288609","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9288670","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","SUCCESS","Type: REG_BINARY, Length: 1 559, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9288750","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","" "19:13:28,9288923","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 1, Name: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" "19:13:28,9289013","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9289083","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","Desired Access: Read" "19:13:28,9289173","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9289241","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9289298","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","SUCCESS","Type: REG_BINARY, Length: 1 377, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9289375","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","" "19:13:28,9289532","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 2, Name: 06083F593F15A104A069A46BA903D006B7970991" "19:13:28,9289619","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9289690","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","Desired Access: Read" "19:13:28,9289776","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9289840","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9289898","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","SUCCESS","Type: REG_BINARY, Length: 1 577, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9289975","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","" "19:13:28,9290129","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 3, Name: 06F1AA330B927B753A40E68CDF22E34BCBEF3352" "19:13:28,9290216","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9290286","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","Desired Access: Read" "19:13:28,9290366","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9290430","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9290491","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","SUCCESS","Type: REG_BINARY, Length: 1 233, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 80 01 00 00" "19:13:28,9290565","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","" "19:13:28,9290735","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 4, Name: 07E032E020B72C3F192F0628A2593A19A70F069E" "19:13:28,9290819","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9290889","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","Desired Access: Read" "19:13:28,9290972","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9291040","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9291133","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 484, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9291210","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","" "19:13:28,9291409","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 5, Name: 093C61F38B8BDC7D55DF7538020500E125F5C836" "19:13:28,9291498","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9291569","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","Desired Access: Read" "19:13:28,9291652","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9291720","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9291806","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","SUCCESS","Type: REG_BINARY, Length: 1 868, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:28,9291899","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","" "19:13:28,9292130","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 6, Name: 1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA" "19:13:28,9292230","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9292300","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","Desired Access: Read" "19:13:28,9292387","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9292454","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9292512","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","SUCCESS","Type: REG_BINARY, Length: 1 034, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9292586","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","" "19:13:28,9292743","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 7, Name: 2796BAE63F1801E277261BA0D77770028F20EEE4" "19:13:28,9292833","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9292900","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","Desired Access: Read" "19:13:28,9292983","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9293051","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9293109","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 512, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9293189","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","" "19:13:28,9293339","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 8, Name: 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E" "19:13:28,9293426","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9293493","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","Desired Access: Read" "19:13:28,9293577","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9293641","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9293699","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 989, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9293779","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","" "19:13:28,9293930","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 9, Name: 2BB1F53E550C1DC5F1D4E6B76A464B550602AC21" "19:13:28,9294016","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9294084","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","Desired Access: Read" "19:13:28,9294164","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9294228","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9294286","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","SUCCESS","Type: REG_BINARY, Length: 1 317, Data: 7F 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:28,9294363","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","" "19:13:28,9294520","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 10, Name: 3679CA35668772304D30A5FB873B0FA77BB70D54" "19:13:28,9294606","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9294674","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","Desired Access: Read" "19:13:28,9294763","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9294828","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9294885","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","SUCCESS","Type: REG_BINARY, Length: 1 781, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9294962","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","" "19:13:28,9295139","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 11, Name: 36B12B49F9819ED74C9EBC380FC6568F5DACB2F7" "19:13:28,9295225","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9295296","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","Desired Access: Read" "19:13:28,9295382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9295447","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9295504","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 370, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:28,9295581","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","" "19:13:28,9295735","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 12, Name: 3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F" "19:13:28,9295822","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9295889","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","Desired Access: Read" "19:13:28,9295976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9296075","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9296136","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","SUCCESS","Type: REG_BINARY, Length: 2 512, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9296216","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","" "19:13:28,9296402","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 13, Name: 47BEABC922EAE80E78783462A79F45C254FDE68B" "19:13:28,9296489","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9296560","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","Desired Access: Read" "19:13:28,9296646","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9296710","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9296771","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9296848","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","" "19:13:28,9296999","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 14, Name: 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5" "19:13:28,9297086","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9297156","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","Desired Access: Read" "19:13:28,9297246","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9297313","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9297371","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 760, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9297448","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","" "19:13:28,9297605","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 15, Name: 503006091D97D4F5AE39F7CBE7927D7D652D3431" "19:13:28,9297688","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9297759","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","Desired Access: Read" "19:13:28,9297842","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9297907","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9297996","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","SUCCESS","Type: REG_BINARY, Length: 1 613, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9298077","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","" "19:13:28,9298247","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 16, Name: 51501FBFCE69189D609CFAF140C576755DCC1FDF" "19:13:28,9298336","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9298407","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","Desired Access: Read" "19:13:28,9298490","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9298587","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9298647","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","SUCCESS","Type: REG_BINARY, Length: 1 808, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:28,9298724","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","" "19:13:28,9298878","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 17, Name: 590D2D7D884F402E617EA562321765CF17D894E9" "19:13:28,9298965","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9299036","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","Desired Access: Read" "19:13:28,9299122","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9299189","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9299244","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 345, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:28,9299321","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","" "19:13:28,9299465","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 18, Name: 5D003860F002ED829DEAA41868F788186D62127F" "19:13:28,9299552","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9299622","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","Desired Access: Read" "19:13:28,9299703","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9299770","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9299860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","SUCCESS","Type: REG_BINARY, Length: 1 679, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9299940","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","" "19:13:28,9300116","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 19, Name: 5F3B8CF2F810B37D78B4CEEC1919C37334B9C774" "19:13:28,9300206","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9300277","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","Desired Access: Read" "19:13:28,9300367","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9300431","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9300488","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","SUCCESS","Type: REG_BINARY, Length: 1 335, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9300565","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","" "19:13:28,9300729","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 20, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:28,9300816","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9300883","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:28,9300970","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9301034","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9301123","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 391, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9301204","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:28,9301300","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 21, Name: 6252DC40F71143A22FDE9EF7348E064251B18118" "19:13:28,9301383","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9301454","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","Desired Access: Read" "19:13:28,9301537","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9301605","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9301662","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","SUCCESS","Type: REG_BINARY, Length: 1 190, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:28,9301736","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","" "19:13:28,9301884","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 22, Name: 742C3192E607E424EB4549542BE1BBC53E6174E2" "19:13:28,9301970","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9302038","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","Desired Access: Read" "19:13:28,9302121","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9302195","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9302252","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 074, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9302329","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","" "19:13:28,9302548","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 23, Name: 75E0ABB6138512271C04F85FDDDE38E4B7242EFE" "19:13:28,9302634","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9302705","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","Desired Access: Read" "19:13:28,9302791","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9302859","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9302913","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 555, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:28,9302993","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","" "19:13:28,9303160","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 24, Name: 7E04DE896A3E666D00E687D33FFAD93BE83D349E" "19:13:28,9303247","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9303317","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","Desired Access: Read" "19:13:28,9303401","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9303465","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9303523","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 059, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9303599","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","" "19:13:28,9303750","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 25, Name: 8782C6C304353BCFD29692D2593E7D44D934FF11" "19:13:28,9303834","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9303904","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","Desired Access: Read" "19:13:28,9303988","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9304052","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9304109","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","SUCCESS","Type: REG_BINARY, Length: 1 354, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9304186","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","" "19:13:28,9304350","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 26, Name: 89DF74FE5CF40F4A80F9E3377D54DA91E101318E" "19:13:28,9304437","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9304504","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","Desired Access: Read" "19:13:28,9304587","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9304651","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9304709","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9304786","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","" "19:13:28,9304940","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 27, Name: 8CF427FD790C3AD166068DE81E57EFBB932272D4" "19:13:28,9305024","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9305094","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","Desired Access: Read" "19:13:28,9305177","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9305242","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9305331","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 639, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:28,9305412","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","" "19:13:28,9305569","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 28, Name: 91C6D6EE3E8AC86384E548C299295C756C817B81" "19:13:28,9305655","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9305726","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","Desired Access: Read" "19:13:28,9305806","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9305873","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9305931","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","SUCCESS","Type: REG_BINARY, Length: 1 515, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9306005","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","" "19:13:28,9306159","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 29, Name: 97817950D81C9670CC34D809CF794431367EF474" "19:13:28,9306245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9306313","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","Desired Access: Read" "19:13:28,9306396","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9306460","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9306518","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 050, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:28,9306592","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","" "19:13:28,9306730","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 30, Name: A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436" "19:13:28,9306813","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9306881","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","Desired Access: Read" "19:13:28,9306967","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9307031","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9307089","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","SUCCESS","Type: REG_BINARY, Length: 1 369, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9307166","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","" "19:13:28,9307349","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 31, Name: AD7E1C28B064EF8F6003402014C3D0E3370EB58A" "19:13:28,9307435","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9307506","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","Desired Access: Read" "19:13:28,9307593","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9307657","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9307746","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9307827","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","" "19:13:28,9308000","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 32, Name: AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4" "19:13:28,9308099","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9308170","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","Desired Access: Read" "19:13:28,9308253","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9308321","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9308378","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","SUCCESS","Type: REG_BINARY, Length: 2 025, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9308455","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","" "19:13:28,9308619","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 33, Name: B1BC968BD4F49D622AA89A81F2150152A41D829C" "19:13:28,9308709","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9308776","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","Desired Access: Read" "19:13:28,9308859","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9308924","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9308985","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 461, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:28,9309061","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","" "19:13:28,9309228","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 34, Name: B31EB1B740E36C8402DADC37D44DF5D4674952F9" "19:13:28,9309315","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9309385","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","Desired Access: Read" "19:13:28,9309469","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9309533","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9309623","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 712, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:28,9309703","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","" "19:13:28,9309895","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 35, Name: B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E" "19:13:28,9309982","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9310053","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","Desired Access: Read" "19:13:28,9310133","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9310200","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9310258","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 498, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9310335","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","" "19:13:28,9310486","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 36, Name: CA3AFBCF1240364B44B216208880483919937CF7" "19:13:28,9310572","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9310643","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","Desired Access: Read" "19:13:28,9310726","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9310790","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9310880","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 937, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:28,9310957","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","" "19:13:28,9311159","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 37, Name: CABD2A79A1076A31F21D253635CB039D4329A5E8" "19:13:28,9311249","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9311319","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","Desired Access: Read" "19:13:28,9311406","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9311470","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9311560","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 717, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:28,9311640","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","" "19:13:28,9311807","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 38, Name: CF9E876DD3EBFC422697A3B5A37AA076A9062348" "19:13:28,9311897","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9311967","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","Desired Access: Read" "19:13:28,9312051","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9312118","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9312173","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","SUCCESS","Type: REG_BINARY, Length: 1 421, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9312259","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","" "19:13:28,9312413","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 39, Name: D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0" "19:13:28,9312500","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9312567","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","Desired Access: Read" "19:13:28,9312654","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9312718","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9312776","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 150, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9312852","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","" "19:13:28,9313077","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 40, Name: D1EB23A46D17D68FD92564C2F1F1601764D8E349" "19:13:28,9313170","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9313237","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","Desired Access: Read" "19:13:28,9313324","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9313391","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9313449","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","SUCCESS","Type: REG_BINARY, Length: 1 545, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9313526","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","" "19:13:28,9313680","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 41, Name: D23209AD23D314232174E40D7F9D62139786633A" "19:13:28,9313767","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9313837","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","Desired Access: Read" "19:13:28,9313920","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9313985","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9314042","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 197, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:28,9314119","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","" "19:13:28,9314286","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 42, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:28,9314373","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9314440","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:28,9314520","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9314584","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9314642","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 460, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:28,9314719","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:28,9314815","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 43, Name: D69B561148F01C77C54578C10926DF5B856976AD" "19:13:28,9314899","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9314966","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","Desired Access: Read" "19:13:28,9315046","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9315110","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9315168","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 363, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:28,9315245","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","" "19:13:28,9315399","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 44, Name: D8C5388AB7301B1B6ED47AE645253A6F9F1A2761" "19:13:28,9315482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9315553","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","Desired Access: Read" "19:13:28,9315633","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9315697","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9315755","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","SUCCESS","Type: REG_BINARY, Length: 1 855, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9315835","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","" "19:13:28,9315989","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 45, Name: DAC9024F54D8F6DF94935FB1732638CA6AD77C13" "19:13:28,9316073","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9316156","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","Desired Access: Read" "19:13:28,9316239","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9316307","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9316364","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","SUCCESS","Type: REG_BINARY, Length: 1 264, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:28,9316441","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","" "19:13:28,9316592","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 46, Name: DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212" "19:13:28,9316682","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9316749","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","Desired Access: Read" "19:13:28,9316833","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9316900","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9316958","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","SUCCESS","Type: REG_BINARY, Length: 1 306, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9317035","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","" "19:13:28,9317195","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 47, Name: DE3F40BD5093D39B6C60F6DABC076201008976C9" "19:13:28,9317285","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9317352","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","Desired Access: Read" "19:13:28,9317436","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9317532","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9317593","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 958, Data: 4B 00 00 00 01 00 00 00 02 00 00 00 00 00 04 00" "19:13:28,9317673","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","" "19:13:28,9317843","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 48, Name: DF3C24F9BFD666761B268073FE06D1CC8D4F82A4" "19:13:28,9317933","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9318003","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","Desired Access: Read" "19:13:28,9318084","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9318151","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9318209","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 378, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9318286","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","" "19:13:28,9318440","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 49, Name: DF717EAA4AD94EC9558499602D48DE5FBCF03A25" "19:13:28,9318523","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9318593","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","Desired Access: Read" "19:13:28,9318674","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9318741","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9318831","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 947, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:28,9318908","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","" "19:13:28,9319062","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 50, Name: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46" "19:13:28,9319148","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9319219","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","Desired Access: Read" "19:13:28,9319306","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9319370","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9319427","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","SUCCESS","Type: REG_BINARY, Length: 1 482, Data: 09 00 00 00 01 00 00 00 22 00 00 00 30 20 06 08" "19:13:28,9319504","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","" "19:13:28,9319662","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 51, Name: F373B387065A28848AF2F34ACE192BDDC78E9CAC" "19:13:28,9319748","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9319815","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","Desired Access: Read" "19:13:28,9319899","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9319963","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9320024","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","SUCCESS","Type: REG_BINARY, Length: 1 917, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9320101","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","" "19:13:28,9320316","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 52, Name: F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7" "19:13:28,9320409","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9320476","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","Desired Access: Read" "19:13:28,9320566","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9320630","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9320688","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 400, Data: 7F 00 00 00 01 00 00 00 36 00 00 00 30 34 06 08" "19:13:28,9320765","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","" "19:13:28,9320922","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 53, Name: FE45659B79035B98A161B5512EACDA580948224D" "19:13:28,9321009","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9321076","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","Desired Access: Read" "19:13:28,9321159","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9321223","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9321281","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 40 00 00 00 30 3E 06 08" "19:13:28,9321358","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","" "19:13:28,9321541","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","" "19:13:28,9321624","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9321698","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9321785","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9321846","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9321910","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","" "19:13:28,9321984","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9322051","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9322125","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9322179","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9322259","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","" "19:13:28,9322324","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:28,9322471","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9322529","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9322644","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9322737","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9322837","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9322917","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9322984","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9323074","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9323132","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9323199","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:28,9323270","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9323337","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9323420","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9323475","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9323539","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:28,9323610","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9323677","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9323754","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9323809","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9323873","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:28,9323934","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:28,9324043","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9324110","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9324222","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Root\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9324309","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9324428","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9324482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9324585","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9324665","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9324748","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9324816","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","" "19:13:28,9324934","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9324992","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9325091","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9325172","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9325249","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9325329","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9325396","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read" "19:13:28,9325486","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9325553","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9325640","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9325694","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9325762","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","" "19:13:28,9325832","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9325900","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9325977","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9326031","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9326092","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","" "19:13:28,9326163","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9326230","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9326307","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9326362","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9326422","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","" "19:13:28,9326487","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","" "19:13:28,9326608","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9326663","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9326766","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\SmartCardRoot","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9326849","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9326932","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9327013","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9327077","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read" "19:13:28,9327163","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9327240","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9327333","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9327391","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9327455","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:28,9327526","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9327593","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9327670","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9327725","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9327789","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:28,9327856","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9327923","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9328000","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9328055","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9328119","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:28,9328183","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","" "19:13:28,9328558","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9328616","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9328709","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9328838","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9328892","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9328988","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9329081","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9329171","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9329235","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read" "19:13:28,9329328","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9329396","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9329482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9329537","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9329604","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:28,9329675","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9329742","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9329819","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9329873","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9329938","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:28,9330008","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9330076","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9330149","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9330204","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9330268","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:28,9330332","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","" "19:13:28,9330390","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9330929","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9330986","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9331076","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9331179","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9331230","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9331323","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9331419","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9331663","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9331718","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9331804","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9331907","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9331958","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9332048","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9332131","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9332205","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9332266","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9332353","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9332407","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9332513","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:28,9332596","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:28,9332997","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9333055","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9333142","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9333244","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9333312","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9333405","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9333485","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9333552","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9333632","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9333697","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:28,9333783","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9333850","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9333940","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9333995","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9334059","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9334133","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9334197","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9334274","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9334328","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9334393","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9334463","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9334527","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9334607","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9334662","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9334726","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9334787","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9335095","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9335153","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9335242","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9335342","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9335396","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9335480","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,9335563","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9335637","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9335691","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9335781","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9335874","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9335954","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9336025","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9336115","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9336169","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9336233","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9336304","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9336371","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9336445","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9336500","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9336564","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9336638","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9336702","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9336779","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9336833","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9336897","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9336955","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9337074","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9337128","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9337247","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9337334","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9337446","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9337500","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9337600","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9337680","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9337760","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9337827","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9337949","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9338007","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9338107","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9338184","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9338260","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9338341","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9338405","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:28,9338491","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9338559","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9338649","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9338703","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9338770","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9338841","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9338908","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9338985","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9339040","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9339104","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9339175","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9339239","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9339316","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9339370","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9339434","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9339495","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9339633","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9339688","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9339794","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9339874","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9339960","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9340034","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9340101","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9340185","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9340243","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9340310","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9340380","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9340448","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9340525","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9340579","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9340643","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9340714","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9340781","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9340868","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9340923","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9340990","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9341048","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9341157","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9341211","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9341317","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9341397","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9341513","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9341567","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9341667","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9341747","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9341824","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9341894","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","" "19:13:28,9342010","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9342068","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9342170","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9342257","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9342331","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9342411","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9342475","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:28,9342561","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9342629","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9342719","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9342773","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9342840","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9342914","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9342982","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9343059","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9343113","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9343174","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9343245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9343312","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9343389","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9343443","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9343508","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9343569","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","" "19:13:28,9344030","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9344088","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9344178","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9344281","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9344335","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9344425","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\trust\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9344518","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9344762","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9344816","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9344903","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9345005","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9345060","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9345150","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9345233","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9345297","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9345358","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9345727","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9345782","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9345871","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9345971","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9346025","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9346115","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9346195","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9346259","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9346343","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9346407","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:28,9346497","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9346564","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9346654","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9346708","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9346776","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9346846","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9346914","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9346991","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9347045","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9347109","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9347180","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9347257","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9347331","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9347385","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9347449","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9347510","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9347892","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9347950","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9348036","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9348136","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9348190","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9348274","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,9348357","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9348431","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9348485","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9348578","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9348665","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9348742","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9348809","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9348896","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9348950","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9349014","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9349088","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9349156","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9349229","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9349284","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9349348","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9349422","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9349496","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9349573","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9349627","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9349691","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9349749","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9349868","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9349922","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9350031","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\trust\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9350115","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9350224","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9350278","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9350378","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9350455","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9350535","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9350605","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9350727","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9350782","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9350881","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9350958","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9351035","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9351122","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9351186","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:28,9351272","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9351340","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9351430","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9351484","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9351551","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9351622","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9351689","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9351766","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9351821","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9351885","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9351952","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9352020","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9352093","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9352148","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9352222","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9352283","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9352421","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9352475","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9352581","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9352661","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9352748","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9352821","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9352889","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9352972","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9353030","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9353097","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9353168","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9353235","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9353312","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9353367","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9353431","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9353501","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9353569","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9353643","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9353697","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9353761","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9353822","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9353925","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9353979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9354082","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\trust\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9354162","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9354268","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9354322","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9354422","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9354499","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9354576","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9354643","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","" "19:13:28,9354762","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9354816","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9354916","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9354996","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9355070","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9355150","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9355214","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Desired Access: Read" "19:13:28,9355304","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9355368","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9355458","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9355512","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9355580","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","" "19:13:28,9355650","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9355718","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9355795","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9355849","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9355910","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","" "19:13:28,9355981","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9356048","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9356125","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9356180","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9356240","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","" "19:13:28,9356305","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","" "19:13:28,9356593","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9356661","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9356741","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9356795","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9356863","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:28,9356933","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9356997","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9357071","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9357126","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9357209","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:28,9357389","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9357456","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9357533","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9357587","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9357652","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:28,9357796","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9357850","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9357940","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9358043","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9358094","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9358187","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read" "19:13:28,9358271","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9358357","EasyAntiCheat_launcher.exe","6076","RegQueryKeySecurity","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:28,9358447","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 D0 7F 76 08 98 C6 D5 01" "19:13:28,9358518","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 D0 7F 76 08 98 C6 D5 01" "19:13:28,9358595","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:28,9358656","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9358973","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9359044","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9359124","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:28,9359182","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:28,9359242","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 0, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:28,9359329","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9359396","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:28,9359477","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9359547","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9359605","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 95 6C C4 8F" "19:13:28,9359685","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:28,9359781","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 1, Name: 18F7C1FCC3090203FD5BAA2F861A754976C8DD25" "19:13:28,9359868","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9359938","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","Desired Access: Read" "19:13:28,9360015","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9360083","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9360140","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","SUCCESS","Type: REG_BINARY, Length: 968, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:28,9360217","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","" "19:13:28,9360323","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 2, Name: 245C97DF7514E7CF2DF8BE72AE957B9E04741E85" "19:13:28,9360410","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9360477","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","Desired Access: Read" "19:13:28,9360554","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9360618","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9360679","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","SUCCESS","Type: REG_BINARY, Length: 907, Data: 19 00 00 00 01 00 00 00 10 00 00 00 7F DF F5 07" "19:13:28,9360756","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","" "19:13:28,9360840","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 3, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:28,9360929","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9360997","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:28,9361071","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9361138","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9361196","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 237, Data: 19 00 00 00 01 00 00 00 10 00 00 00 79 A6 2B 38" "19:13:28,9361273","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:28,9361356","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 4, Name: 3B1EFD3A66EA28B16697394703A72CA340A05BD5" "19:13:28,9361436","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9361504","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","Desired Access: Read" "19:13:28,9361581","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9361648","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9361706","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 835, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:28,9361779","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","" "19:13:28,9361869","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 5, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:28,9361953","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9362020","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:28,9362097","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9362161","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9362228","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 149, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9362305","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:28,9362472","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 6, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:28,9362562","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9362633","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:28,9362713","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9362777","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9362835","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 71 BD 96 83" "19:13:28,9362912","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:28,9362995","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 7, Name: 7D5E3BD28E9429952ADFC4630B770C389E7A64FD" "19:13:28,9363078","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9363146","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","Desired Access: Read" "19:13:28,9363223","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9363287","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9363345","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 134, Data: 19 00 00 00 01 00 00 00 10 00 00 00 78 DD D8 24" "19:13:28,9363422","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","" "19:13:28,9363498","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 8, Name: 7F88CD7223F3C813818C994614A89C99FA3B5247" "19:13:28,9363582","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9363649","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","Desired Access: Read" "19:13:28,9363726","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9363790","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9363848","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","SUCCESS","Type: REG_BINARY, Length: 1 228, Data: 19 00 00 00 01 00 00 00 10 00 00 00 07 D3 4D ED" "19:13:28,9363922","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","" "19:13:28,9364005","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 9, Name: 8F43288AD272F3103B6FB1428485EA3014C0BCFE" "19:13:28,9364089","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9364156","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","Desired Access: Read" "19:13:28,9364230","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9364294","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9364352","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 869, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:28,9364429","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","" "19:13:28,9364515","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 10, Name: 9007A10299C432559B502DB7D6C449757780FDB1" "19:13:28,9364602","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9364669","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","Desired Access: Read" "19:13:28,9364743","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9364807","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9364865","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 D4 65 24 73" "19:13:28,9364942","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","" "19:13:28,9365038","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 11, Name: 92B46C76E13054E104F230517E6E504D43AB10B5" "19:13:28,9365121","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9365189","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","Desired Access: Read" "19:13:28,9365266","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9365330","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9365388","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 255, Data: 09 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:28,9365461","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","" "19:13:28,9365551","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 12, Name: A43489159A520F0D93D032CCAF37E7FE20A8B419" "19:13:28,9365635","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9365702","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","Desired Access: Read" "19:13:28,9365776","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9365843","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9365901","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","SUCCESS","Type: REG_BINARY, Length: 1 310, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9365975","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","" "19:13:28,9366061","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 13, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:28,9366144","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9366212","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:28,9366289","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9366353","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9366411","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 8B 7C EF 92" "19:13:28,9366488","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:28,9366568","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 14, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:28,9366651","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9366722","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:28,9366796","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9366860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9366917","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 823, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 42 25 E4" "19:13:28,9366994","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:28,9367071","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 15, Name: B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD" "19:13:28,9367155","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9367232","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","Desired Access: Read" "19:13:28,9367309","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9367376","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9367431","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 105, Data: 19 00 00 00 01 00 00 00 10 00 00 00 56 57 7B 94" "19:13:28,9367508","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","" "19:13:28,9367585","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 16, Name: BE36A4562FB2EE05DBB3D32323ADF445084ED656" "19:13:28,9368579","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9368656","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","Desired Access: Read" "19:13:28,9368742","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9368813","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9368871","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","SUCCESS","Type: REG_BINARY, Length: 935, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:28,9368954","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","" "19:13:28,9369050","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 17, Name: CDD4EEAE6000AC7F40C3802C171E30148030C072" "19:13:28,9369445","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9369519","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","Desired Access: Read" "19:13:28,9369602","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9369839","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9369977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","SUCCESS","Type: REG_BINARY, Length: 1 759, Data: 59 00 00 00 01 00 00 00 12 00 00 00 52 00 53 00" "19:13:28,9370086","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","" "19:13:28,9370215","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 18, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:28,9370340","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9370429","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:28,9370532","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9370603","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9370660","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 071, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9370747","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:28,9370837","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 19, Name: E06A30801D661F606869D9BC0ACC5EE57C7A48A7" "19:13:28,9370927","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9371000","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","Desired Access: Read" "19:13:28,9371084","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9371151","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9371209","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 102, Data: 19 00 00 00 01 00 00 00 10 00 00 00 B7 B9 C2 BF" "19:13:28,9371289","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","" "19:13:28,9371376","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 20, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:28,9371462","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9371530","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:28,9371610","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9371677","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9371735","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 BB AD 3C 3F" "19:13:28,9371812","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:28,9371898","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","" "19:13:28,9371979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9372049","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9372129","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9372222","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9372290","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","" "19:13:28,9372363","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9372431","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9372505","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9372559","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9372620","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","" "19:13:28,9373852","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9373925","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9374006","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:28,9374063","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:28,9374124","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 0, Name: 02FAF3E291435468607857694DF5E45B68851868" "19:13:28,9374208","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9374275","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","Desired Access: Read" "19:13:28,9374362","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9374432","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9374493","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","SUCCESS","Type: REG_BINARY, Length: 1 559, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9374576","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","" "19:13:28,9374692","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 1, Name: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" "19:13:28,9374782","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9374852","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","Desired Access: Read" "19:13:28,9374929","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9374997","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9375058","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","SUCCESS","Type: REG_BINARY, Length: 1 377, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9375134","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","" "19:13:28,9375247","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 2, Name: 06083F593F15A104A069A46BA903D006B7970991" "19:13:28,9375333","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9375401","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","Desired Access: Read" "19:13:28,9375484","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9375551","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9375609","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","SUCCESS","Type: REG_BINARY, Length: 1 577, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9375686","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","" "19:13:28,9375782","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 3, Name: 06F1AA330B927B753A40E68CDF22E34BCBEF3352" "19:13:28,9375866","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9375933","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","Desired Access: Read" "19:13:28,9376013","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9376081","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9376138","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","SUCCESS","Type: REG_BINARY, Length: 1 233, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 80 01 00 00" "19:13:28,9376212","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","" "19:13:28,9376305","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 4, Name: 07E032E020B72C3F192F0628A2593A19A70F069E" "19:13:28,9376392","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9376459","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","Desired Access: Read" "19:13:28,9376536","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9376603","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9376661","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 484, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9376738","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","" "19:13:28,9376831","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 5, Name: 093C61F38B8BDC7D55DF7538020500E125F5C836" "19:13:28,9376915","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9376982","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","Desired Access: Read" "19:13:28,9377062","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9377129","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9377206","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","SUCCESS","Type: REG_BINARY, Length: 1 868, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:28,9377287","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","" "19:13:28,9377389","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 6, Name: 1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA" "19:13:28,9377473","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9377543","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","Desired Access: Read" "19:13:28,9377620","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9377687","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9377745","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","SUCCESS","Type: REG_BINARY, Length: 1 034, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9377822","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","" "19:13:28,9377915","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 7, Name: 2796BAE63F1801E277261BA0D77770028F20EEE4" "19:13:28,9377999","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9378066","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","Desired Access: Read" "19:13:28,9378143","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9378207","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9378265","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 512, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9378342","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","" "19:13:28,9378432","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 8, Name: 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E" "19:13:28,9378515","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9378582","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","Desired Access: Read" "19:13:28,9378662","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9378727","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9378784","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 989, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9378861","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","" "19:13:28,9378951","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 9, Name: 2BB1F53E550C1DC5F1D4E6B76A464B550602AC21" "19:13:28,9379035","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9379102","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","Desired Access: Read" "19:13:28,9379179","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9379243","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9379301","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","SUCCESS","Type: REG_BINARY, Length: 1 317, Data: 7F 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:28,9379378","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","" "19:13:28,9379487","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 10, Name: 3679CA35668772304D30A5FB873B0FA77BB70D54" "19:13:28,9379570","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9379637","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","Desired Access: Read" "19:13:28,9379721","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9379788","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9379846","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","SUCCESS","Type: REG_BINARY, Length: 1 781, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9379923","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","" "19:13:28,9380022","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 11, Name: 36B12B49F9819ED74C9EBC380FC6568F5DACB2F7" "19:13:28,9380106","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9380173","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","Desired Access: Read" "19:13:28,9380256","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9380324","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9380382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 370, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:28,9380455","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","" "19:13:28,9380571","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 12, Name: 3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F" "19:13:28,9380657","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9380725","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","Desired Access: Read" "19:13:28,9380805","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9380949","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9381033","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","SUCCESS","Type: REG_BINARY, Length: 2 512, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9381116","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","" "19:13:28,9381215","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 13, Name: 47BEABC922EAE80E78783462A79F45C254FDE68B" "19:13:28,9381299","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9381369","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","Desired Access: Read" "19:13:28,9381446","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9381514","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9381571","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9381645","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","" "19:13:28,9381745","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 14, Name: 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5" "19:13:28,9381828","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9381895","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","Desired Access: Read" "19:13:28,9381976","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9382043","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9382101","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 760, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9382178","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","" "19:13:28,9382293","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 15, Name: 503006091D97D4F5AE39F7CBE7927D7D652D3431" "19:13:28,9382380","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9382447","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","Desired Access: Read" "19:13:28,9382527","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9382591","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9382649","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","SUCCESS","Type: REG_BINARY, Length: 1 613, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9382739","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","" "19:13:28,9382838","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 16, Name: 51501FBFCE69189D609CFAF140C576755DCC1FDF" "19:13:28,9382922","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9382989","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","Desired Access: Read" "19:13:28,9383072","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9383140","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9383198","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","SUCCESS","Type: REG_BINARY, Length: 1 808, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:28,9383271","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","" "19:13:28,9383368","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 17, Name: 590D2D7D884F402E617EA562321765CF17D894E9" "19:13:28,9383451","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9383518","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","Desired Access: Read" "19:13:28,9383595","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9383663","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9383720","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 345, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:28,9383797","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","" "19:13:28,9383890","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 18, Name: 5D003860F002ED829DEAA41868F788186D62127F" "19:13:28,9383974","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9384041","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","Desired Access: Read" "19:13:28,9384121","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9384185","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9384243","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","SUCCESS","Type: REG_BINARY, Length: 1 679, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9384317","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","" "19:13:28,9384413","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 19, Name: 5F3B8CF2F810B37D78B4CEEC1919C37334B9C774" "19:13:28,9384497","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9384564","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","Desired Access: Read" "19:13:28,9384644","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9384711","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9384769","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","SUCCESS","Type: REG_BINARY, Length: 1 335, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9384843","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","" "19:13:28,9384933","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 20, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:28,9385016","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9385083","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:28,9385164","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9385228","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9385285","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 391, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9385362","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:28,9385452","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 21, Name: 6252DC40F71143A22FDE9EF7348E064251B18118" "19:13:28,9385536","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9385603","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","Desired Access: Read" "19:13:28,9385683","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9385751","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9385808","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","SUCCESS","Type: REG_BINARY, Length: 1 190, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:28,9385882","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","" "19:13:28,9386084","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 22, Name: 742C3192E607E424EB4549542BE1BBC53E6174E2" "19:13:28,9386174","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9386241","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","Desired Access: Read" "19:13:28,9386325","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9386392","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9386450","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 074, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9386527","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","" "19:13:28,9386626","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 23, Name: 75E0ABB6138512271C04F85FDDDE38E4B7242EFE" "19:13:28,9386710","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9386777","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","Desired Access: Read" "19:13:28,9386854","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9386921","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9386979","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 555, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:28,9387056","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","" "19:13:28,9387155","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 24, Name: 7E04DE896A3E666D00E687D33FFAD93BE83D349E" "19:13:28,9387255","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9387322","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","Desired Access: Read" "19:13:28,9387406","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9387470","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9387531","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 059, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9387604","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","" "19:13:28,9387697","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 25, Name: 8782C6C304353BCFD29692D2593E7D44D934FF11" "19:13:28,9387781","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9387848","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","Desired Access: Read" "19:13:28,9387928","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9387996","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9388053","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","SUCCESS","Type: REG_BINARY, Length: 1 354, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9388130","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","" "19:13:28,9388220","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 26, Name: 89DF74FE5CF40F4A80F9E3377D54DA91E101318E" "19:13:28,9388304","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9388371","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","Desired Access: Read" "19:13:28,9388448","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9388512","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9388570","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9388647","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","" "19:13:28,9388733","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 27, Name: 8CF427FD790C3AD166068DE81E57EFBB932272D4" "19:13:28,9388817","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9388884","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","Desired Access: Read" "19:13:28,9388964","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9389028","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9389086","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 639, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:28,9389163","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","" "19:13:28,9389259","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 28, Name: 91C6D6EE3E8AC86384E548C299295C756C817B81" "19:13:28,9389343","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9389410","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","Desired Access: Read" "19:13:28,9389487","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9389551","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9389612","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","SUCCESS","Type: REG_BINARY, Length: 1 515, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9389686","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","" "19:13:28,9389782","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 29, Name: 97817950D81C9670CC34D809CF794431367EF474" "19:13:28,9389865","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9389933","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","Desired Access: Read" "19:13:28,9390013","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9390077","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9390148","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 050, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:28,9390225","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","" "19:13:28,9390318","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 30, Name: A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436" "19:13:28,9390401","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9390468","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","Desired Access: Read" "19:13:28,9390545","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9390613","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9390671","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","SUCCESS","Type: REG_BINARY, Length: 1 369, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9390744","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","" "19:13:28,9390837","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 31, Name: AD7E1C28B064EF8F6003402014C3D0E3370EB58A" "19:13:28,9390921","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9390988","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","Desired Access: Read" "19:13:28,9391068","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9391132","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9391190","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9391264","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","" "19:13:28,9391357","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 32, Name: AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4" "19:13:28,9391440","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9391508","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","Desired Access: Read" "19:13:28,9391588","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9391652","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9391722","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","SUCCESS","Type: REG_BINARY, Length: 2 025, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9391799","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","" "19:13:28,9391892","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 33, Name: B1BC968BD4F49D622AA89A81F2150152A41D829C" "19:13:28,9391979","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9392046","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","Desired Access: Read" "19:13:28,9392123","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9392220","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9392284","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 461, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:28,9392361","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","" "19:13:28,9392460","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 34, Name: B31EB1B740E36C8402DADC37D44DF5D4674952F9" "19:13:28,9392544","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9392611","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","Desired Access: Read" "19:13:28,9392691","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9392755","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9392813","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 712, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:28,9392890","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","" "19:13:28,9392999","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 35, Name: B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E" "19:13:28,9393086","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9393153","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","Desired Access: Read" "19:13:28,9393230","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9393294","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9393352","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 498, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:28,9393429","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","" "19:13:28,9393522","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 36, Name: CA3AFBCF1240364B44B216208880483919937CF7" "19:13:28,9393602","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9393669","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","Desired Access: Read" "19:13:28,9393749","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9393814","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9393871","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 937, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:28,9393945","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","" "19:13:28,9394038","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 37, Name: CABD2A79A1076A31F21D253635CB039D4329A5E8" "19:13:28,9394122","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9394189","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","Desired Access: Read" "19:13:28,9394269","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9394333","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9394391","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 717, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:28,9394468","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","" "19:13:28,9394555","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 38, Name: CF9E876DD3EBFC422697A3B5A37AA076A9062348" "19:13:28,9394638","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9394705","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","Desired Access: Read" "19:13:28,9394785","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9394846","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9394904","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","SUCCESS","Type: REG_BINARY, Length: 1 421, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:28,9394981","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","" "19:13:28,9395074","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 39, Name: D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0" "19:13:28,9395157","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9395222","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","Desired Access: Read" "19:13:28,9395305","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9395369","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9395427","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 150, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9395501","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","" "19:13:28,9395603","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 40, Name: D1EB23A46D17D68FD92564C2F1F1601764D8E349" "19:13:28,9395687","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9395754","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","Desired Access: Read" "19:13:28,9395837","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9395902","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9395959","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","SUCCESS","Type: REG_BINARY, Length: 1 545, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:28,9396036","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","" "19:13:28,9396126","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 41, Name: D23209AD23D314232174E40D7F9D62139786633A" "19:13:28,9396209","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9396277","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","Desired Access: Read" "19:13:28,9396354","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9396418","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9396476","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 197, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:28,9396553","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","" "19:13:28,9396642","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 42, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:28,9396726","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9396793","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:28,9396870","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9396934","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9396992","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 460, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:28,9397066","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:28,9397162","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 43, Name: D69B561148F01C77C54578C10926DF5B856976AD" "19:13:28,9397265","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9397335","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","Desired Access: Read" "19:13:28,9397415","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9397492","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9397550","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 363, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:28,9397627","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","" "19:13:28,9397733","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 44, Name: D8C5388AB7301B1B6ED47AE645253A6F9F1A2761" "19:13:28,9397816","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9397884","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","Desired Access: Read" "19:13:28,9397964","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9398028","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9398118","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","SUCCESS","Type: REG_BINARY, Length: 1 855, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:28,9398198","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","" "19:13:28,9398291","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 45, Name: DAC9024F54D8F6DF94935FB1732638CA6AD77C13" "19:13:28,9398374","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9398442","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","Desired Access: Read" "19:13:28,9398522","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9398586","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9398644","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","SUCCESS","Type: REG_BINARY, Length: 1 264, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:28,9398721","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","" "19:13:28,9398811","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 46, Name: DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212" "19:13:28,9398894","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9398965","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","Desired Access: Read" "19:13:28,9399038","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9399106","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9399163","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","SUCCESS","Type: REG_BINARY, Length: 1 306, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:28,9399237","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","" "19:13:28,9399330","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 47, Name: DE3F40BD5093D39B6C60F6DABC076201008976C9" "19:13:28,9399414","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9399481","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","Desired Access: Read" "19:13:28,9399561","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9399625","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9399683","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 958, Data: 4B 00 00 00 01 00 00 00 02 00 00 00 00 00 04 00" "19:13:28,9399760","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","" "19:13:28,9399853","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 48, Name: DF3C24F9BFD666761B268073FE06D1CC8D4F82A4" "19:13:28,9399936","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9400004","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","Desired Access: Read" "19:13:28,9400081","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9400145","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9400203","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 378, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9400279","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","" "19:13:28,9400369","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 49, Name: DF717EAA4AD94EC9558499602D48DE5FBCF03A25" "19:13:28,9400453","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9400520","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","Desired Access: Read" "19:13:28,9400597","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9400661","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9400722","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 947, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:28,9400799","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","" "19:13:28,9400892","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 50, Name: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46" "19:13:28,9400975","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9401043","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","Desired Access: Read" "19:13:28,9401123","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9401190","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9401248","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","SUCCESS","Type: REG_BINARY, Length: 1 482, Data: 09 00 00 00 01 00 00 00 22 00 00 00 30 20 06 08" "19:13:28,9401325","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","" "19:13:28,9401412","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 51, Name: F373B387065A28848AF2F34ACE192BDDC78E9CAC" "19:13:28,9401495","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9401562","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","Desired Access: Read" "19:13:28,9401643","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9401704","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9401761","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","SUCCESS","Type: REG_BINARY, Length: 1 917, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:28,9401838","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","" "19:13:28,9401931","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 52, Name: F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7" "19:13:28,9402015","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9402082","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","Desired Access: Read" "19:13:28,9402159","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9402239","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9402300","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 400, Data: 7F 00 00 00 01 00 00 00 36 00 00 00 30 34 06 08" "19:13:28,9402377","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","" "19:13:28,9402470","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 53, Name: FE45659B79035B98A161B5512EACDA580948224D" "19:13:28,9402553","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9402621","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","Desired Access: Read" "19:13:28,9402701","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9402765","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9402823","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 40 00 00 00 30 3E 06 08" "19:13:28,9402897","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","" "19:13:28,9402993","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","" "19:13:28,9403070","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9403134","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9403217","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9403275","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9403339","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","" "19:13:28,9403410","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9403474","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9403544","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9403599","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9403663","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","" "19:13:28,9408920","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 20:09:39, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 114 688, EndOfFile: 110 608, FileAttributes: A" "19:13:28,9409680","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9410100","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\gpapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9410337","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9410742","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Image Base: 0x6df30000, Image Size: 0x1e000" "19:13:28,9411566","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","" "19:13:28,9413141","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9413474","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\gpapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,9413590","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Information: Owner" "19:13:28,9413699","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","" "19:13:28,9414417","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9414491","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9414645","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Diagnostics","NAME NOT FOUND","Desired Access: Read" "19:13:28,9414802","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9414857","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9414962","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read" "19:13:28,9415091","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9415161","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel","NAME NOT FOUND","Length: 144" "19:13:28,9415264","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","" "19:13:28,9415341","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9415395","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9415501","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\System","REPARSE","Desired Access: Read" "19:13:28,9415597","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","Desired Access: Read" "19:13:28,9415706","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9415771","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel","NAME NOT FOUND","Length: 144" "19:13:28,9415860","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","" "19:13:28,9415953","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9416008","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9416095","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:28,9416191","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9416248","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,9416335","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,9416537","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9416595","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9416698","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates","REPARSE","Desired Access: Read" "19:13:28,9416781","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates","SUCCESS","Desired Access: Read" "19:13:28,9416877","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9417130","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9417185","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9417297","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read" "19:13:28,9417384","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read" "19:13:28,9417477","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9417560","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9417628","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9417714","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9417772","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9417843","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:28,9417919","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9417984","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9418064","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9418118","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9418186","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:28,9418253","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9418320","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9418394","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9418449","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9418516","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:28,9418577","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:28,9418785","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9418859","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9418943","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9419000","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9419068","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","" "19:13:28,9419135","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9419199","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9419276","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9419449","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9419558","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","" "19:13:28,9419667","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9419757","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9419857","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9419914","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9419982","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","" "19:13:28,9420238","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9420315","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9420399","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9420456","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9420524","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:28,9420594","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9420662","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9420735","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9420790","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9420854","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:28,9420925","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9420989","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9421063","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9421117","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9421188","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:28,9421435","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9421508","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9421595","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9421653","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9421720","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:28,9421794","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9421861","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9421938","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9421993","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9422066","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:28,9422137","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9422201","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9422285","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9422339","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9422406","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:28,9422631","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9422698","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9422782","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9422839","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9422907","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9422981","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9423048","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9423122","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9423176","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9423240","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9423311","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9423404","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9423516","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9423574","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9423644","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9423789","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9423847","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9423959","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Diagnostics","NAME NOT FOUND","Desired Access: Read" "19:13:28,9424065","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9424119","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9424215","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read" "19:13:28,9424305","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9424369","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel","NAME NOT FOUND","Length: 144" "19:13:28,9424449","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","" "19:13:28,9424520","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9424571","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9424668","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\System","REPARSE","Desired Access: Read" "19:13:28,9424745","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","Desired Access: Read" "19:13:28,9424828","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9424889","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel","NAME NOT FOUND","Length: 144" "19:13:28,9424963","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","" "19:13:28,9425033","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9425088","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9425171","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:28,9425248","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9425303","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,9425380","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:28,9425864","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9425922","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9426018","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9426137","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9426191","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9426284","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates","SUCCESS","Desired Access: Read" "19:13:28,9426374","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9426438","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9426586","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9426640","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9426733","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:28,9426820","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9426900","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9426967","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9427044","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9427102","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9427169","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9427249","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9427314","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9427391","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9427445","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9427509","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9427580","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9427644","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9427714","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9427769","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9427833","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9427891","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9428083","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9428151","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9428231","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9428289","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9428356","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9428423","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9428487","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9428561","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9428616","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9428680","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9428747","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9428811","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9428885","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9428936","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9429001","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9429119","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9429174","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9429276","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read" "19:13:28,9429357","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:28,9429440","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9429514","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9429578","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9429652","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9429706","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9429774","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:28,9429857","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9429924","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9430001","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9430056","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9430120","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:28,9430191","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9430251","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9430325","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9430380","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9430444","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:28,9430502","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:28,9430665","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9430733","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9430810","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9430864","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9430931","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","" "19:13:28,9430999","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9431063","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9431133","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9431188","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9431252","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","" "19:13:28,9431319","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9431384","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9431454","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9431509","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9431573","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","" "19:13:28,9431743","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9431807","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9431884","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 38, Values: 0" "19:13:28,9431938","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 38, Values: 0" "19:13:28,9431999","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: 02D65B95E28370C1570095FA88F923DD937FAD8F" "19:13:28,9432092","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9432160","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F","SUCCESS","Desired Access: Read" "19:13:28,9432250","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9432323","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9432384","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F\Blob","SUCCESS","Type: REG_BINARY, Length: 2 092, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 30 00 37 00" "19:13:28,9432471","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\02D65B95E28370C1570095FA88F923DD937FAD8F","SUCCESS","" "19:13:28,9432580","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 1, Name: 06B25927C42A721631C1EFD9431E648FA62E1E39" "19:13:28,9432670","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9432737","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39","SUCCESS","Desired Access: Read" "19:13:28,9432824","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9432891","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9432949","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39\Blob","SUCCESS","Type: REG_BINARY, Length: 1 508, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 42 00 41 00" "19:13:28,9433029","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\06B25927C42A721631C1EFD9431E648FA62E1E39","SUCCESS","" "19:13:28,9433128","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 2, Name: 1FB86B1168EC743154062E8C9CC5B171A4B7CCB4" "19:13:28,9433212","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9433279","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4","SUCCESS","Desired Access: Read" "19:13:28,9433362","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9433427","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9433484","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 510, Data: 03 00 00 00 01 00 00 00 14 00 00 00 1F B8 6B 11" "19:13:28,9433561","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\1FB86B1168EC743154062E8C9CC5B171A4B7CCB4","SUCCESS","" "19:13:28,9433658","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 3, Name: 27AC9369FAF25207BB2627CEFACCBE4EF9C319B8" "19:13:28,9433741","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9433808","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8","SUCCESS","Desired Access: Read" "19:13:28,9433888","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9433956","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9434014","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 570, Data: 03 00 00 00 01 00 00 00 14 00 00 00 27 AC 93 69" "19:13:28,9434091","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\27AC9369FAF25207BB2627CEFACCBE4EF9C319B8","SUCCESS","" "19:13:28,9434180","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 4, Name: 2F2877C5D778C31E0F29C7E371DF5471BD673173" "19:13:28,9434264","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9434331","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173","SUCCESS","Desired Access: Read" "19:13:28,9434411","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9434475","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9434536","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173\Blob","SUCCESS","Type: REG_BINARY, Length: 1 877, Data: 03 00 00 00 01 00 00 00 14 00 00 00 2F 28 77 C5" "19:13:28,9434610","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\2F2877C5D778C31E0F29C7E371DF5471BD673173","SUCCESS","" "19:13:28,9434700","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 5, Name: 339CDD57CFD5B141169B615FF31428782D1DA639" "19:13:28,9434787","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9434851","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639","SUCCESS","Desired Access: Read" "19:13:28,9434931","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9434995","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9435053","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639\Blob","SUCCESS","Type: REG_BINARY, Length: 1 898, Data: 03 00 00 00 01 00 00 00 14 00 00 00 33 9C DD 57" "19:13:28,9435133","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\339CDD57CFD5B141169B615FF31428782D1DA639","SUCCESS","" "19:13:28,9435223","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 6, Name: 33E4E80807204C2B6182A3A14B591ACD25B5F0DB" "19:13:28,9435306","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9435373","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB","SUCCESS","Desired Access: Read" "19:13:28,9435450","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9435515","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9435572","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB\Blob","SUCCESS","Type: REG_BINARY, Length: 1 909, Data: 03 00 00 00 01 00 00 00 14 00 00 00 33 E4 E8 08" "19:13:28,9435649","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\33E4E80807204C2B6182A3A14B591ACD25B5F0DB","SUCCESS","" "19:13:28,9435739","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 7, Name: 409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875" "19:13:28,9435822","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9435890","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875","SUCCESS","Desired Access: Read" "19:13:28,9435967","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9436034","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9436092","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875\Blob","SUCCESS","Type: REG_BINARY, Length: 1 991, Data: 03 00 00 00 01 00 00 00 14 00 00 00 40 9A A4 A7" "19:13:28,9436169","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\409AA4A74A0CDA7C0FEE6BD0BB8823D16B5F1875","SUCCESS","" "19:13:28,9436255","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 8, Name: 40CEF3046C916ED7AE557F60E76842828B51DE53" "19:13:28,9436339","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9436406","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53","SUCCESS","Desired Access: Read" "19:13:28,9436486","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9436547","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9436608","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53\Blob","SUCCESS","Type: REG_BINARY, Length: 1 915, Data: 03 00 00 00 01 00 00 00 14 00 00 00 40 CE F3 04" "19:13:28,9436698","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\40CEF3046C916ED7AE557F60E76842828B51DE53","SUCCESS","" "19:13:28,9436788","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 9, Name: 440FF68A35E03995AC55E457A67EB1680F9A7CDD" "19:13:28,9436871","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9436939","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD","SUCCESS","Desired Access: Read" "19:13:28,9437022","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9437086","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9437144","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 896, Data: 03 00 00 00 01 00 00 00 14 00 00 00 44 0F F6 8A" "19:13:28,9437234","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\440FF68A35E03995AC55E457A67EB1680F9A7CDD","SUCCESS","" "19:13:28,9437320","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 10, Name: 48504E974C0DAC5B5CD476C8202274B24C8C7172" "19:13:28,9437404","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9437471","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172","SUCCESS","Desired Access: Read" "19:13:28,9437551","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9437615","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9437673","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172\Blob","SUCCESS","Type: REG_BINARY, Length: 1 383, Data: 03 00 00 00 01 00 00 00 14 00 00 00 48 50 4E 97" "19:13:28,9437750","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\48504E974C0DAC5B5CD476C8202274B24C8C7172","SUCCESS","" "19:13:28,9437833","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 11, Name: 4C27431717565A3A07F3E6D0032C4258949CF9EC" "19:13:28,9437917","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9437984","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC","SUCCESS","Desired Access: Read" "19:13:28,9438068","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9438132","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9438189","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC\Blob","SUCCESS","Type: REG_BINARY, Length: 1 439, Data: 03 00 00 00 01 00 00 00 14 00 00 00 4C 27 43 17" "19:13:28,9438266","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\4C27431717565A3A07F3E6D0032C4258949CF9EC","SUCCESS","" "19:13:28,9438353","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 12, Name: 6023192FE7B59D2789130A9FE4094F9B5570D4A2" "19:13:28,9438436","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9438501","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2","SUCCESS","Desired Access: Read" "19:13:28,9438581","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9438645","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9438703","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 60 23 19 2F" "19:13:28,9438780","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\6023192FE7B59D2789130A9FE4094F9B5570D4A2","SUCCESS","" "19:13:28,9438869","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 13, Name: 77B99BB2BD7522E17EC099EA7177516F27787CAD" "19:13:28,9438953","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9439020","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD","SUCCESS","Desired Access: Read" "19:13:28,9439104","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9439168","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9439225","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 613, Data: 03 00 00 00 01 00 00 00 14 00 00 00 77 B9 9B B2" "19:13:28,9439299","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\77B99BB2BD7522E17EC099EA7177516F27787CAD","SUCCESS","" "19:13:28,9439386","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 14, Name: 78892492BAADB0679670F606667544740E416C4C" "19:13:28,9439469","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9439536","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C","SUCCESS","Desired Access: Read" "19:13:28,9439617","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9439681","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9439739","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C\Blob","SUCCESS","Type: REG_BINARY, Length: 2 017, Data: 03 00 00 00 01 00 00 00 14 00 00 00 78 89 24 92" "19:13:28,9439816","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\78892492BAADB0679670F606667544740E416C4C","SUCCESS","" "19:13:28,9439909","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 15, Name: 7CCC2A87E3949F20572B18482980505FA90CAC3B" "19:13:28,9439992","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9440059","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B","SUCCESS","Desired Access: Read" "19:13:28,9440136","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9440200","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9440261","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 501, Data: 03 00 00 00 01 00 00 00 14 00 00 00 7C CC 2A 87" "19:13:28,9440335","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7CCC2A87E3949F20572B18482980505FA90CAC3B","SUCCESS","" "19:13:28,9440422","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 16, Name: 7EDC376DCFD45E6DDF082C160DF6AC21835B95D4" "19:13:28,9440505","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9440572","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4","SUCCESS","Desired Access: Read" "19:13:28,9440653","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9440717","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9440774","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 618, Data: 03 00 00 00 01 00 00 00 14 00 00 00 7E DC 37 6D" "19:13:28,9440851","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\7EDC376DCFD45E6DDF082C160DF6AC21835B95D4","SUCCESS","" "19:13:28,9440938","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 17, Name: 8BFE3107712B3C886B1C96AAEC89984914DC9B6B" "19:13:28,9441021","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9441089","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B","SUCCESS","Desired Access: Read" "19:13:28,9441169","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9441230","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9441288","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 906, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:28,9441365","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\8BFE3107712B3C886B1C96AAEC89984914DC9B6B","SUCCESS","" "19:13:28,9441451","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 18, Name: 902EF2DEEB3C5B13EA4C3D5193629309E231AE55" "19:13:28,9441538","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9441602","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55","SUCCESS","Desired Access: Read" "19:13:28,9441682","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9441746","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9441804","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55\Blob","SUCCESS","Type: REG_BINARY, Length: 1 467, Data: 03 00 00 00 01 00 00 00 14 00 00 00 90 2E F2 DE" "19:13:28,9441881","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\902EF2DEEB3C5B13EA4C3D5193629309E231AE55","SUCCESS","" "19:13:28,9441971","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 19, Name: 94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66" "19:13:28,9442057","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9442125","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66","SUCCESS","Desired Access: Read" "19:13:28,9442215","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9442279","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9442336","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66\Blob","SUCCESS","Type: REG_BINARY, Length: 1 845, Data: 03 00 00 00 01 00 00 00 14 00 00 00 94 C9 5D A1" "19:13:28,9442413","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\94C95DA1E850BD85209A4A2AF3E1FB1604F9BB66","SUCCESS","" "19:13:28,9442500","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 20, Name: 98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D" "19:13:28,9442583","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9442651","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D","SUCCESS","Desired Access: Read" "19:13:28,9442728","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9442792","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9442850","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D\Blob","SUCCESS","Type: REG_BINARY, Length: 1 539, Data: 03 00 00 00 01 00 00 00 14 00 00 00 98 C6 A8 DC" "19:13:28,9442927","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\98C6A8DC887963BA3CF9C2731CBDD3F7DE05AC2D","SUCCESS","" "19:13:28,9443016","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 21, Name: 9E99A48A9960B14926BB7F3B02E22DA2B0AB7280" "19:13:28,9443100","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9443174","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280","SUCCESS","Desired Access: Read" "19:13:28,9443260","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9443324","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9443382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280\Blob","SUCCESS","Type: REG_BINARY, Length: 1 479, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 42 00 36 00" "19:13:28,9443456","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\9E99A48A9960B14926BB7F3B02E22DA2B0AB7280","SUCCESS","" "19:13:28,9443546","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 22, Name: A031C46782E6E6C662C2C87C76DA9AA62CCABD8E" "19:13:28,9443632","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9443696","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E","SUCCESS","Desired Access: Read" "19:13:28,9443780","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9443844","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9443902","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 539, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 45 00 44 00" "19:13:28,9443975","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A031C46782E6E6C662C2C87C76DA9AA62CCABD8E","SUCCESS","" "19:13:28,9444065","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 23, Name: A0863E7F47091FAFA229848C622F5602BB136C38" "19:13:28,9444149","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9444216","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38","SUCCESS","Desired Access: Read" "19:13:28,9444296","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9444367","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9444421","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38\Blob","SUCCESS","Type: REG_BINARY, Length: 1 968, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A0 86 3E 7F" "19:13:28,9444501","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A0863E7F47091FAFA229848C622F5602BB136C38","SUCCESS","" "19:13:28,9444588","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 24, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:28,9444675","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9444739","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:28,9444819","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9444883","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9444944","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 867, Data: 04 00 00 00 01 00 00 00 10 00 00 00 18 23 21 7D" "19:13:28,9445018","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:28,9445104","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 25, Name: B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75" "19:13:28,9445188","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9445252","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75","SUCCESS","Desired Access: Read" "19:13:28,9445335","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9445399","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9445457","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75\Blob","SUCCESS","Type: REG_BINARY, Length: 1 708, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 36 00 42 00" "19:13:28,9445531","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\B0C2D2D13CDD56CDAA6AB6E2C04440BE4A429C75","SUCCESS","" "19:13:28,9445621","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 26, Name: C01B8463C8619676BA102EEBF0C30CDCED9A942B" "19:13:28,9445704","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9445771","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B","SUCCESS","Desired Access: Read" "19:13:28,9445852","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9445919","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9445977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 333, Data: 03 00 00 00 01 00 00 00 14 00 00 00 C0 1B 84 63" "19:13:28,9446050","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C01B8463C8619676BA102EEBF0C30CDCED9A942B","SUCCESS","" "19:13:28,9446137","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 27, Name: C2826E266D7405D34EF89762636AE4B36E86CB5E" "19:13:28,9446220","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9446285","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E","SUCCESS","Desired Access: Read" "19:13:28,9446365","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9446429","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9446487","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E\Blob","SUCCESS","Type: REG_BINARY, Length: 2 119, Data: 03 00 00 00 01 00 00 00 14 00 00 00 C2 82 6E 26" "19:13:28,9446564","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C2826E266D7405D34EF89762636AE4B36E86CB5E","SUCCESS","" "19:13:28,9446666","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 28, Name: C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34" "19:13:28,9446750","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9446817","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34","SUCCESS","Desired Access: Read" "19:13:28,9446897","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9446961","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9447019","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34\Blob","SUCCESS","Type: REG_BINARY, Length: 2 103, Data: 03 00 00 00 01 00 00 00 14 00 00 00 C8 1A 8B D1" "19:13:28,9447099","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\C81A8BD1F9CF6D84C525F378CA1D3F8C30770E34","SUCCESS","" "19:13:28,9447183","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 29, Name: D6AEE31631F7ABC56B9DE8ABECCC4108A626B104" "19:13:28,9447276","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9447343","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104","SUCCESS","Desired Access: Read" "19:13:28,9447420","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9447484","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9447542","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104\Blob","SUCCESS","Type: REG_BINARY, Length: 1 501, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D6 AE E3 16" "19:13:28,9447619","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\D6AEE31631F7ABC56B9DE8ABECCC4108A626B104","SUCCESS","" "19:13:28,9447705","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 30, Name: DFE83023062B997682708B4EAB8E819AFF5D9775" "19:13:28,9447789","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9447856","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775","SUCCESS","Desired Access: Read" "19:13:28,9447936","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9448000","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9448061","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775\Blob","SUCCESS","Type: REG_BINARY, Length: 1 440, Data: 03 00 00 00 01 00 00 00 14 00 00 00 DF E8 30 23" "19:13:28,9448135","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\DFE83023062B997682708B4EAB8E819AFF5D9775","SUCCESS","" "19:13:28,9448225","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 31, Name: E6A3B45B062D509B3382282D196EFE97D5956CCB" "19:13:28,9448312","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9448379","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB","SUCCESS","Desired Access: Read" "19:13:28,9448459","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9448526","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9448584","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB\Blob","SUCCESS","Type: REG_BINARY, Length: 1 508, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 45 00 34 00" "19:13:28,9448658","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\E6A3B45B062D509B3382282D196EFE97D5956CCB","SUCCESS","" "19:13:28,9448751","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 32, Name: EC4191D1F357BD539483286FA67FD219143D2611" "19:13:28,9448834","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9448902","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611","SUCCESS","Desired Access: Read" "19:13:28,9448979","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9449043","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9449101","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611\Blob","SUCCESS","Type: REG_BINARY, Length: 1 536, Data: 03 00 00 00 01 00 00 00 14 00 00 00 EC 41 91 D1" "19:13:28,9449174","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\EC4191D1F357BD539483286FA67FD219143D2611","SUCCESS","" "19:13:28,9449264","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 33, Name: F21C12F46CDB6B2E16F09F9419CDFF328437B2D7" "19:13:28,9449348","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9449412","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7","SUCCESS","Desired Access: Read" "19:13:28,9449492","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9449553","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9449623","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 632, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F2 1C 12 F4" "19:13:28,9449700","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F21C12F46CDB6B2E16F09F9419CDFF328437B2D7","SUCCESS","" "19:13:28,9449784","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 34, Name: F252E794FE438E35ACE6E53762C0A234A2C52135" "19:13:28,9449870","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9449934","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135","SUCCESS","Desired Access: Read" "19:13:28,9450015","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9450079","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9450137","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135\Blob","SUCCESS","Type: REG_BINARY, Length: 2 172, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:28,9450213","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F252E794FE438E35ACE6E53762C0A234A2C52135","SUCCESS","" "19:13:28,9450300","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 35, Name: F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0" "19:13:28,9450383","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9450451","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","Desired Access: Read" "19:13:28,9450528","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9450595","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9450653","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 750, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F5 AD 0B CC" "19:13:28,9450730","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","" "19:13:28,9450820","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 36, Name: F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6" "19:13:28,9450903","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9450970","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6","SUCCESS","Desired Access: Read" "19:13:28,9451051","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9451115","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9451172","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6\Blob","SUCCESS","Type: REG_BINARY, Length: 1 883, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F5 FB 01 DE" "19:13:28,9451249","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F5FB01DEA6E59CA6DD057054F4A3FF72DDE1D5C6","SUCCESS","" "19:13:28,9451355","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 37, Name: F695C5B4037AE8EAE51EA943A4F54D750E0DA609" "19:13:28,9451445","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9451512","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609","SUCCESS","Desired Access: Read" "19:13:28,9451593","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9451660","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9451718","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609\Blob","SUCCESS","Type: REG_BINARY, Length: 1 600, Data: 03 00 00 00 01 00 00 00 14 00 00 00 F6 95 C5 B4" "19:13:28,9451795","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates\F695C5B4037AE8EAE51EA943A4F54D750E0DA609","SUCCESS","" "19:13:28,9451888","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9451961","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9452029","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9452109","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9452164","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9452237","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9452308","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9452372","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9452446","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9452500","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9452561","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9454720","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9454781","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9454886","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:28,9454980","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9455053","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9455117","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9455198","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9455252","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9455326","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9455393","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9455457","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9455534","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9455589","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9455653","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9455724","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9455785","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9455858","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9455913","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9455977","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9456035","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9456227","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9456294","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9456375","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:28,9456432","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:28,9456490","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: 109F1CAED645BB78B3EA2B94C0697C740733031C" "19:13:28,9456574","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9456638","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","Desired Access: Read" "19:13:28,9456721","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9456792","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9456853","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 147, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 B6 53 18" "19:13:28,9456930","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","" "19:13:28,9457016","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 1, Name: C415CBF62AF1B513B81ED7B707BDE0A954E2B813" "19:13:28,9457100","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9457167","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","Desired Access: Read" "19:13:28,9457260","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9457324","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9457382","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","SUCCESS","Type: REG_BINARY, Length: 1 091, Data: 04 00 00 00 01 00 00 00 10 00 00 00 E1 3A 7C 82" "19:13:28,9457459","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","" "19:13:28,9457542","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 2, Name: D559A586669B08F46A30A133F8A9ED3D038E2EA8" "19:13:28,9457626","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9457693","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","Desired Access: Read" "19:13:28,9457773","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9457837","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9457895","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 095, Data: 04 00 00 00 01 00 00 00 10 00 00 00 AC D8 0E A2" "19:13:28,9457972","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","" "19:13:28,9458055","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 3, Name: FEE449EE0E3965A5246F000E87FDE2A065FD89D4" "19:13:28,9458139","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9458203","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","Desired Access: Read" "19:13:28,9458283","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9458350","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9458408","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","SUCCESS","Type: REG_BINARY, Length: 566, Data: 19 00 00 00 01 00 00 00 10 00 00 00 ED BC CD D5" "19:13:28,9458482","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","" "19:13:28,9458568","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9458652","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9458719","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9458799","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9458854","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9458912","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Index: 0, Name: A377D1B1C0538833035211F4083D00FECC414DAB" "19:13:28,9458992","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9459059","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","Desired Access: Read" "19:13:28,9459136","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9459200","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9459261","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","SUCCESS","Type: REG_BINARY, Length: 481, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A3 77 D1 B1" "19:13:28,9459338","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","" "19:13:28,9459425","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9459495","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9459563","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9459643","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9459697","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9459762","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9460018","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9460076","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9460188","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read" "19:13:28,9460275","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:28,9460371","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9460441","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9460509","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9460589","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9460644","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9460714","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:28,9460781","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9460849","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9460923","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9460977","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9461041","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:28,9461112","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9461176","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9461250","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9461304","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9461368","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:28,9461426","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:28,9461622","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9461689","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9461769","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9461824","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9461888","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","" "19:13:28,9461959","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9462023","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9462096","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9462151","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9462225","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","" "19:13:28,9462295","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9462359","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9462433","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9462488","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9462549","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","" "19:13:28,9462815","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9462882","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9462962","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9463017","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9463081","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9463152","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9463216","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9463286","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9463341","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9463405","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9463472","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9463537","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9463610","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9463662","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9463726","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9463844","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9463902","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9464002","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9464091","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9464165","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9464229","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9464306","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9464361","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9464428","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9464495","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9464560","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9464633","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9464688","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9464749","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9464819","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9464884","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9464954","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9465009","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9465073","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9465131","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9465307","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9465374","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9465451","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9465509","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9465573","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9465640","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9465705","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9465778","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9465833","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9465897","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9465964","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9466029","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9466102","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9466157","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9466340","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:28,9466474","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9466577","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:28,9466689","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9466769","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9466837","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:28,9466939","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:28,9467315","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9467507","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9467571","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9467709","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read" "19:13:28,9467812","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9467924","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9468004","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9468078","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9468161","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9468222","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9468296","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9468373","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9468437","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9468521","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9468575","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9468642","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9468713","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9468777","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9468851","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9468905","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9468973","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9469031","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9469242","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9469313","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9469393","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9469448","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9469515","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9469582","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9469646","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9469720","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9469775","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9469864","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9469935","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9469999","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9470073","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9470127","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9470192","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9470374","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9470445","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9470525","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9470580","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9470647","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9470718","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9470782","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9470852","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9470907","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9470971","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9471042","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9471106","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9471179","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9471234","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9471301","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9471680","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9471754","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9471869","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:28,9471972","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9472058","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9472126","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9472318","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9472385","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9472456","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9472533","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9472600","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9472677","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9472732","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9472796","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9472866","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9472931","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9473004","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9473059","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9473123","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9473184","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9473386","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9473466","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9473546","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9473601","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9473668","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9473736","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9473800","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9473874","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9473931","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9473995","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9474063","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9474127","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9474201","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9474255","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9474319","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9474454","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9474515","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9474630","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read" "19:13:28,9474759","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:28,9474861","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9474945","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9475054","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9475137","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9475240","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9475314","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9475391","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9475461","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9475570","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9475631","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9475698","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9475779","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9475846","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9475920","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9475974","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9476042","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9476099","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:28,9476353","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9476423","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9476500","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9476558","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9476625","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:28,9476696","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9476763","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9476876","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9476933","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9477013","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:28,9477087","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9477151","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9477251","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9477309","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9477379","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:28,9477584","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9477687","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:28,9477812","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9477879","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertLastSyncTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 5E FF 14 C3 4E 31 D7 01" "19:13:28,9477969","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:28,9478357","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9478415","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9478511","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9478627","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9478694","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","NAME NOT FOUND","Desired Access: Read" "19:13:28,9478790","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9478864","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9478928","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:28,9479015","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9479076","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertEncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:28,9479146","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertEncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:28,9479204","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertEncodedCtl","SUCCESS","Type: REG_BINARY, Length: 5 906, Data: 30 82 17 0E 06 09 2A 86 48 86 F7 0D 01 07 02 A0" "19:13:28,9479910","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:28,9483659","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\AutoFlags","NAME NOT FOUND","Length: 144" "19:13:28,9484121","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe","SUCCESS","Name: \Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat_launcher.exe" "19:13:28,9484297","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableAutoFlushProcessNameList","NAME NOT FOUND","Length: 144" "19:13:28,9484365","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\AutoFlushFirstDeltaSeconds","NAME NOT FOUND","Length: 144" "19:13:28,9484419","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\AutoFlushNextDeltaSeconds","NAME NOT FOUND","Length: 144" "19:13:28,9485166","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9485227","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9485346","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,9485465","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9485548","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,9485660","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9485728","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,9485856","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9485920","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx","NAME NOT FOUND","Desired Access: Read" "19:13:28,9486016","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,9486080","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,9486173","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9486241","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,9486353","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9486417","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx","NAME NOT FOUND","Desired Access: Read" "19:13:28,9486501","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,9486565","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,9486642","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,9486719","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9486773","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9486879","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,9486969","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9487036","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,9487126","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9487193","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,9487322","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9487386","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo","NAME NOT FOUND","Desired Access: Read" "19:13:28,9487469","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,9487533","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,9487623","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9487700","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,9487806","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9487870","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo","NAME NOT FOUND","Desired Access: Read" "19:13:28,9487947","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,9488011","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,9488082","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,9523246","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9523342","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9523496","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9523650","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9523708","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9523817","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9523974","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9524244","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9524305","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9524401","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9524523","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9524577","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9524686","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9524799","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9524876","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9524943","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","" "19:13:28,9525642","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9525703","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9525841","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","REPARSE","Desired Access: Read" "19:13:28,9525979","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","SUCCESS","Desired Access: Read" "19:13:28,9526082","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9526152","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 46, Data: C:\Users\Administrator" "19:13:28,9526235","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 46, Data: C:\Users\Administrator" "19:13:28,9526319","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-938073984-3743386793-3534349143-500","SUCCESS","" "19:13:28,9526665","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9526726","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9526819","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9526928","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9526983","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9527076","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read" "19:13:28,9527162","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9527255","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9528477","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9529084","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead","SUCCESS","Information: DACL" "19:13:28,9529202","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead","SUCCESS","" "19:13:28,9530071","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9530302","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9530556","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .., 2: 68CA41210CB228E120467087E03087A48F4425D3, 3: 8B22744432B17A34AE2457700439D61BF94B5255, 4: 906CC149415780CFB79F39E1CF449F87CA6D4D16, 5: BF89E52F8D681360E6B84941BD2F9BC0093309F6, 6: D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, 7: F0BD97B4EC6CD8B71C35631738259CF9F2E54381" "19:13:28,9531428","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9531659","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","Information: DACL" "19:13:28,9531768","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","" "19:13:28,9532599","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9532817","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","Information: DACL" "19:13:28,9533003","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","" "19:13:28,9533782","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9533994","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","Information: DACL" "19:13:28,9534096","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","" "19:13:28,9534847","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9535052","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","Information: DACL" "19:13:28,9535152","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","" "19:13:28,9535902","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9536107","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","Information: DACL" "19:13:28,9536204","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","" "19:13:28,9536961","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9537163","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","Information: DACL" "19:13:28,9537281","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","" "19:13:28,9537515","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9537624","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","" "19:13:28,9537884","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9537968","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read" "19:13:28,9538077","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9538160","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\Certificates","NAME NOT FOUND","Desired Access: Read" "19:13:28,9538798","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9538994","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9539350","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .., 2: 68CA41210CB228E120467087E03087A48F4425D3, 3: 8B22744432B17A34AE2457700439D61BF94B5255, 4: 906CC149415780CFB79F39E1CF449F87CA6D4D16, 5: BF89E52F8D681360E6B84941BD2F9BC0093309F6, 6: D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, 7: F0BD97B4EC6CD8B71C35631738259CF9F2E54381" "19:13:28,9540088","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9540309","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 187, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9540431","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","Offset: 0, Length: 1 187, Priority: Normal" "19:13:28,9540723","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","" "19:13:28,9541592","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9541794","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 186, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9541897","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","Offset: 0, Length: 1 186, Priority: Normal" "19:13:28,9542153","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","" "19:13:28,9542984","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9543179","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 578, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9543285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","Offset: 0, Length: 1 578, Priority: Normal" "19:13:28,9543475","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","" "19:13:28,9544299","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9544494","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 691, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9544600","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","Offset: 0, Length: 1 691, Priority: Normal" "19:13:28,9544790","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","" "19:13:28,9545582","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9545774","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 691, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9545874","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","Offset: 0, Length: 1 691, Priority: Normal" "19:13:28,9546060","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","" "19:13:28,9546900","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9547092","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 578, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9547195","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","Offset: 0, Length: 1 578, Priority: Normal" "19:13:28,9547403","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","" "19:13:28,9547657","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9547769","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","" "19:13:28,9548022","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9548109","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\CRLs","NAME NOT FOUND","Desired Access: Read" "19:13:28,9548763","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9549251","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9549421","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:28,9549556","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9549658","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","" "19:13:28,9549902","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9549989","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\CTLs","NAME NOT FOUND","Desired Access: Read" "19:13:28,9550633","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9551044","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9551210","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:28,9551339","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9551441","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","" "19:13:28,9551682","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9551765","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\Keys","NAME NOT FOUND","Desired Access: Read" "19:13:28,9551868","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","" "19:13:28,9552561","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9552782","EasyAntiCheat_launcher.exe","6076","NotifyChangeDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My","CANCELLED","Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_DIR_NAME, FILE_NOTIFY_CHANGE_SIZE, FILE_NOTIFY_CHANGE_LAST_WRITE" "19:13:28,9552968","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9553045","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\Certificates","NAME NOT FOUND","Desired Access: Read" "19:13:28,9553683","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9553873","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9554049","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .., 2: 68CA41210CB228E120467087E03087A48F4425D3, 3: 8B22744432B17A34AE2457700439D61BF94B5255, 4: 906CC149415780CFB79F39E1CF449F87CA6D4D16, 5: BF89E52F8D681360E6B84941BD2F9BC0093309F6, 6: D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, 7: F0BD97B4EC6CD8B71C35631738259CF9F2E54381" "19:13:28,9554777","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9554982","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 187, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9555120","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","Offset: 0, Length: 1 187, Priority: Normal" "19:13:28,9555274","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\68CA41210CB228E120467087E03087A48F4425D3","SUCCESS","" "19:13:28,9556082","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9556307","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 186, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9556406","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","Offset: 0, Length: 1 186, Priority: Normal" "19:13:28,9556547","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\8B22744432B17A34AE2457700439D61BF94B5255","SUCCESS","" "19:13:28,9557391","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9557583","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 578, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9557686","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","Offset: 0, Length: 1 578, Priority: Normal" "19:13:28,9557827","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16","SUCCESS","" "19:13:28,9558619","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9558809","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 691, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9558908","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","Offset: 0, Length: 1 691, Priority: Normal" "19:13:28,9559046","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6","SUCCESS","" "19:13:28,9559828","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9560018","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 691, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9560114","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","Offset: 0, Length: 1 691, Priority: Normal" "19:13:28,9560255","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A","SUCCESS","" "19:13:28,9561034","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9561220","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","AllocationSize: 4 096, EndOfFile: 1 578, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9561317","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","Offset: 0, Length: 1 578, Priority: Normal" "19:13:28,9561455","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381","SUCCESS","" "19:13:28,9561708","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9561814","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","" "19:13:28,9562048","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9562131","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\CRLs","NAME NOT FOUND","Desired Access: Read" "19:13:28,9562786","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9562975","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9563138","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:28,9563263","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9563366","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","" "19:13:28,9563603","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9563684","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\My\CTLs","NAME NOT FOUND","Desired Access: Read" "19:13:28,9564338","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9564524","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:28,9564678","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:28,9564800","EasyAntiCheat_launcher.exe","6076","QueryDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:28,9564902","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","" "19:13:28,9566435","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\cryptnet.dll","NAME NOT FOUND","" "19:13:28,9567189","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:11:35, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 139 264, EndOfFile: 136 704, FileAttributes: A" "19:13:28,9567895","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9568235","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\cryptnet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9568450","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9568899","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Image Base: 0x70900000, Image Size: 0x26000" "19:13:28,9570477","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","" "19:13:28,9571429","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9571721","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cryptnet.dll","BUFFER OVERFLOW","Information: Owner" "19:13:28,9571827","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Information: Owner" "19:13:28,9571923","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","" "19:13:28,9573180","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:28,9574280","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9574957","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9575262","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9575368","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9575541","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9575890","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9576772","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9577468","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9577767","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9577866","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9578026","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9578331","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9579175","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9579816","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9580092","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9580188","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9580345","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9580685","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9581500","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9582129","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9582414","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9582504","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9582661","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9582962","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9583748","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9584390","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9584662","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9584752","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9584912","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9585214","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9585990","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9586612","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9586869","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9586962","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9587116","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9587424","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9588213","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9588938","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9589698","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9590326","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9590602","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9590695","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9590856","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9591157","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9591936","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9592655","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9592918","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9593008","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9593162","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9593447","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9594236","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9594865","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9595144","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9595233","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9595394","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9595689","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9596462","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9597081","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9597363","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9597453","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9597607","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9597892","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9599117","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9599797","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9600064","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9600153","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9600311","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9600618","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9601414","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9602036","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9602322","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9602415","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9602569","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9602870","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9603669","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9604294","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9604554","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9604644","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9604798","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9605093","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9605866","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9606481","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9606738","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9606825","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9606979","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9607309","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9608088","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9608704","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9608961","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9609047","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9609201","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9609483","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9610253","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9610863","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9611116","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9611206","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9611356","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9611642","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9612463","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9613165","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9613855","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9614467","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9614730","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9614824","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9614977","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9615263","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9616033","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9616652","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9616911","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9617001","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9617155","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9617457","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9618233","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9618858","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9619118","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9619208","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9619362","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9619666","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9620449","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9621071","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9621334","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9621421","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9621591","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9621876","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9623028","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9623656","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9623919","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9624012","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9624169","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9624455","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9625231","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9625853","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9626110","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9626200","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9626357","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9626639","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9627451","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9628079","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9628336","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9628422","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9628576","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9628871","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9629641","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9630295","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9630552","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9630642","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9630796","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9631091","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9631857","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9632502","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9632759","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9632848","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9633448","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9634051","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9635312","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9636020","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9636322","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9636424","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9636591","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9636906","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9637768","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9638503","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9639519","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9640171","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9640469","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9640565","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9640729","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9641040","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9642926","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9643593","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9643888","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9643984","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9644144","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9644452","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9645280","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9645921","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9646207","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9646300","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9646457","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9646784","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9647608","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9648237","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9648513","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9648606","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9648763","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9649058","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9650312","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9650953","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9651236","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9651329","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9651489","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9651791","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9652605","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9653231","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9653500","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9653590","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9653744","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9654036","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9654850","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9655479","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9655745","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9655838","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9655995","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9656294","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9657083","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9657894","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9658163","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9658253","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9658410","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9658709","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9659498","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9660120","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9660383","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9660473","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9660630","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9660922","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9661778","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9662413","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9662676","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9662766","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9662920","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9663205","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9663997","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9664706","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9665405","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9666024","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9666294","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9666384","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9666541","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9666849","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9667647","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9668314","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9668584","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9668674","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9668831","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9669119","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9669912","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9670531","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9670797","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9670887","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9671044","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9671329","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9672105","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9672731","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9672994","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9673084","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9673238","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9673520","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9674655","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9675284","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9675550","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9675640","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9675794","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9676082","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9676862","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9677487","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9677747","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9677837","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9677991","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9678276","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9679075","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9679700","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9679960","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9680050","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9680204","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9680512","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9681288","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9681904","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9682160","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9682256","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9682414","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9682709","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9683478","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9684097","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9684357","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9684447","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9684601","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9684909","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9685688","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9686298","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9686554","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9686644","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9686798","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9687083","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9687869","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9688565","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9689255","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9689877","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9690143","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9690233","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9690390","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9690675","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9691445","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9692064","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9692334","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9692423","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9692581","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9692866","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9693645","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9694268","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9694531","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9694620","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9694778","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9695060","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9695830","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9696484","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9696747","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9696837","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9696991","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9697279","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9698411","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9699043","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9699309","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9699412","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9699569","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9699855","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9700637","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9701256","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9701513","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9701603","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9701757","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9702039","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9702841","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9703460","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9703719","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9703809","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9703966","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9704278","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9705054","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9705663","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9705923","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9706013","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9706167","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9706458","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9707225","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9707850","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9708107","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9708200","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9708354","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9708639","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9709406","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9710012","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9710269","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9710359","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9710509","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9710791","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9711568","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9712276","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9712969","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9713588","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9713851","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9713941","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9714098","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9714384","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9715147","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9715760","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9716016","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9716106","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9716260","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9716545","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9717357","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9717979","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9718245","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9718335","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9718492","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9718797","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9719570","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9720189","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9720449","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9720538","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9720692","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9720975","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9722421","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9723088","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9723361","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9723451","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9723608","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9723919","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9724717","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9725340","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9725603","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9725696","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9725875","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9726324","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9727408","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9728114","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9728425","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9728531","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9728707","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9729034","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9729888","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9730539","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9730824","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9730917","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9731081","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9731421","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9732280","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9732931","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9733210","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9733316","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9733483","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9733791","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9734650","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9735292","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9735571","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9735667","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9735827","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9736132","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9736950","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9737710","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9738416","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9739048","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9739323","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9739416","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9739577","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9739881","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9740674","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9741302","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9741572","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9741665","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9741822","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9742110","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9742928","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9743557","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9743830","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9743923","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9744080","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9744368","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9745151","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9745773","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9746039","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9746129","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9746286","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9746575","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9747794","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9748426","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9748695","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9748785","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9748942","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9749237","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9750603","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9751238","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9751521","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9751614","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9751771","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9752085","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9752929","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9753560","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9753827","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9753916","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9754074","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9754375","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9755154","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9755777","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9756033","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9756123","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9756280","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9756578","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9757377","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9757996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9758256","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9758346","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9758503","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9758792","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9759561","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9760174","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9760430","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9760520","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9760674","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9760956","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9761729","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9762457","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9763202","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9763827","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9764090","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9764183","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9764465","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9765299","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9766543","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9767243","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9767557","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9767660","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9767830","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9768141","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9768991","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9769642","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9770174","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9770283","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9770447","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9770764","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9771617","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9772265","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9773227","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9773574","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9773741","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9774058","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9775396","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9776053","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9776338","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9776435","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9776592","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9776900","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9777721","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9778356","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9778625","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9778718","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9778872","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9779171","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9779995","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9780639","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9780915","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9781005","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9781165","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9781473","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9782278","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9782907","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9783173","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9783263","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9783420","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9783741","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9784539","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9785165","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9785434","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9785527","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9785684","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9785980","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9786756","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9787391","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9787651","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9787744","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9787897","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9788186","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9788978","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9789697","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9790473","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9791095","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9791361","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9791451","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9791621","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9791916","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9792782","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9793401","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9793667","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9793757","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9793914","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9794203","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9794986","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9795611","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9795880","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9795970","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9796124","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9796410","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9797189","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9797827","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9798090","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9798183","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9798337","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9798623","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9799758","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9800441","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9800714","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9800804","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9800961","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9801253","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9802029","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9802664","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9802930","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9803020","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9803174","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9803482","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9804290","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9804912","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9805172","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9805262","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9805416","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9805714","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9806484","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9807096","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9807500","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9807593","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9807751","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9808049","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9808822","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9809434","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9809694","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9809781","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9809947","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9810236","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9811006","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9811618","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9811875","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9811962","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9812116","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9812420","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9813190","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9813886","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9814579","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9815195","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9815458","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9815547","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9815701","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9815990","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9816760","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9817382","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9817645","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9817732","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9817885","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9818171","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9818950","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9819569","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9819832","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9819922","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9820076","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9820361","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9821131","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9821744","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9822007","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9822093","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9822257","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9822562","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9823697","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9824326","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9824595","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9824685","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9824839","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9825128","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9825900","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9826516","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9826779","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9826869","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9827020","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9827318","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9828113","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9828752","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9829012","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9829098","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9829252","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9829550","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9830317","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9830987","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9831244","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9831330","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9831484","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9831779","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9832562","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9833175","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9833428","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9833518","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9833668","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9833954","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9834714","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9835327","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9835577","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9835663","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9835814","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9836096","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9836869","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9837575","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9838274","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9838893","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9839156","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9839246","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9839400","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9839685","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9840452","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9841068","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9841331","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9841420","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9841571","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9841876","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9842671","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9843293","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9843560","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9843649","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9843803","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9844089","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9844862","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9845474","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9845734","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9845824","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9845978","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9846276","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9846873","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9846956","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9847113","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\TVO","NAME NOT FOUND","Desired Access: Read" "19:13:28,9847966","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9848602","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9848871","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9848961","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9849115","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9849403","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9850183","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:28,9850808","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9851071","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9851158","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9851312","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9851594","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:28,9852405","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9853028","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9853287","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9853374","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9853525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9853817","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9854583","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:28,9855199","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9855452","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9855542","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9855693","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9855981","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:28,9856745","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9857399","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9857656","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9857742","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9857893","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9858175","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9858942","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:28,9859551","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9859805","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9859891","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9860042","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9860340","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:28,9861148","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9861848","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:28,9862547","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9863163","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9863429","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9863519","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9863672","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9863955","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9864728","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:28,9865337","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9865594","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9865683","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9865837","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9866116","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:28,9866921","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9867550","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9867813","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9867913","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9868066","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9868345","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9869109","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:28,9869718","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9869975","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9870061","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:28,9870215","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9870491","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:28,9871123","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9871194","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9871322","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,9871463","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9871559","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,9871687","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9871768","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,9871938","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9872008","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\UrlDllGetObjectUrl","NAME NOT FOUND","Desired Access: Read" "19:13:28,9872120","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,9872188","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,9872300","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9872371","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,9872496","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9872563","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\UrlDllGetObjectUrl","NAME NOT FOUND","Desired Access: Read" "19:13:28,9872653","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,9872714","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,9872794","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,9872948","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9873006","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9873124","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:28,9873233","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:28,9873365","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9873419","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9873522","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read" "19:13:28,9873605","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read" "19:13:28,9873708","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9873788","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:28,9873884","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:28,9873971","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9874042","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:28,9874160","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9874221","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\SyncDeltaTime","NAME NOT FOUND","Length: 144" "19:13:28,9874292","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\Flags","NAME NOT FOUND","Length: 144" "19:13:28,9874350","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\RootDirUrl","NAME NOT FOUND","Length: 144" "19:13:28,9874443","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:28,9874523","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9874590","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:28,9874673","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9874728","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\LastSyncTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 13 FA 33 C3 4E 31 D7 01" "19:13:28,9874808","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:28,9875235","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9875296","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9875392","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9875520","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9875588","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","NAME NOT FOUND","Desired Access: Read" "19:13:28,9875690","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9875764","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9875828","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:28,9875911","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9875969","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:28,9876883","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:28,9877659","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl","SUCCESS","Type: REG_BINARY, Length: 152 788, Data: 30 83 02 54 CF 06 09 2A 86 48 86 F7 0D 01 07 02" "19:13:28,9891425","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:28,9907022","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9907105","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9907285","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:28,9907452","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9907538","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:28,9907657","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9907737","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:28,9907869","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9907939","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy","NAME NOT FOUND","Desired Access: Read" "19:13:28,9908052","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:28,9908119","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:28,9908209","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9908276","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:28,9908391","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9908456","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy","NAME NOT FOUND","Desired Access: Read" "19:13:28,9908542","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:28,9908603","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:28,9908677","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:28,9909767","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9909828","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9909931","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9910053","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9910104","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9910207","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9910329","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9910588","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9910646","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9910736","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9910851","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9910906","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9911015","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9911114","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9911182","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9911259","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9911352","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9911406","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9911519","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9911615","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9911798","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9911852","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9911939","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9912041","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9912093","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9912186","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9912292","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9912365","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9912417","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9912519","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9912609","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9913036","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9913090","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9913180","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9913283","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9913337","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9913430","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9913520","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9913584","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9913674","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9913741","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9913837","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9913905","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9914004","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9914062","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9914129","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9914200","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9914267","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9914347","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9914402","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9914466","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9914537","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9914604","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9914678","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9914732","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9914793","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9914857","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9915188","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9915245","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9915332","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9915435","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9915486","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9915569","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,9915656","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9915730","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9915781","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9915874","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9915967","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9916047","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9916115","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9916204","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9916262","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9916326","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9916400","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9916464","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9916541","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9916596","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9916660","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9916730","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9916798","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9916872","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9916926","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9916987","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9917048","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9917160","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9917215","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9917333","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9917420","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9917535","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9917587","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9917693","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9917770","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9917856","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9917923","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9918004","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9918058","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9918161","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9918238","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9918401","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9918456","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9918542","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9918642","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9918696","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9918783","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9918873","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9918940","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9918992","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9919091","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9919168","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9919306","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9919357","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9919460","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9919537","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9919617","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9919704","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9919768","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9919857","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9919925","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9920015","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9920072","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9920140","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9920207","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9920278","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9920355","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9920409","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9920473","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9920544","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9920624","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9920701","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9920756","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9920820","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:28,9920906","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9920970","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:28,9921346","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9921442","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9921503","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:28,9921589","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:28,9921862","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9921926","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9922080","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9922141","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9922253","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9922353","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9922455","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9922536","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9922606","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9922696","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9922754","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9922818","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9922892","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9922959","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9923036","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9923090","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9923155","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9923225","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9923289","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9923366","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9923421","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9923485","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9923543","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9923655","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9923706","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9923812","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9923902","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9924017","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9924072","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9924171","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9924251","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9924332","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9924402","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:28,9924518","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9924572","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9924672","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9924749","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9924826","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9924906","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9924973","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9925063","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9925130","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9925217","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9925271","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9925339","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9925409","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9925473","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9925550","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9925605","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9925669","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9925736","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9925804","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9925878","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9925932","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9925996","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9926057","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:28,9926336","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9926404","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9926480","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9926535","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9926599","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9926670","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9926734","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9926808","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9926859","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9926923","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9926994","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9927055","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9927125","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9927180","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9927241","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9927395","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9927452","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9927549","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9927638","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9927709","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9927773","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9927847","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9927901","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9927969","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9928036","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9928100","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9928171","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9928225","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9928286","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9928357","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9928421","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9928491","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9928543","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9928607","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9928665","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9928982","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9929053","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9929126","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9929181","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9929258","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9929329","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9929441","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9929646","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9929726","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9929822","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9929928","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9930018","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9930102","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9930422","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:28,9931141","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:28,9931246","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9931320","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:28,9931413","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9931490","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9931558","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:28,9931651","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:28,9931907","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9932093","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9932151","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9932270","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read" "19:13:28,9932369","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:28,9932462","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9932539","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9932603","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9932715","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9932780","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9932853","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9932927","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9932991","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9933065","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9933120","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9933184","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9933261","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9933325","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9933395","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9933450","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9933514","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9933572","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9933828","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9933896","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9933973","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9934027","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9934091","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:28,9934162","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9934249","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9934325","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9934380","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9934470","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:28,9934556","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9934624","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9934752","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9934810","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9934880","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:28,9935105","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:28,9935240","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9935352","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9935461","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:28,9936029","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9936089","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9936208","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9936330","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9936381","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9936481","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9936628","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9936891","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9936949","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9937042","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9937154","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9937212","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9937324","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9937427","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9937510","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9937578","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9937677","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9937738","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9937850","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9937972","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9938251","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9938319","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9938431","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9938559","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9938617","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9938719","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9938835","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9938970","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9939024","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9939143","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9939242","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9939749","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9939810","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9939903","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9940018","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9940073","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9940176","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9940281","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9940358","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9940455","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9940522","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:28,9940615","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9940689","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9940791","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9940849","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9940920","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9940997","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9941064","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9941147","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9941202","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9941269","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9941340","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9941404","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9941484","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9941535","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9941600","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9941664","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9941997","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9942055","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9942145","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9942251","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9942315","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9942398","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:28,9942488","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9942559","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9942613","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9942706","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9942799","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9942882","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9942950","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9943046","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9943101","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9943168","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9943238","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9943306","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9943386","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9943437","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9943501","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9943575","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9943639","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9943720","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9943771","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9943835","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9943896","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9944037","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9944092","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9944207","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9944297","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9944406","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9944457","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9944563","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9944643","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9944733","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9944800","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9944881","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9944935","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9945038","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9945118","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9945288","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9945342","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:28,9945429","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:28,9945532","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9945586","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9945676","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9945763","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9945833","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9945884","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9945984","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:28,9946061","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:28,9946196","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9946250","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9946350","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9946430","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9946510","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9946590","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9946657","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:28,9946747","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9946815","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9946904","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:28,9946959","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:28,9947023","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 0, Name: 00859AAC6A54B8C1B3C139DE67846E64E7B82DB2" "19:13:28,9947110","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9947177","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","Desired Access: Read" "19:13:28,9947273","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9947360","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9947421","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 586, Data: 03 00 00 00 01 00 00 00 14 00 00 00 00 85 9A AC" "19:13:28,9947507","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","" "19:13:28,9947774","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 1, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:28,9947867","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9947937","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:28,9948024","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9948094","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9948152","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 05 86 4F 16" "19:13:28,9948235","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:28,9948322","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 2, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:28,9948425","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9948495","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:28,9948579","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9948652","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9948713","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 177, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 F2 87 62 B3" "19:13:28,9948790","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:28,9948880","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 3, Name: 6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE" "19:13:28,9948967","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9949034","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","Desired Access: Read" "19:13:28,9949114","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9949182","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9949239","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 503, Data: 03 00 00 00 01 00 00 00 14 00 00 00 6F 47 42 06" "19:13:28,9949316","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","" "19:13:28,9949493","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 4, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:28,9949579","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9949647","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:28,9949733","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9949797","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9949858","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 75 24 FA FD" "19:13:28,9949935","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:28,9950025","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 5, Name: 8880A2309BE334678E3D912671F22049C5A49A78" "19:13:28,9950108","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9950176","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","Desired Access: Read" "19:13:28,9950256","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9950323","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9950381","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","SUCCESS","Type: REG_BINARY, Length: 1 496, Data: 03 00 00 00 01 00 00 00 14 00 00 00 88 80 A2 30" "19:13:28,9950458","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","" "19:13:28,9950634","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 6, Name: 94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A" "19:13:28,9950721","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9950788","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","Desired Access: Read" "19:13:28,9950872","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9950939","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9950997","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 544, Data: 0F 00 00 00 01 00 00 00 14 00 00 00 FA 27 83 F1" "19:13:28,9951074","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","" "19:13:28,9951244","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 7, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:28,9951330","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9951401","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:28,9951481","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9951549","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9951606","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A4 BC 39 BB" "19:13:28,9951683","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:28,9951767","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 8, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:28,9951850","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9951917","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:28,9952001","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9952068","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9952126","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 763, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 D6 1D BD 32" "19:13:28,9952203","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:28,9952289","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 9, Name: CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E" "19:13:28,9952376","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9952443","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","Desired Access: Read" "19:13:28,9952527","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9952594","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9952652","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 CB 7E 84 88" "19:13:28,9952729","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","" "19:13:28,9952892","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 10, Name: D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0" "19:13:28,9952976","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9953043","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","Desired Access: Read" "19:13:28,9953127","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9953197","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9953255","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 920, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D3 BE 73 0B" "19:13:28,9953332","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","" "19:13:28,9953499","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 11, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:28,9953585","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9953652","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:28,9953736","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9953800","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9953861","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FB 35 BB 18" "19:13:28,9953935","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:28,9954021","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 12, Name: FCAC7E666CC54341CA213BECF2EB463F2B62ADB0" "19:13:28,9954105","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9954169","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","Desired Access: Read" "19:13:28,9954252","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9954316","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9954374","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 551, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FC AC 7E 66" "19:13:28,9954451","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","" "19:13:28,9954644","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9954724","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9954797","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9954884","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9954939","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9955003","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9955077","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9955144","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9955221","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9955275","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9955336","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9955400","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9955545","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9955606","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9955718","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9955805","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9955904","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9955981","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9956048","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9956138","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9956193","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9956260","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9956331","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9956408","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9956491","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9956545","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9956610","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9956680","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9956744","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9956828","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9956879","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9956943","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9957004","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9957126","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9957180","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9957290","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores","REPARSE","Desired Access: Read" "19:13:28,9957411","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:28,9957530","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9957588","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9957690","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9957771","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9957854","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9957925","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9958043","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9958098","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9958197","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:28,9958277","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9958354","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9958435","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9958499","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:28,9958588","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9958656","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9958742","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9958800","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9958868","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9958935","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9959002","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9959082","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9959137","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9959201","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9959268","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9959336","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:28,9959413","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9959467","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9959531","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9959592","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9959817","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9959884","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9959961","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9960016","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9960080","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9960150","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9960215","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9960285","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9960340","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9960404","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9960471","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9960535","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9960606","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9960660","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9960721","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9960850","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9960904","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:28,9961004","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:28,9961090","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9961161","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9961225","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9961299","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9961353","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9961417","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9961488","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9961552","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9961623","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9961674","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9961738","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9961805","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9961870","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9961940","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9961991","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9962056","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9962113","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9962354","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9962424","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9962498","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:28,9962553","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:28,9962610","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 0, Name: 00859AAC6A54B8C1B3C139DE67846E64E7B82DB2" "19:13:28,9962691","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9962758","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","Desired Access: Read" "19:13:28,9962835","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9962899","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9962963","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 586, Data: 03 00 00 00 01 00 00 00 14 00 00 00 00 85 9A AC" "19:13:28,9963043","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","" "19:13:28,9963140","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 1, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:28,9963223","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9963290","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:28,9963367","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9963435","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9963496","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 05 86 4F 16" "19:13:28,9963573","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:28,9963653","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 2, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:28,9963736","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9963804","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:28,9963880","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9963945","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9964002","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 177, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 F2 87 62 B3" "19:13:28,9964079","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:28,9964179","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 3, Name: 6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE" "19:13:28,9964262","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9964330","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","Desired Access: Read" "19:13:28,9964406","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9964471","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9964528","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 503, Data: 03 00 00 00 01 00 00 00 14 00 00 00 6F 47 42 06" "19:13:28,9964602","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","" "19:13:28,9964686","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 4, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:28,9964769","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9964836","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:28,9964910","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9964977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9965035","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 75 24 FA FD" "19:13:28,9965109","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:28,9965189","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 5, Name: 8880A2309BE334678E3D912671F22049C5A49A78" "19:13:28,9965272","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9965340","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","Desired Access: Read" "19:13:28,9965414","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9965478","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9965535","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","SUCCESS","Type: REG_BINARY, Length: 1 496, Data: 03 00 00 00 01 00 00 00 14 00 00 00 88 80 A2 30" "19:13:28,9965612","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","" "19:13:28,9965699","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 6, Name: 94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A" "19:13:28,9965779","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9965847","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","Desired Access: Read" "19:13:28,9965924","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9965988","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9966045","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 544, Data: 0F 00 00 00 01 00 00 00 14 00 00 00 FA 27 83 F1" "19:13:28,9966119","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","" "19:13:28,9966196","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 7, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:28,9966276","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9966344","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:28,9966417","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9966482","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9966539","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A4 BC 39 BB" "19:13:28,9966616","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:28,9966693","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 8, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:28,9966777","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9966841","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:28,9966918","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9966982","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9967040","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 763, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 D6 1D BD 32" "19:13:28,9967113","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:28,9967206","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 9, Name: CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E" "19:13:28,9967290","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9967370","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","Desired Access: Read" "19:13:28,9967447","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9967511","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9967569","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 CB 7E 84 88" "19:13:28,9967646","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","" "19:13:28,9967729","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 10, Name: D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0" "19:13:28,9967809","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9967877","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","Desired Access: Read" "19:13:28,9967951","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9968015","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9968095","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 920, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D3 BE 73 0B" "19:13:28,9968172","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","" "19:13:28,9968252","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 11, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:28,9968335","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9968400","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:28,9968473","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9968541","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9968598","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FB 35 BB 18" "19:13:28,9968672","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:28,9968752","EasyAntiCheat_launcher.exe","6076","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 12, Name: FCAC7E666CC54341CA213BECF2EB463F2B62ADB0" "19:13:28,9968833","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9968900","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","Desired Access: Read" "19:13:28,9968974","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9969038","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:28,9969096","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 551, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FC AC 7E 66" "19:13:28,9969169","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","" "19:13:28,9969253","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9969326","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9969391","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9969464","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9969522","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9969586","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9969654","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9969715","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9969785","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9969840","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9969904","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9970420","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:28,9970478","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:28,9970590","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read" "19:13:28,9970677","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:28,9970766","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:28,9970840","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9970904","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9970978","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9971033","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9971100","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9971171","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9971235","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9971305","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9971360","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9971424","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9971491","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9971555","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9971626","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9971681","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9971742","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9971799","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9971988","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9972056","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:28,9972130","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9972194","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9972261","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:28,9972344","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9972412","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:28,9972482","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9972537","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9972601","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:28,9972668","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:28,9972733","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:28,9972803","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9972858","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:28,9972919","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:28,9973114","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9973236","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9973409","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:28,9973512","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:28,9973958","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","" "19:13:28,9975401","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9975664","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9975815","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9975917","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9976081","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9976427","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","" "19:13:28,9977396","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9977656","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9977758","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9977845","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9977996","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9978400","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9978496","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","" "19:13:28,9979397","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9979622","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9979718","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:28,9979801","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\ADMINI~1\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:28,9979952","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:","SUCCESS","SyncType: SyncTypeOther" "19:13:28,9984644","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","" "19:13:28,9987047","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:28,9987281","EasyAntiCheat_launcher.exe","6076","QueryAttributeTagFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Attributes: ANCI, ReparseTag: 0x0" "19:13:28,9987431","EasyAntiCheat_launcher.exe","6076","SetDispositionInformationFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","Delete: True" "19:13:28,9987598","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Local\Temp\4f722c31-2ba4-4db9-66e6-f4f2774da99e","SUCCESS","" "19:13:29,0009773","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0010521","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0010941","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0011063","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0011255","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0011736","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0012589","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0013221","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0013491","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0013580","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0013734","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0014045","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0014876","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0015511","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0015787","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0015880","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0016031","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0016351","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0017128","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0017763","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0018026","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0018112","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0018263","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0018587","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0019369","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0019995","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0020261","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0020351","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0020505","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0020816","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0021666","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0022278","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0022545","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0022634","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0022782","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0023080","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0023866","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0024588","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0025280","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0025906","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0026175","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0026265","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0026422","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0026737","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0028045","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0028978","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0029261","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0029354","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0029508","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0029819","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0030637","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0031278","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0031564","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0031657","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0031810","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0032118","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0032907","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0033526","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0033789","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0033876","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0034027","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0034325","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0036041","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0036673","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0036955","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0037045","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0037199","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0037519","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0038302","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0038911","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0039171","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0039261","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0039412","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0039732","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0040537","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0041156","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0041423","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0041512","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0041666","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0041968","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0042747","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0043357","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0043610","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0043697","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0043847","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0044146","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0044909","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0045522","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0045778","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0045865","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0046019","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0046317","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0047157","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0047776","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0048026","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0048110","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0048261","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0048556","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0049325","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0050089","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0050782","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0051391","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0051657","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0051747","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0051898","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0052199","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0052975","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0053578","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0053835","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0053921","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0054072","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0054367","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0055143","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0055756","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0056016","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0056102","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0056253","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0056545","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0057315","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0057991","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0058248","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0058335","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0058482","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0058963","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0060416","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0061115","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0061430","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0061532","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0061699","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0062026","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0062863","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0063502","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0063774","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0063867","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0064021","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0064335","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0065166","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0065798","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0066067","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0066157","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0066311","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0066641","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0067456","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0068082","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0068348","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0068441","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0068595","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0068899","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0069679","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0070304","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0070564","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0070654","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0070808","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0071112","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0071885","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0072514","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0072831","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0072925","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0073078","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0073383","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0074175","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0074887","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0075583","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0076266","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0076539","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0076629","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0076783","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0077094","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0077893","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0078515","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0078791","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0078880","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0079034","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0079339","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0080144","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0080769","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0081052","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0081142","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0081299","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0081597","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0082380","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0083002","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0083265","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0083355","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0083505","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0083804","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0084916","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0085548","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0085831","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0085924","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0086078","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0086401","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0087190","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0087874","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0088137","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0088226","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0088377","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0088682","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0089477","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0090093","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0090353","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0090439","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0090593","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0090892","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0091658","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0092271","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0092537","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0092624","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0092774","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0093076","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0093839","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0094452","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0094712","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0094798","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0094949","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0095247","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0096017","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0096623","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0096880","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0096963","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0097114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0097418","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0098188","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0098884","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0099574","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0100190","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0100453","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0100542","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0100693","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0100998","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0101761","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0102383","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0102643","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0102730","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0102880","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0103179","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0103961","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0104580","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0104843","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0104933","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0105084","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0105401","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0106184","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0106803","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0107063","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0107149","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0107300","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0107717","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0110629","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0111264","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0111534","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0111627","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0111787","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0112095","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0112945","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,0113570","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0113827","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0113917","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0114067","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0114366","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,0115203","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0115822","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0116082","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0116184","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0116345","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0116678","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0117474","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,0118099","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0118365","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0118455","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0118612","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0118920","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,0120087","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0120796","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0121114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0121220","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0121390","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0121736","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0122605","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,0123288","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0123564","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0123660","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0123817","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0124132","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,0124946","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0125662","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,0126364","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0126996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0127275","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0127374","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0127532","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0127865","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0128660","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,0129286","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0129549","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0129639","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0129793","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0130117","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,0130915","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0131537","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0131810","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0131900","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0132054","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0132384","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,0133163","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,0133779","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,0134045","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,0134132","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,0134283","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,0134607","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9112283","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9112590","EasyAntiCheat_launcher.exe","6076","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\hu*.cfg","NO SUCH FILE","FileInformationClass: FileBothDirectoryInformation, Filter: hu*.cfg" "19:13:29,9112764","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization","SUCCESS","" "19:13:29,9113809","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9114066","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","AllocationSize: 65 536, EndOfFile: 6 175, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:29,9114544","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","Offset: 0, Length: 6 175, Priority: Normal" "19:13:29,9114848","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Localization\en_us.cfg","SUCCESS","" "19:13:29,9117690","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:29,9117866","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:29,9118027","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:29,9118101","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:29,9118219","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:29,9136465","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9137209","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9137614","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9137742","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9137931","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9138393","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9139281","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9139936","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9140215","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9140308","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9140465","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9140821","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9141674","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9142315","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9142598","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9142691","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9142848","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9143197","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9144105","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9144840","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9145112","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9145202","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9145353","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9145683","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9146469","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9147094","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9147364","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9147453","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9147607","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9147963","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9148775","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9149391","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9149657","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9149743","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9149901","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9150225","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9151017","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9151745","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9152441","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9153063","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9153336","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9153441","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9153608","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9153951","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9154734","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9155440","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9155706","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9155796","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9155946","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9156267","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9157069","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9157698","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9157977","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9158066","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9158223","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9158554","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9159330","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9159946","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9160209","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9160299","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9160449","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9160780","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9162547","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9163182","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9163455","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9163554","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9163711","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9164041","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9164827","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9165443","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9165706","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9165793","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9165947","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9166264","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9167056","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9167679","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9167938","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9168025","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9168176","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9168522","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9169301","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9169914","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9170177","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9170264","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9170414","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9170729","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9171492","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9172105","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9172358","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9172445","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9172595","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9172910","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9173683","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9174295","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9174552","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9174638","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9174786","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9175100","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9175873","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9176569","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9177255","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9177871","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9178134","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9178221","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9178372","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9178699","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9179465","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9180078","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9180338","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9180424","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9180575","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9180889","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9181662","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9182278","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9182541","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9182628","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9182778","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9183109","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9183885","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9184501","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9184757","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9184844","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9184995","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9185319","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9186678","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9187307","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9187573","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9187660","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9187811","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9188151","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9188949","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9189565","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9189822","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9189908","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9190059","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9190373","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9191162","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9191778","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9192035","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9192118","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9192269","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9192583","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9193346","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9193969","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9194222","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9194309","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9194459","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9194774","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9195543","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9196153","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9196403","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9196493","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9196643","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9196958","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9197721","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9198324","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9198584","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9198670","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9198821","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9199139","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9199908","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9200640","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9201329","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9201939","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9202195","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9202282","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9202436","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9202756","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9203533","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9204148","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9204408","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9204495","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9204646","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9204969","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9205746","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9206361","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9206618","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9206708","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9206859","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9207192","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9207971","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9208590","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9208850","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9208940","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9209091","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9209405","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9210040","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:29,9210114","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:29,9210249","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\EasyAntiCheat","SUCCESS","Desired Access: Query Value" "19:13:29,9210383","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:29,9210515","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_ServiceState","NAME NOT FOUND","Length: 144" "19:13:29,9210621","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastInitTime","SUCCESS","Type: REG_QWORD, Length: 8, Data: " "19:13:29,9210717","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastInitInfo1","SUCCESS","Type: REG_QWORD, Length: 8, Data: " "19:13:29,9210784","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastInitInfo2","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2367488" "19:13:29,9210848","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastInitGameID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 154" "19:13:29,9210913","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastGameID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 154" "19:13:29,9210977","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameState","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:29,9211038","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashGameID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 154" "19:13:29,9211102","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashPID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4548" "19:13:29,9211160","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashCreateTime","SUCCESS","Type: REG_QWORD, Length: 8, Data: " "19:13:29,9211227","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashExitTime","SUCCESS","Type: REG_QWORD, Length: 8, Data: " "19:13:29,9211294","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashExitStatus","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:29,9211358","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo01","SUCCESS","Type: REG_DWORD, Length: 4, Data: 94625" "19:13:29,9211423","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo02","NAME NOT FOUND","Length: 144" "19:13:29,9211487","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo03","NAME NOT FOUND","Length: 144" "19:13:29,9211548","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo04","NAME NOT FOUND","Length: 144" "19:13:29,9211609","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo05","NAME NOT FOUND","Length: 144" "19:13:29,9211669","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo06","NAME NOT FOUND","Length: 144" "19:13:29,9211730","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo07","NAME NOT FOUND","Length: 144" "19:13:29,9211791","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo08","NAME NOT FOUND","Length: 144" "19:13:29,9211852","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo09","NAME NOT FOUND","Length: 144" "19:13:29,9211913","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo10","NAME NOT FOUND","Length: 144" "19:13:29,9211974","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo11","NAME NOT FOUND","Length: 144" "19:13:29,9212112","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:29,9212888","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\Wevtapi.dll","NAME NOT FOUND","" "19:13:29,9213645","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:11, LastAccessTime: 2021. 02. 12. 20:38:04, LastWriteTime: 2017. 09. 29. 15:42:11, ChangeTime: 2020. 01. 09. 4:43:40, AllocationSize: 319 488, EndOfFile: 316 280, FileAttributes: A" "19:13:29,9214322","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9214617","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\wevtapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9215470","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9215903","EasyAntiCheat_launcher.exe","6076","Load Image","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","Image Base: 0x72840000, Image Size: 0x4e000" "19:13:29,9217350","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","" "19:13:29,9218408","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9218732","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\wevtapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:29,9218844","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","Information: Owner" "19:13:29,9218944","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\wevtapi.dll","SUCCESS","" "19:13:29,9221301","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9221974","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9222273","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9222372","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9222539","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9222892","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9223735","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:29,9224377","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9224656","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9224749","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9224906","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9225239","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:29,9226070","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9226708","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9226981","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9227071","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9227222","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9227552","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9228347","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:29,9228982","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9229245","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9229335","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9229486","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9229810","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:29,9230592","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9231211","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9231474","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9231564","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9231715","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9232055","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9232879","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:29,9233505","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9233764","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9233854","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9234005","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9234326","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:29,9235108","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9235811","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:29,9236494","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9237113","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9237382","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9237472","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9237626","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9237966","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9239570","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:29,9240330","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9240650","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9240756","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9240920","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9241295","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:29,9242164","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9242809","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9243094","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9243191","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9243348","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9243710","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:29,9244531","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:29,9245897","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:29,9246193","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:29,9246286","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:29,9246443","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:29,9246802","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,1489727","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:30,1490478","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1490901","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1491032","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1491225","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1491700","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:30,1492549","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:30,1493185","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1493454","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1493547","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1493704","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1494067","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:30,1494916","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:30,1495561","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1495837","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1495933","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1496090","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1496440","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:30,1497232","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:30,1497854","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1498114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1498204","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1498358","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1498685","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:30,1499474","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:30,1500103","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1500369","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1500455","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1500613","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1500959","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:30,1501735","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:30,1502348","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1502604","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1502691","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1502842","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1503166","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:30,1504080","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:30,1504811","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:30,1505504","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:30,1506123","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1506395","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1506485","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1506642","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1507001","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:30,1507797","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:30,1508413","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1508669","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1508759","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1509035","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1509365","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:30,1510170","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:30,1510799","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1511075","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1511168","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1511322","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1511658","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,1512435","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:30,1513044","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1513304","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1513390","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1513541","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1513881","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,1515103","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:30,1515728","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1515991","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1516081","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1516235","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1516559","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:30,1517335","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:30,1517951","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1518208","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1518294","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1518445","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1518763","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:30,1519568","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:30,1520183","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1520440","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1520527","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1520677","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1520998","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:30,1521787","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:30,1522406","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1522659","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1522746","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1522897","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1523217","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:30,1524087","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:30,1524699","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1524953","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1525039","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1525190","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1525527","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:30,1526300","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:30,1526996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1527249","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1527339","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1527489","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1527807","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:30,1528583","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:30,1529286","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:30,1529975","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:30,1530658","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1530921","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1531011","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1531165","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1531489","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:30,1532256","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:30,1532862","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1533118","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1533205","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1533356","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1533680","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:30,1534469","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:30,1535084","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1535344","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1535431","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1535581","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1535899","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,1536672","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:30,1537281","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1537538","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,1537624","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,1537775","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,1538090","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,1540033","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,1540113","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,1540245","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:30,1540383","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,1540453","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:30,1540569","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:30,1547198","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:30,1547445","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 0, Length: 2, Priority: Normal" "19:13:30,1547808","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2, Length: 998" "19:13:30,1547968","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 000, Length: 962" "19:13:30,1548106","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 962, Length: 963" "19:13:30,1548241","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2 925, Length: 979" "19:13:30,1548587","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 3 904, Length: 995" "19:13:30,1548981","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 4 899, Length: 995" "19:13:30,1549392","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 5 894, Length: 986" "19:13:30,1549790","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 6 880, Length: 980" "19:13:30,1550181","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 7 860, Length: 976" "19:13:30,1550582","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 8 836, Length: 989" "19:13:30,1550765","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 9 825, Length: 968" "19:13:30,1550931","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 10 793, Length: 980" "19:13:30,1551089","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 11 773, Length: 961" "19:13:30,1551303","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 12 734, Length: 985" "19:13:30,1551666","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 13 719, Length: 986" "19:13:30,1552035","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 14 705, Length: 970" "19:13:30,1552436","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 15 675, Length: 987" "19:13:30,1552843","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 16 662, Length: 982" "19:13:30,1553237","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 17 644, Length: 992" "19:13:30,1553638","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 18 636, Length: 985" "19:13:30,1554014","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 19 621, Length: 999" "19:13:30,1554415","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 20 620, Length: 1 000" "19:13:30,1554799","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 21 620, Length: 982" "19:13:30,1555175","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 22 602, Length: 972" "19:13:30,1555544","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 23 574, Length: 995" "19:13:30,1555909","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 24 569, Length: 974" "19:13:30,1556294","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 25 543, Length: 997" "19:13:30,1556679","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 26 540, Length: 999" "19:13:30,1557003","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 27 539, Length: 960" "19:13:30,1557327","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 28 499, Length: 960" "19:13:30,1557660","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 29 459, Length: 987" "19:13:30,1558048","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 30 446, Length: 974" "19:13:30,1558440","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 31 420, Length: 994" "19:13:30,1558841","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 32 414, Length: 987" "19:13:30,1559213","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 33 401, Length: 998" "19:13:30,1559610","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 34 399, Length: 982" "19:13:30,1560008","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 35 381, Length: 992" "19:13:30,1560386","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 36 373, Length: 989" "19:13:30,1560778","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 37 362, Length: 971" "19:13:30,1561153","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 38 333, Length: 973" "19:13:30,1561557","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 39 306, Length: 1 000" "19:13:30,1561955","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 40 306, Length: 1 000" "19:13:30,1562343","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 41 306, Length: 991" "19:13:30,1562728","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 42 297, Length: 996" "19:13:30,1563113","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 43 293, Length: 992" "19:13:30,1563504","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 44 285, Length: 990" "19:13:30,1563898","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 45 275, Length: 976" "19:13:30,1564299","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 46 251, Length: 993" "19:13:30,1564687","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 47 244, Length: 976" "19:13:30,1565072","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 48 220, Length: 981" "19:13:30,1565470","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 49 201, Length: 996" "19:13:30,1565852","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 50 197, Length: 990" "19:13:30,1566230","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 51 187, Length: 1 000" "19:13:30,1566605","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 52 187, Length: 987" "19:13:30,1566977","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 53 174, Length: 981" "19:13:30,1567356","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 54 155, Length: 1 000" "19:13:30,1567728","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 55 155, Length: 998" "19:13:30,1568103","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 56 153, Length: 977" "19:13:30,1568482","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 57 130, Length: 971" "19:13:30,1568886","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 58 101, Length: 986" "19:13:30,1569264","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 59 087, Length: 987" "19:13:30,1569649","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 60 074, Length: 998" "19:13:30,1570044","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 61 072, Length: 1 000" "19:13:30,1570441","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 62 072, Length: 990" "19:13:30,1570897","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 63 062, Length: 997" "19:13:30,1571266","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 64 059, Length: 982" "19:13:30,1571631","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 65 041, Length: 1 000" "19:13:30,1572010","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 66 041, Length: 983" "19:13:30,1572395","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 67 024, Length: 996" "19:13:30,1572754","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 020, Length: 966" "19:13:30,1573164","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 986, Length: 986" "19:13:30,1573568","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 69 972, Length: 997" "19:13:30,1573956","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 70 969, Length: 981" "19:13:30,1574354","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 71 950, Length: 989" "19:13:30,1574742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 72 939, Length: 992" "19:13:30,1575143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 73 931, Length: 983" "19:13:30,1575538","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 74 914, Length: 975" "19:13:30,1575923","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 75 889, Length: 987" "19:13:30,1576311","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 76 876, Length: 981" "19:13:30,1576695","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 77 857, Length: 973" "19:13:30,1577080","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 78 830, Length: 988" "19:13:30,1577446","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 79 818, Length: 982" "19:13:30,1577847","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 80 800, Length: 988" "19:13:30,1578241","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 81 788, Length: 993" "19:13:30,1578652","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 82 781, Length: 991" "19:13:30,1579034","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 83 772, Length: 986" "19:13:30,1579434","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 84 758, Length: 1 000" "19:13:30,1579845","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 85 758, Length: 996" "19:13:30,1580259","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 86 754, Length: 990" "19:13:30,1580653","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 87 744, Length: 996" "19:13:30,1581045","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 88 740, Length: 986" "19:13:30,1581417","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 89 726, Length: 959" "19:13:30,1581798","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 90 685, Length: 933" "19:13:30,1582151","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 91 618, Length: 1 000" "19:13:30,1582542","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 92 618, Length: 992" "19:13:30,1582927","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 93 610, Length: 989" "19:13:30,1583315","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 94 599, Length: 979" "19:13:30,1583700","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 95 578, Length: 974" "19:13:30,1584088","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 96 552, Length: 979" "19:13:30,1584463","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 97 531, Length: 987" "19:13:30,1584852","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 98 518, Length: 999" "19:13:30,1585211","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 99 517, Length: 991" "19:13:30,1585592","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 100 508, Length: 998" "19:13:30,1585977","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 101 506, Length: 971" "19:13:30,1586353","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 102 477, Length: 990" "19:13:30,1586728","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 103 467, Length: 1 000" "19:13:30,1587093","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 104 467, Length: 986" "19:13:30,1587485","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 105 453, Length: 994" "19:13:30,1587863","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 106 447, Length: 988" "19:13:30,1588254","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 107 435, Length: 992" "19:13:30,1588636","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 108 427, Length: 992" "19:13:30,1589024","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 109 419, Length: 992" "19:13:30,1589396","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 110 411, Length: 978" "19:13:30,1589775","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 111 389, Length: 996" "19:13:30,1590137","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 112 385, Length: 986" "19:13:30,1590500","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 113 371, Length: 991" "19:13:30,1590823","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 114 362, Length: 981" "19:13:30,1591196","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 115 343, Length: 997" "19:13:30,1591561","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 116 340, Length: 998" "19:13:30,1591946","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 117 338, Length: 997" "19:13:30,1592308","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 118 335, Length: 997" "19:13:30,1592706","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 119 332, Length: 987" "19:13:30,1593081","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 120 319, Length: 986" "19:13:30,1593441","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 121 305, Length: 965" "19:13:30,1593829","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 122 270, Length: 1 000" "19:13:30,1594210","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 123 270, Length: 992" "19:13:30,1594573","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 124 262, Length: 994" "19:13:30,1594935","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 125 256, Length: 992" "19:13:30,1595304","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 126 248, Length: 969" "19:13:30,1595683","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 127 217, Length: 962" "19:13:30,1596061","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 128 179, Length: 999" "19:13:30,1596439","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 129 178, Length: 1 000" "19:13:30,1596802","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 130 178, Length: 972" "19:13:30,1597177","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 131 150, Length: 981" "19:13:30,1597546","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 132 131, Length: 979" "19:13:30,1597915","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 133 110, Length: 996" "19:13:30,1598290","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 134 106, Length: 973" "19:13:30,1598665","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 135 079, Length: 981" "19:13:30,1599060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 136 060, Length: 1 000" "19:13:30,1599220","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 137 060, Length: 986" "19:13:30,1599640","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 138 046, Length: 977" "19:13:30,1600054","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 139 023, Length: 999" "19:13:30,1600455","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 140 022, Length: 983" "19:13:30,1600865","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 005, Length: 977" "19:13:30,1601270","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 982, Length: 988" "19:13:30,1601683","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 142 970, Length: 982" "19:13:30,1602094","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 143 952, Length: 972" "19:13:30,1602492","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 144 924, Length: 984" "19:13:30,1602899","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 145 908, Length: 994" "19:13:30,1603300","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 146 902, Length: 978" "19:13:30,1603704","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 147 880, Length: 981" "19:13:30,1604114","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 148 861, Length: 996" "19:13:30,1604509","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 149 857, Length: 986" "19:13:30,1604900","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 150 843, Length: 990" "19:13:30,1605295","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 151 833, Length: 984" "19:13:30,1605692","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 152 817, Length: 1 000" "19:13:30,1606071","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 153 817, Length: 990" "19:13:30,1606478","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 154 807, Length: 980" "19:13:30,1606892","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 155 787, Length: 982" "19:13:30,1607309","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 156 769, Length: 1 000" "19:13:30,1607687","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 157 769, Length: 994" "19:13:30,1608082","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 158 763, Length: 995" "19:13:30,1608489","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 159 758, Length: 984" "19:13:30,1608913","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 160 742, Length: 999" "19:13:30,1609317","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 161 741, Length: 973" "19:13:30,1609721","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 162 714, Length: 999" "19:13:30,1610118","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 163 713, Length: 989" "19:13:30,1610529","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 164 702, Length: 984" "19:13:30,1610920","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 165 686, Length: 989" "19:13:30,1611305","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 166 675, Length: 982" "19:13:30,1611696","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 167 657, Length: 987" "19:13:30,1612309","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 168 644, Length: 1 000" "19:13:30,1612761","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 169 644, Length: 971" "19:13:30,1613172","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 170 615, Length: 985" "19:13:30,1613573","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 171 600, Length: 993" "19:13:30,1614035","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 172 593, Length: 997" "19:13:30,1614432","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 173 590, Length: 988" "19:13:30,1614827","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 174 578, Length: 988" "19:13:30,1615228","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 175 566, Length: 994" "19:13:30,1615632","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 176 560, Length: 991" "19:13:30,1616017","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 177 551, Length: 987" "19:13:30,1616408","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 178 538, Length: 998" "19:13:30,1616786","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 179 536, Length: 983" "19:13:30,1617184","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 180 519, Length: 998" "19:13:30,1617575","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 181 517, Length: 981" "19:13:30,1617973","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 182 498, Length: 999" "19:13:30,1618377","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 183 497, Length: 1 000" "19:13:30,1618797","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 184 497, Length: 997" "19:13:30,1619182","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 185 494, Length: 991" "19:13:30,1619570","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 186 485, Length: 975" "19:13:30,1619962","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 187 460, Length: 988" "19:13:30,1620362","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 188 448, Length: 985" "19:13:30,1620757","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 189 433, Length: 993" "19:13:30,1621135","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 190 426, Length: 976" "19:13:30,1621530","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 191 402, Length: 995" "19:13:30,1621905","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 192 397, Length: 969" "19:13:30,1622290","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 193 366, Length: 987" "19:13:30,1622675","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 194 353, Length: 993" "19:13:30,1623053","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 195 346, Length: 997" "19:13:30,1623432","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 196 343, Length: 975" "19:13:30,1623836","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 197 318, Length: 975" "19:13:30,1624227","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 198 293, Length: 986" "19:13:30,1624606","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 199 279, Length: 990" "19:13:30,1625019","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 200 269, Length: 997" "19:13:30,1625436","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 201 266, Length: 987" "19:13:30,1625847","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 202 253, Length: 987" "19:13:30,1626251","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 203 240, Length: 977" "19:13:30,1626646","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 204 217, Length: 978" "19:13:30,1627053","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 205 195, Length: 978" "19:13:30,1627454","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 206 173, Length: 990" "19:13:30,1627858","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 207 163, Length: 995" "19:13:30,1628256","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 208 158, Length: 1 000" "19:13:30,1628653","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 209 158, Length: 989" "19:13:30,1629038","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 210 147, Length: 966" "19:13:30,1629433","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 211 113, Length: 994" "19:13:30,1629827","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 212 107, Length: 986" "19:13:30,1630234","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 213 093, Length: 978" "19:13:30,1630655","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 214 071, Length: 999" "19:13:30,1631052","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 215 070, Length: 984" "19:13:30,1631437","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 216 054, Length: 986" "19:13:30,1631832","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 217 040, Length: 1 000" "19:13:30,1632226","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 218 040, Length: 978" "19:13:30,1632617","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 018, Length: 971" "19:13:30,1633015","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 989, Length: 982" "19:13:30,1633422","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 220 971, Length: 1 000" "19:13:30,1633833","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 221 971, Length: 990" "19:13:30,1634240","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 222 961, Length: 990" "19:13:30,1634651","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 223 951, Length: 996" "19:13:30,1635045","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 224 947, Length: 976" "19:13:30,1635453","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 225 923, Length: 980" "19:13:30,1635854","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 226 903, Length: 998" "19:13:30,1636248","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 227 901, Length: 997" "19:13:30,1636649","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 228 898, Length: 998" "19:13:30,1637056","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 229 896, Length: 986" "19:13:30,1637454","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 230 882, Length: 996" "19:13:30,1637852","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 231 878, Length: 984" "19:13:30,1638253","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 232 862, Length: 1 000" "19:13:30,1638644","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 233 862, Length: 994" "19:13:30,1639067","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 234 856, Length: 981" "19:13:30,1639455","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 235 837, Length: 989" "19:13:30,1639859","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 236 826, Length: 999" "19:13:30,1640257","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 237 825, Length: 974" "19:13:30,1640671","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 238 799, Length: 990" "19:13:30,1641075","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 239 789, Length: 986" "19:13:30,1641473","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 240 775, Length: 992" "19:13:30,1641864","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 241 767, Length: 998" "19:13:30,1642268","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 242 765, Length: 994" "19:13:30,1642672","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 243 759, Length: 976" "19:13:30,1643060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 244 735, Length: 979" "19:13:30,1643455","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 245 714, Length: 982" "19:13:30,1643878","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 246 696, Length: 1 000" "19:13:30,1644282","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 247 696, Length: 985" "19:13:30,1644683","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 248 681, Length: 978" "19:13:30,1645081","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 249 659, Length: 993" "19:13:30,1645479","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 250 652, Length: 983" "19:13:30,1645867","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 251 635, Length: 993" "19:13:30,1646268","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 252 628, Length: 989" "19:13:30,1646643","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 253 617, Length: 980" "19:13:30,1647031","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 254 597, Length: 990" "19:13:30,1647429","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 255 587, Length: 988" "19:13:30,1647813","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 256 575, Length: 998" "19:13:30,1648202","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 257 573, Length: 979" "19:13:30,1648615","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 258 552, Length: 984" "19:13:30,1649029","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 259 536, Length: 996" "19:13:30,1649443","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 260 532, Length: 996" "19:13:30,1649844","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 261 528, Length: 998" "19:13:30,1650283","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 262 526, Length: 972" "19:13:30,1650690","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 263 498, Length: 974" "19:13:30,1651117","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 264 472, Length: 993" "19:13:30,1651518","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 265 465, Length: 970" "19:13:30,1652525","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 266 435, Length: 993" "19:13:30,1652990","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 267 428, Length: 974" "19:13:30,1653417","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 268 402, Length: 998" "19:13:30,1653830","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 269 400, Length: 981" "19:13:30,1654263","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 270 381, Length: 969" "19:13:30,1654700","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 271 350, Length: 1 000" "19:13:30,1655110","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 272 350, Length: 1 000" "19:13:30,1655546","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 273 350, Length: 1 000" "19:13:30,1655938","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 274 350, Length: 973" "19:13:30,1656351","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 275 323, Length: 992" "19:13:30,1656768","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 276 315, Length: 979" "19:13:30,1657336","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 277 294, Length: 983" "19:13:30,1657807","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 278 277, Length: 984" "19:13:30,1658292","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 279 261, Length: 981" "19:13:30,1658814","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 280 242, Length: 989" "19:13:30,1659244","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 281 231, Length: 988" "19:13:30,1659648","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 282 219, Length: 984" "19:13:30,1660059","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 283 203, Length: 1 000" "19:13:30,1660460","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 284 203, Length: 1 000" "19:13:30,1660867","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 285 203, Length: 1 000" "19:13:30,1661274","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 286 203, Length: 986" "19:13:30,1661682","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 287 189, Length: 980" "19:13:30,1662089","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 288 169, Length: 993" "19:13:30,1662474","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 289 162, Length: 992" "19:13:30,1662862","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 290 154, Length: 985" "19:13:30,1663269","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 291 139, Length: 980" "19:13:30,1663670","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 292 119, Length: 990" "19:13:30,1664084","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 293 109, Length: 978" "19:13:30,1664482","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 294 087, Length: 988" "19:13:30,1664876","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 295 075, Length: 978" "19:13:30,1665280","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 296 053, Length: 993" "19:13:30,1665678","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 297 046, Length: 1 000" "19:13:30,1666066","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 298 046, Length: 984" "19:13:30,1666451","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 299 030, Length: 976" "19:13:30,1666855","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 006, Length: 988" "19:13:30,1667266","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 994, Length: 989" "19:13:30,1667667","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 301 983, Length: 997" "19:13:30,1668058","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 302 980, Length: 985" "19:13:30,1668420","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 303 965, Length: 990" "19:13:30,1668776","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 304 955, Length: 990" "19:13:30,1669184","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 305 945, Length: 974" "19:13:30,1669591","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 306 919, Length: 1 000" "19:13:30,1670011","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 307 919, Length: 995" "19:13:30,1670399","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 308 914, Length: 996" "19:13:30,1670800","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 309 910, Length: 998" "19:13:30,1671201","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 310 908, Length: 993" "19:13:30,1671599","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 311 901, Length: 986" "19:13:30,1671980","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 312 887, Length: 976" "19:13:30,1672400","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 313 863, Length: 991" "19:13:30,1672805","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 314 854, Length: 990" "19:13:30,1673209","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 315 844, Length: 990" "19:13:30,1673590","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 316 834, Length: 985" "19:13:30,1673991","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 317 819, Length: 986" "19:13:30,1674373","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 318 805, Length: 979" "19:13:30,1674771","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 319 784, Length: 998" "19:13:30,1675175","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 320 782, Length: 976" "19:13:30,1675572","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 321 758, Length: 992" "19:13:30,1675957","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 322 750, Length: 983" "19:13:30,1676371","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 323 733, Length: 990" "19:13:30,1676766","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 324 723, Length: 977" "19:13:30,1677147","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 325 700, Length: 981" "19:13:30,1677548","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 326 681, Length: 999" "19:13:30,1677946","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 327 680, Length: 985" "19:13:30,1678366","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 328 665, Length: 996" "19:13:30,1678773","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 329 661, Length: 1 000" "19:13:30,1679181","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 330 661, Length: 999" "19:13:30,1679569","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 331 660, Length: 988" "19:13:30,1679979","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 332 648, Length: 983" "19:13:30,1680371","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 333 631, Length: 974" "19:13:30,1680759","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 334 605, Length: 976" "19:13:30,1681150","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 335 581, Length: 989" "19:13:30,1681564","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 336 570, Length: 990" "19:13:30,1681971","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 337 560, Length: 992" "19:13:30,1682365","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 338 552, Length: 990" "19:13:30,1682773","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 339 542, Length: 978" "19:13:30,1683164","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 340 520, Length: 971" "19:13:30,1683552","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 341 491, Length: 982" "19:13:30,1683966","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 342 473, Length: 997" "19:13:30,1684357","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 343 470, Length: 991" "19:13:30,1684752","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 344 461, Length: 985" "19:13:30,1685159","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 345 446, Length: 998" "19:13:30,1685553","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 346 444, Length: 976" "19:13:30,1685945","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 347 420, Length: 981" "19:13:30,1686352","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 348 401, Length: 990" "19:13:30,1686740","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 349 391, Length: 979" "19:13:30,1687131","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 350 370, Length: 997" "19:13:30,1687513","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 351 367, Length: 997" "19:13:30,1687898","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 352 364, Length: 982" "19:13:30,1688276","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 353 346, Length: 981" "19:13:30,1688655","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 354 327, Length: 1 000" "19:13:30,1689046","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 355 327, Length: 1 000" "19:13:30,1689425","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 356 327, Length: 986" "19:13:30,1689803","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 357 313, Length: 986" "19:13:30,1690169","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 358 299, Length: 975" "19:13:30,1690541","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 359 274, Length: 1 000" "19:13:30,1690910","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 360 274, Length: 998" "19:13:30,1691285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 361 272, Length: 994" "19:13:30,1691660","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 362 266, Length: 989" "19:13:30,1692032","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 363 255, Length: 995" "19:13:30,1692407","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 364 250, Length: 980" "19:13:30,1692792","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 365 230, Length: 990" "19:13:30,1693177","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 366 220, Length: 992" "19:13:30,1693549","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 367 212, Length: 977" "19:13:30,1693940","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 368 189, Length: 992" "19:13:30,1694319","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 369 181, Length: 972" "19:13:30,1694688","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 370 153, Length: 979" "19:13:30,1695066","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 371 132, Length: 983" "19:13:30,1695441","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 372 115, Length: 994" "19:13:30,1695826","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 373 109, Length: 996" "19:13:30,1696202","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 374 105, Length: 984" "19:13:30,1696580","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 375 089, Length: 972" "19:13:30,1696959","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 376 061, Length: 991" "19:13:30,1697363","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 377 052, Length: 1 000" "19:13:30,1697757","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 378 052, Length: 976" "19:13:30,1698152","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 379 028, Length: 996" "19:13:30,1698536","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 380 024, Length: 998" "19:13:30,1698976","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 381 022, Length: 984" "19:13:30,1699383","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 382 006, Length: 999" "19:13:30,1699778","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 005, Length: 988" "19:13:30,1700108","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 993, Length: 988" "19:13:30,1700487","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 384 981, Length: 996" "19:13:30,1700875","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 385 977, Length: 976" "19:13:30,1701243","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 386 953, Length: 983" "19:13:30,1701609","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 387 936, Length: 986" "19:13:30,1701975","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 388 922, Length: 1 000" "19:13:30,1702344","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 389 922, Length: 971" "19:13:30,1702751","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 390 893, Length: 999" "19:13:30,1703142","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 391 892, Length: 999" "19:13:30,1703527","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 392 891, Length: 994" "19:13:30,1703925","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 393 885, Length: 994" "19:13:30,1704313","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 394 879, Length: 986" "19:13:30,1704675","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 395 865, Length: 1 000" "19:13:30,1705070","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 396 865, Length: 999" "19:13:30,1705448","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 397 864, Length: 996" "19:13:30,1705811","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 398 860, Length: 974" "19:13:30,1706183","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 399 834, Length: 991" "19:13:30,1706545","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 400 825, Length: 985" "19:13:30,1706917","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 401 810, Length: 968" "19:13:30,1707283","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 402 778, Length: 994" "19:13:30,1707642","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 403 772, Length: 992" "19:13:30,1707998","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 404 764, Length: 992" "19:13:30,1708373","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 405 756, Length: 980" "19:13:30,1708742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 406 736, Length: 986" "19:13:30,1709085","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 407 722, Length: 990" "19:13:30,1709432","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 408 712, Length: 1 000" "19:13:30,1709845","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 409 712, Length: 998" "19:13:30,1710233","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 410 710, Length: 985" "19:13:30,1710621","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 411 695, Length: 979" "19:13:30,1710987","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 412 674, Length: 977" "19:13:30,1711366","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 413 651, Length: 983" "19:13:30,1711747","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 414 634, Length: 973" "19:13:30,1712126","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 415 607, Length: 976" "19:13:30,1712520","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 416 583, Length: 995" "19:13:30,1712915","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 417 578, Length: 978" "19:13:30,1713300","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 418 556, Length: 963" "19:13:30,1713694","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 419 519, Length: 1 000" "19:13:30,1714095","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 420 519, Length: 982" "19:13:30,1714486","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 421 501, Length: 991" "19:13:30,1714874","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 422 492, Length: 979" "19:13:30,1715243","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 423 471, Length: 992" "19:13:30,1715625","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 424 463, Length: 997" "19:13:30,1716016","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 425 460, Length: 988" "19:13:30,1716420","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 426 448, Length: 986" "19:13:30,1716802","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 427 434, Length: 991" "19:13:30,1717193","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 428 425, Length: 987" "19:13:30,1717584","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 429 412, Length: 967" "19:13:30,1717976","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 430 379, Length: 980" "19:13:30,1718364","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 431 359, Length: 971" "19:13:30,1718765","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 432 330, Length: 983" "19:13:30,1719178","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 433 313, Length: 980" "19:13:30,1719576","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 434 293, Length: 988" "19:13:30,1719749","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 435 281, Length: 980" "19:13:30,1719881","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 436 261, Length: 974" "19:13:30,1720125","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 437 235, Length: 989" "19:13:30,1720493","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 438 224, Length: 981" "19:13:30,1720837","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 439 205, Length: 301" "19:13:30,1721061","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","" "19:13:30,9047601","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 5064" "19:13:30,9049401","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:30,9050177","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9050604","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9050732","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9050924","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9051335","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:30,9052210","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:30,9052861","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9053137","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9053230","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9053387","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9053695","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:30,9054552","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:30,9055206","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9055491","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9055581","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9055738","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9056059","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:30,9056861","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:30,9057490","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9057753","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9057842","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9057996","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9058298","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:30,9059084","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:30,9059812","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9060081","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9060171","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9060328","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9060629","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:30,9061406","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:30,9062021","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9062284","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9062371","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9062525","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9062836","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:30,9063641","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:30,9064376","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:30,9065084","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:30,9065710","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9065989","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9066091","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9066252","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9066556","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:30,9067336","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:30,9067955","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9068218","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9068304","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9068458","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9068747","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:30,9069546","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:30,9070181","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9070460","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9070550","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9070703","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9071002","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,9071778","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:30,9072397","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9072657","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9072743","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9072894","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9073179","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:30,9074466","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:30,9075155","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator","SUCCESS","CreationTime: 2020. 01. 09. 4:53:33, LastAccessTime: 2021. 04. 14. 15:44:50, LastWriteTime: 2021. 04. 14. 15:44:50, ChangeTime: 2021. 04. 14. 15:44:50, AllocationSize: 20 480, EndOfFile: 20 480, FileAttributes: DNCI" "19:13:30,9075819","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:30,9076432","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Users\Administrator\AppData\Roaming","SUCCESS","CreationTime: 2020. 01. 09. 4:53:34, LastAccessTime: 2021. 04. 13. 16:48:14, LastWriteTime: 2021. 04. 13. 16:48:14, ChangeTime: 2021. 04. 13. 16:48:14, AllocationSize: 12 288, EndOfFile: 12 288, FileAttributes: DANCI" "19:13:30,9077429","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SHARING VIOLATION","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a" "19:13:30,9078718","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9079007","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","AllocationSize: 1 617 920, EndOfFile: 1 615 712, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9115381","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Offset: 0, Length: 1 615 712, Priority: Normal" "19:13:30,9118983","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","" "19:13:30,9151998","EasyAntiCheat.exe","2900","Process Start","","SUCCESS","Parent PID: 752, Command line: ""C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe"", Current directory: C:\Windows\system32\, Environment: ; ALLUSERSPROFILE=C:\ProgramData ; APPDATA=C:\Windows\system32\config\systemprofile\AppData\Roaming ; CommonProgramFiles=C:\Program Files\Common Files ; CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files ; CommonProgramW6432=C:\Program Files\Common Files ; Compilers=C:\Code\Tools\Compilers ; COMPUTERNAME=DEVLA-PC ; ComSpec=C:\Windows\system32\cmd.exe ; LOCALAPPDATA=C:\Windows\system32\config\systemprofile\AppData\Local ; NUMBER_OF_PROCESSORS=4 ; OS=Windows_NT ; Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\dotnet;C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps ; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JSE;.WSF;.WSH;.MSC ; PROCESSOR_ARCHITECTURE=AMD64 ; PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ; PROCESSOR_LEVEL=6 ; PROCESSOR_REVISION=3a09 ; ProgramData=C:\ProgramData ; ProgramFiles=C:\Program Files ; ProgramFiles(x86)=C:\Program Files (x86) ; ProgramW6432=C:\Program Files ; PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules ; PT8HOME=D:\Program Files\Cisco Packet Tracer 8.0 ; PUBLIC=C:\Users\Public ; QT_DEVICE_PIXEL_RATIO=auto ; SystemDrive=C: ; SystemRoot=C:\Windows ; TEMP=C:\Windows\TEMP ; TMP=C:\Windows\TEMP ; USERDOMAIN=WORKGROUP ; USERNAME=DEVLA-PC$ ; USERPROFILE=C:\Windows\system32\config\systemprofile ; VBOX_MSI_INSTALL_PATH=D:\Program Files\Oracle\VirtualBox\ ; windir=C:\Windows" "19:13:30,9152059","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 5116" "19:13:30,9161713","EasyAntiCheat.exe","2900","Load Image","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe","SUCCESS","Image Base: 0xc00000, Image Size: 0xc7000" "19:13:30,9161838","EasyAntiCheat.exe","2900","Load Image","C:\Windows\System32\ntdll.dll","SUCCESS","Image Base: 0x7ffdd1ff0000, Image Size: 0x1e0000" "19:13:30,9161950","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Image Base: 0x772b0000, Image Size: 0x18d000" "19:13:30,9162775","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value" "19:13:30,9162871","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value" "19:13:30,9163211","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9163288","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9163378","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:30,9163461","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:30,9165642","EasyAntiCheat.exe","2900","CreateFile","C:\Windows","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9166704","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\System32\wow64.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:05, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:05, ChangeTime: 2020. 01. 09. 4:42:23, AllocationSize: 319 488, EndOfFile: 319 352, FileAttributes: A" "19:13:30,9167387","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\wow64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9167698","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\wow64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9167909","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\wow64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9168233","EasyAntiCheat.exe","2900","Load Image","C:\Windows\System32\wow64.dll","SUCCESS","Image Base: 0x600b0000, Image Size: 0x51000" "19:13:30,9168641","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\wow64.dll","SUCCESS","" "19:13:30,9168942","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value" "19:13:30,9169038","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value" "19:13:30,9169138","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16" "19:13:30,9170001","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)\EasyAntiCheat\wow64win.dll","NAME NOT FOUND","" "19:13:30,9170697","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\System32\wow64win.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:05, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:05, ChangeTime: 2020. 01. 09. 4:42:23, AllocationSize: 483 328, EndOfFile: 481 488, FileAttributes: A" "19:13:30,9171373","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\wow64win.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9171665","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\wow64win.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9171854","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\wow64win.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9172130","EasyAntiCheat.exe","2900","Load Image","C:\Windows\System32\wow64win.dll","SUCCESS","Image Base: 0x60030000, Image Size: 0x77000" "19:13:30,9172435","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\wow64win.dll","SUCCESS","" "19:13:30,9174253","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\System32\wow64log.dll","NAME NOT FOUND","" "19:13:30,9174744","EasyAntiCheat.exe","2900","Load Image","C:\Windows\System32\kernel32.dll","SUCCESS","Image Base: 0x3120000, Image Size: 0xae000" "19:13:30,9175187","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Image Base: 0x74a70000, Image Size: 0xd0000" "19:13:30,9175530","EasyAntiCheat.exe","2900","Load Image","C:\Windows\System32\user32.dll","SUCCESS","Image Base: 0x31f0000, Image Size: 0x18e000" "19:13:30,9176242","EasyAntiCheat.exe","2900","CreateFile","C:\Windows","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9176476","EasyAntiCheat.exe","2900","QueryNameInformationFile","C:\Windows","SUCCESS","Name: \Windows" "19:13:30,9176588","EasyAntiCheat.exe","2900","CloseFile","C:\Windows","SUCCESS","" "19:13:30,9176887","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Wow64\x86","SUCCESS","Desired Access: Read" "19:13:30,9176996","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Wow64\x86\EasyAntiCheat.exe","NAME NOT FOUND","Length: 520" "19:13:30,9177057","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Wow64\x86\(Default)","SUCCESS","Type: REG_SZ, Length: 26, Data: wow64cpu.dll" "19:13:30,9177146","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Wow64\x86","SUCCESS","" "19:13:30,9177871","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\System32\wow64cpu.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:05, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:05, ChangeTime: 2020. 01. 09. 4:42:23, AllocationSize: 24 576, EndOfFile: 22 392, FileAttributes: A" "19:13:30,9178535","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\wow64cpu.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9178824","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\wow64cpu.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9179019","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\wow64cpu.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9179315","EasyAntiCheat.exe","2900","Load Image","C:\Windows\System32\wow64cpu.dll","SUCCESS","Image Base: 0x60020000, Image Size: 0xa000" "19:13:30,9179619","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\wow64cpu.dll","SUCCESS","" "19:13:30,9181127","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value" "19:13:30,9181229","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value" "19:13:30,9181540","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9181621","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9181723","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9181787","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:30,9181874","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:30,9184077","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9184642","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Image Base: 0x74a70000, Image Size: 0xd0000" "19:13:30,9185463","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Image Base: 0x747a0000, Image Size: 0x1d7000" "19:13:30,9189998","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\3c74afb9-8d82-44e3-b52c-365dbf48382a","NAME NOT FOUND","Length: 524" "19:13:30,9190553","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\05f95efe-7f75-49c7-a994-60a55cc09571","NAME NOT FOUND","Length: 524" "19:13:30,9191948","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value" "19:13:30,9192057","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "19:13:30,9192198","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read" "19:13:30,9192282","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read" "19:13:30,9192429","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers","REPARSE","Desired Access: Query Value" "19:13:30,9192532","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value" "19:13:30,9192663","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9192731","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80" "19:13:30,9192820","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","" "19:13:30,9192984","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","REPARSE","Desired Access: Query Value" "19:13:30,9193080","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value" "19:13:30,9193282","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem\","REPARSE","Desired Access: Read" "19:13:30,9193362","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","Desired Access: Read" "19:13:30,9193462","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9193529","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:30,9193616","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","" "19:13:30,9194671","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\user32.dll","SUCCESS","Image Base: 0x745c0000, Image Size: 0x175000" "19:13:30,9195383","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\win32u.dll","SUCCESS","Image Base: 0x73f70000, Image Size: 0x16000" "19:13:30,9195996","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 4236" "19:13:30,9196634","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\gdi32.dll","SUCCESS","Image Base: 0x750f0000, Image Size: 0x22000" "19:13:30,9197294","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\gdi32full.dll","SUCCESS","Image Base: 0x74360000, Image Size: 0x15e000" "19:13:30,9197853","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\msvcp_win.dll","SUCCESS","Image Base: 0x75120000, Image Size: 0x7c000" "19:13:30,9198350","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","Image Base: 0x74de0000, Image Size: 0x117000" "19:13:30,9199219","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 952" "19:13:30,9199883","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 6344" "19:13:30,9200268","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\advapi32.dll","SUCCESS","Image Base: 0x742e0000, Image Size: 0x78000" "19:13:30,9201021","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","Image Base: 0x74100000, Image Size: 0xbd000" "19:13:30,9201810","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Image Base: 0x73cf0000, Image Size: 0x43000" "19:13:30,9202333","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9202439","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9202545","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9202612","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:30,9202705","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:30,9203071","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","Image Base: 0x74b40000, Image Size: 0xbe000" "19:13:30,9203783","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\sspicli.dll","SUCCESS","Image Base: 0x73cd0000, Image Size: 0x20000" "19:13:30,9204280","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\cryptbase.dll","SUCCESS","Image Base: 0x73cc0000, Image Size: 0xa000" "19:13:30,9204812","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\bcryptprimitives.dll","SUCCESS","Image Base: 0x73f90000, Image Size: 0x57000" "19:13:30,9206073","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\shell32.dll","SUCCESS","Image Base: 0x75f00000, Image Size: 0x1333000" "19:13:30,9207000","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\cfgmgr32.dll","SUCCESS","Image Base: 0x74030000, Image Size: 0x38000" "19:13:30,9207917","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\SHCore.dll","SUCCESS","Image Base: 0x749e0000, Image Size: 0x88000" "19:13:30,9208725","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\combase.dll","SUCCESS","Image Base: 0x75210000, Image Size: 0x246000" "19:13:30,9209684","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\windows.storage.dll","SUCCESS","Image Base: 0x75930000, Image Size: 0x5c6000" "19:13:30,9210611","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\shlwapi.dll","SUCCESS","Image Base: 0x74290000, Image Size: 0x45000" "19:13:30,9211480","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Image Base: 0x751a0000, Image Size: 0xe000" "19:13:30,9212295","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\powrprof.dll","SUCCESS","Image Base: 0x75070000, Image Size: 0x45000" "19:13:30,9213055","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\profapi.dll","SUCCESS","Image Base: 0x750c0000, Image Size: 0x14000" "19:13:30,9213915","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\ole32.dll","SUCCESS","Image Base: 0x744c0000, Image Size: 0xf7000" "19:13:30,9214848","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "19:13:30,9215698","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe.Local","NAME NOT FOUND","" "19:13:30,9216593","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9217103","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\psapi.dll","SUCCESS","Image Base: 0x741f0000, Image Size: 0x6000" "19:13:30,9217702","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 20:20:15, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:43:25, AllocationSize: 1 474 560, EndOfFile: 1 470 976, FileAttributes: A" "19:13:30,9218446","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9218700","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9218908","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9219251","EasyAntiCheat.exe","2900","Load Image","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","Image Base: 0x6c4a0000, Image Size: 0x16c000" "19:13:30,9220031","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","" "19:13:30,9221760","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read" "19:13:30,9221869","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","Desired Access: Read" "19:13:30,9222010","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9222080","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default)","SUCCESS","Type: REG_SZ, Length: 18, Data: 0006020E" "19:13:30,9224563","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f25bcd2e-2690-55dc-3bc4-07b65b1b41c9","NAME NOT FOUND","Length: 524" "19:13:30,9224970","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Display","REPARSE","Desired Access: Read" "19:13:30,9225069","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Display","NAME NOT FOUND","Desired Access: Read" "19:13:30,9225223","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9225336","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9225438","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9225551","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:30,9225624","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EasyAntiCheat.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9225820","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Display","REPARSE","Desired Access: Read" "19:13:30,9225907","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Display","NAME NOT FOUND","Desired Access: Read" "19:13:30,9226060","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","REPARSE","Desired Access: Read" "19:13:30,9226160","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","Desired Access: Read" "19:13:30,9226256","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9226314","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20" "19:13:30,9226397","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","" "19:13:30,9226705","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.Default\Control Panel\Desktop","SUCCESS","Desired Access: Read" "19:13:30,9226849","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\Desktop\EnablePerProcessSystemDPI","NAME NOT FOUND","Length: 520" "19:13:30,9226962","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Control Panel\Desktop","SUCCESS","" "19:13:30,9227446","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32","SUCCESS","Desired Access: Read" "19:13:30,9227581","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32\EasyAntiCheat","NAME NOT FOUND","Length: 172" "19:13:30,9227696","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32","SUCCESS","" "19:13:30,9227802","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read" "19:13:30,9230188","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Query Value" "19:13:30,9230320","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Query Value" "19:13:30,9230461","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9230547","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY","NAME NOT FOUND","Length: 120" "19:13:30,9230701","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\EMPTY","NAME NOT FOUND","Length: 120" "19:13:30,9231324","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\NLS\Language","REPARSE","Desired Access: Read" "19:13:30,9231426","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\NLS\Language","SUCCESS","Desired Access: Read" "19:13:30,9231555","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Language","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9231635","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Language\InstallLanguageFallback","NAME NOT FOUND","Length: 16" "19:13:30,9231808","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Language","SUCCESS","" "19:13:30,9231943","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","REPARSE","Desired Access: Read" "19:13:30,9232039","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","Desired Access: Read" "19:13:30,9232158","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9232273","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","Index: 0, Name: en-US" "19:13:30,9232510","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:30,9232645","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US","SUCCESS","Desired Access: Read" "19:13:30,9232793","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 273" "19:13:30,9232988","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US\AlternateCodePage","NAME NOT FOUND","Length: 12" "19:13:30,9233100","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\en-US","SUCCESS","" "19:13:30,9233187","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","NO MORE ENTRIES","Index: 1, Length: 512" "19:13:30,9233277","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages","SUCCESS","" "19:13:30,9233424","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete","REPARSE","Desired Access: Read" "19:13:30,9233540","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\UILanguages\PendingDelete","NAME NOT FOUND","Desired Access: Read" "19:13:30,9233697","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:30,9233806","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:30,9233970","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:30,9234095","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:30,9234268","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9234351","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:30,9234473","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read" "19:13:30,9234637","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","REPARSE","Desired Access: Read" "19:13:30,9234743","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","SUCCESS","Desired Access: Read" "19:13:30,9234874","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9234954","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512" "19:13:30,9235057","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\Settings\LanguageConfiguration","SUCCESS","" "19:13:30,9235137","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:30,9235403","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:30,9235548","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:30,9235721","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:30,9235820","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:30,9235977","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9236058","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:30,9236176","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "19:13:30,9236292","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9236365","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:30,9236475","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\Desktop\LanguageConfiguration","NAME NOT FOUND","Desired Access: Read" "19:13:30,9236587","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:30,9236721","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:30,9236824","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:30,9236959","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:30,9237049","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:30,9237177","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9237254","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:30,9237360","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "19:13:30,9237469","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9237543","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:30,9237645","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\Desktop","SUCCESS","Desired Access: Read" "19:13:30,9237757","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Control Panel\Desktop","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9237844","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\Desktop\PreferredUILanguages","NAME NOT FOUND","Length: 12" "19:13:30,9237950","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Control Panel\Desktop","SUCCESS","" "19:13:30,9238027","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:30,9238149","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\MUI\Settings","REPARSE","Desired Access: Read" "19:13:30,9238245","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:30,9238380","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:30,9238469","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:30,9238598","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9238671","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:30,9238781","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\Desktop\MuiCached","SUCCESS","Desired Access: Read" "19:13:30,9238944","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Control Panel\Desktop\MuiCached","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9239027","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12" "19:13:30,9239117","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","SUCCESS","Type: REG_MULTI_SZ, Length: 14, Data: en-US" "19:13:30,9239236","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Control Panel\Desktop\MuiCached","SUCCESS","" "19:13:30,9239316","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:30,9240493","EasyAntiCheat.exe","2900","RegOpenKey","HKLM","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:30,9240644","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9240721","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9240849","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","Desired Access: Read" "19:13:30,9240978","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9241077","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:30,9241205","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","" "19:13:30,9241359","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:30,9241436","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EasyAntiCheat.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9242815","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value" "19:13:30,9242912","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","Desired Access: Query Value" "19:13:30,9243011","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9243075","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:30,9243194","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value" "19:13:30,9243268","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","Desired Access: Query Value" "19:13:30,9243351","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9243409","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20" "19:13:30,9243479","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled","NAME NOT FOUND","Length: 20" "19:13:30,9243547","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","" "19:13:30,9243607","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","" "19:13:30,9243700","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value" "19:13:30,9243781","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value" "19:13:30,9244364","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a6d3c9ac-9128-522a-495a-1821191173c2","NAME NOT FOUND","Length: 524" "19:13:30,9245615","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9245679","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9245788","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE","REPARSE","Desired Access: Read" "19:13:30,9245888","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:30,9245978","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9246039","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144" "19:13:30,9246119","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:30,9246196","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9246253","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9246350","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE","REPARSE","Desired Access: Read" "19:13:30,9246427","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:30,9246504","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9246558","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144" "19:13:30,9246632","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:30,9246702","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9246757","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9246850","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLE","REPARSE","Desired Access: Read" "19:13:30,9246930","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:30,9247004","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9247065","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\AggressiveMTATesting","NAME NOT FOUND","Length: 144" "19:13:30,9247139","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:30,9247453","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9247524","EasyAntiCheat.exe","2900","RegOpenKey","HKLM","SUCCESS","Desired Access: Read" "19:13:30,9247601","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9247684","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9247751","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:30,9247883","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9247947","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:30,9248040","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9248104","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:30,9248386","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Read" "19:13:30,9248463","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:30,9248547","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9248630","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9248697","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings","SUCCESS","Desired Access: Read" "19:13:30,9248803","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:30,9248896","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9248964","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:30,9249057","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9249124","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:30,9249211","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9249275","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Ole","NAME NOT FOUND","Desired Access: Read" "19:13:30,9249358","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:30,9249422","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft","SUCCESS","Desired Access: Read" "19:13:30,9249730","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9249833","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9249939","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing","REPARSE","Desired Access: Read" "19:13:30,9250028","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole\Tracing","NAME NOT FOUND","Desired Access: Read" "19:13:30,9250388","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be","NAME NOT FOUND","Length: 524" "19:13:30,9250827","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f0558438-f56a-5987-47da-040ca75aef05","NAME NOT FOUND","Length: 524" "19:13:30,9252504","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:30,9253957","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:30,9255798","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:30,9258034","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108","NAME NOT FOUND","Length: 524" "19:13:30,9258480","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033","NAME NOT FOUND","Length: 524" "19:13:30,9258842","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a40b455c-253c-4311-ac6d-6e667edccefc","NAME NOT FOUND","Length: 524" "19:13:30,9259182","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:30,9259525","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:30,9260529","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:30,9262078","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108","NAME NOT FOUND","Length: 524" "19:13:30,9262437","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033","NAME NOT FOUND","Length: 524" "19:13:30,9262781","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:30,9263095","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:30,9263512","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9263582","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9263711","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\OLE\Tracing","REPARSE","Desired Access: Read" "19:13:30,9263817","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Ole\Tracing","NAME NOT FOUND","Desired Access: Read" "19:13:30,9264076","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be","NAME NOT FOUND","Length: 524" "19:13:30,9264387","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f0558438-f56a-5987-47da-040ca75aef05","NAME NOT FOUND","Length: 524" "19:13:30,9265385","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 593 920, EndOfFile: 593 536, FileAttributes: A" "19:13:30,9266222","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:30,9266549","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\oleaut32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:30,9266655","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 593 536, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:30,9266828","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:30,9267171","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","" "19:13:30,9269692","EasyAntiCheat.exe","2900","QueryNameInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe","SUCCESS","Name: \Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe" "19:13:30,9270048","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9270138","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9270250","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Services","REPARSE","Desired Access: Read" "19:13:30,9270347","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Desired Access: Read" "19:13:30,9270452","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Services","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9270545","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\System\CurrentControlSet\Services","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:30,9270616","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Services\EasyAntiCheat","SUCCESS","Desired Access: Read" "19:13:30,9270712","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Services\EasyAntiCheat\Alias","NAME NOT FOUND","Length: 144" "19:13:30,9270818","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Services\EasyAntiCheat","SUCCESS","" "19:13:30,9270885","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Services","SUCCESS","" "19:13:30,9271180","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9271241","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9271354","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Rpc","REPARSE","Desired Access: Read" "19:13:30,9271459","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","Desired Access: Read" "19:13:30,9271549","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9271620","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize","NAME NOT FOUND","Length: 144" "19:13:30,9271706","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","" "19:13:30,9271979","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","REPARSE","Desired Access: Read" "19:13:30,9272066","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","Desired Access: Read" "19:13:30,9272168","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9272223","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName","SUCCESS","Type: REG_SZ, Length: 18, Data: DEVLA-PC" "19:13:30,9272306","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","" "19:13:30,9272399","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:30,9272489","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9272547","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SYSTEM\Setup\OOBEInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:30,9272617","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:30,9272701","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:30,9272781","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9272861","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:30,9272944","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:30,9273044","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:30,9273114","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EasyAntiCheat.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:30,9273589","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9273650","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9273762","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows NT\Rpc","REPARSE","Desired Access: Read" "19:13:30,9273849","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Rpc","NAME NOT FOUND","Desired Access: Read" "19:13:30,9274195","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:30,9274253","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:30,9274356","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Rpc","REPARSE","Desired Access: Query Value" "19:13:30,9274439","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","Desired Access: Query Value" "19:13:30,9274519","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:30,9274612","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow","NAME NOT FOUND","Length: 144" "19:13:30,9274721","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","" "19:13:30,9278487","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 3816" "19:13:31,0403806","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0403912","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0404098","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","Desired Access: Read" "19:13:31,0404300","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0404627","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0404714","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}","SUCCESS","Desired Access: Read" "19:13:31,0404851","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions","SUCCESS","" "19:13:31,0404944","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2" "19:13:31,0405025","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name","SUCCESS","Type: REG_SZ, Length: 32, Data: ProgramFilesX86" "19:13:31,0405098","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder","NAME NOT FOUND","Length: 144" "19:13:31,0405163","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description","NAME NOT FOUND","Length: 144" "19:13:31,0405217","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath","NAME NOT FOUND","Length: 144" "19:13:31,0405272","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName","NAME NOT FOUND","Length: 144" "19:13:31,0405326","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip","NAME NOT FOUND","Length: 144" "19:13:31,0405381","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName","SUCCESS","Type: REG_EXPAND_SZ, Length: 84, Data: @%SystemRoot%\system32\shell32.dll,-21817" "19:13:31,0405454","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon","NAME NOT FOUND","Length: 144" "19:13:31,0405509","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security","NAME NOT FOUND","Length: 144" "19:13:31,0405563","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource","NAME NOT FOUND","Length: 144" "19:13:31,0405618","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType","NAME NOT FOUND","Length: 144" "19:13:31,0405669","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly","NAME NOT FOUND","Length: 144" "19:13:31,0405724","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable","NAME NOT FOUND","Length: 144" "19:13:31,0405778","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:31,0405836","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream","NAME NOT FOUND","Length: 144" "19:13:31,0405891","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath","NAME NOT FOUND","Length: 144" "19:13:31,0405945","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\DefinitionFlags","NAME NOT FOUND","Length: 144" "19:13:31,0406000","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:31,0406054","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID","NAME NOT FOUND","Length: 144" "19:13:31,0406109","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler","NAME NOT FOUND","Length: 144" "19:13:31,0406227","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0406298","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag","SUCCESS","Desired Access: Read" "19:13:31,0406497","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}","SUCCESS","" "19:13:31,0406670","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0406728","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0406846","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion","SUCCESS","Desired Access: Read" "19:13:31,0406955","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir","SUCCESS","Type: REG_SZ, Length: 46, Data: C:\Program Files (x86)" "19:13:31,0407042","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion","SUCCESS","" "19:13:31,0407360","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value" "19:13:31,0407475","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value" "19:13:31,0407587","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0407642","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16" "19:13:31,0409021","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)\EasyAntiCheat\PROPSYS.dll","NAME NOT FOUND","" "19:13:31,0409839","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\propsys.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:11, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:11, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 1 556 480, EndOfFile: 1 555 232, FileAttributes: A" "19:13:31,0410580","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\propsys.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0411003","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\propsys.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0411237","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\propsys.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0411664","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\propsys.dll","SUCCESS","Image Base: 0x72620000, Image Size: 0x17a000" "19:13:31,0412526","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","Image Base: 0x75890000, Image Size: 0x93000" "19:13:31,0413457","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\propsys.dll","SUCCESS","" "19:13:31,0415121","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:31,0416013","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\ole32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:13, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:42:13, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 003 520, EndOfFile: 1 003 152, FileAttributes: A" "19:13:31,0416539","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0416606","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0416728","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value" "19:13:31,0417539","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:31,0418065","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:31,0418835","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag\FoldersDependentOn","NAME NOT FOUND","Length: 144" "19:13:31,0419647","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:31,0420352","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)","SUCCESS","CreationTime: 2017. 09. 29. 15:46:33, LastAccessTime: 2021. 04. 13. 19:05:31, LastWriteTime: 2021. 04. 13. 19:05:31, ChangeTime: 2021. 04. 13. 19:05:31, AllocationSize: 8 192, EndOfFile: 8 192, FileAttributes: RDNCI" "19:13:31,0420532","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0420593","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0420724","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value" "19:13:31,0420846","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0420897","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0421006","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings","NAME NOT FOUND","Desired Access: Query Value" "19:13:31,0421786","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","Desired Access: Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0422033","EasyAntiCheat.exe","2900","SetBasicInformationFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","CreationTime: 1601. 01. 01. 2:00:00, LastAccessTime: 1601. 01. 01. 2:00:00, LastWriteTime: 1601. 01. 01. 2:00:00, ChangeTime: 1601. 01. 01. 2:00:00, FileAttributes: N" "19:13:31,0422161","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","" "19:13:31,0422886","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","Desired Access: Read Attributes, Delete, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0423072","EasyAntiCheat.exe","2900","QueryAttributeTagFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","Attributes: D, ReparseTag: 0x0" "19:13:31,0423194","EasyAntiCheat.exe","2900","SetDispositionInformationFile","C:\Program Files (x86)\EasyAntiCheat","NOT EMPTY","Delete: True" "19:13:31,0423345","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","" "19:13:31,0424050","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat","NAME COLLISION","Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Open Reparse Point, Attributes: N, ShareMode: Read, Write, AllocationSize: 0" "19:13:31,0424701","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0424907","EasyAntiCheat.exe","2900","SetBasicInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","CreationTime: 1601. 01. 01. 2:00:00, LastAccessTime: 1601. 01. 01. 2:00:00, LastWriteTime: 1601. 01. 01. 2:00:00, ChangeTime: 1601. 01. 01. 2:00:00, FileAttributes: N" "19:13:31,0425407","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:31,0426295","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0, OpenResult: Overwritten" "19:13:31,0432251","EasyAntiCheat.exe","2900","WriteFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Offset: 0, Length: 2 353 608, Priority: Normal" "19:13:31,0439791","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:31,0440850","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 732" "19:13:31,0442174","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\wintrust.dll","SUCCESS","Image Base: 0x74d90000, Image Size: 0x46000" "19:13:31,0442842","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Image Base: 0x73ff0000, Image Size: 0xe000" "19:13:31,0443518","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","Image Base: 0x74c00000, Image Size: 0x182000" "19:13:31,0446318","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:31,0447338","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\de5dcaee-6f88-585a-05ee-d8b05b912772","NAME NOT FOUND","Length: 524" "19:13:31,0447935","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0448021","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0448188","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\msasn1","NAME NOT FOUND","Desired Access: Read" "19:13:31,0449253","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0449493","EasyAntiCheat.exe","2900","QueryDirectory","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: EasyAntiCheat.sys, 2: EasyAntiCheat.sys" "19:13:31,0449728","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat","SUCCESS","" "19:13:31,0450087","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0450151","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0450286","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0450456","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0450533","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0450613","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 50, Data: WintrustCertificateTrust" "19:13:31,0450719","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0450805","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0450860","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0450975","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0451087","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0451161","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0451238","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 40, Data: SoftpubAuthenticode" "19:13:31,0451322","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0451402","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0451456","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0451569","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0451678","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0451739","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0451806","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 36, Data: SoftpubInitialize" "19:13:31,0451886","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0451963","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0452014","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0452123","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0452226","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0452281","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0452342","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 38, Data: SoftpubLoadMessage" "19:13:31,0452415","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0452492","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0452544","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0452649","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0452755","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0452810","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0452871","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 42, Data: SoftpubLoadSignature" "19:13:31,0452941","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0453018","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0453070","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0453175","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0453326","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0453470","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0453563","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 34, Data: SoftpubCheckCert" "19:13:31,0453666","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0453782","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0453849","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0454000","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","NAME NOT FOUND","Desired Access: Read" "19:13:31,0454166","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0454221","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0454340","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0454468","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0454526","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL","SUCCESS","Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0454593","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function","SUCCESS","Type: REG_SZ, Length: 30, Data: SoftpubCleanup" "19:13:31,0454680","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}","SUCCESS","" "19:13:31,0455677","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)\EasyAntiCheat\CRYPTSP.dll","NAME NOT FOUND","" "19:13:31,0456585","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 69 632, EndOfFile: 68 264, FileAttributes: A" "19:13:31,0457319","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0457646","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\cryptsp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0457858","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0458220","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Image Base: 0x71fe0000, Image Size: 0x13000" "19:13:31,0458740","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","" "19:13:31,0459305","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0459365","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0459487","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:31,0459654","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0459731","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 24" "19:13:31,0459805","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0459866","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0459940","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0459997","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0460873","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:11:35, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:35, AllocationSize: 188 416, EndOfFile: 184 984, FileAttributes: A" "19:13:31,0461572","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0461883","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\rsaenh.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0462072","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0462403","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Image Base: 0x70790000, Image Size: 0x2f000" "19:13:31,0463086","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","" "19:13:31,0463621","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)\EasyAntiCheat\bcrypt.dll","NAME NOT FOUND","" "19:13:31,0464330","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:17, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 16. 16:14:10, AllocationSize: 98 304, EndOfFile: 97 152, FileAttributes: A" "19:13:31,0465023","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0465321","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0465511","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0465831","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Image Base: 0x73050000, Image Size: 0x19000" "19:13:31,0466415","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","" "19:13:31,0467182","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f3a71a4b-6118-4257-8ccb-39a33ba059d4","NAME NOT FOUND","Length: 524" "19:13:31,0467996","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0468080","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Policies\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:31,0468198","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0468275","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems","NAME NOT FOUND","Length: 144" "19:13:31,0468352","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds","NAME NOT FOUND","Length: 144" "19:13:31,0468416","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds","NAME NOT FOUND","Length: 144" "19:13:31,0468503","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Cryptography","SUCCESS","" "19:13:31,0468644","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0468718","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:31,0468817","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0468881","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0468952","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0469023","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0469090","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0469221","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:31,0469311","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0469369","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0469484","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:31,0469872","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0469940","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0470052","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\DESHashSessionKeyBackward","NAME NOT FOUND","Desired Access: Read" "19:13:31,0470168","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","" "19:13:31,0470395","EasyAntiCheat.exe","2900","RegOpenKey","HKU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0470514","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0470572","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0470658","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0470742","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0470867","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0470921","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0471030","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0471207","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0471277","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0471338","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State","SUCCESS","Type: REG_DWORD, Length: 4, Data: 146432" "19:13:31,0471409","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing","SUCCESS","" "19:13:31,0471540","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0471595","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0471681","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0471755","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0471851","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0471903","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0471989","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Security","NAME NOT FOUND","Desired Access: Read" "19:13:31,0472095","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0472188","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0472243","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0472348","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,0472438","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0472647","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0472701","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0472788","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0472858","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0472955","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0473006","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0473089","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0473195","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0473263","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0473314","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0473417","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,0473506","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0473792","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0473849","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0473936","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32","REPARSE","Desired Access: Read" "19:13:31,0474029","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","Desired Access: Read" "19:13:31,0474125","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0474186","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Services\crypt32\DiagLevel","NAME NOT FOUND","Length: 144" "19:13:31,0474244","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Services\crypt32\DiagMatchAnyMask","NAME NOT FOUND","Length: 144" "19:13:31,0474311","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","" "19:13:31,0474382","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0474433","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0474517","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\crypt32","REPARSE","Desired Access: Read" "19:13:31,0474590","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","Desired Access: Read" "19:13:31,0474667","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0475296","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 3540" "19:13:31,0476146","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0476409","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0476524","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0476592","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0476710","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:31,0476880","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0476980","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0477147","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0477547","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0477608","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0477711","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0477820","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0477900","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0478013","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0478083","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0478247","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read" "19:13:31,0478330","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Read" "19:13:31,0478436","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0478490","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US","NAME NOT FOUND","Length: 532" "19:13:31,0478567","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","" "19:13:31,0478686","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read" "19:13:31,0478830","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","Desired Access: Read" "19:13:31,0478965","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0479032","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US","NAME NOT FOUND","Length: 532" "19:13:31,0479116","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","" "19:13:31,0479234","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\000602xx","SUCCESS","Type: REG_SZ, Length: 26, Data: kernel32.dll" "19:13:31,0480097","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0480344","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0480482","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","AllocationSize: 3 371 008, EndOfFile: 3 368 788, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,0480652","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0480870","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\Globalization\Sorting\SortDefault.nls","SUCCESS","" "19:13:31,0481255","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","REPARSE","Desired Access: Read" "19:13:31,0481348","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","Desired Access: Read" "19:13:31,0481467","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0481550","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en-US","NAME NOT FOUND","Length: 90" "19:13:31,0481656","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\en","NAME NOT FOUND","Length: 90" "19:13:31,0481874","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0481951","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Desired Access: Read" "19:13:31,0482095","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 0, Name: {000C10F1-0000-0000-C000-000000000046}" "19:13:31,0482211","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0482281","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Desired Access: Read" "19:13:31,0482397","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0482487","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\MSISIP.DLL" "19:13:31,0482551","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: MsiSIPPutSignedDataMsg" "19:13:31,0482730","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","" "19:13:31,0482798","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 1, Name: {06C9E010-38CE-11D4-A2A3-00104BD35090}" "19:13:31,0482900","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0482971","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:31,0483064","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0483128","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0483186","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: PutSignedDataMsg" "19:13:31,0483298","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:31,0483359","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 2, Name: {0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}" "19:13:31,0483458","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0483526","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Desired Access: Read" "19:13:31,0483619","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0483702","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0483805","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: AppxSipPutSignedDataMsg" "19:13:31,0483949","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","" "19:13:31,0484020","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 3, Name: {0F5F58B3-AADE-4B9A-A434-95742D92ECEB}" "19:13:31,0484154","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0484231","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Desired Access: Read" "19:13:31,0484331","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0484389","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0484453","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: AppxBundleSipPutSignedDataMsg" "19:13:31,0484565","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","" "19:13:31,0484629","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 4, Name: {1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}" "19:13:31,0484725","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0484793","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Desired Access: Read" "19:13:31,0484879","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0484950","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0485008","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: PutSignedDataMsg" "19:13:31,0485110","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","" "19:13:31,0485171","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 5, Name: {1A610570-38CE-11D4-A2A3-00104BD35090}" "19:13:31,0485271","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0485338","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:31,0485428","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0485489","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0485550","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: PutSignedDataMsg" "19:13:31,0485716","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:31,0485784","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 6, Name: {5598CFF1-68DB-4340-B57F-1CACF88C9A51}" "19:13:31,0485883","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0485951","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Desired Access: Read" "19:13:31,0486037","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0486101","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0486159","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: P7xSipPutSignedDataMsg" "19:13:31,0486262","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","" "19:13:31,0486323","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 7, Name: {603BCC1F-4B59-4E08-B724-D2C6297EF351}" "19:13:31,0486419","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0486486","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Desired Access: Read" "19:13:31,0486570","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0486634","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 112, Data: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll" "19:13:31,0486695","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 30, Data: PsPutSignature" "19:13:31,0486800","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","" "19:13:31,0486861","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 8, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:31,0486954","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0487051","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0487163","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0487237","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0487298","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:31,0487410","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:31,0487474","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 9, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:31,0487573","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0487644","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:31,0487740","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0487804","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:31,0487878","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EsdSipPutSignature" "19:13:31,0487994","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:31,0488058","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 10, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0488154","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0488224","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0488317","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0488382","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0488446","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:31,0488545","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0488606","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 11, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0488699","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0488767","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0488856","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0488920","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0488978","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:31,0489074","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0489132","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 12, Name: {CF78C6DE-64A2-4799-B506-89ADFF5D16D6}" "19:13:31,0489225","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0489315","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Desired Access: Read" "19:13:31,0489411","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0489475","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0489536","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EappxSipPutSignedDataMsg" "19:13:31,0489642","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","" "19:13:31,0489706","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 13, Name: {D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}" "19:13:31,0489806","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0489876","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Desired Access: Read" "19:13:31,0489969","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0490030","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0490088","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 62, Data: EappxBundleSipPutSignedDataMsg" "19:13:31,0490191","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","" "19:13:31,0490284","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 14, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0490383","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0490450","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0490537","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0490601","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0490659","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:31,0490755","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0490813","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Index: 15, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0490906","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0490973","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0491056","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0491121","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0491178","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPPutSignedDataMsg" "19:13:31,0491271","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0491332","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","NO MORE ENTRIES","Index: 16, Length: 288" "19:13:31,0491403","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg","SUCCESS","" "19:13:31,0491461","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0491525","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0491615","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0491685","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0491804","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0491871","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllPutSignedDataMsg","NAME NOT FOUND","Desired Access: Read" "19:13:31,0491955","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0492015","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0492086","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0492519","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 4728" "19:13:31,0492651","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0492711","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0492827","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0492926","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0493000","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0493096","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0493164","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0493276","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0493343","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Desired Access: Read" "19:13:31,0493440","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 0, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:31,0493542","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0493654","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0493760","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0493828","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:31,0493933","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:31,0494087","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:31,0494152","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 1, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:31,0494248","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0494318","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:31,0494408","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0494472","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:31,0494530","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 28, Data: EsdSipGetCaps" "19:13:31,0494629","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:31,0494690","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 2, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0494783","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0494854","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0494947","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0495008","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:31,0495069","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:31,0495162","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0495223","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 3, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0495325","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0495396","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0495486","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0495547","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:31,0495604","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:31,0495701","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0495762","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 4, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0495858","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0495928","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0496015","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0496079","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:31,0496146","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:31,0496243","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0496307","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Index: 5, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0496403","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0496480","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0496563","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0496624","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\WINTRUST.DLL" "19:13:31,0496682","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 32, Data: CryptSIPGetCaps" "19:13:31,0496778","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0496839","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","NO MORE ENTRIES","Index: 6, Length: 288" "19:13:31,0496910","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetCaps","SUCCESS","" "19:13:31,0496968","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0497025","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0497157","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0497224","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0497343","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0497407","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetCaps","NAME NOT FOUND","Desired Access: Read" "19:13:31,0497487","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0497548","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0497619","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0497849","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0497910","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0498023","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0498116","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0498180","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0498282","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0498350","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0498462","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0498526","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Desired Access: Read" "19:13:31,0498619","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 0, Name: {000C10F1-0000-0000-C000-000000000046}" "19:13:31,0498712","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0498780","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Desired Access: Read" "19:13:31,0498866","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0498934","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\MSISIP.DLL" "19:13:31,0498994","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: MsiSIPGetSignedDataMsg" "19:13:31,0499110","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","" "19:13:31,0499174","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 1, Name: {06C9E010-38CE-11D4-A2A3-00104BD35090}" "19:13:31,0499280","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0499379","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:31,0499476","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0499540","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0499601","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: GetSignedDataMsg" "19:13:31,0499707","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:31,0499767","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 2, Name: {0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}" "19:13:31,0499864","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0499941","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Desired Access: Read" "19:13:31,0500024","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0500085","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0500146","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: AppxSipGetSignedDataMsg" "19:13:31,0500245","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","" "19:13:31,0500309","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 3, Name: {0F5F58B3-AADE-4B9A-A434-95742D92ECEB}" "19:13:31,0500402","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0500470","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Desired Access: Read" "19:13:31,0500556","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0500617","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0500678","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: AppxBundleSipGetSignedDataMsg" "19:13:31,0500781","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","" "19:13:31,0500874","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 4, Name: {1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}" "19:13:31,0500983","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0501050","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Desired Access: Read" "19:13:31,0501137","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0501201","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0501262","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: GetSignedDataMsg" "19:13:31,0501368","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","" "19:13:31,0501429","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 5, Name: {1A610570-38CE-11D4-A2A3-00104BD35090}" "19:13:31,0501522","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0501589","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:31,0501673","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0501734","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0501791","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: GetSignedDataMsg" "19:13:31,0501891","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:31,0501952","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 6, Name: {5598CFF1-68DB-4340-B57F-1CACF88C9A51}" "19:13:31,0502048","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0502115","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Desired Access: Read" "19:13:31,0502202","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0502272","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0502330","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: P7xSipGetSignedDataMsg" "19:13:31,0502433","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","" "19:13:31,0502490","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 7, Name: {603BCC1F-4B59-4E08-B724-D2C6297EF351}" "19:13:31,0502587","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0502651","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Desired Access: Read" "19:13:31,0502766","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0502840","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 112, Data: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll" "19:13:31,0502901","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 30, Data: PsGetSignature" "19:13:31,0503020","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","" "19:13:31,0503081","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 8, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:31,0503177","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0503247","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0503337","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0503401","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0503462","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:31,0503562","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:31,0503623","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 9, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:31,0503716","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0503783","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:31,0503870","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0503927","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:31,0503985","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EsdSipGetSignature" "19:13:31,0504078","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:31,0504139","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 10, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0504232","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0504296","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0504383","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0504447","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0504505","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:31,0504601","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0504662","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 11, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0504758","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0504829","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0504915","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0504986","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0505043","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:31,0505140","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0505201","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 12, Name: {CF78C6DE-64A2-4799-B506-89ADFF5D16D6}" "19:13:31,0505294","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0505364","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Desired Access: Read" "19:13:31,0505444","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0505505","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0505563","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EappxSipGetSignedDataMsg" "19:13:31,0505662","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","" "19:13:31,0505720","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 13, Name: {D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}" "19:13:31,0505813","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0505881","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Desired Access: Read" "19:13:31,0505967","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0506025","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0506083","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 62, Data: EappxBundleSipGetSignedDataMsg" "19:13:31,0506182","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","" "19:13:31,0506243","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 14, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0506333","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0506400","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0506490","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0506554","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0506612","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:31,0506766","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0506823","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Index: 15, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0506920","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0506987","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0507074","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0507151","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0507212","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: CryptSIPGetSignedDataMsg" "19:13:31,0507308","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0507365","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","NO MORE ENTRIES","Index: 16, Length: 288" "19:13:31,0507436","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg","SUCCESS","" "19:13:31,0507500","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0507558","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0507712","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0507789","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0507940","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0508020","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetSignedDataMsg","NAME NOT FOUND","Desired Access: Read" "19:13:31,0508113","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0508177","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0508247","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0508709","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\imagehlp.dll","SUCCESS","Image Base: 0x74010000, Image Size: 0x19000" "19:13:31,0510178","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0510307","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0510406","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0510573","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0510990","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0511185","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0511282","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0511365","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0511516","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0511782","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0511846","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0511978","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:31,0520730","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0520785","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0520887","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:31,0521423","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0521481","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0521596","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:31,0521718","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0521801","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 24" "19:13:31,0521875","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0521933","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0521997","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0522058","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:31,0522327","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0522401","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:31,0522488","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0522552","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0522616","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0522696","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0522828","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:31,0522950","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:31,0523049","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0523104","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0523219","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:31,0523472","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0523533","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0523671","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\DESHashSessionKeyBackward","NAME NOT FOUND","Desired Access: Read" "19:13:31,0523783","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider","SUCCESS","" "19:13:31,0524293","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0524351","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0524454","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0524556","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0524694","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0524768","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0524893","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0524967","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Desired Access: Read" "19:13:31,0525066","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Index: 0, Name: 1.3.6.1.4.1.311.64.1.1!7" "19:13:31,0525172","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0525240","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Desired Access: Read" "19:13:31,0525326","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Query: Cached, SubKeys: 0, Values: 1" "19:13:31,0525400","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Index: 0, Name: Name, Type: REG_SZ, Length: 78, Data: @%SystemRoot%\system32\dnsapi.dll,-103" "19:13:31,0525522","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0525580","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0525695","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","Desired Access: Read" "19:13:31,0525798","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0525865","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name","SUCCESS","Type: REG_SZ, Length: 78, Data: @%SystemRoot%\system32\dnsapi.dll,-103" "19:13:31,0526035","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:31,0526125","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:31,0526224","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0526279","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:31,0526365","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:31,0526506","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0526583","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0526699","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0526757","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0526846","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:31,0526991","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0527058","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0527135","EasyAntiCheat.exe","2900","RegSetValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:31,0528024","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:09:43, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 598 016, EndOfFile: 597 160, FileAttributes: A" "19:13:31,0528181","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\dnsapi.dll,-103","SUCCESS","Type: REG_SZ, Length: 76, Data: Domain Name System (DNS) Server Trust" "19:13:31,0528270","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:31,0528347","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name","SUCCESS","Type: REG_SZ, Length: 78, Data: @%SystemRoot%\system32\dnsapi.dll,-103" "19:13:31,0528495","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:31,0528582","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:31,0528668","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0528723","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:31,0528793","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:31,0528915","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0528986","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0529098","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0529169","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0529262","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:31,0529351","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0529412","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0529476","EasyAntiCheat.exe","2900","RegSetValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:31,0530198","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:09:43, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 598 016, EndOfFile: 597 160, FileAttributes: A" "19:13:31,0530336","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\dnsapi.dll,-103","SUCCESS","Type: REG_SZ, Length: 76, Data: Domain Name System (DNS) Server Trust" "19:13:31,0530426","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:31,0530519","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","" "19:13:31,0530602","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7","SUCCESS","" "19:13:31,0530670","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Index: 1, Name: 1.3.6.1.4.1.311.80.1!7" "19:13:31,0530779","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0530852","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Desired Access: Read" "19:13:31,0530945","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Query: Cached, SubKeys: 0, Values: 1" "19:13:31,0531016","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Index: 0, Name: Name, Type: REG_SZ, Length: 132, Data: @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124" "19:13:31,0531141","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0531199","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0531314","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","Desired Access: Read" "19:13:31,0531417","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0531484","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7\Name","SUCCESS","Type: REG_SZ, Length: 132, Data: @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124" "19:13:31,0531619","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:31,0531702","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:31,0531786","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0531840","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:31,0531911","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:31,0532033","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0532106","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0532212","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0532270","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0532357","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:31,0532440","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0532501","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0532565","EasyAntiCheat.exe","2900","RegSetValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:31,0533290","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:43:19, LastAccessTime: 2021. 02. 13. 20:09:40, LastWriteTime: 2017. 09. 29. 15:43:19, ChangeTime: 2020. 01. 12. 12:29:30, AllocationSize: 434 176, EndOfFile: 431 616, FileAttributes: A" "19:13:31,0533437","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124","SUCCESS","Type: REG_SZ, Length: 40, Data: Document Encryption" "19:13:31,0533534","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:31,0533604","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7\Name","SUCCESS","Type: REG_SZ, Length: 132, Data: @%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124" "19:13:31,0533748","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings","REPARSE","Desired Access: Query Value" "19:13:31,0533832","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","Desired Access: Query Value" "19:13:31,0533918","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0533970","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1215" "19:13:31,0534037","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings","SUCCESS","" "19:13:31,0534159","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0534230","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0534342","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0534396","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0534483","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","Desired Access: Read/Write" "19:13:31,0534566","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0534627","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0534691","EasyAntiCheat.exe","2900","RegSetValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\LanguageList","SUCCESS","Type: REG_MULTI_SZ, Length: 20, Data: en-US, en" "19:13:31,0535375","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:43:19, LastAccessTime: 2021. 02. 13. 20:09:40, LastWriteTime: 2017. 09. 29. 15:43:19, ChangeTime: 2020. 01. 12. 12:29:30, AllocationSize: 434 176, EndOfFile: 431 616, FileAttributes: A" "19:13:31,0535509","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124","SUCCESS","Type: REG_SZ, Length: 40, Data: Document Encryption" "19:13:31,0535596","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Classes\Local Settings\MuiCache\4bf\52C64B7E","SUCCESS","" "19:13:31,0535670","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","" "19:13:31,0535759","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.80.1!7","SUCCESS","" "19:13:31,0535827","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0535904","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo","SUCCESS","" "19:13:31,0535962","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0536019","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0536103","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0536173","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Cryptography\ECCParameters","REPARSE","Desired Access: Read" "19:13:31,0536260","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","SUCCESS","Desired Access: Read" "19:13:31,0536356","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0536411","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","NO MORE ENTRIES","Index: 0, Length: 288" "19:13:31,0536484","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\ECCParameters","SUCCESS","" "19:13:31,0538640","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\CMF\Config","REPARSE","Desired Access: Read" "19:13:31,0538726","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","Desired Access: Read" "19:13:31,0538829","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0538887","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CMF\Config\SYSTEM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:31,0538964","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","" "19:13:31,0539666","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0539906","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0540015","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","SUCCESS","AllocationSize: 40 960, EndOfFile: 40 448, NumberOfLinks: 4, DeletePending: False, Directory: False" "19:13:31,0540185","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\System32\en-US\crypt32.dll.mui","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0542803","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:31,0542928","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:31,0543066","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:31,0543159","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:31,0543255","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:31,0543370","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:31,0544544","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0544608","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0544727","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0544830","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0544900","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0545016","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0545086","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0545208","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0545272","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Desired Access: Read" "19:13:31,0545365","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Index: 0, Name: #16" "19:13:31,0545458","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0545526","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Desired Access: Read" "19:13:31,0545615","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0545689","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll" "19:13:31,0545753","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore" "19:13:31,0545878","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16","SUCCESS","" "19:13:31,0545939","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Index: 1, Name: Ldap" "19:13:31,0546032","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0546100","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Desired Access: Read" "19:13:31,0546183","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0546247","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\cryptnet.dll" "19:13:31,0546308","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: LdapProvOpenStore" "19:13:31,0546408","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap","SUCCESS","" "19:13:31,0546465","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0546536","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv","SUCCESS","" "19:13:31,0546594","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0546655","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0546744","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0546815","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0546937","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0547001","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv","NAME NOT FOUND","Desired Access: Read" "19:13:31,0547084","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0547145","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0547219","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0547334","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0547392","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0547495","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0547588","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0547652","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0547742","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0547809","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0547915","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0547976","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx","NAME NOT FOUND","Desired Access: Read" "19:13:31,0548063","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0548123","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0548210","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0548274","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0548377","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0548441","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Desired Access: Read" "19:13:31,0548531","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 0, Name: 1.2.840.113549.1.9.16.1.1" "19:13:31,0548627","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0548691","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Desired Access: Read" "19:13:31,0548775","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0548842","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0548906","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: EssReceiptDecodeEx" "19:13:31,0549015","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1","SUCCESS","" "19:13:31,0549073","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 1, Name: 1.2.840.113549.1.9.16.2.1" "19:13:31,0549166","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0549233","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Desired Access: Read" "19:13:31,0549317","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0549381","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0549438","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: EssReceiptRequestDecodeEx" "19:13:31,0549535","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1","SUCCESS","" "19:13:31,0549596","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 2, Name: 1.2.840.113549.1.9.16.2.11" "19:13:31,0549685","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0549753","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Desired Access: Read" "19:13:31,0549836","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0549900","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0549971","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: EssKeyExchPreferenceDecodeEx" "19:13:31,0550064","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11","SUCCESS","" "19:13:31,0550125","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 3, Name: 1.2.840.113549.1.9.16.2.12" "19:13:31,0550215","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0550279","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Desired Access: Read" "19:13:31,0550362","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0550426","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0550484","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: EssSignCertificateDecodeEx" "19:13:31,0550577","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12","SUCCESS","" "19:13:31,0550638","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 4, Name: 1.2.840.113549.1.9.16.2.2" "19:13:31,0550728","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0550792","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Desired Access: Read" "19:13:31,0550875","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0550939","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0550997","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: EssSecurityLabelDecodeEx" "19:13:31,0551090","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2","SUCCESS","" "19:13:31,0551148","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 5, Name: 1.2.840.113549.1.9.16.2.3" "19:13:31,0551238","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0551305","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Desired Access: Read" "19:13:31,0551388","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0551453","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0551510","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: EssMLHistoryDecodeEx" "19:13:31,0551603","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3","SUCCESS","" "19:13:31,0551664","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Index: 6, Name: 1.2.840.113549.1.9.16.2.4" "19:13:31,0551754","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0551818","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Desired Access: Read" "19:13:31,0551905","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0551969","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 66, Data: C:\Windows\SysWOW64\inetcomm.dll" "19:13:31,0552024","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 46, Data: EssContentHintDecodeEx" "19:13:31,0552117","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4","SUCCESS","" "19:13:31,0552177","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","NO MORE ENTRIES","Index: 7, Length: 288" "19:13:31,0552245","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx","SUCCESS","" "19:13:31,0552303","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0552360","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0552428","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0553063","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0553120","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0553226","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0553322","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0553387","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0553483","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0553547","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0553656","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0553720","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObject","NAME NOT FOUND","Desired Access: Read" "19:13:31,0553807","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0553864","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0553951","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0554015","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0554118","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0554182","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Desired Access: Read" "19:13:31,0554265","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 0, Name: #2000" "19:13:31,0554355","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0554419","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Desired Access: Read" "19:13:31,0554500","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0554567","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0554628","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: WVTAsn1SpcSpAgencyInfoDecode" "19:13:31,0554730","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000","SUCCESS","" "19:13:31,0554791","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 1, Name: #2001" "19:13:31,0554881","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0554958","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Desired Access: Read" "19:13:31,0555042","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0555109","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0555167","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcMinimalCriteriaInfoDecode" "19:13:31,0555266","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001","SUCCESS","" "19:13:31,0555327","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 2, Name: #2002" "19:13:31,0555417","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0555484","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Desired Access: Read" "19:13:31,0555564","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0555628","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0555689","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 76, Data: WVTAsn1SpcFinancialCriteriaInfoDecode" "19:13:31,0555798","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002","SUCCESS","" "19:13:31,0555872","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 3, Name: #2003" "19:13:31,0555962","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0556029","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Desired Access: Read" "19:13:31,0556116","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0556180","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0556238","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcIndirectDataContentDecode" "19:13:31,0556334","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003","SUCCESS","" "19:13:31,0556392","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 4, Name: #2004" "19:13:31,0556482","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0556546","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Desired Access: Read" "19:13:31,0556629","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0556693","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0556754","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1SpcPeImageDataDecode" "19:13:31,0556847","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004","SUCCESS","" "19:13:31,0556908","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 5, Name: #2005" "19:13:31,0556995","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0557062","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Desired Access: Read" "19:13:31,0557142","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0557203","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0557261","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:31,0557354","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005","SUCCESS","" "19:13:31,0557412","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 6, Name: #2006" "19:13:31,0557498","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0557566","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Desired Access: Read" "19:13:31,0557649","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0557713","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0557771","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: WVTAsn1SpcStatementTypeDecode" "19:13:31,0557867","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006","SUCCESS","" "19:13:31,0557925","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 7, Name: #2007" "19:13:31,0558011","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0558079","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Desired Access: Read" "19:13:31,0558159","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0558223","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0558281","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1SpcSpOpusInfoDecode" "19:13:31,0558377","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007","SUCCESS","" "19:13:31,0558435","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 8, Name: #2008" "19:13:31,0558521","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0558589","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Desired Access: Read" "19:13:31,0558669","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0558730","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0558788","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:31,0558877","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008","SUCCESS","" "19:13:31,0558938","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 9, Name: #2009" "19:13:31,0559025","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0559092","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Desired Access: Read" "19:13:31,0559176","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0559233","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0559291","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:31,0559381","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009","SUCCESS","" "19:13:31,0559442","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 10, Name: #2010" "19:13:31,0559529","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0559593","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Desired Access: Read" "19:13:31,0559673","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0559737","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0559795","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 70, Data: WVTAsn1IntentToSealAttributeDecode" "19:13:31,0559894","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2010","SUCCESS","" "19:13:31,0559958","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 11, Name: #2011" "19:13:31,0560048","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0560115","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Desired Access: Read" "19:13:31,0560199","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0560263","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0560324","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingSignatureAttributeDecode" "19:13:31,0560420","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2011","SUCCESS","" "19:13:31,0560478","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 12, Name: #2012" "19:13:31,0560564","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0560632","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Desired Access: Read" "19:13:31,0560712","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0560776","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0560834","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingTimestampAttributeDecode" "19:13:31,0560930","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2012","SUCCESS","" "19:13:31,0560988","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 13, Name: #2130" "19:13:31,0561074","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0561139","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Desired Access: Read" "19:13:31,0561222","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0561286","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0561344","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: WVTAsn1SpcSigInfoDecode" "19:13:31,0561437","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130","SUCCESS","" "19:13:31,0561498","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 14, Name: #2221" "19:13:31,0561584","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0561649","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Desired Access: Read" "19:13:31,0561732","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0561796","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0561854","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: WVTAsn1CatNameValueDecode" "19:13:31,0561950","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221","SUCCESS","" "19:13:31,0562008","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 15, Name: #2222" "19:13:31,0562094","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0562162","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Desired Access: Read" "19:13:31,0562242","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0562309","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0562367","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1CatMemberInfoDecode" "19:13:31,0562463","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222","SUCCESS","" "19:13:31,0562521","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 16, Name: #2223" "19:13:31,0562611","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0562678","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Desired Access: Read" "19:13:31,0562758","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0562822","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0562880","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1CatMemberInfo2Decode" "19:13:31,0562976","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2223","SUCCESS","" "19:13:31,0563034","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 17, Name: 1.3.6.1.4.1.311.12.2.1" "19:13:31,0563156","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0563227","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Desired Access: Read" "19:13:31,0563310","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0563374","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0563432","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: WVTAsn1CatNameValueDecode" "19:13:31,0563538","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1","SUCCESS","" "19:13:31,0563599","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 18, Name: 1.3.6.1.4.1.311.12.2.2" "19:13:31,0563692","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0563769","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Desired Access: Read" "19:13:31,0563852","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0563919","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0563977","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1CatMemberInfoDecode" "19:13:31,0564076","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2","SUCCESS","" "19:13:31,0564134","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 19, Name: 1.3.6.1.4.1.311.12.2.3" "19:13:31,0564224","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0564291","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Desired Access: Read" "19:13:31,0564375","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0564439","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0564497","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1CatMemberInfo2Decode" "19:13:31,0564593","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.3","SUCCESS","" "19:13:31,0564654","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 20, Name: 1.3.6.1.4.1.311.16.1.1" "19:13:31,0564740","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0564808","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Desired Access: Read" "19:13:31,0564891","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0564958","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: cryptdlg.dll" "19:13:31,0565016","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: DecodeAttrSequence" "19:13:31,0565119","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1","SUCCESS","" "19:13:31,0565177","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 21, Name: 1.3.6.1.4.1.311.16.4" "19:13:31,0565266","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0565334","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Desired Access: Read" "19:13:31,0565420","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0565484","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: cryptdlg.dll" "19:13:31,0565542","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 36, Data: DecodeRecipientID" "19:13:31,0565635","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4","SUCCESS","" "19:13:31,0565693","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 22, Name: 1.3.6.1.4.1.311.2.1.10" "19:13:31,0565783","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0565850","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Desired Access: Read" "19:13:31,0565930","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0565994","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0566052","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 58, Data: WVTAsn1SpcSpAgencyInfoDecode" "19:13:31,0566152","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10","SUCCESS","" "19:13:31,0566209","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 23, Name: 1.3.6.1.4.1.311.2.1.11" "19:13:31,0566299","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0566363","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Desired Access: Read" "19:13:31,0566450","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0566511","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0566572","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 60, Data: WVTAsn1SpcStatementTypeDecode" "19:13:31,0566668","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11","SUCCESS","" "19:13:31,0566726","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 24, Name: 1.3.6.1.4.1.311.2.1.12" "19:13:31,0566815","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0566883","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Desired Access: Read" "19:13:31,0566966","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0567030","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0567088","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: WVTAsn1SpcSpOpusInfoDecode" "19:13:31,0567184","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12","SUCCESS","" "19:13:31,0567242","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 25, Name: 1.3.6.1.4.1.311.2.1.15" "19:13:31,0567332","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0567399","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Desired Access: Read" "19:13:31,0567483","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0567547","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0567604","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 56, Data: WVTAsn1SpcPeImageDataDecode" "19:13:31,0567701","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15","SUCCESS","" "19:13:31,0567758","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 26, Name: 1.3.6.1.4.1.311.2.1.20" "19:13:31,0567848","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0567912","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Desired Access: Read" "19:13:31,0567996","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0568057","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0568114","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:31,0568207","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20","SUCCESS","" "19:13:31,0568265","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 27, Name: 1.3.6.1.4.1.311.2.1.25" "19:13:31,0568355","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0568419","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Desired Access: Read" "19:13:31,0568499","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0568560","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0568618","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:31,0568711","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25","SUCCESS","" "19:13:31,0568769","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 28, Name: 1.3.6.1.4.1.311.2.1.26" "19:13:31,0568858","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0568923","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Desired Access: Read" "19:13:31,0569006","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0569070","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0569128","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcMinimalCriteriaInfoDecode" "19:13:31,0569227","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26","SUCCESS","" "19:13:31,0569285","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 29, Name: 1.3.6.1.4.1.311.2.1.27" "19:13:31,0569372","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0569439","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Desired Access: Read" "19:13:31,0569522","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0569587","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0569644","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 76, Data: WVTAsn1SpcFinancialCriteriaInfoDecode" "19:13:31,0569740","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27","SUCCESS","" "19:13:31,0569798","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 30, Name: 1.3.6.1.4.1.311.2.1.28" "19:13:31,0569885","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0569962","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Desired Access: Read" "19:13:31,0570045","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0570103","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0570161","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 42, Data: WVTAsn1SpcLinkDecode" "19:13:31,0570254","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28","SUCCESS","" "19:13:31,0570311","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 31, Name: 1.3.6.1.4.1.311.2.1.30" "19:13:31,0570401","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0570469","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Desired Access: Read" "19:13:31,0570549","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0570613","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0570671","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 48, Data: WVTAsn1SpcSigInfoDecode" "19:13:31,0570767","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30","SUCCESS","" "19:13:31,0570825","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 32, Name: 1.3.6.1.4.1.311.2.1.4" "19:13:31,0570918","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0570985","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Desired Access: Read" "19:13:31,0571065","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0571129","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0571187","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 72, Data: WVTAsn1SpcIndirectDataContentDecode" "19:13:31,0571286","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4","SUCCESS","" "19:13:31,0571354","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 33, Name: 1.3.6.1.4.1.311.2.4.2" "19:13:31,0571447","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0571511","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Desired Access: Read" "19:13:31,0571594","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0571658","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0571716","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 70, Data: WVTAsn1IntentToSealAttributeDecode" "19:13:31,0571816","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.2","SUCCESS","" "19:13:31,0571873","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 34, Name: 1.3.6.1.4.1.311.2.4.3" "19:13:31,0571960","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0572027","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Desired Access: Read" "19:13:31,0572111","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0572175","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0572236","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingSignatureAttributeDecode" "19:13:31,0572332","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.3","SUCCESS","" "19:13:31,0572390","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Index: 35, Name: 1.3.6.1.4.1.311.2.4.4" "19:13:31,0572480","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0572544","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Desired Access: Read" "19:13:31,0572627","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0572691","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0572749","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 78, Data: WVTAsn1SealingTimestampAttributeDecode" "19:13:31,0572858","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.4.4","SUCCESS","" "19:13:31,0572919","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","NO MORE ENTRIES","Index: 36, Length: 288" "19:13:31,0572989","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject","SUCCESS","" "19:13:31,0573047","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0573102","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0573169","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0573329","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0573384","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0573493","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0573586","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0573650","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0573743","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0573811","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0573916","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0573981","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Desired Access: Read" "19:13:31,0574070","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 0, Name: {000C10F1-0000-0000-C000-000000000046}" "19:13:31,0574163","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0574227","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Desired Access: Read" "19:13:31,0574314","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0574378","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\MSISIP.DLL" "19:13:31,0574442","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: MsiSIPVerifyIndirectData" "19:13:31,0574555","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}","SUCCESS","" "19:13:31,0574616","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 1, Name: {06C9E010-38CE-11D4-A2A3-00104BD35090}" "19:13:31,0574709","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0574773","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:31,0574856","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0574920","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0574988","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: VerifyIndirectData" "19:13:31,0575097","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:31,0575154","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 2, Name: {0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}" "19:13:31,0575247","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0575315","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Desired Access: Read" "19:13:31,0575398","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0575462","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0575523","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 52, Data: AppxSipVerifyIndirectData" "19:13:31,0575626","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}","SUCCESS","" "19:13:31,0575684","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 3, Name: {0F5F58B3-AADE-4B9A-A434-95742D92ECEB}" "19:13:31,0575773","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0575841","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Desired Access: Read" "19:13:31,0575924","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0575988","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0576046","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 64, Data: AppxBundleSipVerifyIndirectData" "19:13:31,0576149","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}","SUCCESS","" "19:13:31,0576210","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 4, Name: {1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}" "19:13:31,0576299","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0576367","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Desired Access: Read" "19:13:31,0576447","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0576511","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0576569","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: VerifyIndirectData" "19:13:31,0576675","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}","SUCCESS","" "19:13:31,0576732","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 5, Name: {1A610570-38CE-11D4-A2A3-00104BD35090}" "19:13:31,0576822","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0576889","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Desired Access: Read" "19:13:31,0576970","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0577034","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\wshext.dll" "19:13:31,0577095","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 38, Data: VerifyIndirectData" "19:13:31,0577197","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}","SUCCESS","" "19:13:31,0577258","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 6, Name: {5598CFF1-68DB-4340-B57F-1CACF88C9A51}" "19:13:31,0577348","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0577415","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Desired Access: Read" "19:13:31,0577499","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0577563","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0577624","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 50, Data: P7xSipVerifyIndirectData" "19:13:31,0577727","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}","SUCCESS","" "19:13:31,0577784","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 7, Name: {603BCC1F-4B59-4E08-B724-D2C6297EF351}" "19:13:31,0577874","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0577938","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Desired Access: Read" "19:13:31,0578022","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0578086","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 112, Data: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshsip.dll" "19:13:31,0578147","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 26, Data: PsVerifyHash" "19:13:31,0578253","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}","SUCCESS","" "19:13:31,0578310","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 8, Name: {9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}" "19:13:31,0578400","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0578467","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0578548","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0578612","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0578673","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:31,0578769","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}","SUCCESS","" "19:13:31,0578827","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 9, Name: {9F3053C5-439D-4BF7-8A77-04F0450A1D9F}" "19:13:31,0578916","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0578984","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Desired Access: Read" "19:13:31,0579067","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0579138","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 62, Data: C:\Windows\SysWOW64\EsdSip.dll" "19:13:31,0579199","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 34, Data: EsdSipVerifyHash" "19:13:31,0579298","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}","SUCCESS","" "19:13:31,0579356","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 10, Name: {C689AAB8-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0579449","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0579516","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0579596","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0579664","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0579722","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:31,0579818","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0579875","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 11, Name: {C689AABA-8E78-11D0-8C47-00C04FC295EE}" "19:13:31,0579975","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0580042","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0580126","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0580190","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0580248","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:31,0580344","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0580405","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 12, Name: {CF78C6DE-64A2-4799-B506-89ADFF5D16D6}" "19:13:31,0580494","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0580562","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Desired Access: Read" "19:13:31,0580645","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0580706","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0580767","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: EappxSipVerifyIndirectData" "19:13:31,0580870","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}","SUCCESS","" "19:13:31,0580927","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 13, Name: {D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}" "19:13:31,0581017","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0581085","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Desired Access: Read" "19:13:31,0581165","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0581229","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 64, Data: C:\Windows\SysWOW64\AppxSip.dll" "19:13:31,0581287","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 66, Data: EappxBundleSipVerifyIndirectData" "19:13:31,0581389","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}","SUCCESS","" "19:13:31,0581447","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 14, Name: {DE351A42-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0581540","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0581607","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0581694","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0581755","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0581816","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:31,0581912","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0581970","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Index: 15, Name: {DE351A43-8E59-11D0-8C47-00C04FC295EE}" "19:13:31,0582063","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0582127","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Desired Access: Read" "19:13:31,0582214","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Query: Cached, SubKeys: 0, Values: 2" "19:13:31,0582278","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 0, Name: Dll, Type: REG_SZ, Length: 26, Data: WINTRUST.DLL" "19:13:31,0582335","EasyAntiCheat.exe","2900","RegEnumValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","Index: 1, Name: FuncName, Type: REG_SZ, Length: 54, Data: CryptSIPVerifyIndirectData" "19:13:31,0582432","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}","SUCCESS","" "19:13:31,0582489","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","NO MORE ENTRIES","Index: 16, Length: 288" "19:13:31,0582560","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData","SUCCESS","" "19:13:31,0582618","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0582672","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0582762","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0582829","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0582935","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0582999","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllVerifyIndirectData","NAME NOT FOUND","Desired Access: Read" "19:13:31,0583083","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0583140","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0583208","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0583561","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0583618","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0583731","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:31,0583875","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0583971","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0584022","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0584122","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Wintrust\Config","NAME NOT FOUND","Desired Access: Read" "19:13:31,0584260","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0584362","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,0584523","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0585751","EasyAntiCheat.exe","2900","ReadFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Offset: 0, Length: 524 288, Priority: Normal" "19:13:31,0722958","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0723064","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0723218","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0723282","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0723375","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\International","SUCCESS","Desired Access: Read" "19:13:31,0723478","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Control Panel\International","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0723555","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0723815","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Control Panel\International","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0723885","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍","SUCCESS","Desired Access: Query Value" "19:13:31,0724007","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍\Currencies","NAME NOT FOUND","Length: 182" "19:13:31,0724071","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍\NLS Currency Data","NAME NOT FOUND","Length: 182" "19:13:31,0724123","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍\Clock","NAME NOT FOUND","Length: 182" "19:13:31,0724196","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0724260","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍\Gregorian","NAME NOT FOUND","Desired Access: Query Value" "19:13:31,0724334","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Control Panel\International\🌎🌏🌍","SUCCESS","" "19:13:31,0724491","EasyAntiCheat.exe","2900","RegQueryMultipleValueKey","HKU\.DEFAULT\Control Panel\International","SUCCESS","" "19:13:31,0724838","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Control Panel\International\sCurrencyOverride","NAME NOT FOUND","Length: 182" "19:13:31,0724992","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","REPARSE","Desired Access: Read" "19:13:31,0725088","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","Desired Access: Read" "19:13:31,0725194","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0725251","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\hu-HU","NAME NOT FOUND","Length: 532" "19:13:31,0725316","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","" "19:13:31,0725409","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","REPARSE","Desired Access: Read" "19:13:31,0725482","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","Desired Access: Read" "19:13:31,0725569","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0725652","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\hu-HU","NAME NOT FOUND","Length: 532" "19:13:31,0725713","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale","SUCCESS","" "19:13:31,0726028","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\hu-HU","NAME NOT FOUND","Length: 90" "19:13:31,0726130","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids\hu","SUCCESS","Type: REG_SZ, Length: 78, Data: {00000004-57EE-1E5C-00B4-D0000BB1E11E}" "19:13:31,0727089","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0727150","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0727262","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0727371","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0727452","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0727561","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0727631","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0727753","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0727817","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature","NAME NOT FOUND","Desired Access: Read" "19:13:31,0727910","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0727974","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0728067","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0728144","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0728263","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0728324","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature","NAME NOT FOUND","Desired Access: Read" "19:13:31,0728407","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0728472","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0728545","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0728626","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0728680","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0728783","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0728869","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0728937","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0729030","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0729094","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0729203","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0729267","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2","NAME NOT FOUND","Desired Access: Read" "19:13:31,0729350","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0729411","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0729501","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0729565","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0729668","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0729732","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2","NAME NOT FOUND","Desired Access: Read" "19:13:31,0729812","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0729873","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0729944","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0730213","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:31,0730329","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:31,0730460","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:31,0730553","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:31,0730646","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:31,0730758","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:31,0734816","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0734893","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0735043","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:31,0735162","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:31,0735386","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0735444","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0735547","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read" "19:13:31,0735630","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read" "19:13:31,0735742","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0735848","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:31,0735954","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:31,0736038","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0736108","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","Desired Access: Read" "19:13:31,0736227","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0736304","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0736368","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:31,0736467","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0736528","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertSyncDeltaTime","NAME NOT FOUND","Length: 144" "19:13:31,0736615","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:31,0736685","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0736737","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0736839","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:31,0736920","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:31,0737016","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0737067","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0737163","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\ChainEngine\Config","REPARSE","Desired Access: Read" "19:13:31,0737240","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\ChainEngine\Config","NAME NOT FOUND","Desired Access: Read" "19:13:31,0737327","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints","NAME NOT FOUND","Length: 144" "19:13:31,0737385","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints","NAME NOT FOUND","Length: 144" "19:13:31,0737446","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions","NAME NOT FOUND","Length: 144" "19:13:31,0737500","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert","NAME NOT FOUND","Length: 144" "19:13:31,0737555","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain","NAME NOT FOUND","Length: 144" "19:13:31,0737606","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount","NAME NOT FOUND","Length: 144" "19:13:31,0737657","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount","NAME NOT FOUND","Length: 144" "19:13:31,0737709","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount","NAME NOT FOUND","Length: 144" "19:13:31,0737760","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds","NAME NOT FOUND","Length: 144" "19:13:31,0737814","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags","NAME NOT FOUND","Length: 144" "19:13:31,0737866","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MinRsaPubKeyBitLength","NAME NOT FOUND","Length: 144" "19:13:31,0737917","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakRsaPubKeyTime","NAME NOT FOUND","Length: 144" "19:13:31,0737972","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime","NAME NOT FOUND","Length: 144" "19:13:31,0738023","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableStrictChecksFlags","NAME NOT FOUND","Length: 144" "19:13:31,0738109","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:31,0738177","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default","SUCCESS","Desired Access: Read" "19:13:31,0738276","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0738340","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\CI\Config","REPARSE","Desired Access: Read" "19:13:31,0738421","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","Desired Access: Read" "19:13:31,0738510","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0738584","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:31,0738645","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\CI\Config\Default","SUCCESS","Desired Access: Read" "19:13:31,0738741","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5ThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0738809","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartyFlags","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2291138560" "19:13:31,0738879","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartyAfterTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 00 C0 29 B8 43 9A C9 01" "19:13:31,0738943","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartyAfterTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 00 C0 29 B8 43 9A C9 01" "19:13:31,0739011","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0739068","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0739123","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0739184","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakMD5AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0739251","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739319","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739379","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartySha256Allow","BUFFER OVERFLOW","Length: 144" "19:13:31,0739450","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartySha256Allow","BUFFER OVERFLOW","Length: 144" "19:13:31,0739514","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5ThirdPartySha256Allow","SUCCESS","Type: REG_MULTI_SZ, Length: 782, Data: 01A8F438E1A14A904BA530942BEDBD94708CA654B8DF3C4585F17B60DA6690D1, 8421A0182C854C1F4266C95FC8302E217A14C7797FE41F2A87CA6B2734C43F1D, 1AD335187A1DC540738FB2EA82B7366678C2EEDCDAE75FEADD6ECD89779CB983, 4B480E8EE1B8DFF231005E9DC5D8267227684D07A38BA6FECDB288DE53FB0A3E, E059080EF4409BC0D96FBCBDDEEE6C0AFBE871AD3D68BBA6A743C64631F599C9, 26ED148B33F377BA01B68A9A97FEB2391FBED7D51E3F6EB83BEBC2FBA90920B1" "19:13:31,0739601","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739668","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakMD5ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739729","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739790","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakMD5ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739854","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakMD5AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0739966","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1ThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0740027","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1ThirdPartyFlags","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2147745792" "19:13:31,0740095","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1ThirdPartyAfterTime","NAME NOT FOUND","Length: 144" "19:13:31,0740156","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0740213","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0740268","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0740326","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakSHA1AllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0740387","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0740451","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0740656","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0740755","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0740832","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0740897","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0740964","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakSHA1ThirdPartySha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0741028","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\System\CurrentControlSet\Control\CI\Config\Default\WeakSHA1AllSha256Allow","NAME NOT FOUND","Length: 144" "19:13:31,0741092","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakRSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741150","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakRSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741211","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakRSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741265","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakRSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741326","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741381","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741439","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741493","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741554","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakECDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741609","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakECDSAThirdPartyFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741666","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\WeakECDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741721","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\WeakECDSAAllFlags","NAME NOT FOUND","Length: 144" "19:13:31,0741811","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default","SUCCESS","" "19:13:31,0741881","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI\Config","SUCCESS","" "19:13:31,0741942","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\CI\Config\Default","SUCCESS","" "19:13:31,0742516","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0742584","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0742693","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0742786","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0742904","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0742959","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0743052","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0743164","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0743408","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0743466","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0743555","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0743629","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0743738","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0743793","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0743895","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0743995","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0744065","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0744133","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0744524","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0744582","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0744668","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0744742","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0744845","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0744899","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0745005","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0745095","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0745159","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0745255","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0745323","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:31,0745435","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0745505","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0745602","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0745663","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0745727","EasyAntiCheat.exe","2900","RegEnumKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0" "19:13:31,0745816","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0745881","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","Desired Access: Read" "19:13:31,0745999","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0746073","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0746137","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 716, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 35 00 34 00" "19:13:31,0746221","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","" "19:13:31,0746458","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0746541","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0746615","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0746721","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0746779","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0746843","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0746913","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0746981","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0747071","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0747125","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0747189","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0747250","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0747619","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0747680","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0747770","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0747847","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0747946","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0748001","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0748081","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,0748155","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0748222","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0748296","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0748366","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0748479","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0748546","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0748658","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0748713","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0748777","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0748851","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0748918","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0749011","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0749065","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0749130","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0749200","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0749268","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0749357","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0749412","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0749476","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0749537","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0749659","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0749717","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0749829","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\CA\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0749925","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0750069","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0750124","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0750226","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0750310","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0750393","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0750483","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0750615","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0750672","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0750775","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0750855","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0750935","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0751025","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0751092","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:31,0751182","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0751250","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0751339","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:31,0751394","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:31,0751455","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: 109F1CAED645BB78B3EA2B94C0697C740733031C" "19:13:31,0751541","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0751609","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","Desired Access: Read" "19:13:31,0751702","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0751776","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0751833","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 147, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 B6 53 18" "19:13:31,0751917","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","" "19:13:31,0752128","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 1, Name: C415CBF62AF1B513B81ED7B707BDE0A954E2B813" "19:13:31,0752221","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0752289","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","Desired Access: Read" "19:13:31,0752379","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0752446","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0752507","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","SUCCESS","Type: REG_BINARY, Length: 1 091, Data: 04 00 00 00 01 00 00 00 10 00 00 00 E1 3A 7C 82" "19:13:31,0752587","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","" "19:13:31,0752767","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 2, Name: D559A586669B08F46A30A133F8A9ED3D038E2EA8" "19:13:31,0752856","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0752924","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","Desired Access: Read" "19:13:31,0753010","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0753075","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0753135","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 095, Data: 04 00 00 00 01 00 00 00 10 00 00 00 AC D8 0E A2" "19:13:31,0753212","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","" "19:13:31,0753389","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 3, Name: FEE449EE0E3965A5246F000E87FDE2A065FD89D4" "19:13:31,0753479","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0753549","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","Desired Access: Read" "19:13:31,0753633","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0753700","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0753758","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","SUCCESS","Type: REG_BINARY, Length: 566, Data: 19 00 00 00 01 00 00 00 10 00 00 00 ED BC CD D5" "19:13:31,0753835","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","" "19:13:31,0753985","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0754066","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0754136","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0754220","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0754277","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0754335","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Index: 0, Name: A377D1B1C0538833035211F4083D00FECC414DAB" "19:13:31,0754418","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0754483","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","Desired Access: Read" "19:13:31,0754566","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0754633","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0754691","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","SUCCESS","Type: REG_BINARY, Length: 481, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A3 77 D1 B1" "19:13:31,0754768","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","" "19:13:31,0755018","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0755098","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0755172","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0755259","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0755316","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0755384","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0755445","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0755595","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0755656","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0755765","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0755852","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0755951","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0756032","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0756099","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0756189","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0756243","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0756311","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0756384","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0756449","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0756526","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0756580","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0756644","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0756715","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0756782","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0756859","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0756914","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0756978","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0757036","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0757151","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0757206","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0757315","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\CA\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0757408","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0757526","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0757578","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0757677","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0757757","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0757837","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0757911","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","" "19:13:31,0758036","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0758091","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0758193","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\CA","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0758270","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0758347","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0758437","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0758501","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Desired Access: Read" "19:13:31,0758594","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0758674","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0758764","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0758819","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0758889","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","" "19:13:31,0758960","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0759027","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0759111","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0759165","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0759229","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","" "19:13:31,0759300","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0759367","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0759444","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0759499","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0759563","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","" "19:13:31,0759624","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","" "19:13:31,0760098","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0760156","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0760246","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0760323","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0760426","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0760477","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0760567","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0760666","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0760894","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0760952","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0761035","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0761109","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0761208","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0761263","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0761349","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0761436","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0761500","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0761564","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0761654","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0761709","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0761811","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,0761895","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0762045","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0762100","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0762183","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0762254","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0762350","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0762404","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0762491","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0762584","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0762651","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0762703","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0762802","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,0762882","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0763264","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0763322","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0763405","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0763476","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0763575","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0763630","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0763716","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0763800","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0763864","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0763950","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0764015","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,0764104","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0764172","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0764284","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0764342","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0764406","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0764480","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0764544","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0764637","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0764694","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0764755","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0764826","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0764890","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0764999","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0765057","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0765121","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0765182","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0765480","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0765541","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0765625","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0765698","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0765795","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0765849","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0765926","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,0766000","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0766064","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0766138","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0766205","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0766317","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0766382","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0766487","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0766542","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0766606","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0766680","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0766747","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0766837","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0766891","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0766956","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0767033","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0767097","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0767183","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0767238","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0767302","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0767363","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0767478","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0767536","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0767642","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0767725","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0767841","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0767892","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0767992","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0768081","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0768165","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0768239","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0768322","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0768376","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0768479","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,0768556","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0768704","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0768758","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0768841","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0768912","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0769005","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0769060","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0769146","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0769233","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0769303","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0769355","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0769451","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,0769531","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,0769672","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0769727","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0769823","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0769903","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0769999","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0770089","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0770156","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,0770249","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0770317","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0770407","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0770464","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0770532","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0770605","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0770670","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0770750","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0770804","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0770868","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0770939","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0771003","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0771080","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0771131","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0771192","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:31,0771279","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0771343","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:31,0771436","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0771507","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0771571","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:31,0771648","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:31,0771959","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0772026","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0772171","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0772228","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0772341","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0772424","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0772517","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0772597","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0772665","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0772754","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0772809","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0772876","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0772947","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0773014","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0773094","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0773149","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0773213","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0773284","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0773351","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0773428","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0773482","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0773547","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0773607","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0773717","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0773771","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0773877","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0773957","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0774069","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0774124","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0774223","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0774300","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0774380","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0774448","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,0774566","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0774621","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0774717","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0774794","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0774871","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0774990","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0775057","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,0775153","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0775221","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0775307","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0775365","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0775432","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0775503","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0775570","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0775647","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0775702","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0775766","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0775837","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0775901","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0775978","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0776032","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0776106","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0776170","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,0776619","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0776677","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0776763","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0776840","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0776940","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0776994","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0777078","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0777177","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0777402","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0777459","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0777543","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0777617","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0777716","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0777771","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0777854","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0777941","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0778005","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0778069","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:31,0778152","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0778204","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0778306","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:31,0778386","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:31,0778675","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0778730","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0778816","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0778887","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0778999","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0779053","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0779140","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0779220","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0779345","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0779397","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0779480","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0779547","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0779647","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0779701","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0779785","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read" "19:13:31,0779897","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0779993","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:31,0780057","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0780138","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0780205","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read" "19:13:31,0780295","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0780362","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0780465","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0780519","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0780587","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:31,0780657","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0780724","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0780814","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0780869","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0780933","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:31,0781003","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0781071","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0781161","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0781212","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0781276","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:31,0781398","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0781452","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0781536","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0781610","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0781911","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0781969","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0782055","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read" "19:13:31,0782145","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0782248","EasyAntiCheat.exe","2900","RegQueryKeySecurity","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:31,0782360","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 B0 90 42 D9 96 C6 D5 01" "19:13:31,0782431","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 B0 90 42 D9 96 C6 D5 01" "19:13:31,0782508","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:31,0782569","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0782633","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:31,0782690","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0782806","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0782864","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0782970","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Root\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0783056","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Root\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0783172","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0783226","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0783326","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0783406","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0783486","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0783560","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","" "19:13:31,0783640","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0783694","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0783794","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:31,0783877","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:31,0784044","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0784102","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0784198","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0784278","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0784355","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0784442","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0784506","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Desired Access: Read" "19:13:31,0784599","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0784666","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0784756","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:31,0784814","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:31,0784875","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 0, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:31,0784980","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0785048","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:31,0785141","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0785208","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0785269","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 95 6C C4 8F" "19:13:31,0785353","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:31,0785503","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 1, Name: 18F7C1FCC3090203FD5BAA2F861A754976C8DD25" "19:13:31,0785593","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0785664","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","Desired Access: Read" "19:13:31,0785750","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0785818","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0785888","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","SUCCESS","Type: REG_BINARY, Length: 968, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:31,0785968","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","" "19:13:31,0786103","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 2, Name: 245C97DF7514E7CF2DF8BE72AE957B9E04741E85" "19:13:31,0786193","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0786260","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","Desired Access: Read" "19:13:31,0786344","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0786411","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0786469","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","SUCCESS","Type: REG_BINARY, Length: 907, Data: 19 00 00 00 01 00 00 00 10 00 00 00 7F DF F5 07" "19:13:31,0786546","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","" "19:13:31,0786671","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 3, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:31,0786761","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0786831","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:31,0786914","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0786982","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0787040","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 237, Data: 19 00 00 00 01 00 00 00 10 00 00 00 79 A6 2B 38" "19:13:31,0787117","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:31,0787274","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 4, Name: 3B1EFD3A66EA28B16697394703A72CA340A05BD5" "19:13:31,0787363","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0787431","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","Desired Access: Read" "19:13:31,0787517","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0787582","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0787643","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 835, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:31,0787719","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","" "19:13:31,0787896","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 5, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:31,0787982","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0788053","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:31,0788136","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0788204","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0788265","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 149, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0788342","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:31,0788489","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 6, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:31,0788576","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0788643","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:31,0788730","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0788797","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0788855","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 71 BD 96 83" "19:13:31,0788932","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:31,0789054","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 7, Name: 7D5E3BD28E9429952ADFC4630B770C389E7A64FD" "19:13:31,0789140","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0789208","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","Desired Access: Read" "19:13:31,0789291","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0789358","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0789416","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 134, Data: 19 00 00 00 01 00 00 00 10 00 00 00 78 DD D8 24" "19:13:31,0789493","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","" "19:13:31,0789641","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 8, Name: 7F88CD7223F3C813818C994614A89C99FA3B5247" "19:13:31,0789727","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0789795","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","Desired Access: Read" "19:13:31,0789878","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0789939","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0790016","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","SUCCESS","Type: REG_BINARY, Length: 1 228, Data: 19 00 00 00 01 00 00 00 10 00 00 00 07 D3 4D ED" "19:13:31,0790096","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","" "19:13:31,0790311","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 9, Name: 8F43288AD272F3103B6FB1428485EA3014C0BCFE" "19:13:31,0790404","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0790471","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","Desired Access: Read" "19:13:31,0790561","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0790625","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0790686","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 869, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:31,0790766","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","" "19:13:31,0790940","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 10, Name: 9007A10299C432559B502DB7D6C449757780FDB1" "19:13:31,0791026","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0791097","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","Desired Access: Read" "19:13:31,0791180","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0791244","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0791341","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 D4 65 24 73" "19:13:31,0791417","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","" "19:13:31,0791591","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 11, Name: 92B46C76E13054E104F230517E6E504D43AB10B5" "19:13:31,0791680","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0791751","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","Desired Access: Read" "19:13:31,0791834","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0791899","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0791960","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 255, Data: 09 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:31,0792036","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","" "19:13:31,0792200","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 12, Name: A43489159A520F0D93D032CCAF37E7FE20A8B419" "19:13:31,0792287","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0792357","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","Desired Access: Read" "19:13:31,0792437","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0792505","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0792562","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","SUCCESS","Type: REG_BINARY, Length: 1 310, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0792639","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","" "19:13:31,0792781","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 13, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:31,0792867","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0792935","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:31,0793018","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0793085","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0793140","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 8B 7C EF 92" "19:13:31,0793217","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:31,0793339","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 14, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:31,0793425","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0793493","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:31,0793576","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0793679","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0793749","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 823, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 42 25 E4" "19:13:31,0793829","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:31,0793974","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 15, Name: B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD" "19:13:31,0794063","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0794134","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","Desired Access: Read" "19:13:31,0794217","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0794282","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0794371","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 105, Data: 19 00 00 00 01 00 00 00 10 00 00 00 56 57 7B 94" "19:13:31,0794452","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","" "19:13:31,0794589","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 16, Name: BE36A4562FB2EE05DBB3D32323ADF445084ED656" "19:13:31,0794679","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0794747","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","Desired Access: Read" "19:13:31,0794833","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0794901","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0794997","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","SUCCESS","Type: REG_BINARY, Length: 935, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:31,0795077","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","" "19:13:31,0795221","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 17, Name: CDD4EEAE6000AC7F40C3802C171E30148030C072" "19:13:31,0795308","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0795378","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","Desired Access: Read" "19:13:31,0795468","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0795532","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0795625","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","SUCCESS","Type: REG_BINARY, Length: 1 759, Data: 59 00 00 00 01 00 00 00 12 00 00 00 52 00 53 00" "19:13:31,0795706","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","" "19:13:31,0795860","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 18, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:31,0795946","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0796017","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:31,0796103","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0796167","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0796228","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 071, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0796305","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:31,0796446","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 19, Name: E06A30801D661F606869D9BC0ACC5EE57C7A48A7" "19:13:31,0796530","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0796597","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","Desired Access: Read" "19:13:31,0796684","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0796745","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0796802","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 102, Data: 19 00 00 00 01 00 00 00 10 00 00 00 B7 B9 C2 BF" "19:13:31,0796879","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","" "19:13:31,0797040","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 20, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:31,0797130","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0797197","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:31,0797280","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0797345","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0797402","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 BB AD 3C 3F" "19:13:31,0797479","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:31,0797608","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","" "19:13:31,0797688","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0797765","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0797854","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0797909","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0797976","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","" "19:13:31,0798047","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0798114","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0798191","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0798246","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0798310","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","" "19:13:31,0798371","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","" "19:13:31,0798499","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0798560","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0798676","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0798765","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0798858","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0798945","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0799012","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read" "19:13:31,0799105","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0799173","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0799259","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:31,0799314","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:31,0799372","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 0, Name: 02FAF3E291435468607857694DF5E45B68851868" "19:13:31,0799455","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0799519","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","Desired Access: Read" "19:13:31,0799612","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0799683","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0799740","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","SUCCESS","Type: REG_BINARY, Length: 1 559, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0799821","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","" "19:13:31,0800077","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 1, Name: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" "19:13:31,0800170","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0800241","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","Desired Access: Read" "19:13:31,0800330","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0800398","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0800456","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","SUCCESS","Type: REG_BINARY, Length: 1 377, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0800533","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","" "19:13:31,0800693","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 2, Name: 06083F593F15A104A069A46BA903D006B7970991" "19:13:31,0800780","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0800847","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","Desired Access: Read" "19:13:31,0800933","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0800998","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0801091","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","SUCCESS","Type: REG_BINARY, Length: 1 577, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0801171","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","" "19:13:31,0801328","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 3, Name: 06F1AA330B927B753A40E68CDF22E34BCBEF3352" "19:13:31,0801415","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0801485","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","Desired Access: Read" "19:13:31,0801568","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0801633","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0801690","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","SUCCESS","Type: REG_BINARY, Length: 1 233, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 80 01 00 00" "19:13:31,0801777","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","" "19:13:31,0801953","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 4, Name: 07E032E020B72C3F192F0628A2593A19A70F069E" "19:13:31,0802040","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0802107","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","Desired Access: Read" "19:13:31,0802191","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0802258","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0802316","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 484, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0802396","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","" "19:13:31,0802563","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 5, Name: 093C61F38B8BDC7D55DF7538020500E125F5C836" "19:13:31,0802649","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0802717","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","Desired Access: Read" "19:13:31,0802803","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0802900","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0802960","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","SUCCESS","Type: REG_BINARY, Length: 1 868, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:31,0803041","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","" "19:13:31,0803198","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 6, Name: 1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA" "19:13:31,0803284","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0803355","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","Desired Access: Read" "19:13:31,0803438","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0803502","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0803560","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","SUCCESS","Type: REG_BINARY, Length: 1 034, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0803637","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","" "19:13:31,0803814","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 7, Name: 2796BAE63F1801E277261BA0D77770028F20EEE4" "19:13:31,0803900","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0803971","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","Desired Access: Read" "19:13:31,0804051","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0804112","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0804205","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 512, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0804285","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","" "19:13:31,0804449","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 8, Name: 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E" "19:13:31,0804535","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0804606","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","Desired Access: Read" "19:13:31,0804692","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0804757","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0804814","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 989, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0804891","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","" "19:13:31,0805077","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 9, Name: 2BB1F53E550C1DC5F1D4E6B76A464B550602AC21" "19:13:31,0805167","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0805238","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","Desired Access: Read" "19:13:31,0805318","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0805382","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0805475","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","SUCCESS","Type: REG_BINARY, Length: 1 317, Data: 7F 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:31,0805552","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","" "19:13:31,0805760","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 10, Name: 3679CA35668772304D30A5FB873B0FA77BB70D54" "19:13:31,0805850","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0805921","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","Desired Access: Read" "19:13:31,0806007","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0806072","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0806158","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","SUCCESS","Type: REG_BINARY, Length: 1 781, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0806238","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","" "19:13:31,0806415","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 11, Name: 36B12B49F9819ED74C9EBC380FC6568F5DACB2F7" "19:13:31,0806504","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0806572","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","Desired Access: Read" "19:13:31,0806662","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0806726","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0806784","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 370, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:31,0806860","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","" "19:13:31,0807018","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 12, Name: 3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F" "19:13:31,0807104","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0807175","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","Desired Access: Read" "19:13:31,0807258","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0807326","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0807383","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","SUCCESS","Type: REG_BINARY, Length: 2 512, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0807463","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","" "19:13:31,0807646","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 13, Name: 47BEABC922EAE80E78783462A79F45C254FDE68B" "19:13:31,0807733","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0807800","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","Desired Access: Read" "19:13:31,0807884","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0807951","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0808041","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0808121","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","" "19:13:31,0808291","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 14, Name: 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5" "19:13:31,0808381","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0808451","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","Desired Access: Read" "19:13:31,0808535","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0808602","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0808689","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 760, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0808769","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","" "19:13:31,0808932","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 15, Name: 503006091D97D4F5AE39F7CBE7927D7D652D3431" "19:13:31,0809022","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0809090","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","Desired Access: Read" "19:13:31,0809173","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0809237","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0809295","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","SUCCESS","Type: REG_BINARY, Length: 1 613, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0809372","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","" "19:13:31,0809539","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 16, Name: 51501FBFCE69189D609CFAF140C576755DCC1FDF" "19:13:31,0809625","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0809693","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","Desired Access: Read" "19:13:31,0809782","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0809879","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0809946","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","SUCCESS","Type: REG_BINARY, Length: 1 808, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:31,0810093","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","" "19:13:31,0810254","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 17, Name: 590D2D7D884F402E617EA562321765CF17D894E9" "19:13:31,0810344","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0810414","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","Desired Access: Read" "19:13:31,0810501","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0810568","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0810626","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 345, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:31,0810703","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","" "19:13:31,0810898","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 18, Name: 5D003860F002ED829DEAA41868F788186D62127F" "19:13:31,0810988","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0811059","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","Desired Access: Read" "19:13:31,0811142","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0811206","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0811267","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","SUCCESS","Type: REG_BINARY, Length: 1 679, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0811344","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","" "19:13:31,0811569","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 19, Name: 5F3B8CF2F810B37D78B4CEEC1919C37334B9C774" "19:13:31,0811662","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0811729","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","Desired Access: Read" "19:13:31,0811816","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0811880","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0811938","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","SUCCESS","Type: REG_BINARY, Length: 1 335, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0812018","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","" "19:13:31,0812191","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 20, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:31,0812278","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0812348","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:31,0812432","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0812499","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0812557","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 391, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0812634","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:31,0812733","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 21, Name: 6252DC40F71143A22FDE9EF7348E064251B18118" "19:13:31,0812816","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0812884","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","Desired Access: Read" "19:13:31,0812967","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0813031","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0813089","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","SUCCESS","Type: REG_BINARY, Length: 1 190, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:31,0813166","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","" "19:13:31,0813310","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 22, Name: 742C3192E607E424EB4549542BE1BBC53E6174E2" "19:13:31,0813400","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0813467","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","Desired Access: Read" "19:13:31,0813551","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0813618","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0813676","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 074, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0813750","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","" "19:13:31,0813949","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 23, Name: 75E0ABB6138512271C04F85FDDDE38E4B7242EFE" "19:13:31,0814042","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0814109","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","Desired Access: Read" "19:13:31,0814192","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0814256","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0814314","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 555, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:31,0814394","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","" "19:13:31,0814561","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 24, Name: 7E04DE896A3E666D00E687D33FFAD93BE83D349E" "19:13:31,0814648","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0814715","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","Desired Access: Read" "19:13:31,0814798","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0814863","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0814920","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 059, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0815013","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","" "19:13:31,0815164","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 25, Name: 8782C6C304353BCFD29692D2593E7D44D934FF11" "19:13:31,0815254","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0815321","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","Desired Access: Read" "19:13:31,0815405","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0815469","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0815530","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","SUCCESS","Type: REG_BINARY, Length: 1 354, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0815607","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","" "19:13:31,0815838","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 26, Name: 89DF74FE5CF40F4A80F9E3377D54DA91E101318E" "19:13:31,0815931","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0816001","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","Desired Access: Read" "19:13:31,0816085","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0816206","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0816267","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0816348","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","" "19:13:31,0816514","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 27, Name: 8CF427FD790C3AD166068DE81E57EFBB932272D4" "19:13:31,0816604","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0816672","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","Desired Access: Read" "19:13:31,0816755","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0816819","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0816877","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 639, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:31,0816957","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","" "19:13:31,0817108","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 28, Name: 91C6D6EE3E8AC86384E548C299295C756C817B81" "19:13:31,0817194","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0817265","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","Desired Access: Read" "19:13:31,0817345","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0817409","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0817480","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","SUCCESS","Type: REG_BINARY, Length: 1 515, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0817560","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","" "19:13:31,0817714","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 29, Name: 97817950D81C9670CC34D809CF794431367EF474" "19:13:31,0817804","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0817874","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","Desired Access: Read" "19:13:31,0817958","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0818035","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0818096","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 050, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:31,0818173","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","" "19:13:31,0818320","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 30, Name: A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436" "19:13:31,0818407","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0818474","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","Desired Access: Read" "19:13:31,0818557","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0818622","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0818682","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","SUCCESS","Type: REG_BINARY, Length: 1 369, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0818759","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","" "19:13:31,0818933","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 31, Name: AD7E1C28B064EF8F6003402014C3D0E3370EB58A" "19:13:31,0819019","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0819087","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","Desired Access: Read" "19:13:31,0819170","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0819237","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0819295","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0819375","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","" "19:13:31,0819542","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 32, Name: AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4" "19:13:31,0819629","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0819696","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","Desired Access: Read" "19:13:31,0819783","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0819847","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0819937","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","SUCCESS","Type: REG_BINARY, Length: 2 025, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0820036","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","" "19:13:31,0820190","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 33, Name: B1BC968BD4F49D622AA89A81F2150152A41D829C" "19:13:31,0820280","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0820350","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","Desired Access: Read" "19:13:31,0820437","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0820501","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0820559","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 461, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:31,0820636","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","" "19:13:31,0820793","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 34, Name: B31EB1B740E36C8402DADC37D44DF5D4674952F9" "19:13:31,0820879","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0820947","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","Desired Access: Read" "19:13:31,0821030","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0821094","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0821184","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 712, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:31,0821268","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","" "19:13:31,0821466","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 35, Name: B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E" "19:13:31,0821556","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0821627","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","Desired Access: Read" "19:13:31,0821713","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0821778","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0821867","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 498, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0821947","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","" "19:13:31,0822101","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 36, Name: CA3AFBCF1240364B44B216208880483919937CF7" "19:13:31,0822191","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0822262","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","Desired Access: Read" "19:13:31,0822345","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0822409","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0822467","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 937, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:31,0822547","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","" "19:13:31,0822708","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 37, Name: CABD2A79A1076A31F21D253635CB039D4329A5E8" "19:13:31,0822794","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0822862","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","Desired Access: Read" "19:13:31,0822945","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0823009","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0823064","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 717, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:31,0823144","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","" "19:13:31,0823288","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 38, Name: CF9E876DD3EBFC422697A3B5A37AA076A9062348" "19:13:31,0823375","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0823987","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","Desired Access: Read" "19:13:31,0824093","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0824164","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0824260","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","SUCCESS","Type: REG_BINARY, Length: 1 421, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0824340","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","" "19:13:31,0824513","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 39, Name: D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0" "19:13:31,0824606","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0824680","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","Desired Access: Read" "19:13:31,0824763","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0824831","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0824889","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 150, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0824985","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","" "19:13:31,0825142","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 40, Name: D1EB23A46D17D68FD92564C2F1F1601764D8E349" "19:13:31,0825232","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0825299","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","Desired Access: Read" "19:13:31,0825386","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0825450","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0825508","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","SUCCESS","Type: REG_BINARY, Length: 1 545, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0825588","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","" "19:13:31,0825742","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 41, Name: D23209AD23D314232174E40D7F9D62139786633A" "19:13:31,0825828","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0825899","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","Desired Access: Read" "19:13:31,0825979","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0826046","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0826104","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 197, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:31,0826178","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","" "19:13:31,0826345","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 42, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:31,0826434","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0826502","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:31,0826598","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0826694","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0826755","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 460, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:31,0826835","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:31,0826986","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 43, Name: D69B561148F01C77C54578C10926DF5B856976AD" "19:13:31,0827073","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0827143","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","Desired Access: Read" "19:13:31,0827227","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0827294","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0827352","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 363, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:31,0827429","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","" "19:13:31,0827637","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 44, Name: D8C5388AB7301B1B6ED47AE645253A6F9F1A2761" "19:13:31,0827730","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0827801","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","Desired Access: Read" "19:13:31,0827884","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0827948","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0828006","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","SUCCESS","Type: REG_BINARY, Length: 1 855, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0828086","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","" "19:13:31,0828240","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 45, Name: DAC9024F54D8F6DF94935FB1732638CA6AD77C13" "19:13:31,0828327","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0828397","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","Desired Access: Read" "19:13:31,0828481","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0828545","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0828603","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","SUCCESS","Type: REG_BINARY, Length: 1 264, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:31,0828680","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","" "19:13:31,0828834","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 46, Name: DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212" "19:13:31,0828917","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0828987","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","Desired Access: Read" "19:13:31,0829068","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0829135","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0829193","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","SUCCESS","Type: REG_BINARY, Length: 1 306, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0829270","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","" "19:13:31,0829420","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 47, Name: DE3F40BD5093D39B6C60F6DABC076201008976C9" "19:13:31,0829507","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0829574","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","Desired Access: Read" "19:13:31,0829658","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0829722","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0829783","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 958, Data: 4B 00 00 00 01 00 00 00 02 00 00 00 00 00 04 00" "19:13:31,0829860","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","" "19:13:31,0830039","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 48, Name: DF3C24F9BFD666761B268073FE06D1CC8D4F82A4" "19:13:31,0830129","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0830197","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","Desired Access: Read" "19:13:31,0830280","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0830347","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0830437","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 378, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0830517","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","" "19:13:31,0830671","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 49, Name: DF717EAA4AD94EC9558499602D48DE5FBCF03A25" "19:13:31,0830758","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0830828","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","Desired Access: Read" "19:13:31,0830912","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0830976","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0831034","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 947, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:31,0831111","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","" "19:13:31,0831265","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 50, Name: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46" "19:13:31,0831351","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0831422","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","Desired Access: Read" "19:13:31,0831505","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0831573","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0831630","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","SUCCESS","Type: REG_BINARY, Length: 1 482, Data: 09 00 00 00 01 00 00 00 22 00 00 00 30 20 06 08" "19:13:31,0831707","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","" "19:13:31,0831858","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 51, Name: F373B387065A28848AF2F34ACE192BDDC78E9CAC" "19:13:31,0831945","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0832015","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","Desired Access: Read" "19:13:31,0832099","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0832163","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0832220","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","SUCCESS","Type: REG_BINARY, Length: 1 917, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0832297","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","" "19:13:31,0832455","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 52, Name: F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7" "19:13:31,0832541","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0832608","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","Desired Access: Read" "19:13:31,0832692","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0832759","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0832849","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 400, Data: 7F 00 00 00 01 00 00 00 36 00 00 00 30 34 06 08" "19:13:31,0832929","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","" "19:13:31,0833154","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 53, Name: FE45659B79035B98A161B5512EACDA580948224D" "19:13:31,0833247","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0833314","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","Desired Access: Read" "19:13:31,0833401","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0833465","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0833539","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 40 00 00 00 30 3E 06 08" "19:13:31,0833616","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","" "19:13:31,0833802","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","" "19:13:31,0833891","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0833975","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0834065","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0834126","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0834190","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","" "19:13:31,0834260","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0834328","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0834405","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0834459","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0834533","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","" "19:13:31,0834600","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:31,0834773","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0834838","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0834979","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0835075","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0835181","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0835264","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0835335","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0835424","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0835482","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0835550","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:31,0835623","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0835691","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0835768","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0835822","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0835886","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:31,0835957","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0836024","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0836098","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0836153","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0836217","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:31,0836278","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:31,0836396","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0836451","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0836563","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Root\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0836656","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0836778","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0836832","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0836935","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0837015","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0837102","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0837176","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","" "19:13:31,0837297","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0837352","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0837455","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Root","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0837532","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0837612","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0837695","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0837763","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Desired Access: Read" "19:13:31,0837856","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0837923","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0838010","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0838067","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0838135","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","" "19:13:31,0838205","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0838273","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0838349","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0838404","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0838468","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","" "19:13:31,0838539","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0838603","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0838680","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0838734","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0838798","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","" "19:13:31,0838859","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","" "19:13:31,0838985","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0839039","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0839142","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\SmartCardRoot","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0839225","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0839308","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0839389","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0839453","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read" "19:13:31,0839543","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0839610","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0839697","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0839754","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0839822","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:31,0839892","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0839976","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0840053","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0840110","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0840174","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:31,0840242","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0840309","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0840389","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0840444","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0840505","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:31,0840569","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","" "19:13:31,0840919","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0840976","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0841063","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0841140","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0841262","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0841316","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0841409","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0841499","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0841582","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0841647","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Desired Access: Read" "19:13:31,0841740","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0841807","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0841919","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0841977","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0842044","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:31,0842115","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0842182","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0842275","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0842333","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0842394","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:31,0842471","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0842535","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0842634","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0842692","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0842756","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:31,0842820","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","" "19:13:31,0842878","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0843305","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0843362","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0843449","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0843523","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0843622","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0843674","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0843763","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0843863","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0844087","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0844145","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0844228","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0844299","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0844398","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0844453","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0844540","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0844623","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0844687","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0844748","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0844835","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0844889","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0845011","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:31,0845101","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:31,0845479","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0845537","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0845620","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0845694","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0845794","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0845848","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0845935","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0846015","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0846079","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0846162","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0846227","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:31,0846313","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0846380","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0846486","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0846544","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0846608","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0846682","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0846749","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0846839","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0846890","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0846955","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0847028","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0847093","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0847182","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0847237","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0847301","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0847362","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0847750","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0847811","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0847894","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0847968","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0848064","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0848119","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0848196","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,0848270","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0848334","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0848407","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0848475","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0848590","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0848654","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0848767","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0848821","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0848889","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0848959","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0849026","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0849119","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0849174","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0849235","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0849306","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0849373","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0849463","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0849517","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0849581","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0849639","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0849761","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0849819","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0849925","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0850034","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0850146","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0850200","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0850300","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0850380","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0850463","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0850534","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0850656","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0850710","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0850810","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0850890","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0850967","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0851047","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0851111","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:31,0851201","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0851268","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0851358","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0851413","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0851480","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0851554","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0851618","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0851695","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0851753","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0851814","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0851884","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0851964","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0852041","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0852096","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0852160","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0852221","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0852356","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0852413","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0852516","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0852599","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0852686","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0852763","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0852830","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0852910","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0852968","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0853036","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0853106","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0853170","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0853250","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0853305","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0853369","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0853440","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0853507","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0853584","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0853639","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0853699","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0853760","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0853869","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0853924","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0854027","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0854110","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0854222","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0854277","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0854376","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0854453","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0854533","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0854601","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","" "19:13:31,0854719","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0854774","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0854873","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPeople","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0854954","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0855047","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0855127","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0855194","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:31,0855284","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0855351","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0855441","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0855496","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0855563","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0855633","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0855698","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0855778","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0855832","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0855893","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0855964","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0856031","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0856108","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0856163","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0856227","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0856288","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","" "19:13:31,0856721","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0856778","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0856865","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0856936","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0857038","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0857093","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0857179","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0857276","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0857497","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0857551","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0857635","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0857705","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0857805","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0857859","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0857946","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0858026","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0858090","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0858151","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0858510","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0858568","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0858652","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0858722","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0858821","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0858876","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0858963","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0859040","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0859104","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0859184","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0859248","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:31,0859338","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0859405","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0859514","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0859569","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0859633","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0859707","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0859771","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0859864","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0859918","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0859999","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0860076","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0860140","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0860229","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0860284","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0860348","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0860412","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0860720","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0860778","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0860865","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0860935","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0861031","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0861086","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0861163","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,0861237","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0861301","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0861371","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0861442","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0861551","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0861615","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0861721","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0861775","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0861843","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0861913","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0861981","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0862070","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0862125","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0862189","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0862260","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0862327","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0862417","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0862471","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0862536","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0862596","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0862715","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0862770","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0862879","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\trust\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0862962","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0863074","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0863129","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0863228","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0863305","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0863385","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0863453","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0863575","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0863629","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0863729","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0863809","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0863886","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0863966","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0864030","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:31,0864123","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0864187","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0864277","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0864332","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0864399","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0864470","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0864537","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0864617","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0864672","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0864736","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0864806","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0864870","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0864947","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0865040","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0865105","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0865165","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0865303","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0865361","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0865464","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0865544","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0865631","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0865708","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0865775","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0865858","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0865913","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0865980","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0866054","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0866118","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0866198","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0866253","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0866317","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0866391","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0866455","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0866532","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0866586","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0866650","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0866711","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0866817","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0866872","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0866971","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\trust\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,0867051","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,0867160","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0867215","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0867314","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0867388","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0867468","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0867542","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","" "19:13:31,0867661","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0867718","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0867821","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\trust","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,0867898","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0867975","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0868062","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0868126","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Desired Access: Read" "19:13:31,0868219","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0868286","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0868373","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0868430","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0868507","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","" "19:13:31,0868581","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0868649","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0868729","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0868783","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0868847","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","" "19:13:31,0868918","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0868982","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,0869059","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0869114","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0869175","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","" "19:13:31,0869239","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","" "19:13:31,0869531","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0869601","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0869681","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0869736","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0869803","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:31,0869871","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0869935","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0870028","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0870079","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0870143","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:31,0870214","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0870278","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0870348","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0870403","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0870467","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:31,0870595","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0870650","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0870737","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0870810","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0870913","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0870967","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0871054","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","Desired Access: Read" "19:13:31,0871144","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0871269","EasyAntiCheat.exe","2900","RegQueryKeySecurity","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:31,0871365","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 B0 90 42 D9 96 C6 D5 01" "19:13:31,0871436","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates","SUCCESS","Type: REG_BINARY, Length: 24, Data: 18 00 00 00 01 00 00 00 B0 90 42 D9 96 C6 D5 01" "19:13:31,0871513","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Root\ProtectedRoots","SUCCESS","" "19:13:31,0871574","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0871917","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0871991","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0872071","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:31,0872125","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: Cached, SubKeys: 21, Values: 0" "19:13:31,0872186","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 0, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:31,0872273","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0872337","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:31,0872420","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0872491","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0872549","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 95 6C C4 8F" "19:13:31,0872626","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:31,0872722","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 1, Name: 18F7C1FCC3090203FD5BAA2F861A754976C8DD25" "19:13:31,0872808","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0872876","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","Desired Access: Read" "19:13:31,0872956","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0873020","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0873078","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob","SUCCESS","Type: REG_BINARY, Length: 968, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:31,0873155","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25","SUCCESS","" "19:13:31,0873241","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 2, Name: 245C97DF7514E7CF2DF8BE72AE957B9E04741E85" "19:13:31,0873325","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0873392","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","Desired Access: Read" "19:13:31,0873469","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0873533","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0873591","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob","SUCCESS","Type: REG_BINARY, Length: 907, Data: 19 00 00 00 01 00 00 00 10 00 00 00 7F DF F5 07" "19:13:31,0873665","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85","SUCCESS","" "19:13:31,0873748","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 3, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:31,0873835","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0873899","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:31,0873976","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0874043","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0874101","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 237, Data: 19 00 00 00 01 00 00 00 10 00 00 00 79 A6 2B 38" "19:13:31,0874178","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:31,0874258","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 4, Name: 3B1EFD3A66EA28B16697394703A72CA340A05BD5" "19:13:31,0874341","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0874409","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","Desired Access: Read" "19:13:31,0874486","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0874550","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0874608","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 835, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:31,0874685","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5","SUCCESS","" "19:13:31,0874771","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 5, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:31,0874855","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0874922","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:31,0875044","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0875111","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0875169","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 149, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0875243","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:31,0875387","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 6, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:31,0875477","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0875547","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:31,0875631","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0875695","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0875753","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 71 BD 96 83" "19:13:31,0875830","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:31,0875913","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 7, Name: 7D5E3BD28E9429952ADFC4630B770C389E7A64FD" "19:13:31,0876000","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0876064","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","Desired Access: Read" "19:13:31,0876144","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0876205","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0876263","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 134, Data: 19 00 00 00 01 00 00 00 10 00 00 00 78 DD D8 24" "19:13:31,0876349","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7D5E3BD28E9429952ADFC4630B770C389E7A64FD","SUCCESS","" "19:13:31,0876433","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 8, Name: 7F88CD7223F3C813818C994614A89C99FA3B5247" "19:13:31,0876516","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0876580","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","Desired Access: Read" "19:13:31,0876660","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0876724","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0876782","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob","SUCCESS","Type: REG_BINARY, Length: 1 228, Data: 19 00 00 00 01 00 00 00 10 00 00 00 07 D3 4D ED" "19:13:31,0876859","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247","SUCCESS","" "19:13:31,0876939","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 9, Name: 8F43288AD272F3103B6FB1428485EA3014C0BCFE" "19:13:31,0877023","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0877090","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","Desired Access: Read" "19:13:31,0877170","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0877238","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0877295","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 869, Data: 59 00 00 00 01 00 00 00 16 00 00 00 52 00 53 00" "19:13:31,0877372","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\8F43288AD272F3103B6FB1428485EA3014C0BCFE","SUCCESS","" "19:13:31,0877462","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 10, Name: 9007A10299C432559B502DB7D6C449757780FDB1" "19:13:31,0877546","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0877610","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","Desired Access: Read" "19:13:31,0877690","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0877754","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0877809","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 D4 65 24 73" "19:13:31,0877882","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\9007A10299C432559B502DB7D6C449757780FDB1","SUCCESS","" "19:13:31,0877966","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 11, Name: 92B46C76E13054E104F230517E6E504D43AB10B5" "19:13:31,0878049","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0878116","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","Desired Access: Read" "19:13:31,0878197","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0878261","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0878318","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 255, Data: 09 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:31,0878392","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\92B46C76E13054E104F230517E6E504D43AB10B5","SUCCESS","" "19:13:31,0878479","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 12, Name: A43489159A520F0D93D032CCAF37E7FE20A8B419" "19:13:31,0878562","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0878630","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","Desired Access: Read" "19:13:31,0878707","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0878771","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0878828","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob","SUCCESS","Type: REG_BINARY, Length: 1 310, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0878902","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419","SUCCESS","" "19:13:31,0878989","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 13, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:31,0879072","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0879140","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:31,0879217","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0879281","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0879338","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 8B 7C EF 92" "19:13:31,0879415","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:31,0879496","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 14, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:31,0879579","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0879643","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:31,0879723","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0879787","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0879845","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 823, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 42 25 E4" "19:13:31,0879922","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:31,0880015","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 15, Name: B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD" "19:13:31,0880102","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0880169","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","Desired Access: Read" "19:13:31,0880249","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0880313","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0880371","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 105, Data: 19 00 00 00 01 00 00 00 10 00 00 00 56 57 7B 94" "19:13:31,0880448","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B19E4C59E30113AD86EBCF90F3DB3E8DBD8D42FD","SUCCESS","" "19:13:31,0880528","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 16, Name: BE36A4562FB2EE05DBB3D32323ADF445084ED656" "19:13:31,0880612","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0880676","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","Desired Access: Read" "19:13:31,0880756","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0880823","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0880881","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob","SUCCESS","Type: REG_BINARY, Length: 935, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:31,0880955","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656","SUCCESS","" "19:13:31,0881041","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 17, Name: CDD4EEAE6000AC7F40C3802C171E30148030C072" "19:13:31,0881125","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0881192","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","Desired Access: Read" "19:13:31,0881272","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0881337","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0881394","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob","SUCCESS","Type: REG_BINARY, Length: 1 759, Data: 59 00 00 00 01 00 00 00 12 00 00 00 52 00 53 00" "19:13:31,0881468","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072","SUCCESS","" "19:13:31,0881555","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 18, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:31,0881641","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0881705","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:31,0881786","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0881853","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0881911","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 071, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0881984","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:31,0882068","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 19, Name: E06A30801D661F606869D9BC0ACC5EE57C7A48A7" "19:13:31,0882151","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0882219","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","Desired Access: Read" "19:13:31,0882299","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0882363","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0882421","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 102, Data: 19 00 00 00 01 00 00 00 10 00 00 00 B7 B9 C2 BF" "19:13:31,0882494","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\E06A30801D661F606869D9BC0ACC5EE57C7A48A7","SUCCESS","" "19:13:31,0882575","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Index: 20, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:31,0882658","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0882725","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:31,0882802","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0882866","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0882924","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 176, Data: 19 00 00 00 01 00 00 00 10 00 00 00 BB AD 3C 3F" "19:13:31,0882998","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:31,0883085","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates","SUCCESS","" "19:13:31,0883158","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0883226","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0883303","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0883370","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0883434","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs","SUCCESS","" "19:13:31,0883505","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0883569","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0883643","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0883697","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0883758","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs","SUCCESS","" "19:13:31,0884951","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0885041","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0885121","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:31,0885179","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 54, Values: 0" "19:13:31,0885233","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 0, Name: 02FAF3E291435468607857694DF5E45B68851868" "19:13:31,0885317","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0885381","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","Desired Access: Read" "19:13:31,0885461","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0885528","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0885586","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob","SUCCESS","Type: REG_BINARY, Length: 1 559, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0885666","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868","SUCCESS","" "19:13:31,0885766","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 1, Name: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" "19:13:31,0885852","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0885920","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","Desired Access: Read" "19:13:31,0885997","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0886064","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0886122","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob","SUCCESS","Type: REG_BINARY, Length: 1 377, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0886199","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43","SUCCESS","" "19:13:31,0886289","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 2, Name: 06083F593F15A104A069A46BA903D006B7970991" "19:13:31,0886372","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0886439","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","Desired Access: Read" "19:13:31,0886523","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0886587","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0886645","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991\Blob","SUCCESS","Type: REG_BINARY, Length: 1 577, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0886722","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06083F593F15A104A069A46BA903D006B7970991","SUCCESS","" "19:13:31,0886811","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 3, Name: 06F1AA330B927B753A40E68CDF22E34BCBEF3352" "19:13:31,0886895","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0886962","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","Desired Access: Read" "19:13:31,0887039","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0887103","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0887161","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352\Blob","SUCCESS","Type: REG_BINARY, Length: 1 233, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 80 01 00 00" "19:13:31,0887238","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\06F1AA330B927B753A40E68CDF22E34BCBEF3352","SUCCESS","" "19:13:31,0887328","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 4, Name: 07E032E020B72C3F192F0628A2593A19A70F069E" "19:13:31,0887411","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0887478","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","Desired Access: Read" "19:13:31,0887555","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0887620","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0887677","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 484, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0887754","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E","SUCCESS","" "19:13:31,0887857","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 5, Name: 093C61F38B8BDC7D55DF7538020500E125F5C836" "19:13:31,0887940","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0888008","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","Desired Access: Read" "19:13:31,0888085","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0888149","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0888207","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836\Blob","SUCCESS","Type: REG_BINARY, Length: 1 868, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:31,0888283","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\093C61F38B8BDC7D55DF7538020500E125F5C836","SUCCESS","" "19:13:31,0888377","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 6, Name: 1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA" "19:13:31,0888460","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0888527","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","Desired Access: Read" "19:13:31,0888607","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0888668","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0888726","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA\Blob","SUCCESS","Type: REG_BINARY, Length: 1 034, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0888803","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA","SUCCESS","" "19:13:31,0888896","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 7, Name: 2796BAE63F1801E277261BA0D77770028F20EEE4" "19:13:31,0888976","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0889044","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","Desired Access: Read" "19:13:31,0889124","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0889188","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0889246","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 512, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0889319","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4","SUCCESS","" "19:13:31,0889412","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 8, Name: 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E" "19:13:31,0889496","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0889563","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","Desired Access: Read" "19:13:31,0889643","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0889708","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0889762","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 989, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0889839","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E","SUCCESS","" "19:13:31,0889932","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 9, Name: 2BB1F53E550C1DC5F1D4E6B76A464B550602AC21" "19:13:31,0890031","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0890099","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","Desired Access: Read" "19:13:31,0890176","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0890240","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0890298","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21\Blob","SUCCESS","Type: REG_BINARY, Length: 1 317, Data: 7F 00 00 00 01 00 00 00 0C 00 00 00 30 0A 06 08" "19:13:31,0890375","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2BB1F53E550C1DC5F1D4E6B76A464B550602AC21","SUCCESS","" "19:13:31,0890464","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 10, Name: 3679CA35668772304D30A5FB873B0FA77BB70D54" "19:13:31,0890551","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0890615","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","Desired Access: Read" "19:13:31,0890692","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0890756","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0890814","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob","SUCCESS","Type: REG_BINARY, Length: 1 781, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0890891","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54","SUCCESS","" "19:13:31,0890984","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 11, Name: 36B12B49F9819ED74C9EBC380FC6568F5DACB2F7" "19:13:31,0891071","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0891138","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","Desired Access: Read" "19:13:31,0891218","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0891282","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0891340","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 370, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:31,0891417","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\36B12B49F9819ED74C9EBC380FC6568F5DACB2F7","SUCCESS","" "19:13:31,0891584","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 12, Name: 3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F" "19:13:31,0891683","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0891754","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","Desired Access: Read" "19:13:31,0891831","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0891911","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0891969","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F\Blob","SUCCESS","Type: REG_BINARY, Length: 2 512, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0892049","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F","SUCCESS","" "19:13:31,0892145","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 13, Name: 47BEABC922EAE80E78783462A79F45C254FDE68B" "19:13:31,0892232","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0892299","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","Desired Access: Read" "19:13:31,0892376","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0892437","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0892495","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0892572","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B","SUCCESS","" "19:13:31,0892671","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 14, Name: 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5" "19:13:31,0892754","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0892822","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","Desired Access: Read" "19:13:31,0892899","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0892963","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0893021","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob","SUCCESS","Type: REG_BINARY, Length: 1 760, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0893098","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5","SUCCESS","" "19:13:31,0893187","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 15, Name: 503006091D97D4F5AE39F7CBE7927D7D652D3431" "19:13:31,0893271","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0893338","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","Desired Access: Read" "19:13:31,0893415","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0893479","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0893540","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431\Blob","SUCCESS","Type: REG_BINARY, Length: 1 613, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0893617","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\503006091D97D4F5AE39F7CBE7927D7D652D3431","SUCCESS","" "19:13:31,0893723","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 16, Name: 51501FBFCE69189D609CFAF140C576755DCC1FDF" "19:13:31,0893806","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0893874","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","Desired Access: Read" "19:13:31,0893957","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0894021","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0894079","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF\Blob","SUCCESS","Type: REG_BINARY, Length: 1 808, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:31,0894156","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\51501FBFCE69189D609CFAF140C576755DCC1FDF","SUCCESS","" "19:13:31,0894246","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 17, Name: 590D2D7D884F402E617EA562321765CF17D894E9" "19:13:31,0894329","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0894397","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","Desired Access: Read" "19:13:31,0894477","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0894541","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0894602","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 345, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:31,0894676","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\590D2D7D884F402E617EA562321765CF17D894E9","SUCCESS","" "19:13:31,0894765","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 18, Name: 5D003860F002ED829DEAA41868F788186D62127F" "19:13:31,0894849","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0894913","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","Desired Access: Read" "19:13:31,0895025","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0895093","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0895150","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F\Blob","SUCCESS","Type: REG_BINARY, Length: 1 679, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0895230","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5D003860F002ED829DEAA41868F788186D62127F","SUCCESS","" "19:13:31,0895336","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 19, Name: 5F3B8CF2F810B37D78B4CEEC1919C37334B9C774" "19:13:31,0895423","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0895493","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","Desired Access: Read" "19:13:31,0895574","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0895638","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0895695","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774\Blob","SUCCESS","Type: REG_BINARY, Length: 1 335, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0895772","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5F3B8CF2F810B37D78B4CEEC1919C37334B9C774","SUCCESS","" "19:13:31,0895862","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 20, Name: 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25" "19:13:31,0895946","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0896013","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","Desired Access: Read" "19:13:31,0896090","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0896154","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0896212","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 391, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0896289","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25","SUCCESS","" "19:13:31,0896382","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 21, Name: 6252DC40F71143A22FDE9EF7348E064251B18118" "19:13:31,0896465","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0896533","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","Desired Access: Read" "19:13:31,0896610","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0896674","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0896731","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118\Blob","SUCCESS","Type: REG_BINARY, Length: 1 190, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:31,0896808","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118","SUCCESS","" "19:13:31,0896898","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 22, Name: 742C3192E607E424EB4549542BE1BBC53E6174E2" "19:13:31,0896982","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0897049","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","Desired Access: Read" "19:13:31,0897129","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0897196","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0897254","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 074, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0897328","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2","SUCCESS","" "19:13:31,0897424","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 23, Name: 75E0ABB6138512271C04F85FDDDE38E4B7242EFE" "19:13:31,0897508","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0897575","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","Desired Access: Read" "19:13:31,0897652","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0897716","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0897774","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 555, Data: 7F 00 00 00 01 00 00 00 16 00 00 00 30 14 06 08" "19:13:31,0897851","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\75E0ABB6138512271C04F85FDDDE38E4B7242EFE","SUCCESS","" "19:13:31,0897950","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 24, Name: 7E04DE896A3E666D00E687D33FFAD93BE83D349E" "19:13:31,0898034","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0898101","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","Desired Access: Read" "19:13:31,0898181","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0898248","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0898303","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 059, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0898380","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\7E04DE896A3E666D00E687D33FFAD93BE83D349E","SUCCESS","" "19:13:31,0898473","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 25, Name: 8782C6C304353BCFD29692D2593E7D44D934FF11" "19:13:31,0898560","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0898624","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","Desired Access: Read" "19:13:31,0898704","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0898781","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0898839","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11\Blob","SUCCESS","Type: REG_BINARY, Length: 1 354, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0898916","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8782C6C304353BCFD29692D2593E7D44D934FF11","SUCCESS","" "19:13:31,0899076","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 26, Name: 89DF74FE5CF40F4A80F9E3377D54DA91E101318E" "19:13:31,0899166","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0899236","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","Desired Access: Read" "19:13:31,0899317","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0899374","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0899435","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 472, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0899515","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\89DF74FE5CF40F4A80F9E3377D54DA91E101318E","SUCCESS","" "19:13:31,0899602","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 27, Name: 8CF427FD790C3AD166068DE81E57EFBB932272D4" "19:13:31,0899685","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0899753","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","Desired Access: Read" "19:13:31,0899830","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0899894","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0899955","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 639, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:31,0900051","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8CF427FD790C3AD166068DE81E57EFBB932272D4","SUCCESS","" "19:13:31,0900147","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 28, Name: 91C6D6EE3E8AC86384E548C299295C756C817B81" "19:13:31,0900234","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0900301","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","Desired Access: Read" "19:13:31,0900378","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0900445","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0900503","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob","SUCCESS","Type: REG_BINARY, Length: 1 515, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0900577","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81","SUCCESS","" "19:13:31,0900744","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 29, Name: 97817950D81C9670CC34D809CF794431367EF474" "19:13:31,0900834","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0900901","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","Desired Access: Read" "19:13:31,0900981","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0901045","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0901106","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 050, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 04 00 00" "19:13:31,0901183","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474","SUCCESS","" "19:13:31,0901276","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 30, Name: A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436" "19:13:31,0901360","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0901427","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","Desired Access: Read" "19:13:31,0901504","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0901565","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0901626","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob","SUCCESS","Type: REG_BINARY, Length: 1 369, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0901703","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436","SUCCESS","" "19:13:31,0901815","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 31, Name: AD7E1C28B064EF8F6003402014C3D0E3370EB58A" "19:13:31,0901898","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0901966","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","Desired Access: Read" "19:13:31,0902046","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0902113","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0902171","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0902248","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A","SUCCESS","" "19:13:31,0902338","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 32, Name: AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4" "19:13:31,0902421","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0902488","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","Desired Access: Read" "19:13:31,0902565","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0902662","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0902723","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4\Blob","SUCCESS","Type: REG_BINARY, Length: 2 025, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0902803","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4","SUCCESS","" "19:13:31,0902896","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 33, Name: B1BC968BD4F49D622AA89A81F2150152A41D829C" "19:13:31,0902979","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0903047","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","Desired Access: Read" "19:13:31,0903127","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0903194","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0903249","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 461, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:31,0903322","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C","SUCCESS","" "19:13:31,0903419","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 34, Name: B31EB1B740E36C8402DADC37D44DF5D4674952F9" "19:13:31,0903502","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0903569","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","Desired Access: Read" "19:13:31,0903646","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0903710","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0903771","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 712, Data: 7F 00 00 00 01 00 00 00 2C 00 00 00 30 2A 06 0A" "19:13:31,0903848","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B31EB1B740E36C8402DADC37D44DF5D4674952F9","SUCCESS","" "19:13:31,0903945","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 35, Name: B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E" "19:13:31,0904028","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0904095","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","Desired Access: Read" "19:13:31,0904176","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0904240","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0904297","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 498, Data: 09 00 00 00 01 00 00 00 54 00 00 00 30 52 06 08" "19:13:31,0904371","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B51C067CEE2B0C3DF855AB2D92F4FE39D4E70F0E","SUCCESS","" "19:13:31,0904461","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 36, Name: CA3AFBCF1240364B44B216208880483919937CF7" "19:13:31,0904544","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0904612","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","Desired Access: Read" "19:13:31,0904689","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0904753","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0904811","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 937, Data: 09 00 00 00 01 00 00 00 3E 00 00 00 30 3C 06 08" "19:13:31,0904888","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CA3AFBCF1240364B44B216208880483919937CF7","SUCCESS","" "19:13:31,0904993","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 37, Name: CABD2A79A1076A31F21D253635CB039D4329A5E8" "19:13:31,0905080","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0905147","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","Desired Access: Read" "19:13:31,0905224","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0905288","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0905346","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 717, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:31,0905423","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8","SUCCESS","" "19:13:31,0905510","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 38, Name: CF9E876DD3EBFC422697A3B5A37AA076A9062348" "19:13:31,0905593","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0905660","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","Desired Access: Read" "19:13:31,0905734","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0905802","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0905859","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348\Blob","SUCCESS","Type: REG_BINARY, Length: 1 421, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 08 00 00" "19:13:31,0905933","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CF9E876DD3EBFC422697A3B5A37AA076A9062348","SUCCESS","" "19:13:31,0906039","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 39, Name: D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0" "19:13:31,0906122","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0906190","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","Desired Access: Read" "19:13:31,0906267","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0906331","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0906389","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 150, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0906466","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0","SUCCESS","" "19:13:31,0906568","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 40, Name: D1EB23A46D17D68FD92564C2F1F1601764D8E349" "19:13:31,0906652","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0906719","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","Desired Access: Read" "19:13:31,0906796","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0906863","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0906921","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob","SUCCESS","Type: REG_BINARY, Length: 1 545, Data: 53 00 00 00 01 00 00 00 43 00 00 00 30 41 30 22" "19:13:31,0906995","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349","SUCCESS","" "19:13:31,0907085","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 41, Name: D23209AD23D314232174E40D7F9D62139786633A" "19:13:31,0907168","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0907235","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","Desired Access: Read" "19:13:31,0907312","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0907376","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0907434","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 197, Data: 09 00 00 00 01 00 00 00 20 00 00 00 30 1E 06 08" "19:13:31,0907511","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A","SUCCESS","" "19:13:31,0907655","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 42, Name: D4DE20D05E66FC53FE1A50882C78DB2852CAE474" "19:13:31,0907742","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0907813","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","Desired Access: Read" "19:13:31,0907890","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0907957","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0908015","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob","SUCCESS","Type: REG_BINARY, Length: 1 460, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:31,0908092","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474","SUCCESS","" "19:13:31,0908188","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 43, Name: D69B561148F01C77C54578C10926DF5B856976AD" "19:13:31,0908271","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0908339","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","Desired Access: Read" "19:13:31,0908412","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0908476","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0908534","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD\Blob","SUCCESS","Type: REG_BINARY, Length: 1 363, Data: 53 00 00 00 01 00 00 00 40 00 00 00 30 3E 30 1F" "19:13:31,0908611","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD","SUCCESS","" "19:13:31,0908701","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 44, Name: D8C5388AB7301B1B6ED47AE645253A6F9F1A2761" "19:13:31,0908788","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0908855","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","Desired Access: Read" "19:13:31,0908929","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0908993","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0909051","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761\Blob","SUCCESS","Type: REG_BINARY, Length: 1 855, Data: 09 00 00 00 01 00 00 00 2A 00 00 00 30 28 06 08" "19:13:31,0909131","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D8C5388AB7301B1B6ED47AE645253A6F9F1A2761","SUCCESS","" "19:13:31,0909221","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 45, Name: DAC9024F54D8F6DF94935FB1732638CA6AD77C13" "19:13:31,0909301","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0909368","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","Desired Access: Read" "19:13:31,0909445","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0909509","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0909570","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob","SUCCESS","Type: REG_BINARY, Length: 1 264, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 01 B3" "19:13:31,0909644","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13","SUCCESS","" "19:13:31,0909734","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 46, Name: DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212" "19:13:31,0909817","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0909884","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","Desired Access: Read" "19:13:31,0909961","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0910042","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0910099","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob","SUCCESS","Type: REG_BINARY, Length: 1 306, Data: 7E 00 00 00 01 00 00 00 08 00 00 00 00 C0 03 2F" "19:13:31,0910176","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212","SUCCESS","" "19:13:31,0910337","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 47, Name: DE3F40BD5093D39B6C60F6DABC076201008976C9" "19:13:31,0910426","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0910494","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","Desired Access: Read" "19:13:31,0910571","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0910638","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0910706","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9\Blob","SUCCESS","Type: REG_BINARY, Length: 1 958, Data: 4B 00 00 00 01 00 00 00 02 00 00 00 00 00 04 00" "19:13:31,0910786","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9","SUCCESS","" "19:13:31,0910879","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 48, Name: DF3C24F9BFD666761B268073FE06D1CC8D4F82A4" "19:13:31,0910965","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0911033","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","Desired Access: Read" "19:13:31,0911110","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0911174","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0911232","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\Blob","SUCCESS","Type: REG_BINARY, Length: 1 378, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0911308","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4","SUCCESS","" "19:13:31,0911398","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 49, Name: DF717EAA4AD94EC9558499602D48DE5FBCF03A25" "19:13:31,0911482","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0911549","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","Desired Access: Read" "19:13:31,0911626","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0911690","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0911748","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25\Blob","SUCCESS","Type: REG_BINARY, Length: 1 947, Data: 5C 00 00 00 01 00 00 00 04 00 00 00 00 10 00 00" "19:13:31,0911825","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25","SUCCESS","" "19:13:31,0911918","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 50, Name: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46" "19:13:31,0912001","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0912065","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","Desired Access: Read" "19:13:31,0912142","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0912210","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0912267","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46\Blob","SUCCESS","Type: REG_BINARY, Length: 1 482, Data: 09 00 00 00 01 00 00 00 22 00 00 00 30 20 06 08" "19:13:31,0912341","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46","SUCCESS","" "19:13:31,0912431","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 51, Name: F373B387065A28848AF2F34ACE192BDDC78E9CAC" "19:13:31,0912514","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0912582","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","Desired Access: Read" "19:13:31,0912656","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0912723","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0912781","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC\Blob","SUCCESS","Type: REG_BINARY, Length: 1 917, Data: 09 00 00 00 01 00 00 00 34 00 00 00 30 32 06 08" "19:13:31,0912854","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC","SUCCESS","" "19:13:31,0912944","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 52, Name: F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7" "19:13:31,0913028","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0913095","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","Desired Access: Read" "19:13:31,0913182","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0913246","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0913303","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7\Blob","SUCCESS","Type: REG_BINARY, Length: 1 400, Data: 7F 00 00 00 01 00 00 00 36 00 00 00 30 34 06 08" "19:13:31,0913380","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7","SUCCESS","" "19:13:31,0913473","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Index: 53, Name: FE45659B79035B98A161B5512EACDA580948224D" "19:13:31,0913560","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0913627","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","Desired Access: Read" "19:13:31,0913704","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0913768","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0913826","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D\Blob","SUCCESS","Type: REG_BINARY, Length: 1 529, Data: 09 00 00 00 01 00 00 00 40 00 00 00 30 3E 06 08" "19:13:31,0913900","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D","SUCCESS","" "19:13:31,0913993","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates","SUCCESS","" "19:13:31,0914067","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0914134","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0914211","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0914266","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0914330","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs","SUCCESS","" "19:13:31,0914397","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0914461","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0914532","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0914586","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0914650","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs","SUCCESS","" "19:13:31,0919952","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:16, LastAccessTime: 2021. 02. 13. 20:09:39, LastWriteTime: 2017. 09. 29. 15:42:16, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 114 688, EndOfFile: 110 608, FileAttributes: A" "19:13:31,0920731","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,0921152","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\gpapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,0921383","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:31,0921848","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Image Base: 0x6df30000, Image Size: 0x1e000" "19:13:31,0922701","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","" "19:13:31,0923653","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0923727","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0923878","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Diagnostics","NAME NOT FOUND","Desired Access: Read" "19:13:31,0924029","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0924083","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0924192","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read" "19:13:31,0924311","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0924385","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel","NAME NOT FOUND","Length: 144" "19:13:31,0924484","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","" "19:13:31,0924558","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0924612","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0924718","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\System","REPARSE","Desired Access: Read" "19:13:31,0924811","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","Desired Access: Read" "19:13:31,0924911","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0924975","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel","NAME NOT FOUND","Length: 144" "19:13:31,0925074","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","" "19:13:31,0925167","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0925222","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0925308","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:31,0925404","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0925462","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:31,0925546","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:31,0925741","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0925796","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0925898","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates","REPARSE","Desired Access: Read" "19:13:31,0925982","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates","SUCCESS","Desired Access: Read" "19:13:31,0926075","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0926270","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0926328","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0926424","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root","REPARSE","Desired Access: Read" "19:13:31,0926508","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Desired Access: Read" "19:13:31,0926591","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0926668","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0926735","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0926822","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0926880","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0926950","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates","SUCCESS","" "19:13:31,0927024","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0927088","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0927162","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0927217","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0927284","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs","SUCCESS","" "19:13:31,0927351","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0927415","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0927489","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0927544","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0927608","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs","SUCCESS","" "19:13:31,0927666","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:31,0927871","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0927938","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0928018","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0928073","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0928140","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates","SUCCESS","" "19:13:31,0928211","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0928275","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0928349","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0928403","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0928467","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs","SUCCESS","" "19:13:31,0928535","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0928599","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0928669","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0928721","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0928785","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs","SUCCESS","" "19:13:31,0928961","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0929025","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0929102","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0929157","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0929224","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:31,0929292","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0929353","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0929426","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0929481","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0929542","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:31,0929721","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0929811","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0929904","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0929962","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0930058","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:31,0930270","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0930344","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0930424","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0930478","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0930549","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates","SUCCESS","" "19:13:31,0930619","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0930687","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0930757","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0930812","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0930879","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs","SUCCESS","" "19:13:31,0930947","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0931011","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0931078","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0931136","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0931200","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs","SUCCESS","" "19:13:31,0931408","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0931476","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0931550","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0931604","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0931668","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0931739","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0931803","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0931870","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0931928","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0931992","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0932060","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0932124","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0932194","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0932249","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0932316","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0932441","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0932502","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0932627","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Diagnostics","NAME NOT FOUND","Desired Access: Read" "19:13:31,0932746","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0932804","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0932919","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","Desired Access: Read" "19:13:31,0933022","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0933092","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel","NAME NOT FOUND","Length: 144" "19:13:31,0933176","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon","SUCCESS","" "19:13:31,0933243","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0933298","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0933397","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\System","REPARSE","Desired Access: Read" "19:13:31,0933480","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","Desired Access: Read" "19:13:31,0933570","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0933631","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel","NAME NOT FOUND","Length: 144" "19:13:31,0933708","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS","" "19:13:31,0933779","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0933833","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0933917","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:31,0933997","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0934054","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:31,0934131","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:31,0934516","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0934574","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0934667","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0934750","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0934856","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0934911","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,0935017","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates","SUCCESS","Desired Access: Read" "19:13:31,0935106","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0935174","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0935318","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0935389","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:31,0935488","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0935552","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0935626","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0935681","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0935748","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0935815","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0935879","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0935953","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0936008","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0936072","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0936139","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0936203","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0936277","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0936332","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0936396","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0936454","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0936662","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0936733","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0936810","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0936864","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0936931","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0937012","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0937079","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0937153","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0937210","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0937278","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0937345","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0937412","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0937483","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0937541","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0937605","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0937717","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0937775","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0937878","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\trust","REPARSE","Desired Access: Read" "19:13:31,0937961","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Desired Access: Read" "19:13:31,0938048","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0938121","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0938185","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0938259","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0938317","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0938384","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates","SUCCESS","" "19:13:31,0938458","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0938522","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0938596","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0938654","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0938721","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs","SUCCESS","" "19:13:31,0938792","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0938859","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0938930","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0938984","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0939048","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs","SUCCESS","" "19:13:31,0939109","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:31,0939350","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0939423","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0939500","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0939555","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0939622","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates","SUCCESS","" "19:13:31,0939693","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0939757","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0939831","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0939882","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0939946","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs","SUCCESS","" "19:13:31,0940023","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0940087","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0940158","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0940209","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0940273","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs","SUCCESS","" "19:13:31,0940450","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0940517","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0940597","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0940652","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0940713","EasyAntiCheat.exe","2900","RegEnumKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0" "19:13:31,0940799","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0940867","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","Desired Access: Read" "19:13:31,0940957","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0941030","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0941088","EasyAntiCheat.exe","2900","RegQueryValue","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 716, Data: 4B 00 00 00 01 00 00 00 44 00 00 00 35 00 34 00" "19:13:31,0941171","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0","SUCCESS","" "19:13:31,0941293","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0941367","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0941434","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0941511","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0941566","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0941630","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0941697","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0941758","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0941832","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0941883","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0941948","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0942159","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0942227","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:31,0942332","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0942397","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0942467","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0942522","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0942589","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0942660","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0942721","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0942794","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0942849","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0942913","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0942980","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0943044","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0943118","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0943173","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0943234","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0943291","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0943484","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0943551","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0943737","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:31,0943795","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 4, Values: 0" "19:13:31,0943856","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 0, Name: 109F1CAED645BB78B3EA2B94C0697C740733031C" "19:13:31,0943939","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0944007","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","Desired Access: Read" "19:13:31,0944090","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0944170","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0944234","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob","SUCCESS","Type: REG_BINARY, Length: 1 147, Data: 19 00 00 00 01 00 00 00 10 00 00 00 83 B6 53 18" "19:13:31,0944315","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C","SUCCESS","" "19:13:31,0944404","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 1, Name: C415CBF62AF1B513B81ED7B707BDE0A954E2B813" "19:13:31,0944491","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0944558","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","Desired Access: Read" "19:13:31,0944645","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0944709","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0944767","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813\Blob","SUCCESS","Type: REG_BINARY, Length: 1 091, Data: 04 00 00 00 01 00 00 00 10 00 00 00 E1 3A 7C 82" "19:13:31,0944844","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\C415CBF62AF1B513B81ED7B707BDE0A954E2B813","SUCCESS","" "19:13:31,0944930","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 2, Name: D559A586669B08F46A30A133F8A9ED3D038E2EA8" "19:13:31,0945023","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0945091","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","Desired Access: Read" "19:13:31,0945174","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0945238","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0945296","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob","SUCCESS","Type: REG_BINARY, Length: 1 095, Data: 04 00 00 00 01 00 00 00 10 00 00 00 AC D8 0E A2" "19:13:31,0945370","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8","SUCCESS","" "19:13:31,0945453","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Index: 3, Name: FEE449EE0E3965A5246F000E87FDE2A065FD89D4" "19:13:31,0945536","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0945601","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","Desired Access: Read" "19:13:31,0945684","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0945748","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0945809","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob","SUCCESS","Type: REG_BINARY, Length: 566, Data: 19 00 00 00 01 00 00 00 10 00 00 00 ED BC CD D5" "19:13:31,0945883","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4","SUCCESS","" "19:13:31,0945969","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0946043","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0946107","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0946188","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0946245","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0946300","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Index: 0, Name: A377D1B1C0538833035211F4083D00FECC414DAB" "19:13:31,0946380","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0946444","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","Desired Access: Read" "19:13:31,0946524","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0946588","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0946649","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob","SUCCESS","Type: REG_BINARY, Length: 481, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A3 77 D1 B1" "19:13:31,0946723","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB","SUCCESS","" "19:13:31,0946810","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0946884","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0946951","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0947028","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0947082","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0947147","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0947400","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0947458","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0947570","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\CA","REPARSE","Desired Access: Read" "19:13:31,0947660","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Desired Access: Read" "19:13:31,0947753","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0947830","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0947894","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0947971","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0948029","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0948096","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates","SUCCESS","" "19:13:31,0948166","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0948231","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0948304","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0948359","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0948423","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs","SUCCESS","" "19:13:31,0948490","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0948555","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0948625","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0948683","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0948744","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs","SUCCESS","" "19:13:31,0948805","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:31,0948991","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0949058","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0949135","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0949190","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0949257","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates","SUCCESS","" "19:13:31,0949324","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0949388","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0949465","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0949520","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0949584","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs","SUCCESS","" "19:13:31,0949651","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0949712","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0949789","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0949844","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0949905","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs","SUCCESS","" "19:13:31,0950174","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0950242","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0950319","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0950373","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0950437","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0950508","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0950572","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0950646","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0950700","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0950764","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0950832","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0950893","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0950963","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0951018","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0951079","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0951191","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0951258","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,0951364","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0951428","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0951499","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0951553","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0951617","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0951688","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0951765","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0951839","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0951893","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0951954","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0952025","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0952086","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0952160","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0952211","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0952275","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0952333","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0952503","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0952567","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0952650","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0952705","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0952769","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0952839","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0952904","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0952977","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0953032","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0953096","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0953163","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0953228","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0953301","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0953353","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,0953410","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:31,0953494","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0953558","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:31,0953641","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0953709","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,0953766","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:31,0953843","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:31,0954135","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0954299","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0954356","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0954469","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read" "19:13:31,0954559","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,0954652","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0954729","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0954793","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0954873","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0954927","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0955004","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0955075","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0955139","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0955216","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0955271","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0955335","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0955402","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0955466","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0955540","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0955594","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0955659","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0955716","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,0955902","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0955970","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0956047","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0956104","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0956169","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,0956239","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0956300","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0956374","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0956428","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0956493","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,0956557","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0956621","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0956695","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0956749","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0956813","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,0956974","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0957041","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0957115","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0957169","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0957233","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0957304","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0957368","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0957439","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0957493","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0957557","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0957625","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0957689","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0957759","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0957814","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0957875","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0957997","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0958064","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:31,0958167","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0958228","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0958301","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0958356","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0958420","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0958491","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0958555","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0958625","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0958680","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0958744","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0958811","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0958876","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0958946","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0959001","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0959062","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0959119","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0959292","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0959369","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0959450","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0959504","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0959568","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0959639","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0959703","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0959774","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0959828","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0959892","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0959960","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0960126","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0960207","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0960261","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0960325","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0960441","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0960498","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0960604","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPeople","REPARSE","Desired Access: Read" "19:13:31,0960688","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Desired Access: Read" "19:13:31,0960777","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0960851","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0960915","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0960989","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0961047","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0961114","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0961182","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0961246","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0961319","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0961374","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0961438","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0961506","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0961570","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0961643","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0961698","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0961762","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0961820","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:31,0961990","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0962060","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Desired Access: Read" "19:13:31,0962134","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0962189","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0962256","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates","SUCCESS","" "19:13:31,0962323","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0962388","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Desired Access: Read" "19:13:31,0962461","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0962516","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0962580","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs","SUCCESS","" "19:13:31,0962647","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0962711","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Desired Access: Read" "19:13:31,0962782","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0962837","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,0962897","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs","SUCCESS","" "19:13:31,0963067","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0963135","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:31,0963237","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0963295","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertLastSyncTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 5E FF 14 C3 4E 31 D7 01" "19:13:31,0963375","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:31,0963738","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0963795","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,0963885","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,0963962","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,0964065","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0964132","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","NAME NOT FOUND","Desired Access: Read" "19:13:31,0964219","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,0964289","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0964354","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:31,0964434","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0964491","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertEncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:31,0964559","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertEncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:31,0964671","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\DisallowedCertEncodedCtl","SUCCESS","Type: REG_BINARY, Length: 5 906, Data: 30 82 17 0E 06 09 2A 86 48 86 F7 0D 01 07 02 A0" "19:13:31,0965210","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:31,0968154","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\AutoFlags","NAME NOT FOUND","Length: 144" "19:13:31,0968712","EasyAntiCheat.exe","2900","QueryNameInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe","SUCCESS","Name: \Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe" "19:13:31,0968879","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableAutoFlushProcessNameList","NAME NOT FOUND","Length: 144" "19:13:31,0968946","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\AutoFlushFirstDeltaSeconds","NAME NOT FOUND","Length: 144" "19:13:31,0968998","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\AutoFlushNextDeltaSeconds","NAME NOT FOUND","Length: 144" "19:13:31,0969694","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0969755","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0969870","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0969992","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0970066","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0970178","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0970245","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0970374","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0970438","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx","NAME NOT FOUND","Desired Access: Read" "19:13:31,0970531","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0970595","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0970691","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0970758","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0970874","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0970938","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx","NAME NOT FOUND","Desired Access: Read" "19:13:31,0971021","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0971082","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0971156","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0971236","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,0971291","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,0971394","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,0971480","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,0971544","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,0971634","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0971701","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,0971807","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0971871","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo","NAME NOT FOUND","Desired Access: Read" "19:13:31,0971952","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,0972013","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,0972099","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0972166","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,0972269","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,0972333","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo","NAME NOT FOUND","Desired Access: Read" "19:13:31,0972423","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,0972484","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,0972558","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,0975011","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","REPARSE","Desired Access: Read" "19:13:31,0975146","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","Desired Access: Read" "19:13:31,0975287","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Providers","SUCCESS","" "19:13:31,0975380","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","REPARSE","Desired Access: Read" "19:13:31,0975480","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","Desired Access: Read" "19:13:31,0975589","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\System\CurrentControlSet\Control\Cryptography\Configuration","SUCCESS","" "19:13:31,1005891","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1005971","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1006087","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1006180","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1006295","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1006356","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1006452","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1006571","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1006811","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1006872","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1006962","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1007039","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1007148","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1007203","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1007305","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1007405","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1007482","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1007549","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","" "19:13:31,1008136","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1008197","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1008319","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","REPARSE","Desired Access: Read" "19:13:31,1008431","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS","Desired Access: Read" "19:13:31,1008524","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1008588","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 86, Data: %systemroot%\system32\config\systemprofile" "19:13:31,1008668","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 86, Data: %systemroot%\system32\config\systemprofile" "19:13:31,1008758","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18","SUCCESS","" "19:13:31,1009085","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1009143","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1009236","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1009313","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1009416","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1009470","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1009557","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read" "19:13:31,1009647","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1009717","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1011289","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1011712","EasyAntiCheat.exe","2900","QuerySecurityFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead","SUCCESS","Information: DACL" "19:13:31,1011831","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\AppContainerUserCertRead","SUCCESS","" "19:13:31,1012694","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1013088","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1013297","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1013441","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1013553","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","" "19:13:31,1013823","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1013903","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read" "19:13:31,1014005","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1014073","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\Certificates","NAME NOT FOUND","Desired Access: Read" "19:13:31,1014740","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1014935","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1015128","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1015259","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1015365","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","" "19:13:31,1015609","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1015689","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\CRLs","NAME NOT FOUND","Desired Access: Read" "19:13:31,1016337","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1016767","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1016937","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1017075","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1017184","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","" "19:13:31,1017421","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1017501","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\CTLs","NAME NOT FOUND","Desired Access: Read" "19:13:31,1018136","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1018550","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1018717","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1018842","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1018945","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","" "19:13:31,1019179","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1019256","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\Keys","NAME NOT FOUND","Desired Access: Read" "19:13:31,1019358","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","" "19:13:31,1020118","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1020353","EasyAntiCheat.exe","2900","NotifyChangeDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My","CANCELLED","Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_DIR_NAME, FILE_NOTIFY_CHANGE_SIZE, FILE_NOTIFY_CHANGE_LAST_WRITE" "19:13:31,1020516","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1020593","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\Certificates","NAME NOT FOUND","Desired Access: Read" "19:13:31,1021244","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1021427","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1021597","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1021722","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1021825","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates","SUCCESS","" "19:13:31,1022065","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1022142","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\CRLs","NAME NOT FOUND","Desired Access: Read" "19:13:31,1022761","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1022938","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1023098","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1023220","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1023322","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs","SUCCESS","" "19:13:31,1023553","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1023627","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\My\CTLs","NAME NOT FOUND","Desired Access: Read" "19:13:31,1024230","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1024407","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *, 2: ." "19:13:31,1024564","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","FileInformationClass: FileBothDirectoryInformation, 1: .." "19:13:31,1024682","EasyAntiCheat.exe","2900","QueryDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:31,1024785","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs","SUCCESS","" "19:13:31,1026036","EasyAntiCheat.exe","2900","QueryOpen","C:\Program Files (x86)\EasyAntiCheat\cryptnet.dll","NAME NOT FOUND","" "19:13:31,1026738","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 20:11:35, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 139 264, EndOfFile: 136 704, FileAttributes: A" "19:13:31,1027469","EasyAntiCheat.exe","2900","CreateFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1027777","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\cryptnet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,1027983","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:31,1028348","EasyAntiCheat.exe","2900","Load Image","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Image Base: 0x70900000, Image Size: 0x26000" "19:13:31,1029676","EasyAntiCheat.exe","2900","CloseFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","" "19:13:31,1030661","EasyAntiCheat.exe","2900","QueryOpen","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:08:58, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 933 312, EndOfFile: 1 930 224, FileAttributes: A" "19:13:31,1031225","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1031293","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1031418","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\TVO","NAME NOT FOUND","Desired Access: Read" "19:13:31,1031623","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1031677","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1031780","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,1031902","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1031979","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,1032082","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1032155","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,1032284","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1032351","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\UrlDllGetObjectUrl","NAME NOT FOUND","Desired Access: Read" "19:13:31,1032447","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,1032514","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,1032611","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1032678","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,1032790","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1032854","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\UrlDllGetObjectUrl","NAME NOT FOUND","Desired Access: Read" "19:13:31,1032941","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,1033002","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,1033079","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,1033210","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1033268","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1033377","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","REPARSE","Desired Access: Read" "19:13:31,1033467","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots","NAME NOT FOUND","Desired Access: Read" "19:13:31,1033573","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1033627","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1033727","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\AuthRoot","REPARSE","Desired Access: Read" "19:13:31,1033807","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","Desired Access: Read" "19:13:31,1033903","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1033974","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot\DisableRootAutoUpdate","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:31,1034060","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:31,1034141","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1034211","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:31,1034304","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1034362","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\SyncDeltaTime","NAME NOT FOUND","Length: 144" "19:13:31,1034429","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\Flags","NAME NOT FOUND","Length: 144" "19:13:31,1034487","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\RootDirUrl","NAME NOT FOUND","Length: 144" "19:13:31,1034574","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:31,1034647","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1034718","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:31,1034804","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1034865","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\LastSyncTime","SUCCESS","Type: REG_BINARY, Length: 8, Data: 13 FA 33 C3 4E 31 D7 01" "19:13:31,1034955","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:31,1035247","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1035308","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1035398","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1035478","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1035584","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1035651","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","NAME NOT FOUND","Desired Access: Read" "19:13:31,1035738","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1035808","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1035873","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","Desired Access: Read" "19:13:31,1035956","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1036014","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:31,1036873","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl","BUFFER OVERFLOW","Length: 144" "19:13:31,1037637","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl","SUCCESS","Type: REG_BINARY, Length: 152 788, Data: 30 83 02 54 CF 06 09 2A 86 48 86 F7 0D 01 07 02" "19:13:31,1051652","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate","SUCCESS","" "19:13:31,1064658","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1064735","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1064876","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Desired Access: Read" "19:13:31,1065007","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1065084","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 0, Name: EncodingType 0" "19:13:31,1065190","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1065264","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Desired Access: Read" "19:13:31,1065386","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1065453","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy","NAME NOT FOUND","Desired Access: Read" "19:13:31,1065553","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0","SUCCESS","" "19:13:31,1065620","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Index: 1, Name: EncodingType 1" "19:13:31,1065713","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1065780","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Desired Access: Read" "19:13:31,1065889","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1065954","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy","NAME NOT FOUND","Desired Access: Read" "19:13:31,1066040","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 1","SUCCESS","" "19:13:31,1066101","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","NO MORE ENTRIES","Index: 2, Length: 288" "19:13:31,1066178","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID","SUCCESS","" "19:13:31,1067050","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1067111","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1067204","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1067288","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1067397","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1067451","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1067541","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1067641","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1067871","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1067929","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1068016","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1068090","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1068199","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1068250","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1068346","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1068442","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1068510","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1068571","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1068657","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1068712","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1068821","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1068907","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1069061","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1069116","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1069199","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1069270","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1069379","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1069430","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1069520","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1069616","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1069687","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1069738","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1069838","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1069921","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1070447","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1070505","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1070591","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1070662","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1070764","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1070816","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1070909","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1070995","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1071063","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1071143","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1071210","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1071300","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1071367","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1071460","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1071518","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1071582","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1071656","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1071720","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1071797","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1071852","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1071913","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1071983","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1072047","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1072121","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1072176","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1072240","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1072301","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1072618","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1072676","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1072763","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1072833","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1072929","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1072984","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1073061","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,1073138","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1073202","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1073272","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1073343","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1073449","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1073516","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1073600","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1073654","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1073718","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1073789","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1073856","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1073930","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1073985","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1074045","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1074116","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1074183","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1074254","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1074308","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1074373","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1074430","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1074539","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1074594","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1074700","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1074783","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1074892","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1074947","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1075062","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1075142","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1075229","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1075296","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1075380","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1075431","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1075534","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1075611","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1075755","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1075809","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1075893","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1075963","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1076060","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1076111","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1076198","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1076284","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1076355","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1076406","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1076505","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1076582","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1076714","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1076768","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1076868","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1076948","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1077028","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1077112","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1077176","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1077266","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1077333","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1077426","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1077480","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1077548","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1077622","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1077686","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1077766","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1077817","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1077885","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1077952","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1078019","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1078093","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1078148","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1078208","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:31,1078295","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1078359","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:31,1078446","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1078523","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1078581","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:31,1078664","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:31,1078911","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1078975","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1079116","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1079177","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1079293","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1079379","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1079472","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1079552","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1079620","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1079703","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1079761","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1079828","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1079899","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1079966","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1080053","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1080107","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1080171","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1080242","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1080309","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1080383","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1080434","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1080502","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1080559","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1080668","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1080723","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1080826","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1080912","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1081021","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1081076","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1081175","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1081255","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1081336","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1081403","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,1081522","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1081576","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1081676","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1081756","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1081829","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1081910","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1081974","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1082064","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1082131","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1082211","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1082269","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1082333","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1082404","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1082471","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1082542","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1082596","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1082660","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1082731","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1082795","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1082869","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1082920","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1082984","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1083045","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,1083250","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1083318","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1083391","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1083446","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1083510","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1083577","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1083642","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1083712","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1083767","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1083831","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1083898","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1083959","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1084030","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1084081","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1084145","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1084277","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1084341","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1084440","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1084504","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1084575","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1084629","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1084690","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1084761","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1084825","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1084892","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1084947","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1085018","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1085088","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1085152","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1085220","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1085274","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1085335","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1085393","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1085637","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1085704","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1085778","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1085832","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1085900","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1085967","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1086031","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1086102","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1086153","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1086217","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1086284","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1086349","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1086419","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1086470","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1086531","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:31,1086615","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1086679","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:31,1086759","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1086826","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1086887","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:31,1086968","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:31,1087218","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1087397","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1087455","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1087567","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read" "19:13:31,1087654","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1087744","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1087817","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1087882","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1087955","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1088013","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1088080","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1088148","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1088212","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1088283","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1088337","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1088401","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1088469","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1088529","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1088603","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1088655","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1088719","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1088776","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1088982","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1089049","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1089123","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1089177","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1089242","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1089309","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1089373","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1089444","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1089498","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1089559","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1089626","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1089691","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1089758","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1089812","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1089873","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1090072","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,1090197","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1090297","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1090399","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1090861","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1090922","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1091012","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1091089","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1091192","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1091246","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1091333","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1091432","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1091663","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1091718","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1091801","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1091875","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1091977","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1092032","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1092122","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1092215","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1092282","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1092340","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1092430","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1092481","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1092587","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1092667","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1092814","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1092869","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1092949","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1093016","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1093113","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1093164","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1093247","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1093337","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1093405","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1093456","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1093555","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1093635","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1094014","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1094068","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1094155","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1094226","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1094325","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1094376","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1094469","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1094553","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1094617","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1094700","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1094764","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1094851","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1094918","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1095040","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1095098","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1095165","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1095239","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1095306","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1095399","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1095454","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1095518","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1095589","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1095656","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1095746","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1095797","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1095861","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1095922","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1096233","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1096291","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1096374","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1096448","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1096541","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1096596","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1096673","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,1096750","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1096814","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1096884","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1096952","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1097061","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1097125","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1097231","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1097285","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1097353","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1097423","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1097491","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1097580","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1097648","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1097712","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1097786","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1097850","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1097943","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1097997","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1098062","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1098122","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1098241","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1098296","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1098401","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1098488","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1098597","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1098652","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1098751","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1098834","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1098918","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1098985","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1099069","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1099120","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1099223","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1099300","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1099447","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1099502","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1099585","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1099652","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1099749","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1099803","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1099886","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1099973","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1100050","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1100101","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1100198","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1100275","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1100409","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1100464","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1100563","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1100643","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1100720","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1100801","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1100865","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1100954","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1101022","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1101105","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1101160","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1101221","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 0, Name: 00859AAC6A54B8C1B3C139DE67846E64E7B82DB2" "19:13:31,1101307","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1101371","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","Desired Access: Read" "19:13:31,1101461","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1101532","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1101593","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 586, Data: 03 00 00 00 01 00 00 00 14 00 00 00 00 85 9A AC" "19:13:31,1101679","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","" "19:13:31,1101913","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 1, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:31,1102006","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1102074","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:31,1102160","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1102231","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1102289","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 05 86 4F 16" "19:13:31,1102369","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:31,1102455","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 2, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:31,1102542","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1102609","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:31,1102693","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1102760","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1102818","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 177, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 F2 87 62 B3" "19:13:31,1102898","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:31,1102981","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 3, Name: 6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE" "19:13:31,1103065","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1103132","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","Desired Access: Read" "19:13:31,1103212","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1103277","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1103334","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 503, Data: 03 00 00 00 01 00 00 00 14 00 00 00 6F 47 42 06" "19:13:31,1103411","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","" "19:13:31,1103591","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 4, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:31,1103677","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1103745","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:31,1103828","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1103892","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1103950","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 75 24 FA FD" "19:13:31,1104027","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:31,1104114","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 5, Name: 8880A2309BE334678E3D912671F22049C5A49A78" "19:13:31,1104197","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1104264","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","Desired Access: Read" "19:13:31,1104345","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1104409","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1104466","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","SUCCESS","Type: REG_BINARY, Length: 1 496, Data: 03 00 00 00 01 00 00 00 14 00 00 00 88 80 A2 30" "19:13:31,1104547","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","" "19:13:31,1104729","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 6, Name: 94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A" "19:13:31,1104816","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1104883","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","Desired Access: Read" "19:13:31,1104967","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1105041","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1105098","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 544, Data: 0F 00 00 00 01 00 00 00 14 00 00 00 FA 27 83 F1" "19:13:31,1105178","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","" "19:13:31,1105342","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 7, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:31,1105429","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1105496","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:31,1105576","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1105647","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1105704","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A4 BC 39 BB" "19:13:31,1105781","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:31,1105865","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 8, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:31,1105958","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1106028","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:31,1106109","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1106176","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1106234","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 763, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 D6 1D BD 32" "19:13:31,1106311","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:31,1106394","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 9, Name: CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E" "19:13:31,1106477","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1106545","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","Desired Access: Read" "19:13:31,1106625","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1106692","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1106750","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 CB 7E 84 88" "19:13:31,1106827","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","" "19:13:31,1106987","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 10, Name: D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0" "19:13:31,1107074","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1107141","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","Desired Access: Read" "19:13:31,1107225","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1107292","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1107350","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 920, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D3 BE 73 0B" "19:13:31,1107430","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","" "19:13:31,1107632","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 11, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:31,1107722","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1107792","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:31,1107876","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1107940","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1108001","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FB 35 BB 18" "19:13:31,1108075","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:31,1108158","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 12, Name: FCAC7E666CC54341CA213BECF2EB463F2B62ADB0" "19:13:31,1108241","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1108309","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","Desired Access: Read" "19:13:31,1108389","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1108456","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1108514","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 551, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FC AC 7E 66" "19:13:31,1108591","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","" "19:13:31,1108758","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1108838","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1108912","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1108998","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1109056","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1109117","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1109191","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1109258","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1109335","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1109390","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1109454","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1109515","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1109659","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1109717","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1109832","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1109916","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1110021","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1110188","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1110259","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1110349","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1110403","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1110470","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1110541","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1110608","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1110689","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1110743","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1110807","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1110878","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1110942","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1111025","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1111080","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1111141","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1111202","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1111314","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1111368","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1111478","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1111561","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1111673","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1111728","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1111830","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1111910","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1111994","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1112064","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1112183","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1112238","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1112337","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1112417","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1112494","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1112574","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1112642","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1112728","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1112796","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1112882","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1112937","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1113004","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1113075","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1113142","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1113219","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1113274","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1113338","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1113408","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1113472","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1113549","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1113604","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1113668","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1113729","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1113902","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1113979","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1114053","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1114111","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1114175","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1114245","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1114310","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1114377","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1114431","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1114496","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1114563","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1114624","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1114694","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1114746","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1114810","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1114932","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1115009","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1115108","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1115172","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1115243","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1115297","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1115362","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1115432","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1115496","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1115564","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1115618","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1115682","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1115750","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1115814","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1115881","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1115936","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1115997","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1116054","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1116227","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1116295","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1116369","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1116423","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1116481","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 0, Name: 00859AAC6A54B8C1B3C139DE67846E64E7B82DB2" "19:13:31,1116564","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1116628","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","Desired Access: Read" "19:13:31,1116705","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1116792","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1116850","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 586, Data: 03 00 00 00 01 00 00 00 14 00 00 00 00 85 9A AC" "19:13:31,1116930","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","" "19:13:31,1117020","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 1, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:31,1117109","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1117177","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:31,1117254","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1117321","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1117379","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 05 86 4F 16" "19:13:31,1117456","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:31,1117536","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 2, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:31,1117619","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1117687","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:31,1117761","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1117825","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1117882","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 177, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 F2 87 62 B3" "19:13:31,1117959","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:31,1118040","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 3, Name: 6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE" "19:13:31,1118123","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1118190","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","Desired Access: Read" "19:13:31,1118264","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1118328","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1118386","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 503, Data: 03 00 00 00 01 00 00 00 14 00 00 00 6F 47 42 06" "19:13:31,1118460","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","" "19:13:31,1118540","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 4, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:31,1118623","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1118691","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:31,1118764","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1118829","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1118886","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 75 24 FA FD" "19:13:31,1118960","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:31,1119040","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 5, Name: 8880A2309BE334678E3D912671F22049C5A49A78" "19:13:31,1119124","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1119188","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","Desired Access: Read" "19:13:31,1119265","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1119329","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1119387","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","SUCCESS","Type: REG_BINARY, Length: 1 496, Data: 03 00 00 00 01 00 00 00 14 00 00 00 88 80 A2 30" "19:13:31,1119464","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","" "19:13:31,1119547","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 6, Name: 94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A" "19:13:31,1119634","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1119698","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","Desired Access: Read" "19:13:31,1119772","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1119836","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1119893","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 544, Data: 0F 00 00 00 01 00 00 00 14 00 00 00 FA 27 83 F1" "19:13:31,1119967","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","" "19:13:31,1120054","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 7, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:31,1120137","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1120205","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:31,1120278","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1120342","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1120400","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A4 BC 39 BB" "19:13:31,1120474","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:31,1120554","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 8, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:31,1120634","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1120702","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:31,1120775","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1120840","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1120897","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 763, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 D6 1D BD 32" "19:13:31,1120971","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:31,1121077","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 9, Name: CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E" "19:13:31,1121163","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1121231","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","Desired Access: Read" "19:13:31,1121321","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1121385","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1121443","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 CB 7E 84 88" "19:13:31,1121519","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","" "19:13:31,1121596","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 10, Name: D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0" "19:13:31,1121683","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1121747","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","Desired Access: Read" "19:13:31,1121824","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1121885","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1121956","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 920, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D3 BE 73 0B" "19:13:31,1122033","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","" "19:13:31,1122113","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 11, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:31,1122196","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1122264","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:31,1122337","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1122401","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1122459","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FB 35 BB 18" "19:13:31,1122533","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:31,1122613","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 12, Name: FCAC7E666CC54341CA213BECF2EB463F2B62ADB0" "19:13:31,1122697","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1122761","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","Desired Access: Read" "19:13:31,1122838","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1122899","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1122960","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 551, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FC AC 7E 66" "19:13:31,1123033","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","" "19:13:31,1123120","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1123190","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1123258","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1123332","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1123386","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1123450","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1123518","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1123582","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1123652","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1123707","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1123768","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1124265","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1124323","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1124435","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read" "19:13:31,1124521","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1124611","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1124685","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1124749","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1124823","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1124881","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1124948","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1125025","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1125089","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1125163","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1125217","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1125282","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1125349","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1125410","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1125480","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1125535","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1125599","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1125657","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1125833","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1125901","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1125971","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1126026","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1126093","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1126160","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1126225","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1126292","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1126346","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1126411","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1126478","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1126539","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1126609","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1126664","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1126725","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1126911","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1127030","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1127200","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1127315","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1128341","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1128495","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,1128604","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1128771","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,1129983","EasyAntiCheat.exe","2900","ReadFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Offset: 0, Length: 524 288" "19:13:31,1345477","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1345599","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1345762","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1345897","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1346048","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1346105","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1346205","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1346368","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1346631","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1346689","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1346801","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1346882","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1346994","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1347052","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1347161","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1347276","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1347360","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1347427","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1347526","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1347581","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1347696","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1347809","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1347985","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1348039","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1348126","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1348197","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1348299","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1348351","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1348437","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1348540","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1348610","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1348662","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1348768","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1348861","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1349287","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1349348","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1349431","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1349505","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1349608","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1349662","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1349755","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1349848","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1349922","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1350009","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1350086","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1350182","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1350249","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1350352","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1350413","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1350483","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1350557","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1350621","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1350705","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1350756","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1350823","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1350894","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1350958","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1351035","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1351086","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1351151","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1351215","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1351513","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1351571","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1351657","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1351731","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1351830","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1351882","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1351962","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,1352042","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1352106","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1352177","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1352247","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1352356","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1352424","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1352507","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1352562","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1352626","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1352700","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1352764","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1352844","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1352895","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1352959","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1353030","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1353097","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1353174","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1353226","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1353290","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1353347","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1353463","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1353517","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1353623","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1353710","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1353825","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1353880","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1353983","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1354063","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1354149","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1354217","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1354300","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1354355","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1354457","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1354534","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1354685","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1354739","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1354823","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1354893","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1354990","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1355188","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1355281","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1355374","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1355445","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1355500","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1355599","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1355679","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1355817","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1355872","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1355971","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1356051","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1356135","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1356228","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1356292","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1356385","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1356452","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1356539","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1356596","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1356667","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1356738","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1356802","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1356882","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1356946","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1357010","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1357081","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1357148","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1357225","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1357280","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1357350","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:31,1357443","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1357511","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:31,1357607","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1357693","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1357754","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:31,1357838","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:31,1358107","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1358174","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1358319","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1358376","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1358489","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1358575","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1358678","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1358755","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1358826","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1358912","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1358970","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1359037","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1359108","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1359175","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1359252","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1359307","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1359371","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1359441","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1359505","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1359582","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1359637","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1359701","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1359759","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1359868","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1359922","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1360025","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1360128","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1360246","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1360301","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1360397","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1360477","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1360561","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1360628","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,1360747","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1360801","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1360901","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\Disallowed","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1360981","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1361058","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1361138","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1361202","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1361292","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1361359","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1361443","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1361497","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1361565","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1361635","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1361702","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1361776","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1361831","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1361895","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1361962","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1362030","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1362103","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1362158","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1362222","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1362283","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,1362562","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1362629","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1362706","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1362758","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1362825","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1362892","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1362956","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1363027","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1363082","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1363142","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1363210","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1363274","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1363345","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1363396","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1363460","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1363601","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1363668","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1363768","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1363829","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1363899","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1363954","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1364018","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1364089","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1364150","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1364220","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1364275","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1364336","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1364406","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1364470","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1364538","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1364592","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1364656","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1364714","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1365060","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1365128","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1365205","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1365259","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1365327","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1365407","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1365471","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1365542","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1365596","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1365660","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1365728","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1365792","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1365862","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1365917","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 1, Values: 0" "19:13:31,1365978","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Index: 0, Name: 27748148BBE67A43CDBFEC6C3784862CE134E6EA" "19:13:31,1366061","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1366125","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","Desired Access: Read" "19:13:31,1366205","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1366273","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1366337","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA\Blob","SUCCESS","Type: REG_BINARY, Length: 598, Data: 03 00 00 00 01 00 01 00 14 00 00 00 27 74 81 48" "19:13:31,1366417","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs\27748148BBE67A43CDBFEC6C3784862CE134E6EA","SUCCESS","" "19:13:31,1366645","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1366805","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1366863","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1366975","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\Disallowed","REPARSE","Desired Access: Read" "19:13:31,1367059","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Desired Access: Read" "19:13:31,1367152","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1367225","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1367289","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1367363","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1367421","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1367488","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1367559","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1367623","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1367694","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1367748","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1367812","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1367880","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1367944","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1368014","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1368069","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1368133","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1368191","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1368377","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1368444","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1368518","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1368572","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1368640","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates","SUCCESS","" "19:13:31,1368707","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1368771","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1368842","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1368896","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1368960","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs","SUCCESS","" "19:13:31,1369028","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1369092","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1369159","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1369214","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1369278","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs","SUCCESS","" "19:13:31,1369467","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:31,1369592","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1369689","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1369791","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:31,1370372","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1370429","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1370522","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1370596","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1370702","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1370753","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1370840","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1370936","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1371183","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1371241","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1371324","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1371398","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1371501","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1371555","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1371645","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1371735","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1371799","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1371863","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1371950","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1372004","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1372110","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1372193","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1372341","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1372395","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1372476","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1372546","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1372639","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1372694","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1372777","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1372864","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1372931","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1372982","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1373082","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1373162","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1373553","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1373611","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1373694","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1373768","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1373864","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1373919","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1374009","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1374095","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1374159","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1374240","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1374307","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1374397","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1374464","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1374548","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1374605","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1374669","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1374740","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1374807","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1374884","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1374936","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1375000","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1375080","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1375144","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1375221","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1375272","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1375337","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1375397","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1375689","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1375763","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1375846","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1375920","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1376020","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1376071","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1376151","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Read" "19:13:31,1376225","EasyAntiCheat.exe","2900","RegSetInfoKey","HKU\.DEFAULT","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1376289","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1376360","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1376430","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1376533","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1376597","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1376680","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1376735","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1376799","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1376870","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1376937","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1377011","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1377065","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1377129","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1377200","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1377264","EasyAntiCheat.exe","2900","RegCreateKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1377341","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1377396","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1377457","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1377514","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1377630","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1377684","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1377793","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1377873","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1377989","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1378043","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1378143","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1378223","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1378313","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1378380","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1378460","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1378515","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1378614","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1378695","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1378839","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1378893","EasyAntiCheat.exe","2900","RegQueryKey","HKU","SUCCESS","Query: Name" "19:13:31,1378977","EasyAntiCheat.exe","2900","RegOpenKey","HKU\S-1-5-18","REPARSE","Desired Access: Maximum Allowed" "19:13:31,1379047","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:31,1379140","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1379195","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: Name" "19:13:31,1379278","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1379365","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1379432","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1379484","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1379580","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher\Safer","REPARSE","Desired Access: Read" "19:13:31,1379657","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Safer","NAME NOT FOUND","Desired Access: Read" "19:13:31,1379791","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1379846","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1379945","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1380022","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1380112","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1380192","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1380256","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1380346","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1380410","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1380494","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1380548","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1380609","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 0, Name: 00859AAC6A54B8C1B3C139DE67846E64E7B82DB2" "19:13:31,1380696","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1380763","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","Desired Access: Read" "19:13:31,1380850","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1380924","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1380985","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 586, Data: 03 00 00 00 01 00 00 00 14 00 00 00 00 85 9A AC" "19:13:31,1381071","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","" "19:13:31,1381276","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 1, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:31,1381366","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1381437","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:31,1381523","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1381591","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1381652","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 05 86 4F 16" "19:13:31,1381732","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:31,1381815","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 2, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:31,1381905","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1381972","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:31,1382053","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1382123","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1382181","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 177, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 F2 87 62 B3" "19:13:31,1382258","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:31,1382341","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 3, Name: 6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE" "19:13:31,1382425","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1382492","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","Desired Access: Read" "19:13:31,1382572","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1382639","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1382697","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 503, Data: 03 00 00 00 01 00 00 00 14 00 00 00 6F 47 42 06" "19:13:31,1382774","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","" "19:13:31,1382944","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 4, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:31,1383034","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1383101","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:31,1383185","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1383249","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1383310","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 75 24 FA FD" "19:13:31,1383387","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:31,1383470","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 5, Name: 8880A2309BE334678E3D912671F22049C5A49A78" "19:13:31,1383554","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1383621","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","Desired Access: Read" "19:13:31,1383701","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1383765","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1383823","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","SUCCESS","Type: REG_BINARY, Length: 1 496, Data: 03 00 00 00 01 00 00 00 14 00 00 00 88 80 A2 30" "19:13:31,1383903","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","" "19:13:31,1384089","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 6, Name: 94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A" "19:13:31,1384179","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1384250","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","Desired Access: Read" "19:13:31,1384330","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1384397","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1384455","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 544, Data: 0F 00 00 00 01 00 00 00 14 00 00 00 FA 27 83 F1" "19:13:31,1384532","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","" "19:13:31,1384695","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 7, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:31,1384779","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1384849","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:31,1384929","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1384997","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1385064","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A4 BC 39 BB" "19:13:31,1385144","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:31,1385228","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 8, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:31,1385314","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1385382","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:31,1385462","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1385529","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1385587","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 763, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 D6 1D BD 32" "19:13:31,1385664","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:31,1385741","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 9, Name: CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E" "19:13:31,1385828","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1385895","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","Desired Access: Read" "19:13:31,1385975","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1386039","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1386097","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 CB 7E 84 88" "19:13:31,1386174","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","" "19:13:31,1386360","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 10, Name: D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0" "19:13:31,1386450","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1386517","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","Desired Access: Read" "19:13:31,1386600","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1386665","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1386722","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 920, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D3 BE 73 0B" "19:13:31,1386803","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","" "19:13:31,1386960","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 11, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:31,1387046","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1387117","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:31,1387197","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1387261","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1387322","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FB 35 BB 18" "19:13:31,1387396","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:31,1387476","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 12, Name: FCAC7E666CC54341CA213BECF2EB463F2B62ADB0" "19:13:31,1387559","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1387627","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","Desired Access: Read" "19:13:31,1387707","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1387774","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1387832","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 551, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FC AC 7E 66" "19:13:31,1387906","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","" "19:13:31,1388073","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1388153","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1388227","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1388310","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1388364","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1388432","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1388499","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1388567","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1388644","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1388698","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1388762","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1388823","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1388967","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1389025","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1389141","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1389227","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1389327","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1389400","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1389468","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1389551","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1389609","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1389676","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1389747","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1389811","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1389891","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1389946","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1390007","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1390087","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1390154","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1390231","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1390286","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1390350","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1390408","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1390520","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1390577","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1390687","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores","REPARSE","Desired Access: Read" "19:13:31,1390770","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\PhysicalStores","NAME NOT FOUND","Desired Access: Read" "19:13:31,1390885","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1390940","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1391039","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1391123","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1391206","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1391273","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1391395","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1391450","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1391553","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\Software\WOW6432Node\Microsoft\EnterpriseCertificates\TrustedPublisher","REPARSE","Desired Access: Read/Write, Delete" "19:13:31,1391629","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1391710","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1391790","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1391854","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1391944","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1392024","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1392111","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1392165","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1392232","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1392303","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1392370","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1392447","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1392502","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1392563","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1392633","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1392697","EasyAntiCheat.exe","2900","RegCreateKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read/Write, Delete, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,1392774","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1392826","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1392893","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1392954","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1393127","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1393195","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1393272","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1393326","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1393390","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1393458","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1393522","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1393592","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1393647","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1393711","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1393778","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1393842","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1393910","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1393964","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1394029","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1394150","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1394215","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1394314","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1394375","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1394445","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1394500","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1394564","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1394635","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1394699","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1394769","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1394821","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1394885","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1394952","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1395016","EasyAntiCheat.exe","2900","RegOpenKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1395100","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1395151","EasyAntiCheat.exe","2900","RegQueryKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1395215","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1395273","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1395453","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1395520","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1395594","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1395648","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 13, Values: 0" "19:13:31,1395706","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 0, Name: 00859AAC6A54B8C1B3C139DE67846E64E7B82DB2" "19:13:31,1395789","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1395853","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","Desired Access: Read" "19:13:31,1395930","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1396001","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1396059","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2\Blob","SUCCESS","Type: REG_BINARY, Length: 1 586, Data: 03 00 00 00 01 00 00 00 14 00 00 00 00 85 9A AC" "19:13:31,1396139","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\00859AAC6A54B8C1B3C139DE67846E64E7B82DB2","SUCCESS","" "19:13:31,1396225","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 1, Name: 05864F160192CA3836DD2C06F4445417B09E6684" "19:13:31,1396312","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1396379","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","Desired Access: Read" "19:13:31,1396453","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1396521","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1396578","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 05 86 4F 16" "19:13:31,1396655","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\05864F160192CA3836DD2C06F4445417B09E6684","SUCCESS","" "19:13:31,1396735","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 2, Name: 2952F2806BFA00D2305797D0035D597F4EB80913" "19:13:31,1396819","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1396886","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","Desired Access: Read" "19:13:31,1396963","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1397027","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1397085","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913\Blob","SUCCESS","Type: REG_BINARY, Length: 1 177, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 F2 87 62 B3" "19:13:31,1397162","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\2952F2806BFA00D2305797D0035D597F4EB80913","SUCCESS","" "19:13:31,1397242","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 3, Name: 6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE" "19:13:31,1397326","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1397393","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","Desired Access: Read" "19:13:31,1397467","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1397531","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1397589","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE\Blob","SUCCESS","Type: REG_BINARY, Length: 1 503, Data: 03 00 00 00 01 00 00 00 14 00 00 00 6F 47 42 06" "19:13:31,1397666","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\6F474206BCBB391BB82BA9E5DC0302DEF37AEBBE","SUCCESS","" "19:13:31,1397746","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 4, Name: 7524FAFDE19E2469EE8D37E62DF1035D8997E6EE" "19:13:31,1397829","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1397896","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","Desired Access: Read" "19:13:31,1397970","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1398034","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1398092","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 75 24 FA FD" "19:13:31,1398166","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7524FAFDE19E2469EE8D37E62DF1035D8997E6EE","SUCCESS","" "19:13:31,1398246","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 5, Name: 8880A2309BE334678E3D912671F22049C5A49A78" "19:13:31,1398329","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1398394","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","Desired Access: Read" "19:13:31,1398471","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1398535","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1398592","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78\Blob","SUCCESS","Type: REG_BINARY, Length: 1 496, Data: 03 00 00 00 01 00 00 00 14 00 00 00 88 80 A2 30" "19:13:31,1398666","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\8880A2309BE334678E3D912671F22049C5A49A78","SUCCESS","" "19:13:31,1398766","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 6, Name: 94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A" "19:13:31,1398852","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1398920","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","Desired Access: Read" "19:13:31,1398993","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1399054","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1399115","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A\Blob","SUCCESS","Type: REG_BINARY, Length: 1 544, Data: 0F 00 00 00 01 00 00 00 14 00 00 00 FA 27 83 F1" "19:13:31,1399189","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\94054C2DDE5F232994F2DDEA8E29DFB0853D5D1A","SUCCESS","" "19:13:31,1399266","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 7, Name: A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E" "19:13:31,1399359","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1399430","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","Desired Access: Read" "19:13:31,1399503","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1399567","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1399625","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 A4 BC 39 BB" "19:13:31,1399702","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A4BC39BBFA62D29CF346605701C4CE4CDA9F3F4E","SUCCESS","" "19:13:31,1399782","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 8, Name: A98087ECB8D6D3794EB582386A55724BB5B8BCF3" "19:13:31,1399866","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1399930","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","Desired Access: Read" "19:13:31,1400007","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1400077","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1400135","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3\Blob","SUCCESS","Type: REG_BINARY, Length: 1 763, Data: 0F 00 00 00 01 00 00 00 20 00 00 00 D6 1D BD 32" "19:13:31,1400212","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\A98087ECB8D6D3794EB582386A55724BB5B8BCF3","SUCCESS","" "19:13:31,1400286","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 9, Name: CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E" "19:13:31,1400369","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1400433","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","Desired Access: Read" "19:13:31,1400507","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1400575","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1400632","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E\Blob","SUCCESS","Type: REG_BINARY, Length: 1 459, Data: 03 00 00 00 01 00 00 00 14 00 00 00 CB 7E 84 88" "19:13:31,1400706","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\CB7E84887F3C6015FE7EDFB4F8F36DF7DC10590E","SUCCESS","" "19:13:31,1400786","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 10, Name: D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0" "19:13:31,1400870","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1400937","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","Desired Access: Read" "19:13:31,1401014","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1401075","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1401133","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 920, Data: 03 00 00 00 01 00 00 00 14 00 00 00 D3 BE 73 0B" "19:13:31,1401210","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D3BE730B2EA45B8F32F922B2D2DE70D6EBE7E0C0","SUCCESS","" "19:13:31,1401290","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 11, Name: FB35BB188390A844C92000D3788A37B6287E676E" "19:13:31,1401370","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1401437","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","Desired Access: Read" "19:13:31,1401511","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1401572","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1401633","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E\Blob","SUCCESS","Type: REG_BINARY, Length: 956, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FB 35 BB 18" "19:13:31,1401707","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FB35BB188390A844C92000D3788A37B6287E676E","SUCCESS","" "19:13:31,1401784","EasyAntiCheat.exe","2900","RegEnumKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Index: 12, Name: FCAC7E666CC54341CA213BECF2EB463F2B62ADB0" "19:13:31,1401867","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1401931","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","Desired Access: Read" "19:13:31,1402008","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1402069","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","BUFFER OVERFLOW","Length: 144" "19:13:31,1402127","EasyAntiCheat.exe","2900","RegQueryValue","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0\Blob","SUCCESS","Type: REG_BINARY, Length: 1 551, Data: 03 00 00 00 01 00 00 00 14 00 00 00 FC AC 7E 66" "19:13:31,1402204","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FCAC7E666CC54341CA213BECF2EB463F2B62ADB0","SUCCESS","" "19:13:31,1402287","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1402358","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1402425","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1402499","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1402557","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1402621","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1402688","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1402749","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1402820","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1402874","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1402935","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1403432","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:31,1403487","EasyAntiCheat.exe","2900","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:31,1403599","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\SystemCertificates\TrustedPublisher","REPARSE","Desired Access: Read" "19:13:31,1403686","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Desired Access: Read" "19:13:31,1403775","EasyAntiCheat.exe","2900","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:31,1403849","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1403917","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1403987","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1404042","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1404112","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1404180","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1404244","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1404317","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1404372","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1404433","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1404500","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1404564","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1404635","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1404689","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1404754","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1404811","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1404991","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1405068","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Desired Access: Read" "19:13:31,1405145","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1405199","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1405264","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\Certificates","SUCCESS","" "19:13:31,1405334","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1405398","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Desired Access: Read" "19:13:31,1405469","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1405523","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1405588","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CRLs","SUCCESS","" "19:13:31,1405652","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:31,1405716","EasyAntiCheat.exe","2900","RegOpenKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Desired Access: Read" "19:13:31,1405786","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1405841","EasyAntiCheat.exe","2900","RegQueryKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","Query: Cached, SubKeys: 0, Values: 0" "19:13:31,1405905","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher\CTLs","SUCCESS","" "19:13:31,1406088","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1406210","EasyAntiCheat.exe","2900","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1406377","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT","SUCCESS","" "19:13:31,1406479","EasyAntiCheat.exe","2900","RegCloseKey","HKU\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPublisher","SUCCESS","" "19:13:31,1406720","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:31,1408602","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1408862","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1409029","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,1409135","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1409305","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,1409645","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:31,1410658","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1410873","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1410976","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,1411075","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1411229","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,1411604","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1411701","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:31,1412589","EasyAntiCheat.exe","2900","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,1412785","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1412887","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:31,1412971","EasyAntiCheat.exe","2900","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,1413118","EasyAntiCheat.exe","2900","CreateFileMapping","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","SyncType: SyncTypeOther" "19:13:31,1422127","EasyAntiCheat.exe","2900","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:31,1424552","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 732, User Time: 0.0468750, Kernel Time: 0.0468750" "19:13:31,1424956","EasyAntiCheat.exe","2900","NotifyChangeDirectory","C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\SystemCertificates\My","","Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_DIR_NAME" "19:13:31,6025248","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 5880" "19:13:31,6740261","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6740528","EasyAntiCheat_launcher.exe","6076","RegSetValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastInitGameID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 154" "19:13:31,6740669","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6740775","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6740861","EasyAntiCheat_launcher.exe","6076","RegSetValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_LastGameID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 154" "19:13:31,6740935","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6741018","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6741099","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameState","SUCCESS","" "19:13:31,6741461","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6741535","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6741609","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashGameID","SUCCESS","" "19:13:31,6741727","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6741798","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6741868","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashPID","SUCCESS","" "19:13:31,6742003","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6742074","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6742141","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashCreateTime","SUCCESS","" "19:13:31,6742253","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6742324","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6742391","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashExitTime","SUCCESS","" "19:13:31,6742551","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6742619","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6742689","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashExitStatus","SUCCESS","" "19:13:31,6742808","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6742879","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6742946","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo01","SUCCESS","" "19:13:31,6743049","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6743116","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6743187","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo02","NAME NOT FOUND","" "19:13:31,6743257","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6743324","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6743392","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo03","NAME NOT FOUND","" "19:13:31,6743459","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6743526","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6743594","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo04","NAME NOT FOUND","" "19:13:31,6743661","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6743732","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6743799","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo05","NAME NOT FOUND","" "19:13:31,6743866","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6743934","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6744001","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo06","NAME NOT FOUND","" "19:13:31,6744069","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6744136","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6744203","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo07","NAME NOT FOUND","" "19:13:31,6744271","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6744338","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6744405","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo08","NAME NOT FOUND","" "19:13:31,6744473","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6744537","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6744604","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo09","NAME NOT FOUND","" "19:13:31,6744671","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6744739","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6744806","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo10","NAME NOT FOUND","" "19:13:31,6744874","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6744941","EasyAntiCheat_launcher.exe","6076","RegCreateKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Write, Disposition: REG_OPENED_EXISTING_KEY" "19:13:31,6745008","EasyAntiCheat_launcher.exe","6076","RegDeleteValue","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat\ErrRpt_GameCrashInfo11","NAME NOT FOUND","" "19:13:31,6745076","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6745156","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Wow6432Node\EasyAntiCheat","SUCCESS","Desired Access: Read" "19:13:31,6745242","EasyAntiCheat_launcher.exe","6076","RegFlushKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6751769","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Windows\System32\config\SOFTWARE.LOG2","SUCCESS","Offset: 950 272, Length: 36 864, I/O Flags: Non-cached, Priority: Normal" "19:13:31,6780917","EasyAntiCheat_launcher.exe","6076","FlushBuffersFile","C:\Windows\System32\config\SOFTWARE.LOG2","SUCCESS","" "19:13:31,6781491","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\EasyAntiCheat","SUCCESS","" "19:13:31,6836887","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6837265","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","AllocationSize: 8 593 408, EndOfFile: 8 592 280, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6838029","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","Offset: 0, Length: 8 592 280, Priority: Normal" "19:13:31,6865303","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","" "19:13:31,6869312","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\hal.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6869749","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\hal.dll","SUCCESS","AllocationSize: 475 136, EndOfFile: 471 448, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6869915","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\hal.dll","SUCCESS","Offset: 0, Length: 471 448, Priority: Normal" "19:13:31,6871705","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\hal.dll","SUCCESS","" "19:13:31,6872619","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\kd.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6872876","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\kd.dll","SUCCESS","AllocationSize: 16 384, EndOfFile: 15 768, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6872982","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\kd.dll","SUCCESS","Offset: 0, Length: 15 768, Priority: Normal" "19:13:31,6873148","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\kd.dll","SUCCESS","" "19:13:31,6895096","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\msrpc.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6895384","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\msrpc.sys","SUCCESS","AllocationSize: 380 928, EndOfFile: 376 864, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6895497","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\msrpc.sys","SUCCESS","Offset: 0, Length: 376 864, Priority: Normal" "19:13:31,6896068","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\msrpc.sys","SUCCESS","" "19:13:31,6912466","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ksecdd.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6912736","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ksecdd.sys","SUCCESS","AllocationSize: 143 360, EndOfFile: 139 672, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6912858","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ksecdd.sys","SUCCESS","Offset: 0, Length: 139 672, Priority: Normal" "19:13:31,6913140","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ksecdd.sys","SUCCESS","" "19:13:31,6921565","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\werkernel.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6921748","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\werkernel.sys","SUCCESS","AllocationSize: 49 152, EndOfFile: 45 464, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6921864","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\werkernel.sys","SUCCESS","Offset: 0, Length: 45 464, Priority: Normal" "19:13:31,6922037","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\werkernel.sys","SUCCESS","" "19:13:31,6949196","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\clfs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6949469","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\clfs.sys","SUCCESS","AllocationSize: 376 832, EndOfFile: 373 656, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6949584","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\clfs.sys","SUCCESS","Offset: 0, Length: 373 656, Priority: Normal" "19:13:31,6950136","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\clfs.sys","SUCCESS","" "19:13:31,6961297","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\tm.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6961573","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\tm.sys","SUCCESS","AllocationSize: 131 072, EndOfFile: 128 408, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6961698","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\tm.sys","SUCCESS","Offset: 0, Length: 128 408, Priority: Normal" "19:13:31,6961971","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\tm.sys","SUCCESS","" "19:13:31,6966195","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\PSHED.DLL","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6966445","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\PSHED.DLL","SUCCESS","AllocationSize: 69 632, EndOfFile: 66 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6966563","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\PSHED.DLL","SUCCESS","Offset: 0, Length: 66 456, Priority: Normal" "19:13:31,6966759","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\PSHED.DLL","SUCCESS","" "19:13:31,6969671","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\BOOTVID.DLL","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,6969928","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\BOOTVID.DLL","SUCCESS","AllocationSize: 28 672, EndOfFile: 26 008, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,6970040","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\BOOTVID.DLL","SUCCESS","Offset: 0, Length: 26 008, Priority: Normal" "19:13:31,6970213","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\BOOTVID.DLL","SUCCESS","" "19:13:31,7004986","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\fltMgr.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7005266","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\fltMgr.sys","SUCCESS","AllocationSize: 401 408, EndOfFile: 398 744, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7005384","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\fltMgr.sys","SUCCESS","Offset: 0, Length: 398 744, Priority: Normal" "19:13:31,7005978","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\fltMgr.sys","SUCCESS","" "19:13:31,7048609","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ClipSp.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7048884","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ClipSp.sys","SUCCESS","AllocationSize: 1 007 616, EndOfFile: 1 007 512, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7049000","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ClipSp.sys","SUCCESS","Offset: 0, Length: 1 007 512, Priority: Normal" "19:13:31,7050607","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ClipSp.sys","SUCCESS","" "19:13:31,7053214","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\cmimcext.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7053480","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\cmimcext.sys","SUCCESS","AllocationSize: 28 672, EndOfFile: 28 568, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7053596","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\cmimcext.sys","SUCCESS","Offset: 0, Length: 28 568, Priority: Normal" "19:13:31,7053772","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\cmimcext.sys","SUCCESS","" "19:13:31,7056303","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ntosext.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7056559","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ntosext.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 864, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7056662","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ntosext.sys","SUCCESS","Offset: 0, Length: 19 864, Priority: Normal" "19:13:31,7056810","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ntosext.sys","SUCCESS","" "19:13:31,7096336","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\ci.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7096599","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\ci.dll","SUCCESS","AllocationSize: 712 704, EndOfFile: 710 912, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7096711","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\ci.dll","SUCCESS","Offset: 0, Length: 710 912, Priority: Normal" "19:13:31,7097892","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\ci.dll","SUCCESS","" "19:13:31,7135853","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\cng.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7136138","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\cng.sys","SUCCESS","AllocationSize: 679 936, EndOfFile: 676 384, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7136257","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\cng.sys","SUCCESS","Offset: 0, Length: 676 384, Priority: Normal" "19:13:31,7137171","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\cng.sys","SUCCESS","" "19:13:31,7192843","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\Wdf01000.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7193119","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\Wdf01000.sys","SUCCESS","AllocationSize: 921 600, EndOfFile: 918 240, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7193234","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\Wdf01000.sys","SUCCESS","Offset: 0, Length: 918 240, Priority: Normal" "19:13:31,7194706","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\Wdf01000.sys","SUCCESS","" "19:13:31,7202978","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\WdfLdr.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7203254","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\WdfLdr.sys","SUCCESS","AllocationSize: 65 536, EndOfFile: 61 664, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7203379","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\WdfLdr.sys","SUCCESS","Offset: 0, Length: 61 664, Priority: Normal" "19:13:31,7203578","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\WdfLdr.sys","SUCCESS","" "19:13:31,7207093","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\WppRecorder.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7207269","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\WppRecorder.sys","SUCCESS","AllocationSize: 36 864, EndOfFile: 33 176, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7207381","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\WppRecorder.sys","SUCCESS","Offset: 0, Length: 33 176, Priority: Normal" "19:13:31,7207542","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\WppRecorder.sys","SUCCESS","" "19:13:31,7211086","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\SleepStudyHelper.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7211262","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\SleepStudyHelper.sys","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 200, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7211371","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\SleepStudyHelper.sys","SUCCESS","Offset: 0, Length: 34 200, Priority: Normal" "19:13:31,7211528","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\SleepStudyHelper.sys","SUCCESS","" "19:13:31,7221452","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\acpiex.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7221718","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\acpiex.sys","SUCCESS","AllocationSize: 131 072, EndOfFile: 127 896, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7221837","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\acpiex.sys","SUCCESS","Offset: 0, Length: 127 896, Priority: Normal" "19:13:31,7222112","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\acpiex.sys","SUCCESS","" "19:13:31,7251885","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mssecflt.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7252152","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mssecflt.sys","SUCCESS","AllocationSize: 294 912, EndOfFile: 293 272, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7252264","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mssecflt.sys","SUCCESS","Offset: 0, Length: 293 272, Priority: Normal" "19:13:31,7252739","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mssecflt.sys","SUCCESS","" "19:13:31,7306172","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\acpi.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7308763","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\acpi.sys","SUCCESS","AllocationSize: 737 280, EndOfFile: 733 592, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7308885","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\acpi.sys","SUCCESS","Offset: 0, Length: 733 592, Priority: Normal" "19:13:31,7312304","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\acpi.sys","SUCCESS","" "19:13:31,7319334","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\wmilib.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7321948","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\wmilib.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 20 376, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7322061","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\wmilib.sys","SUCCESS","Offset: 0, Length: 20 376, Priority: Normal" "19:13:31,7322221","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\wmilib.sys","SUCCESS","" "19:13:31,7367809","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\intelpep.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7368098","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\intelpep.sys","SUCCESS","AllocationSize: 131 072, EndOfFile: 130 640, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7368287","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\intelpep.sys","SUCCESS","Offset: 0, Length: 130 640, Priority: Normal" "19:13:31,7368604","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\intelpep.sys","SUCCESS","" "19:13:31,7393054","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\WindowsTrustedRT.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7395562","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\WindowsTrustedRT.sys","SUCCESS","AllocationSize: 73 728, EndOfFile: 71 248, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7395687","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\WindowsTrustedRT.sys","SUCCESS","Offset: 0, Length: 71 248, Priority: Normal" "19:13:31,7395908","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\WindowsTrustedRT.sys","SUCCESS","" "19:13:31,7404988","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7405164","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 18 000, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7405315","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys","SUCCESS","Offset: 0, Length: 18 000, Priority: Normal" "19:13:31,7407801","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys","SUCCESS","" "19:13:31,7426849","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\pcw.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7429443","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\pcw.sys","SUCCESS","AllocationSize: 53 248, EndOfFile: 53 144, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7429642","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\pcw.sys","SUCCESS","Offset: 0, Length: 53 144, Priority: Normal" "19:13:31,7429860","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\pcw.sys","SUCCESS","" "19:13:31,7441650","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\msisadrv.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7441945","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\msisadrv.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 18 840, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7442086","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\msisadrv.sys","SUCCESS","Offset: 0, Length: 18 840, Priority: Normal" "19:13:31,7444607","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\msisadrv.sys","SUCCESS","" "19:13:31,7533513","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\pci.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7536165","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\pci.sys","SUCCESS","AllocationSize: 364 544, EndOfFile: 362 904, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7536367","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\pci.sys","SUCCESS","Offset: 0, Length: 362 904, Priority: Normal" "19:13:31,7537352","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\pci.sys","SUCCESS","" "19:13:31,7539491","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\iusb3hcs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7539687","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\iusb3hcs.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 20 464, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,7539796","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\iusb3hcs.sys","SUCCESS","Offset: 0, Length: 20 464, Priority: Normal" "19:13:31,7540004","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\iusb3hcs.sys","SUCCESS","" "19:13:31,7553340","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\pdc.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7553619","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\pdc.sys","SUCCESS","AllocationSize: 126 976, EndOfFile: 123 288, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7553741","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\pdc.sys","SUCCESS","Offset: 0, Length: 123 288, Priority: Normal" "19:13:31,7554116","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\pdc.sys","SUCCESS","" "19:13:31,7563648","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\CEA.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7563918","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\CEA.sys","SUCCESS","AllocationSize: 81 920, EndOfFile: 78 744, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7564033","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\CEA.sys","SUCCESS","Offset: 0, Length: 78 744, Priority: Normal" "19:13:31,7564331","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\CEA.sys","SUCCESS","" "19:13:31,7576801","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\partmgr.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7577064","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\partmgr.sys","SUCCESS","AllocationSize: 167 936, EndOfFile: 165 784, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7577186","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\partmgr.sys","SUCCESS","Offset: 0, Length: 165 784, Priority: Normal" "19:13:31,7577626","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\partmgr.sys","SUCCESS","" "19:13:31,7610763","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\spaceport.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7610962","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\spaceport.sys","SUCCESS","AllocationSize: 573 440, EndOfFile: 571 288, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7611068","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\spaceport.sys","SUCCESS","Offset: 0, Length: 571 288, Priority: Normal" "19:13:31,7612405","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\spaceport.sys","SUCCESS","" "19:13:31,7619734","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\volmgr.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7620003","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\volmgr.sys","SUCCESS","AllocationSize: 86 016, EndOfFile: 83 864, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,7620125","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\volmgr.sys","SUCCESS","Offset: 0, Length: 83 864, Priority: Normal" "19:13:31,7620439","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\volmgr.sys","SUCCESS","" "19:13:31,7641229","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\volmgrx.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7641495","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\volmgrx.sys","SUCCESS","AllocationSize: 376 832, EndOfFile: 373 144, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7641607","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\volmgrx.sys","SUCCESS","Offset: 0, Length: 373 144, Priority: Normal" "19:13:31,7642438","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\volmgrx.sys","SUCCESS","" "19:13:31,7650726","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mountmgr.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7651008","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mountmgr.sys","SUCCESS","AllocationSize: 106 496, EndOfFile: 103 320, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7651127","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mountmgr.sys","SUCCESS","Offset: 0, Length: 103 320, Priority: Normal" "19:13:31,7651473","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mountmgr.sys","SUCCESS","" "19:13:31,7752977","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\iaStor.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7753176","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\iaStor.sys","SUCCESS","AllocationSize: 569 344, EndOfFile: 569 152, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,7753285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\iaStor.sys","SUCCESS","Offset: 0, Length: 569 152, Priority: Normal" "19:13:31,7754590","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\iaStor.sys","SUCCESS","" "19:13:31,7761518","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\EhStorClass.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7761704","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\EhStorClass.sys","SUCCESS","AllocationSize: 90 112, EndOfFile: 87 960, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7761819","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\EhStorClass.sys","SUCCESS","Offset: 0, Length: 87 960, Priority: Normal" "19:13:31,7762146","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\EhStorClass.sys","SUCCESS","" "19:13:31,7769808","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\fileinfo.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7770100","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\fileinfo.sys","SUCCESS","AllocationSize: 86 016, EndOfFile: 85 400, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7770219","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\fileinfo.sys","SUCCESS","Offset: 0, Length: 85 400, Priority: Normal" "19:13:31,7770537","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\fileinfo.sys","SUCCESS","" "19:13:31,7914508","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ntfs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7914800","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ntfs.sys","SUCCESS","AllocationSize: 2 404 352, EndOfFile: 2 400 664, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7915271","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ntfs.sys","SUCCESS","Offset: 0, Length: 2 400 664, Priority: Normal" "19:13:31,7921666","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ntfs.sys","SUCCESS","" "19:13:31,7925133","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\fs_rec.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,7925451","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\fs_rec.sys","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 200, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,7925579","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\fs_rec.sys","SUCCESS","Offset: 0, Length: 34 200, Priority: Normal" "19:13:31,7925887","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\fs_rec.sys","SUCCESS","" "19:13:31,8067357","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ndis.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8067661","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ndis.sys","SUCCESS","AllocationSize: 1 282 048, EndOfFile: 1 278 872, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8067786","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ndis.sys","SUCCESS","Offset: 0, Length: 1 278 872, Priority: Normal" "19:13:31,8071026","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ndis.sys","SUCCESS","" "19:13:31,8117384","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\netio.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8117669","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\netio.sys","SUCCESS","AllocationSize: 536 576, EndOfFile: 535 960, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8117788","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\netio.sys","SUCCESS","Offset: 0, Length: 535 960, Priority: Normal" "19:13:31,8119331","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\netio.sys","SUCCESS","" "19:13:31,8133471","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ksecpkg.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8133744","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ksecpkg.sys","SUCCESS","AllocationSize: 172 032, EndOfFile: 170 904, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8133866","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ksecpkg.sys","SUCCESS","Offset: 0, Length: 170 904, Priority: Normal" "19:13:31,8134331","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ksecpkg.sys","SUCCESS","" "19:13:31,8289877","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\tcpip.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8290288","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\tcpip.sys","SUCCESS","AllocationSize: 2 777 088, EndOfFile: 2 773 400, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8290875","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\tcpip.sys","SUCCESS","Offset: 0, Length: 2 773 400, Priority: Normal" "19:13:31,8303967","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\tcpip.sys","SUCCESS","" "19:13:31,8351569","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\FWPKCLNT.SYS","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8352204","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\FWPKCLNT.SYS","SUCCESS","AllocationSize: 442 368, EndOfFile: 441 240, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8352448","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\FWPKCLNT.SYS","SUCCESS","Offset: 0, Length: 441 240, Priority: Normal" "19:13:31,8356165","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\FWPKCLNT.SYS","SUCCESS","" "19:13:31,8371701","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\wfplwfs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8372217","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\wfplwfs.sys","SUCCESS","AllocationSize: 163 840, EndOfFile: 163 736, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8372407","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\wfplwfs.sys","SUCCESS","Offset: 0, Length: 163 736, Priority: Normal" "19:13:31,8373609","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\wfplwfs.sys","SUCCESS","" "19:13:31,8375851","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\volume.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8376175","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\volume.sys","SUCCESS","AllocationSize: 16 384, EndOfFile: 15 392, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8376294","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\volume.sys","SUCCESS","Offset: 0, Length: 15 392, Priority: Normal" "19:13:31,8376525","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\volume.sys","SUCCESS","" "19:13:31,8399040","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\volsnap.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8399412","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\volsnap.sys","SUCCESS","AllocationSize: 401 408, EndOfFile: 401 304, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8399556","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\volsnap.sys","SUCCESS","Offset: 0, Length: 401 304, Priority: Normal" "19:13:31,8401243","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\volsnap.sys","SUCCESS","" "19:13:31,8403126","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\pwdrvio.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8403302","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\pwdrvio.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 152, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,8403405","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\pwdrvio.sys","SUCCESS","Offset: 0, Length: 19 152, Priority: Normal" "19:13:31,8403623","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\pwdrvio.sys","SUCCESS","" "19:13:31,8412915","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mup.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8413184","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mup.sys","SUCCESS","AllocationSize: 126 976, EndOfFile: 123 800, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8413303","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mup.sys","SUCCESS","Offset: 0, Length: 123 800, Priority: Normal" "19:13:31,8413687","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mup.sys","SUCCESS","" "19:13:31,8420442","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\disk.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8420711","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\disk.sys","SUCCESS","AllocationSize: 94 208, EndOfFile: 94 104, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8420830","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\disk.sys","SUCCESS","Offset: 0, Length: 94 104, Priority: Normal" "19:13:31,8421167","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\disk.sys","SUCCESS","" "19:13:31,8454875","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\Classpnp.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8455145","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\Classpnp.sys","SUCCESS","AllocationSize: 405 504, EndOfFile: 403 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8455254","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\Classpnp.sys","SUCCESS","Offset: 0, Length: 403 352, Priority: Normal" "19:13:31,8456312","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\Classpnp.sys","SUCCESS","" "19:13:31,8462223","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\filecrypt.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8462409","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\filecrypt.sys","SUCCESS","AllocationSize: 57 344, EndOfFile: 55 808, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8462528","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\filecrypt.sys","SUCCESS","Offset: 0, Length: 55 808, Priority: Normal" "19:13:31,8462865","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\filecrypt.sys","SUCCESS","" "19:13:31,8465652","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\tbs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8465915","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\tbs.sys","SUCCESS","AllocationSize: 28 672, EndOfFile: 28 056, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8466040","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\tbs.sys","SUCCESS","Offset: 0, Length: 28 056, Priority: Normal" "19:13:31,8466248","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\tbs.sys","SUCCESS","" "19:13:31,8467932","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\null.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8468185","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\null.sys","SUCCESS","AllocationSize: 8 192, EndOfFile: 7 168, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8468285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\null.sys","SUCCESS","Offset: 0, Length: 7 168, Priority: Normal" "19:13:31,8468458","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\null.sys","SUCCESS","" "19:13:31,8473631","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\BasicDisplay.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8473808","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\BasicDisplay.sys","SUCCESS","AllocationSize: 61 440, EndOfFile: 58 880, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8473920","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\BasicDisplay.sys","SUCCESS","Offset: 0, Length: 58 880, Priority: Normal" "19:13:31,8474183","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\BasicDisplay.sys","SUCCESS","" "19:13:31,8482012","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\watchdog.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8482278","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\watchdog.sys","SUCCESS","AllocationSize: 57 344, EndOfFile: 56 320, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8482400","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\watchdog.sys","SUCCESS","Offset: 0, Length: 56 320, Priority: Normal" "19:13:31,8482657","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\watchdog.sys","SUCCESS","" "19:13:31,8601752","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\dxgkrnl.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8602124","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\dxgkrnl.sys","SUCCESS","AllocationSize: 2 576 384, EndOfFile: 2 573 208, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8602628","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\dxgkrnl.sys","SUCCESS","Offset: 0, Length: 2 573 208, Priority: Normal" "19:13:31,8609328","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\dxgkrnl.sys","SUCCESS","" "19:13:31,8618882","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\vmbkmclr.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8619306","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\vmbkmclr.sys","SUCCESS","AllocationSize: 81 920, EndOfFile: 80 384, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8619479","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\vmbkmclr.sys","SUCCESS","Offset: 0, Length: 80 384, Priority: Normal" "19:13:31,8619947","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\vmbkmclr.sys","SUCCESS","" "19:13:31,8624036","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\BasicRender.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8624219","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\BasicRender.sys","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 816, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8624338","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\BasicRender.sys","SUCCESS","Offset: 0, Length: 34 816, Priority: Normal" "19:13:31,8624572","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\BasicRender.sys","SUCCESS","" "19:13:31,8631692","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\npfs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8631984","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\npfs.sys","SUCCESS","AllocationSize: 73 728, EndOfFile: 73 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8632103","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\npfs.sys","SUCCESS","Offset: 0, Length: 73 216, Priority: Normal" "19:13:31,8632423","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\npfs.sys","SUCCESS","" "19:13:31,8636615","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\msfs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8636882","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\msfs.sys","SUCCESS","AllocationSize: 32 768, EndOfFile: 31 232, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8637000","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\msfs.sys","SUCCESS","Offset: 0, Length: 31 232, Priority: Normal" "19:13:31,8637221","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\msfs.sys","SUCCESS","" "19:13:31,8671183","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\afd.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8671469","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\afd.sys","SUCCESS","AllocationSize: 614 400, EndOfFile: 614 296, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8671584","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\afd.sys","SUCCESS","Offset: 0, Length: 614 296, Priority: Normal" "19:13:31,8673473","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\afd.sys","SUCCESS","" "19:13:31,8678412","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\tdi.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8678695","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\tdi.sys","SUCCESS","AllocationSize: 40 960, EndOfFile: 40 344, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8678813","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\tdi.sys","SUCCESS","Offset: 0, Length: 40 344, Priority: Normal" "19:13:31,8679060","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\tdi.sys","SUCCESS","" "19:13:31,8687463","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\vwififlt.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8687765","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\vwififlt.sys","SUCCESS","AllocationSize: 77 824, EndOfFile: 76 800, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8687887","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\vwififlt.sys","SUCCESS","Offset: 0, Length: 76 800, Priority: Normal" "19:13:31,8688259","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\vwififlt.sys","SUCCESS","" "19:13:31,8721627","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\rdbss.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8722006","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\rdbss.sys","SUCCESS","AllocationSize: 430 080, EndOfFile: 426 904, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8722144","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\rdbss.sys","SUCCESS","Offset: 0, Length: 426 904, Priority: Normal" "19:13:31,8723555","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\rdbss.sys","SUCCESS","" "19:13:31,8854450","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\VBoxDrv.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8854658","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\VBoxDrv.sys","SUCCESS","AllocationSize: 1 040 384, EndOfFile: 1 037 824, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,8854780","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\VBoxDrv.sys","SUCCESS","Offset: 0, Length: 1 037 824, Priority: Normal" "19:13:31,8857414","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\VBoxDrv.sys","SUCCESS","" "19:13:31,8862443","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\nsiproxy.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8862773","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\nsiproxy.sys","SUCCESS","AllocationSize: 45 056, EndOfFile: 44 544, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8862892","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\nsiproxy.sys","SUCCESS","Offset: 0, Length: 44 544, Priority: Normal" "19:13:31,8863142","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\nsiproxy.sys","SUCCESS","" "19:13:31,8866262","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\npsvctrig.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8866445","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\npsvctrig.sys","SUCCESS","AllocationSize: 28 672, EndOfFile: 26 112, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8866557","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\npsvctrig.sys","SUCCESS","Offset: 0, Length: 26 112, Priority: Normal" "19:13:31,8866766","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\npsvctrig.sys","SUCCESS","" "19:13:31,8870409","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mssmbios.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8870676","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mssmbios.sys","SUCCESS","AllocationSize: 40 960, EndOfFile: 40 856, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8870794","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mssmbios.sys","SUCCESS","Offset: 0, Length: 40 856, Priority: Normal" "19:13:31,8871076","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mssmbios.sys","SUCCESS","" "19:13:31,8883229","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\dfsc.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8883501","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\dfsc.sys","SUCCESS","AllocationSize: 151 552, EndOfFile: 151 040, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8883620","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\dfsc.sys","SUCCESS","Offset: 0, Length: 151 040, Priority: Normal" "19:13:31,8884140","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\dfsc.sys","SUCCESS","" "19:13:31,8917444","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ahcache.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8917729","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ahcache.sys","SUCCESS","AllocationSize: 241 664, EndOfFile: 240 640, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:31,8917851","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ahcache.sys","SUCCESS","Offset: 0, Length: 240 640, Priority: Normal" "19:13:31,8918663","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ahcache.sys","SUCCESS","" "19:13:31,8945774","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\VBoxNetAdp6.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8945963","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\VBoxNetAdp6.sys","SUCCESS","AllocationSize: 241 664, EndOfFile: 239 872, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:31,8946088","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\VBoxNetAdp6.sys","SUCCESS","Offset: 0, Length: 239 872, Priority: Normal" "19:13:31,8946842","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\VBoxNetAdp6.sys","SUCCESS","" "19:13:31,8951573","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\umbus.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:31,8951848","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\umbus.sys","SUCCESS","AllocationSize: 57 344, EndOfFile: 56 320, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:31,8951970","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\umbus.sys","SUCCESS","Offset: 0, Length: 56 320, Priority: Normal" "19:13:31,8952236","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\umbus.sys","SUCCESS","" "19:13:32,0999156","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f86391af4abfe0cb\nvlddmkm.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,0999374","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f86391af4abfe0cb\nvlddmkm.sys","SUCCESS","AllocationSize: 38 699 008, EndOfFile: 38 696 720, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,1001580","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f86391af4abfe0cb\nvlddmkm.sys","SUCCESS","Offset: 0, Length: 38 696 720, Priority: Normal" "19:13:32,1115599","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f86391af4abfe0cb\nvlddmkm.sys","SUCCESS","" "19:13:32,1156171","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\USBXHCI.SYS","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1156578","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\USBXHCI.SYS","SUCCESS","AllocationSize: 438 272, EndOfFile: 437 656, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1156703","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\USBXHCI.SYS","SUCCESS","Offset: 0, Length: 437 656, Priority: Normal" "19:13:32,1157823","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\USBXHCI.SYS","SUCCESS","" "19:13:32,1168772","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\Ucx01000.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1169061","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\Ucx01000.sys","SUCCESS","AllocationSize: 229 376, EndOfFile: 227 224, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1169186","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\Ucx01000.sys","SUCCESS","Offset: 0, Length: 227 224, Priority: Normal" "19:13:32,1170029","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\Ucx01000.sys","SUCCESS","" "19:13:32,1177057","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\usbehci.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1177425","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\usbehci.sys","SUCCESS","AllocationSize: 98 304, EndOfFile: 95 640, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1177554","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\usbehci.sys","SUCCESS","Offset: 0, Length: 95 640, Priority: Normal" "19:13:32,1178137","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\usbehci.sys","SUCCESS","" "19:13:32,1198382","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\usbport.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1198661","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\usbport.sys","SUCCESS","AllocationSize: 454 656, EndOfFile: 454 040, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1198779","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\usbport.sys","SUCCESS","Offset: 0, Length: 454 040, Priority: Normal" "19:13:32,1199947","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\usbport.sys","SUCCESS","" "19:13:32,1207070","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\hdaudbus.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1207340","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\hdaudbus.sys","SUCCESS","AllocationSize: 86 016, EndOfFile: 86 016, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1207462","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\hdaudbus.sys","SUCCESS","Offset: 0, Length: 86 016, Priority: Normal" "19:13:32,1207776","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\hdaudbus.sys","SUCCESS","" "19:13:32,1239509","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\portcls.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1239788","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\portcls.sys","SUCCESS","AllocationSize: 380 928, EndOfFile: 379 392, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1239906","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\portcls.sys","SUCCESS","Offset: 0, Length: 379 392, Priority: Normal" "19:13:32,1241067","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\portcls.sys","SUCCESS","" "19:13:32,1248139","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\drmk.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1248415","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\drmk.sys","SUCCESS","AllocationSize: 98 304, EndOfFile: 96 768, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1248540","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\drmk.sys","SUCCESS","Offset: 0, Length: 96 768, Priority: Normal" "19:13:32,1248893","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\drmk.sys","SUCCESS","" "19:13:32,1287910","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ks.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1288439","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ks.sys","SUCCESS","AllocationSize: 397 312, EndOfFile: 394 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1288586","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ks.sys","SUCCESS","Offset: 0, Length: 394 752, Priority: Normal" "19:13:32,1290562","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ks.sys","SUCCESS","" "19:13:32,1306059","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\intelppm.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1306602","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\intelppm.sys","SUCCESS","AllocationSize: 200 704, EndOfFile: 198 656, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1306762","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\intelppm.sys","SUCCESS","Offset: 0, Length: 198 656, Priority: Normal" "19:13:32,1307945","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\intelppm.sys","SUCCESS","" "19:13:32,1310899","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\wmiacpi.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1311226","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\wmiacpi.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 18 432, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1311348","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\wmiacpi.sys","SUCCESS","Offset: 0, Length: 18 432, Priority: Normal" "19:13:32,1311618","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\wmiacpi.sys","SUCCESS","" "19:13:32,1313670","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\swenum.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1313933","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\swenum.sys","SUCCESS","AllocationSize: 20 480, EndOfFile: 18 328, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1314042","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\swenum.sys","SUCCESS","Offset: 0, Length: 18 328, Priority: Normal" "19:13:32,1314283","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\swenum.sys","SUCCESS","" "19:13:32,1316134","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\vmulti.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1316332","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\vmulti.sys","SUCCESS","AllocationSize: 12 288, EndOfFile: 10 752, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,1316432","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\vmulti.sys","SUCCESS","Offset: 0, Length: 10 752, Priority: Normal" "19:13:32,1316653","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\vmulti.sys","SUCCESS","" "19:13:32,1318420","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mshidkmdf.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1318590","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mshidkmdf.sys","SUCCESS","AllocationSize: 12 288, EndOfFile: 8 704, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1318683","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mshidkmdf.sys","SUCCESS","Offset: 0, Length: 8 704, Priority: Normal" "19:13:32,1318873","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mshidkmdf.sys","SUCCESS","" "19:13:32,1336519","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\hidclass.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1336901","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\hidclass.sys","SUCCESS","AllocationSize: 188 416, EndOfFile: 187 392, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1337087","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\hidclass.sys","SUCCESS","Offset: 0, Length: 187 392, Priority: Normal" "19:13:32,1338219","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\hidclass.sys","SUCCESS","" "19:13:32,1342924","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\hidparse.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1343302","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\hidparse.sys","SUCCESS","AllocationSize: 49 152, EndOfFile: 45 568, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1343427","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\hidparse.sys","SUCCESS","Offset: 0, Length: 45 568, Priority: Normal" "19:13:32,1343751","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\hidparse.sys","SUCCESS","" "19:13:32,1377011","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\usbhub.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1377553","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\usbhub.sys","SUCCESS","AllocationSize: 516 096, EndOfFile: 513 944, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1377739","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\usbhub.sys","SUCCESS","Offset: 0, Length: 513 944, Priority: Normal" "19:13:32,1380988","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\usbhub.sys","SUCCESS","" "19:13:32,1386748","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\usbd.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1387325","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\usbd.sys","SUCCESS","AllocationSize: 32 768, EndOfFile: 32 152, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1387553","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\usbd.sys","SUCCESS","Offset: 0, Length: 32 152, Priority: Normal" "19:13:32,1388252","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\usbd.sys","SUCCESS","" "19:13:32,1394202","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mouhid.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1394757","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mouhid.sys","SUCCESS","AllocationSize: 32 768, EndOfFile: 32 768, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1394981","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mouhid.sys","SUCCESS","Offset: 0, Length: 32 768, Priority: Normal" "19:13:32,1395651","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mouhid.sys","SUCCESS","" "19:13:32,1401245","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mouclass.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1401620","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mouclass.sys","SUCCESS","AllocationSize: 57 344, EndOfFile: 57 240, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1401764","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mouclass.sys","SUCCESS","Offset: 0, Length: 57 240, Priority: Normal" "19:13:32,1402262","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mouclass.sys","SUCCESS","" "19:13:32,1436890","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\USBHUB3.SYS","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1437314","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\USBHUB3.SYS","SUCCESS","AllocationSize: 557 056, EndOfFile: 555 416, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1437477","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\USBHUB3.SYS","SUCCESS","Offset: 0, Length: 555 416, Priority: Normal" "19:13:32,1439613","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\USBHUB3.SYS","SUCCESS","" "19:13:32,1768971","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\RTKVHD64.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1769212","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\RTKVHD64.sys","SUCCESS","AllocationSize: 6 402 048, EndOfFile: 6 398 976, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,1769889","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\RTKVHD64.sys","SUCCESS","Offset: 0, Length: 6 398 976, Priority: Normal" "19:13:32,1788154","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\RTKVHD64.sys","SUCCESS","" "19:13:32,1793629","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ksthunk.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1794055","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ksthunk.sys","SUCCESS","AllocationSize: 28 672, EndOfFile: 27 136, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1794213","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ksthunk.sys","SUCCESS","Offset: 0, Length: 27 136, Priority: Normal" "19:13:32,1794581","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ksthunk.sys","SUCCESS","" "19:13:32,1807920","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\usbccgp.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1808190","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\usbccgp.sys","SUCCESS","AllocationSize: 172 032, EndOfFile: 168 856, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1808312","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\usbccgp.sys","SUCCESS","Offset: 0, Length: 168 856, Priority: Normal" "19:13:32,1808879","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\usbccgp.sys","SUCCESS","" "19:13:32,1951382","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\netr28ux.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1951629","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\netr28ux.sys","SUCCESS","AllocationSize: 2 260 992, EndOfFile: 2 260 904, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,1952100","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\netr28ux.sys","SUCCESS","Offset: 0, Length: 2 260 904, Priority: Normal" "19:13:32,1958681","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\netr28ux.sys","SUCCESS","" "19:13:32,1962540","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\vwifibus.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1962915","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\vwifibus.sys","SUCCESS","AllocationSize: 28 672, EndOfFile: 27 136, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1963047","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\vwifibus.sys","SUCCESS","Offset: 0, Length: 27 136, Priority: Normal" "19:13:32,1963335","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\vwifibus.sys","SUCCESS","" "19:13:32,1967700","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\hidusb.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1967963","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\hidusb.sys","SUCCESS","AllocationSize: 40 960, EndOfFile: 40 960, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1968095","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\hidusb.sys","SUCCESS","Offset: 0, Length: 40 960, Priority: Normal" "19:13:32,1968361","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\hidusb.sys","SUCCESS","" "19:13:32,1972530","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\kbdhid.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1972793","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\kbdhid.sys","SUCCESS","AllocationSize: 40 960, EndOfFile: 40 448, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1972912","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\kbdhid.sys","SUCCESS","Offset: 0, Length: 40 448, Priority: Normal" "19:13:32,1973140","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\kbdhid.sys","SUCCESS","" "19:13:32,1978207","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\kbdclass.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1978467","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\kbdclass.sys","SUCCESS","AllocationSize: 65 536, EndOfFile: 63 384, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,1978586","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\kbdclass.sys","SUCCESS","Offset: 0, Length: 63 384, Priority: Normal" "19:13:32,1978865","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\kbdclass.sys","SUCCESS","" "19:13:32,1979654","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\win32k.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1979901","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\win32k.sys","SUCCESS","AllocationSize: 466 944, EndOfFile: 463 360, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1980007","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\win32k.sys","SUCCESS","Offset: 0, Length: 463 360, Priority: Normal" "19:13:32,1981241","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\win32k.sys","SUCCESS","" "19:13:32,1981909","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\win32kfull.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1982072","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\win32kfull.sys","SUCCESS","AllocationSize: 3 674 112, EndOfFile: 3 670 528, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1982457","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\win32kfull.sys","SUCCESS","Offset: 0, Length: 3 670 528, Priority: Normal" "19:13:32,1993512","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\win32kfull.sys","SUCCESS","" "19:13:32,1995293","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\win32kbase.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,1995488","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\win32kbase.sys","SUCCESS","AllocationSize: 2 109 440, EndOfFile: 2 106 880, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,1995947","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\win32kbase.sys","SUCCESS","Offset: 0, Length: 2 106 880, Priority: Normal" "19:13:32,2003028","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\win32kbase.sys","SUCCESS","" "19:13:32,2048155","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\dxgmms2.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2048492","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\dxgmms2.sys","SUCCESS","AllocationSize: 753 664, EndOfFile: 749 976, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2048620","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\dxgmms2.sys","SUCCESS","Offset: 0, Length: 749 976, Priority: Normal" "19:13:32,2050390","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\dxgmms2.sys","SUCCESS","" "19:13:32,2054492","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\monitor.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2054762","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\monitor.sys","SUCCESS","AllocationSize: 40 960, EndOfFile: 38 912, NumberOfLinks: 3, DeletePending: False, Directory: False" "19:13:32,2054880","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\monitor.sys","SUCCESS","Offset: 0, Length: 38 912, Priority: Normal" "19:13:32,2055143","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\monitor.sys","SUCCESS","" "19:13:32,2055839","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\tsddd.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2056077","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\tsddd.dll","SUCCESS","AllocationSize: 16 384, EndOfFile: 15 360, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2056179","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\tsddd.dll","SUCCESS","Offset: 0, Length: 15 360, Priority: Normal" "19:13:32,2056365","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\tsddd.dll","SUCCESS","" "19:13:32,2057161","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\cdd.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2057395","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\cdd.dll","SUCCESS","AllocationSize: 237 568, EndOfFile: 234 496, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2057501","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\cdd.dll","SUCCESS","Offset: 0, Length: 234 496, Priority: Normal" "19:13:32,2058190","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\cdd.dll","SUCCESS","" "19:13:32,2070891","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\wcifs.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2071154","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\wcifs.sys","SUCCESS","AllocationSize: 151 552, EndOfFile: 147 864, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2071273","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\wcifs.sys","SUCCESS","Offset: 0, Length: 147 864, Priority: Normal" "19:13:32,2071709","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\wcifs.sys","SUCCESS","" "19:13:32,2078630","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\storqosflt.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2078810","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\storqosflt.sys","SUCCESS","AllocationSize: 81 920, EndOfFile: 79 872, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2078922","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\storqosflt.sys","SUCCESS","Offset: 0, Length: 79 872, Priority: Normal" "19:13:32,2079233","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\storqosflt.sys","SUCCESS","" "19:13:32,2110809","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\nwifi.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2111072","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\nwifi.sys","SUCCESS","AllocationSize: 532 480, EndOfFile: 528 896, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2111184","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\nwifi.sys","SUCCESS","Offset: 0, Length: 528 896, Priority: Normal" "19:13:32,2112521","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\nwifi.sys","SUCCESS","" "19:13:32,2118452","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ndisuio.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2118715","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ndisuio.sys","SUCCESS","AllocationSize: 65 536, EndOfFile: 65 024, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2118837","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ndisuio.sys","SUCCESS","Offset: 0, Length: 65 024, Priority: Normal" "19:13:32,2119109","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ndisuio.sys","SUCCESS","" "19:13:32,2120880","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mi2c.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2121056","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mi2c.sys","SUCCESS","AllocationSize: 24 576, EndOfFile: 20 784, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,2121159","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mi2c.sys","SUCCESS","Offset: 0, Length: 20 784, Priority: Normal" "19:13:32,2121358","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mi2c.sys","SUCCESS","" "19:13:32,2122762","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\inpoutx64.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2122929","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\inpoutx64.sys","SUCCESS","AllocationSize: 16 384, EndOfFile: 15 008, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,2123025","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\inpoutx64.sys","SUCCESS","Offset: 0, Length: 15 008, Priority: Normal" "19:13:32,2123211","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\inpoutx64.sys","SUCCESS","" "19:13:32,2124866","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\ei2c.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2125033","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\ei2c.sys","SUCCESS","AllocationSize: 24 576, EndOfFile: 20 784, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,2125126","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\ei2c.sys","SUCCESS","Offset: 0, Length: 20 784, Priority: Normal" "19:13:32,2125322","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\ei2c.sys","SUCCESS","" "19:13:32,2129478","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\mmcss.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2129735","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\mmcss.sys","SUCCESS","AllocationSize: 45 056, EndOfFile: 43 520, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2129854","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\mmcss.sys","SUCCESS","Offset: 0, Length: 43 520, Priority: Normal" "19:13:32,2130085","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\mmcss.sys","SUCCESS","" "19:13:32,2166878","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\PEAuth.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2167183","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\PEAuth.sys","SUCCESS","AllocationSize: 724 992, EndOfFile: 723 968, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2167308","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\PEAuth.sys","SUCCESS","Offset: 0, Length: 723 968, Priority: Normal" "19:13:32,2169095","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\PEAuth.sys","SUCCESS","" "19:13:32,2174024","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\condrv.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2174294","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\condrv.sys","SUCCESS","AllocationSize: 57 344, EndOfFile: 55 704, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,2174419","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\condrv.sys","SUCCESS","Offset: 0, Length: 55 704, Priority: Normal" "19:13:32,2174707","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\condrv.sys","SUCCESS","" "19:13:32,2175641","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Program Files\Process Hacker 2\kprocesshacker.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2175814","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Program Files\Process Hacker 2\kprocesshacker.sys","SUCCESS","AllocationSize: 49 152, EndOfFile: 45 208, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,2175923","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Program Files\Process Hacker 2\kprocesshacker.sys","SUCCESS","Offset: 0, Length: 45 208, Priority: Normal" "19:13:32,2176160","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Program Files\Process Hacker 2\kprocesshacker.sys","SUCCESS","" "19:13:32,2181561","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\PROCMON24.SYS","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2181738","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\System32\drivers\PROCMON24.SYS","SUCCESS","AllocationSize: 94 208, EndOfFile: 92 008, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,2181847","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\PROCMON24.SYS","SUCCESS","Offset: 0, Length: 92 008, Priority: Normal" "19:13:32,2182110","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\PROCMON24.SYS","SUCCESS","" "19:13:32,2303697","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,2303928","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","AllocationSize: 2 355 200, EndOfFile: 2 353 608, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:32,2304400","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","Offset: 0, Length: 2 353 608, Priority: Normal" "19:13:32,2310885","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys","SUCCESS","" "19:13:32,3106817","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:32,3107010","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllhost.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:32,3107180","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Wow64\x86\xtajit","NAME NOT FOUND","Desired Access: Query Value" "19:13:32,3108726","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3109188","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dllhost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "19:13:32,3109444","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3109752","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dllhost.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:32,3110002","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Information: Label" "19:13:32,3110361","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Name: \Windows\SysWOW64\dllhost.exe" "19:13:32,3114290","EasyAntiCheat_launcher.exe","6076","Process Create","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","PID: 7000, Command line: /Processid:{ACDD2981-749D-0A23-677B-D70938FD6D56}" "19:13:32,3114893","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls","REPARSE","Desired Access: Query Value" "19:13:32,3115025","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls","NAME NOT FOUND","Desired Access: Query Value" "19:13:32,3115224","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value" "19:13:32,3115313","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "19:13:32,3115464","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Policies\Microsoft\Windows\Safer\CodeIdentifiers","REPARSE","Desired Access: Query Value" "19:13:32,3115573","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value" "19:13:32,3115721","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3115801","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80" "19:13:32,3115884","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:32,3115987","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","" "19:13:32,3116157","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value" "19:13:32,3117389","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:32,3118101","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3118421","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3118527","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3118700","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3119104","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:32,3119961","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:32,3120609","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3120888","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3120981","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3121135","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3121439","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:32,3122302","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:32,3122953","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3123232","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3123328","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3123489","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3123803","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:32,3124602","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:32,3125234","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3125500","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3125590","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3125743","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3126042","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:32,3126853","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:32,3127588","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3127863","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3127956","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3128114","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3128444","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:32,3129243","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:32,3129865","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3130125","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3130218","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3130368","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3130660","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:32,3131456","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:32,3132196","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:32,3132902","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:32,3133537","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3133816","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3133909","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3134066","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3134374","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:32,3135160","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:32,3135782","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3136045","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3136135","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3136289","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3136587","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:32,3137402","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:32,3138207","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3138499","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3138601","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3138762","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3139063","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:32,3139865","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:32,3140494","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3140795","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3140891","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3141049","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3141340","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:32,3142274","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:32,3142453","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3142540","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:32,3142671","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:32,3142822","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion","SUCCESS","Desired Access: Enumerate Sub Keys" "19:13:32,3142941","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3143063","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:32,3143146","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Query Value" "19:13:32,3143249","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3143319","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Windows\SysWOW64\dllhost.exe","NAME NOT FOUND","Length: 16" "19:13:32,3143425","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:32,3143627","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:32,3144378","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3144689","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:32,3144820","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:32,3145596","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3145888","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:32,3145985","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:32,3146257","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:14, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:22, FileAttributes: A" "19:13:32,3146693","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:14, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:22, FileAttributes: A" "19:13:32,3146892","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Name: \Windows\SysWOW64\dllhost.exe" "19:13:32,3147935","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3148201","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3148313","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3148435","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:32,3148550","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3148752","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3149926","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3150609","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read" "19:13:32,3150860","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Windows\SysWOW64\dllhost.exe","NAME NOT FOUND","Length: 1 024" "19:13:32,3150985","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:32,3151132","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read" "19:13:32,3151264","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Windows\SysWOW64\dllhost.exe","NAME NOT FOUND","Length: 1 024" "19:13:32,3151376","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:32,3151488","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\dllhost.exe","NAME NOT FOUND","Desired Access: Read" "19:13:32,3151841","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3151979","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dllhost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "19:13:32,3152107","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3152325","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3172865","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:32,3173708","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","Desired Access: Read" "19:13:32,3173885","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3173958","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20" "19:13:32,3174051","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","" "19:13:32,3180594","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:32,3180748","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3180832","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:32,3180963","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:32,3181104","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:32,3181797","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3182060","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:32,3182137","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:32,3182878","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3183118","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:32,3183195","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:32,3183433","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:14, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:22, FileAttributes: A" "19:13:32,3184340","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3185168","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:14, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:22, AllocationSize: 20 480, EndOfFile: 19 352, FileAttributes: A" "19:13:32,3185845","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3186143","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dllhost.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3186342","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3186598","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","" "19:13:32,3187448","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:32,3188099","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3188375","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3188474","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3188638","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3188968","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:32,3189770","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:32,3190412","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3190678","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3190771","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3190928","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3191226","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:32,3192070","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:32,3192714","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3192981","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3193077","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3193231","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3193532","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:32,3194321","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:32,3194947","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3195207","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3195296","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3195450","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3195761","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:32,3196570","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:32,3197205","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3197474","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3197567","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3197721","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3198016","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:32,3198795","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:32,3199414","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3199668","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3199761","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3199912","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3200200","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:32,3200992","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:32,3201785","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:32,3202490","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:32,3203122","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3203392","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3203485","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3203638","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3203937","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:32,3204713","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:32,3205332","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3205588","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3205681","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3205832","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3206121","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:32,3206932","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:32,3207567","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3207837","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3207927","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3208081","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3208376","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:32,3209155","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:32,3209771","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3210027","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3210120","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3210271","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3210553","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:32,3211432","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3211557","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Offset: 10 752, Length: 32, Priority: Normal" "19:13:32,3211820","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","AllocationSize: 20 480, EndOfFile: 19 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3211900","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Offset: 19 320, Length: 32" "19:13:32,3212135","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","" "19:13:32,3212378","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:32,3212539","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:32,3212622","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:32,3212744","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:32,3212907","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:32,3213042","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 21:50:14, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:22, FileAttributes: A" "19:13:32,3214158","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3214418","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3214505","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3214595","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:32,3214684","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:32,3214832","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3215236","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:32,3216532","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dllhost.exe","SUCCESS","" "19:13:32,3216923","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 729, Length: 64" "19:13:32,3218838","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\GameOverlayRenderer.dll","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:24, ChangeTime: 2021. 04. 13. 19:00:27, AllocationSize: 1 507 328, EndOfFile: 1 486 568, FileAttributes: ANCI" "19:13:32,3238251","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:32,3238380","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\R5Apex.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:32,3238502","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Wow64\x86\xtajit","NAME NOT FOUND","Desired Access: Query Value" "19:13:32,3239323","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:32,3239566","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "19:13:32,3239765","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:32,3240063","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\R5Apex.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:32,3240323","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Label" "19:13:32,3240731","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Name: \Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe" "19:13:32,8677097","EasyAntiCheat_launcher.exe","6076","Process Create","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe","SUCCESS","PID: 3708, Command line: ""D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe"" -steam -eac_executablename ""R5Apex.exe""" "19:13:32,8677165","R5Apex.exe","3708","Process Start","","SUCCESS","Parent PID: 6076, Command line: ""D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe"" -steam -eac_executablename ""R5Apex.exe"", Current directory: D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\, Environment: ; =::=::\ ; =D:=D:\Program Files (x86)\Steam ; ALLUSERSPROFILE=C:\ProgramData ; APPDATA=C:\Users\Administrator\AppData\Roaming ; CommonProgramFiles=C:\Program Files (x86)\Common Files ; CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files ; CommonProgramW6432=C:\Program Files\Common Files ; COMMON_MYDOCS=C:\Users\Public\Documents ; Compilers=C:\Code\Tools\Compilers ; COMPUTERNAME=DEVLA-PC ; ComSpec=C:\Windows\system32\cmd.exe ; FPS_BROWSER_APP_PROFILE_STRING=Internet Explorer ; FPS_BROWSER_USER_PROFILE_STRING=Default ; HOMEDRIVE=C: ; HOMEPATH=\Users\Administrator ; INSTALLDIR=D:\Program Files (x86)\Steam\steamapps\common\Apex Legends ; LOCALAPPDATA=C:\Users\Administrator\AppData\Local ; LOCAL_APPDATA=C:\Users\Administrator\AppData\Local ; LOGONSERVER=\\DEVLA-PC ; NUMBER_OF_PROCESSORS=4 ; OANOCACHE=1 ; OS=Windows_NT ; Path=D:\Program Files (x86)\Steam;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\dotnet;C:\Code\tools\.bin;C:\Code\tools\Cmder\bin;C:\Windows\Custom;C:\Users\Administrator\AppData\Local\Programs\Microsoft VS Code\bin;C:\Code\Tools\Compilers\C\mingw\bin; ; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JSE;.WSF;.WSH;.MSC ; PROCESSOR_ARCHITECTURE=x86 ; PROCESSOR_ARCHITEW6432=AMD64 ; PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ; PROCESSOR_LEVEL=6 ; PROCESSOR_REVISION=3a09 ; ProgramData=C:\ProgramData ; ProgramFiles=C:\Program Files (x86) ; ProgramFiles(x86)=C:\Program Files (x86) ; ProgramW6432=C:\Program Files ; PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules ; PT8HOME=D:\Program Files\Cisco Packet Tracer 8.0 ; PUBLIC=C:\Users\Public ; QT_DEVICE_PIXEL_RATIO=auto ; ROOTDRIVE=D ; SESSIONNAME=Console ; STEAMID=76561198178935861 ; SteamPath=D:\Program Files (x86)\Steam ; SteamUser=tomifiu15 ; SystemDrive=C: ; SystemRoot=C:\Windows ; TEMP=C:\Users\ADMINI~1\AppData\Local\Temp ; TMP=C:\Users\ADMINI~1\AppData\Local\Temp ; USERDOMAIN=DEVLA-PC ; USERDOMAIN_ROAMINGPROFILE=DEVLA-PC ; USERNAME=Administrator ; USERPROFILE=C:\Users\Administrator ; USER_MYDOCS=D:\Users\Administrator\Documents ; ValvePlatformMutex=d:/program files (x86)/steam/steam.exe ; VBOX_MSI_INSTALL_PATH=D:\Program Files\Oracle\VirtualBox\ ; windir=C:\Windows ; _MSYS2_PREFIX=x86_64 ; SteamClientLaunch=1 ; SteamNoOverlayUI=1 ; EnableConfiguratorSupport=0 ; SDL_GAMECONTROLLER_ALLOW_STEAM_VIRTUAL_GAMEPAD=1 ; SDL_JOYSTICK_HIDAPI_STEAMXBOX=0 ; SteamStreamingHardwareEncodingNVIDIA=1 ; SteamStreamingHardwareEncodingAMD=1 ; SteamStreamingHardwareEncodingIntel=1 ; SteamGameId=1172470 ; SteamAppId=1172470 ; SteamOverlayGameId=1172470 ; SteamAppUser=tomifiu15 ; MESA_GLSL_CACHE_DIR=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470 ; MESA_GLSL_CACHE_MAX_SIZE=5G ; __COMPAT_LAYER=ElevateCreateProcess ; __GL_SHADER_DISK_CACHE_PATH=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\nvidiav1 ; __GL_SHADER_DISK_CACHE_APP_NAME=steamapp_shader_cache ; __GL_SHADER_DISK_CACHE_READ_ONLY_APP_NAME=steam_shader_cache;steamapp_merged_shader_cache ; __GL_SHADER_DISK_CACHE_SKIP_CLEANUP=1 ; AMD_VK_PIPELINE_CACHE_PATH=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\AMDv1 ; AMD_VK_PIPELINE_CACHE_FILENAME=steamapp_shader_cache ; AMD_VK_USE_PIPELINE_CACHE=1 ; STEAM_FOSSILIZE_DUMP_PATH=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\fozpipelinesv5\steamapprun_pipeline_cache ; STEAM_FOSSILIZE_DUMP_PATH_READ_ONLY=D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\fozpipelinesv5\steam_pipeline_cache.foz;D:\Program Files (x86)\Steam\steamapps\shadercache\1172470\fozpipelinesv5\steamapp_pipeline_cache.foz ; FOSSILIZE_APPLICATION_INFO_FILTER_PATH=D:\Program Files (x86)\Steam\fossilize_engine_filters.json ; ENABLE_VK_LAYER_VALVE_steam_fossilize_1=1 ; STEAM_COMPAT" "19:13:33,5920733","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","Offset: 287 744, Length: 32 768, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal" "19:13:37,2348817","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows Activation Technologies\AdminObject\Store","NAME NOT FOUND","Desired Access: Read" "19:13:37,3283323","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe.local","NAME NOT FOUND","Desired Access: Delete, Disposition: Open, Options: Delete On Close, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "19:13:37,3283974","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe.local","NAME NOT FOUND","" "19:13:37,3284385","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe.local","SUCCESS","Desired Access: Generic Read/Write, Delete, Disposition: Create, Options: Delete On Close, Attributes: H, ShareMode: None, AllocationSize: 0, OpenResult: Created" "19:13:37,3286806","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Name: \Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe" "19:13:37,3287438","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3287618","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3289600","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 0, Length: 33 708 280, Priority: Normal" "19:13:37,3397403","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:37,3420700","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 2888" "19:13:37,3423449","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:37,3423882","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3424007","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:37,3424328","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:37,3424514","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:37,3424616","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Query Value" "19:13:37,3424751","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3424834","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe","NAME NOT FOUND","Length: 16" "19:13:37,3425113","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:37,3425441","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:37,3426672","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3427022","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3427115","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3427952","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3428212","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3428292","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3428568","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI" "19:13:37,3429174","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI" "19:13:37,3429392","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Name: \Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe" "19:13:37,3430627","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3430896","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3431012","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3431201","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:37,3431377","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3431627","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3433090","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3434081","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read" "19:13:37,3434434","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe","NAME NOT FOUND","Length: 1 024" "19:13:37,3434716","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:37,3434880","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read" "19:13:37,3435056","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\R5Apex.exe","NAME NOT FOUND","Length: 1 024" "19:13:37,3435316","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:37,3435444","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\r5apex.exe","NAME NOT FOUND","Desired Access: Read" "19:13:37,3436563","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3436695","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "19:13:37,3436833","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3437054","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3451086","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3452308","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","Desired Access: Read" "19:13:37,3452609","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3452699","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20" "19:13:37,3452879","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","" "19:13:37,3458145","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:37,3458344","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3458427","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:37,3458623","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:37,3458761","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:37,3459438","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3459697","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3459778","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3460493","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3460730","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3460804","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3461035","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI" "19:13:37,3461753","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3462417","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, AllocationSize: 33 751 040, EndOfFile: 33 708 280, FileAttributes: ANCI" "19:13:37,3462892","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3463184","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3463694","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3463864","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3464194","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:37,3465137","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:37,3465817","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3466112","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3466221","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3466388","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3466766","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:37,3467597","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:37,3468251","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3468524","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3468620","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3468774","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3469108","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:37,3469961","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:37,3470605","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3470881","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3470977","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3471131","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3471468","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:37,3472260","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:37,3472889","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3473162","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3473255","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3473405","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3473732","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:37,3474525","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:37,3475153","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3475423","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3475516","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3475670","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3476029","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:37,3476824","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:37,3477446","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3477706","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3477799","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3477960","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3478293","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:37,3479101","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:37,3479842","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:37,3480554","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:37,3481186","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3481456","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3481552","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3481709","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3482049","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:37,3482915","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:37,3483547","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3483810","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3483903","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3484057","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3484381","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:37,3485189","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:37,3485827","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3486106","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3486199","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3486353","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3486683","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:37,3487472","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:37,3488098","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3488361","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3488454","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3488605","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3488925","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:37,3559889","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:37,3560403","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:37,3560669","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3560762","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:37,3560989","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:37,3561192","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:37,3561339","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI" "19:13:37,3562545","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3562862","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3562952","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3563065","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3563167","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3563324","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3563767","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3564883","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:37,3565377","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 793, Length: 64, Priority: Normal" "19:13:37,3566297","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 857, Length: 62" "19:13:37,3567054","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, AllocationSize: 458 752, EndOfFile: 412 392, FileAttributes: ANCI" "19:13:37,3567535","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, AllocationSize: 458 752, EndOfFile: 412 392, FileAttributes: ANCI" "19:13:37,3567824","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:37,3567927","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\x64launcher.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:37,3568068","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Wow64\x86\xtajit","NAME NOT FOUND","Desired Access: Query Value" "19:13:37,3568706","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3568915","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "19:13:37,3569104","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3569396","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\x64launcher.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:37,3569627","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Information: Label" "19:13:37,3570034","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Name: \Program Files (x86)\Steam\bin\x64launcher.exe" "19:13:37,3593441","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Name: \Program Files (x86)\Steam\bin\x64launcher.exe" "19:13:37,3594005","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3594175","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","AllocationSize: 458 752, EndOfFile: 412 392, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3594271","EasyAntiCheat_launcher.exe","6076","ReadFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Offset: 0, Length: 412 392, Priority: Normal" "19:13:37,3595214","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","" "19:13:37,3597014","EasyAntiCheat_launcher.exe","6076","Process Create","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","PID: 5976, Command line: ""D:\Program Files (x86)\Steam\bin\x64launcher.exe"" -hproc 7fc -hthread 7e0 -baseoverlayname D:\Program Files (x86)\Steam\gameoverlayrenderer64.dll" "19:13:37,3597738","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:37,3597995","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3598082","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:37,3598277","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:37,3598402","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:37,3598492","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Query Value" "19:13:37,3598601","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3598678","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\D:\Program Files (x86)\Steam\bin\x64launcher.exe","NAME NOT FOUND","Length: 16" "19:13:37,3598883","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:37,3599047","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:37,3599794","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3600096","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3600186","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3600930","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3601170","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3601247","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3601484","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, FileAttributes: ANCI" "19:13:37,3601873","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, FileAttributes: ANCI" "19:13:37,3602036","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Name: \Program Files (x86)\Steam\bin\x64launcher.exe" "19:13:37,3603062","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3603325","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3603434","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3603563","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:37,3603688","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3603893","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3605041","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","AllocationSize: 458 752, EndOfFile: 412 392, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3605708","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read" "19:13:37,3605891","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\D:\Program Files (x86)\Steam\bin\x64launcher.exe","NAME NOT FOUND","Length: 1 024" "19:13:37,3606106","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:37,3606244","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read" "19:13:37,3606369","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\D:\Program Files (x86)\Steam\bin\x64launcher.exe","NAME NOT FOUND","Length: 1 024" "19:13:37,3606542","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","" "19:13:37,3606655","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\x64launcher.exe","NAME NOT FOUND","Desired Access: Read" "19:13:37,3607703","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","AllocationSize: 458 752, EndOfFile: 412 392, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3607828","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE" "19:13:37,3607941","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","AllocationSize: 458 752, EndOfFile: 412 392, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,3608156","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3614214","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3615032","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","Desired Access: Read" "19:13:37,3615218","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3615292","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20" "19:13:37,3615433","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","" "19:13:37,3619137","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:37,3619301","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3619381","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:37,3619548","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:37,3619676","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:37,3620334","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3620593","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3620670","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3621379","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3621613","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:37,3621690","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3621918","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, FileAttributes: ANCI" "19:13:37,3622537","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3623146","EasyAntiCheat_launcher.exe","6076","QueryOpen","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, AllocationSize: 458 752, EndOfFile: 412 392, FileAttributes: ANCI" "19:13:37,3623605","EasyAntiCheat_launcher.exe","6076","CreateFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3623852","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3624333","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3624481","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3624705","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","" "19:13:37,3625603","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:37,3626280","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3626578","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3626681","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3626851","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3627175","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:37,3628012","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:37,3628656","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3628926","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3629019","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3629173","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3629474","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:37,3630315","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:37,3630982","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3631264","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3631357","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3631511","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3631844","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:37,3632646","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:37,3633345","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3633608","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3633702","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3633852","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3634154","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:37,3634933","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:37,3635562","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3635828","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3635921","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3636075","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3636376","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:37,3637153","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:37,3637765","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3638028","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3638121","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3638272","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3638557","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:37,3639343","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:37,3640068","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:37,3640777","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:37,3641399","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3641665","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3641761","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3641912","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3642214","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:37,3642996","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:37,3643612","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3643872","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3643965","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3644116","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3644404","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:37,3645196","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:37,3645828","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3646101","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3646194","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3646348","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3646643","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:37,3647429","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:37,3648051","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3648314","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3648407","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3648558","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3648846","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:37,3649674","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","" "19:13:37,3650001","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:37,3650177","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3650261","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:37,3650424","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:37,3650572","EasyAntiCheat_launcher.exe","6076","QuerySecurityFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:37,3650694","EasyAntiCheat_launcher.exe","6076","QueryBasicInformationFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:27, FileAttributes: ANCI" "19:13:37,3651608","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3651871","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3651961","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3652054","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3652143","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,3652294","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3652660","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:37,3653753","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\bin\x64launcher.exe","SUCCESS","" "19:13:37,3713114","R5Apex.exe","3708","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Image Base: 0x7ff7d1770000, Image Size: 0xb54d000" "19:13:37,3714454","R5Apex.exe","3708","Load Image","C:\Windows\System32\ntdll.dll","SUCCESS","Image Base: 0x7ffdd1ff0000, Image Size: 0x1e0000" "19:13:37,3715753","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Segment Heap","REPARSE","Desired Access: Query Value" "19:13:37,3715907","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\Segment Heap","NAME NOT FOUND","Desired Access: Query Value" "19:13:37,3716436","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:37,3716542","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:37,3716670","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:37,3717001","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:37,3720330","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3720516","EasyAntiCheat_launcher.exe","6076","Thread Create","","SUCCESS","Thread ID: 5932" "19:13:37,3723659","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:37,3723758","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:37,3723922","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:37,3724028","R5Apex.exe","3708","Load Image","C:\Windows\System32\kernel32.dll","SUCCESS","Image Base: 0x7ffdcfc00000, Image Size: 0xae000" "19:13:37,3724076","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:37,3724179","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:37,3724342","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:37,3725106","R5Apex.exe","3708","Load Image","C:\Windows\System32\KernelBase.dll","SUCCESS","Image Base: 0x7ffdcefd0000, Image Size: 0x266000" "19:13:37,3730734","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\3c74afb9-8d82-44e3-b52c-365dbf48382a","NAME NOT FOUND","Length: 524" "19:13:37,3731472","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\05f95efe-7f75-49c7-a994-60a55cc09571","NAME NOT FOUND","Length: 524" "19:13:37,3732056","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3732335","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 0, Length: 2, Priority: Normal" "19:13:37,3732716","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2, Length: 998" "19:13:37,3732883","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 000, Length: 962" "19:13:37,3733031","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 962, Length: 963" "19:13:37,3733169","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2 925, Length: 979" "19:13:37,3733316","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value" "19:13:37,3733457","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value" "19:13:37,3733528","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 3 904, Length: 995" "19:13:37,3733595","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","REPARSE","Desired Access: Read" "19:13:37,3733685","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\GP\DLL","NAME NOT FOUND","Desired Access: Read" "19:13:37,3733807","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value" "19:13:37,3733916","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 4 899, Length: 995" "19:13:37,3733980","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","NAME NOT FOUND","Length: 80" "19:13:37,3734108","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","" "19:13:37,3734256","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","NAME NOT FOUND","Desired Access: Query Value" "19:13:37,3734326","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 5 894, Length: 986" "19:13:37,3734500","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem\","REPARSE","Desired Access: Read" "19:13:37,3734593","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","Desired Access: Read" "19:13:37,3734708","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\FileSystem\LongPathsEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:37,3734734","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 6 880, Length: 980" "19:13:37,3734836","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\FileSystem","SUCCESS","" "19:13:37,3735128","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 7 860, Length: 976" "19:13:37,3735532","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 8 836, Length: 989" "19:13:37,3735722","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 9 825, Length: 968" "19:13:37,3735895","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 10 793, Length: 980" "19:13:37,3736058","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 11 773, Length: 961" "19:13:37,3736276","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 12 734, Length: 985" "19:13:37,3736309","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\apphelp.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:39, LastAccessTime: 2021. 02. 13. 21:50:33, LastWriteTime: 2017. 09. 29. 15:41:39, ChangeTime: 2020. 01. 09. 4:45:23, AllocationSize: 536 576, EndOfFile: 533 504, FileAttributes: A" "19:13:37,3736652","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 13 719, Length: 986" "19:13:37,3737027","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 14 705, Length: 970" "19:13:37,3737136","R5Apex.exe","3708","CreateFile","C:\Windows\System32\apphelp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,3737431","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 15 675, Length: 987" "19:13:37,3737521","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,3737749","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\apphelp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,3737842","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 16 662, Length: 982" "19:13:37,3738252","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 17 644, Length: 992" "19:13:37,3738692","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 18 636, Length: 985" "19:13:37,3739060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 19 621, Length: 999" "19:13:37,3739471","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 20 620, Length: 1 000" "19:13:37,3739856","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 21 620, Length: 982" "19:13:37,3740241","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 22 602, Length: 972" "19:13:37,3740609","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 23 574, Length: 995" "19:13:37,3740969","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 24 569, Length: 974" "19:13:37,3741357","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 25 543, Length: 997" "19:13:37,3741742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 26 540, Length: 999" "19:13:37,3742072","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 27 539, Length: 960" "19:13:37,3742396","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 28 499, Length: 960" "19:13:37,3742733","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 29 459, Length: 987" "19:13:37,3743130","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 30 446, Length: 974" "19:13:37,3743525","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 31 420, Length: 994" "19:13:37,3743916","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 32 414, Length: 987" "19:13:37,3744455","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 33 401, Length: 998" "19:13:37,3744926","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 34 399, Length: 982" "19:13:37,3745340","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 35 381, Length: 992" "19:13:37,3745831","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 36 373, Length: 989" "19:13:37,3746501","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 37 362, Length: 971" "19:13:37,3747313","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 38 333, Length: 973" "19:13:37,3747742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 39 306, Length: 1 000" "19:13:37,3748156","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 40 306, Length: 1 000" "19:13:37,3748557","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 41 306, Length: 991" "19:13:37,3748942","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 42 297, Length: 996" "19:13:37,3749330","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 43 293, Length: 992" "19:13:37,3749737","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 44 285, Length: 990" "19:13:37,3750125","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 45 275, Length: 976" "19:13:37,3750526","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 46 251, Length: 993" "19:13:37,3750918","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 47 244, Length: 976" "19:13:37,3751306","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 48 220, Length: 981" "19:13:37,3751703","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 49 201, Length: 996" "19:13:37,3752095","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 50 197, Length: 990" "19:13:37,3752476","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 51 187, Length: 1 000" "19:13:37,3752861","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 52 187, Length: 987" "19:13:37,3753246","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 53 174, Length: 981" "19:13:37,3753628","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 54 155, Length: 1 000" "19:13:37,3754115","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 55 155, Length: 998" "19:13:37,3754702","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 56 153, Length: 977" "19:13:37,3755478","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 57 130, Length: 971" "19:13:37,3755895","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 58 101, Length: 986" "19:13:37,3756280","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 59 087, Length: 987" "19:13:37,3756662","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 60 074, Length: 998" "19:13:37,3757060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 61 072, Length: 1 000" "19:13:37,3757464","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 62 072, Length: 990" "19:13:37,3757945","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 63 062, Length: 997" "19:13:37,3758326","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 64 059, Length: 982" "19:13:37,3758695","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 65 041, Length: 1 000" "19:13:37,3759074","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 66 041, Length: 983" "19:13:37,3759465","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 67 024, Length: 996" "19:13:37,3759831","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 020, Length: 966" "19:13:37,3760241","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 986, Length: 986" "19:13:37,3760652","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 69 972, Length: 997" "19:13:37,3761040","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 70 969, Length: 981" "19:13:37,3761242","R5Apex.exe","3708","Load Image","C:\Windows\System32\apphelp.dll","SUCCESS","Image Base: 0x7ffdcc740000, Image Size: 0x87000" "19:13:37,3761441","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 71 950, Length: 989" "19:13:37,3761826","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 72 939, Length: 992" "19:13:37,3762236","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 73 931, Length: 983" "19:13:37,3762634","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 74 914, Length: 975" "19:13:37,3763032","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 75 889, Length: 987" "19:13:37,3763423","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 76 876, Length: 981" "19:13:37,3763811","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 77 857, Length: 973" "19:13:37,3764205","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 78 830, Length: 988" "19:13:37,3764577","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 79 818, Length: 982" "19:13:37,3764982","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 80 800, Length: 988" "19:13:37,3765389","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 81 788, Length: 993" "19:13:37,3765803","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 82 781, Length: 991" "19:13:37,3766181","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 83 772, Length: 986" "19:13:37,3766582","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 84 758, Length: 1 000" "19:13:37,3766996","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 85 758, Length: 996" "19:13:37,3767615","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 86 754, Length: 990" "19:13:37,3768147","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 87 744, Length: 996" "19:13:37,3768567","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 88 740, Length: 986" "19:13:37,3768952","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 89 726, Length: 959" "19:13:37,3769770","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 90 685, Length: 933" "19:13:37,3770161","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 91 618, Length: 1 000" "19:13:37,3770739","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 92 618, Length: 992" "19:13:37,3771207","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 93 610, Length: 989" "19:13:37,3771611","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 94 599, Length: 979" "19:13:37,3772005","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 95 578, Length: 974" "19:13:37,3772394","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 96 552, Length: 979" "19:13:37,3772772","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 97 531, Length: 987" "19:13:37,3773173","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 98 518, Length: 999" "19:13:37,3773539","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 99 517, Length: 991" "19:13:37,3773923","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 100 508, Length: 998" "19:13:37,3774318","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 101 506, Length: 971" "19:13:37,3774696","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 102 477, Length: 990" "19:13:37,3775081","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 103 467, Length: 1 000" "19:13:37,3775453","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 104 467, Length: 986" "19:13:37,3775848","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 105 453, Length: 994" "19:13:37,3776233","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 106 447, Length: 988" "19:13:37,3776627","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 107 435, Length: 992" "19:13:37,3777044","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 108 427, Length: 992" "19:13:37,3777439","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 109 419, Length: 992" "19:13:37,3777817","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 110 411, Length: 978" "19:13:37,3778202","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 111 389, Length: 996" "19:13:37,3778568","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 112 385, Length: 986" "19:13:37,3778930","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 113 371, Length: 991" "19:13:37,3779257","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 114 362, Length: 981" "19:13:37,3779632","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 115 343, Length: 997" "19:13:37,3780001","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 116 340, Length: 998" "19:13:37,3780386","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 117 338, Length: 997" "19:13:37,3780748","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 118 335, Length: 997" "19:13:37,3781143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 119 332, Length: 987" "19:13:37,3781518","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 120 319, Length: 986" "19:13:37,3781999","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 121 305, Length: 965" "19:13:37,3782464","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 122 270, Length: 1 000" "19:13:37,3782875","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 123 270, Length: 992" "19:13:37,3783263","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 124 262, Length: 994" "19:13:37,3783629","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 125 256, Length: 992" "19:13:37,3784004","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 126 248, Length: 969" "19:13:37,3784392","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 127 217, Length: 962" "19:13:37,3784774","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 128 179, Length: 999" "19:13:37,3785155","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 129 178, Length: 1 000" "19:13:37,3785521","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 130 178, Length: 972" "19:13:37,3785903","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 131 150, Length: 981" "19:13:37,3786271","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 132 131, Length: 979" "19:13:37,3786643","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 133 110, Length: 996" "19:13:37,3787019","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 134 106, Length: 973" "19:13:37,3787397","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 135 079, Length: 981" "19:13:37,3787785","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 136 060, Length: 1 000" "19:13:37,3787942","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 137 060, Length: 986" "19:13:37,3788385","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 138 046, Length: 977" "19:13:37,3788802","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 139 023, Length: 999" "19:13:37,3789354","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 140 022, Length: 983" "19:13:37,3789835","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 005, Length: 977" "19:13:37,3790370","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 982, Length: 988" "19:13:37,3790839","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 142 970, Length: 982" "19:13:37,3791272","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 143 952, Length: 972" "19:13:37,3791679","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 144 924, Length: 984" "19:13:37,3792093","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 145 908, Length: 994" "19:13:37,3792500","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 146 902, Length: 978" "19:13:37,3792904","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 147 880, Length: 981" "19:13:37,3793321","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 148 861, Length: 996" "19:13:37,3793722","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 149 857, Length: 986" "19:13:37,3794113","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 150 843, Length: 990" "19:13:37,3794511","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 151 833, Length: 984" "19:13:37,3794899","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 152 817, Length: 1 000" "19:13:37,3795277","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 153 817, Length: 990" "19:13:37,3795685","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 154 807, Length: 980" "19:13:37,3796105","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 155 787, Length: 982" "19:13:37,3796519","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 156 769, Length: 1 000" "19:13:37,3796897","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 157 769, Length: 994" "19:13:37,3797292","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 158 763, Length: 995" "19:13:37,3797737","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 159 758, Length: 984" "19:13:37,3798241","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 160 742, Length: 999" "19:13:37,3798651","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 161 741, Length: 973" "19:13:37,3799194","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 162 714, Length: 999" "19:13:37,3799652","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 163 713, Length: 989" "19:13:37,3800082","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 164 702, Length: 984" "19:13:37,3800480","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 165 686, Length: 989" "19:13:37,3800871","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 166 675, Length: 982" "19:13:37,3801262","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 167 657, Length: 987" "19:13:37,3801670","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 168 644, Length: 1 000" "19:13:37,3802054","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 169 644, Length: 971" "19:13:37,3802465","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 170 615, Length: 985" "19:13:37,3802856","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 171 600, Length: 993" "19:13:37,3803405","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 172 593, Length: 997" "19:13:37,3803838","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 173 590, Length: 988" "19:13:37,3804235","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 174 578, Length: 988" "19:13:37,3804643","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 175 566, Length: 994" "19:13:37,3805053","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 176 560, Length: 991" "19:13:37,3805438","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 177 551, Length: 987" "19:13:37,3805829","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 178 538, Length: 998" "19:13:37,3806211","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 179 536, Length: 983" "19:13:37,3806609","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 180 519, Length: 998" "19:13:37,3807083","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 181 517, Length: 981" "19:13:37,3807526","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 182 498, Length: 999" "19:13:37,3807933","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 183 497, Length: 1 000" "19:13:37,3808446","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 184 497, Length: 997" "19:13:37,3808950","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 185 494, Length: 991" "19:13:37,3809386","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 186 485, Length: 975" "19:13:37,3809787","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 187 460, Length: 988" "19:13:37,3810198","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 188 448, Length: 985" "19:13:37,3810595","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 189 433, Length: 993" "19:13:37,3810977","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 190 426, Length: 976" "19:13:37,3811372","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 191 402, Length: 995" "19:13:37,3811750","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 192 397, Length: 969" "19:13:37,3812148","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 193 366, Length: 987" "19:13:37,3812536","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 194 353, Length: 993" "19:13:37,3812921","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 195 346, Length: 997" "19:13:37,3813331","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 196 343, Length: 975" "19:13:37,3813713","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 197 318, Length: 975" "19:13:37,3814101","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 198 293, Length: 986" "19:13:37,3814479","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 199 279, Length: 990" "19:13:37,3814896","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 200 269, Length: 997" "19:13:37,3815310","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 201 266, Length: 987" "19:13:37,3815724","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 202 253, Length: 987" "19:13:37,3816131","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 203 240, Length: 977" "19:13:37,3816526","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 204 217, Length: 978" "19:13:37,3816930","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 205 195, Length: 978" "19:13:37,3817420","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 206 173, Length: 990" "19:13:37,3817869","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 207 163, Length: 995" "19:13:37,3818312","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 208 158, Length: 1 000" "19:13:37,3818774","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 209 158, Length: 989" "19:13:37,3819156","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 210 147, Length: 966" "19:13:37,3819553","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 211 113, Length: 994" "19:13:37,3819941","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 212 107, Length: 986" "19:13:37,3820349","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 213 093, Length: 978" "19:13:37,3820769","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 214 071, Length: 999" "19:13:37,3821163","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 215 070, Length: 984" "19:13:37,3821551","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 216 054, Length: 986" "19:13:37,3821943","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 217 040, Length: 1 000" "19:13:37,3822340","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 218 040, Length: 978" "19:13:37,3822735","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 018, Length: 971" "19:13:37,3823168","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 989, Length: 982" "19:13:37,3823575","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 220 971, Length: 1 000" "19:13:37,3823973","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 221 971, Length: 990" "19:13:37,3824377","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 222 961, Length: 990" "19:13:37,3824791","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 223 951, Length: 996" "19:13:37,3825185","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 224 947, Length: 976" "19:13:37,3825596","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 225 923, Length: 980" "19:13:37,3825993","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 226 903, Length: 998" "19:13:37,3826513","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 227 901, Length: 997" "19:13:37,3826978","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 228 898, Length: 998" "19:13:37,3827494","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 229 896, Length: 986" "19:13:37,3827956","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 230 882, Length: 996" "19:13:37,3828380","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 231 878, Length: 984" "19:13:37,3828793","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 232 862, Length: 1 000" "19:13:37,3829194","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 233 862, Length: 994" "19:13:37,3829595","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 234 856, Length: 981" "19:13:37,3829987","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 235 837, Length: 989" "19:13:37,3830397","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 236 826, Length: 999" "19:13:37,3830804","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 237 825, Length: 974" "19:13:37,3831225","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 238 799, Length: 990" "19:13:37,3831629","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 239 789, Length: 986" "19:13:37,3832026","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 240 775, Length: 992" "19:13:37,3832424","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 241 767, Length: 998" "19:13:37,3832947","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 242 765, Length: 994" "19:13:37,3833399","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 243 759, Length: 976" "19:13:37,3833797","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 244 735, Length: 979" "19:13:37,3834259","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 245 714, Length: 982" "19:13:37,3834692","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 246 696, Length: 1 000" "19:13:37,3835163","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 247 696, Length: 985" "19:13:37,3835580","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 248 681, Length: 978" "19:13:37,3835984","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 249 659, Length: 993" "19:13:37,3836388","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 250 652, Length: 983" "19:13:37,3836776","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 251 635, Length: 993" "19:13:37,3837180","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 252 628, Length: 989" "19:13:37,3837559","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 253 617, Length: 980" "19:13:37,3837947","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 254 597, Length: 990" "19:13:37,3838361","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 255 587, Length: 988" "19:13:37,3838749","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 256 575, Length: 998" "19:13:37,3839143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 257 573, Length: 979" "19:13:37,3839557","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 258 552, Length: 984" "19:13:37,3839958","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 259 536, Length: 996" "19:13:37,3840365","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 260 532, Length: 996" "19:13:37,3840769","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 261 528, Length: 998" "19:13:37,3841209","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 262 526, Length: 972" "19:13:37,3841757","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 263 498, Length: 974" "19:13:37,3842219","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 264 472, Length: 993" "19:13:37,3842719","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 265 465, Length: 970" "19:13:37,3843714","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 266 435, Length: 993" "19:13:37,3844220","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 267 428, Length: 974" "19:13:37,3844660","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 268 402, Length: 998" "19:13:37,3845064","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 269 400, Length: 981" "19:13:37,3845497","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 270 381, Length: 969" "19:13:37,3845930","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 271 350, Length: 1 000" "19:13:37,3846347","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 272 350, Length: 1 000" "19:13:37,3846773","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 273 350, Length: 1 000" "19:13:37,3847165","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 274 350, Length: 973" "19:13:37,3847582","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 275 323, Length: 992" "19:13:37,3847986","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 276 315, Length: 979" "19:13:37,3848419","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 277 294, Length: 983" "19:13:37,3848820","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 278 277, Length: 984" "19:13:37,3849221","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 279 261, Length: 981" "19:13:37,3849625","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 280 242, Length: 989" "19:13:37,3850013","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 281 231, Length: 988" "19:13:37,3850410","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 282 219, Length: 984" "19:13:37,3851511","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 283 203, Length: 1 000" "19:13:37,3851934","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 284 203, Length: 1 000" "19:13:37,3852575","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 285 203, Length: 1 000" "19:13:37,3853214","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 286 203, Length: 986" "19:13:37,3853634","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 287 189, Length: 980" "19:13:37,3854038","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 288 169, Length: 993" "19:13:37,3854429","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 289 162, Length: 992" "19:13:37,3854820","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 290 154, Length: 985" "19:13:37,3855231","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 291 139, Length: 980" "19:13:37,3855632","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 292 119, Length: 990" "19:13:37,3856036","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 293 109, Length: 978" "19:13:37,3856456","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 294 087, Length: 988" "19:13:37,3856851","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 295 075, Length: 978" "19:13:37,3857255","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 296 053, Length: 993" "19:13:37,3857656","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 297 046, Length: 1 000" "19:13:37,3858053","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 298 046, Length: 984" "19:13:37,3858445","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 299 030, Length: 976" "19:13:37,3858852","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 006, Length: 988" "19:13:37,3859262","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 994, Length: 989" "19:13:37,3859670","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 301 983, Length: 997" "19:13:37,3860071","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 302 980, Length: 985" "19:13:37,3860651","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 303 965, Length: 990" "19:13:37,3861219","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 304 955, Length: 990" "19:13:37,3861636","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 305 945, Length: 974" "19:13:37,3862046","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 306 919, Length: 1 000" "19:13:37,3862473","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 307 919, Length: 995" "19:13:37,3862864","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 308 914, Length: 996" "19:13:37,3863272","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 309 910, Length: 998" "19:13:37,3863679","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 310 908, Length: 993" "19:13:37,3864080","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 311 901, Length: 986" "19:13:37,3864461","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 312 887, Length: 976" "19:13:37,3864878","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 313 863, Length: 991" "19:13:37,3865289","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 314 854, Length: 990" "19:13:37,3865699","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 315 844, Length: 990" "19:13:37,3866088","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 316 834, Length: 985" "19:13:37,3866479","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 317 819, Length: 986" "19:13:37,3866861","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 318 805, Length: 979" "19:13:37,3867261","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 319 784, Length: 998" "19:13:37,3867666","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 320 782, Length: 976" "19:13:37,3868285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 321 758, Length: 992" "19:13:37,3868685","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 322 750, Length: 983" "19:13:37,3869308","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 323 733, Length: 990" "19:13:37,3869715","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 324 723, Length: 977" "19:13:37,3870103","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 325 700, Length: 981" "19:13:37,3870507","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 326 681, Length: 999" "19:13:37,3870911","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 327 680, Length: 985" "19:13:37,3871331","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 328 665, Length: 996" "19:13:37,3871742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 329 661, Length: 1 000" "19:13:37,3872143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 330 661, Length: 999" "19:13:37,3872537","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 331 660, Length: 988" "19:13:37,3872948","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 332 648, Length: 983" "19:13:37,3873352","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 333 631, Length: 974" "19:13:37,3873737","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 334 605, Length: 976" "19:13:37,3874131","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 335 581, Length: 989" "19:13:37,3874545","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 336 570, Length: 990" "19:13:37,3874952","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 337 560, Length: 992" "19:13:37,3875350","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 338 552, Length: 990" "19:13:37,3875764","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 339 542, Length: 978" "19:13:37,3876370","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 340 520, Length: 971" "19:13:37,3876777","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 341 491, Length: 982" "19:13:37,3877380","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 342 473, Length: 997" "19:13:37,3877788","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 343 470, Length: 991" "19:13:37,3878195","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 344 461, Length: 985" "19:13:37,3878606","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 345 446, Length: 998" "19:13:37,3879006","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 346 444, Length: 976" "19:13:37,3879414","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 347 420, Length: 981" "19:13:37,3879828","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 348 401, Length: 990" "19:13:37,3880219","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 349 391, Length: 979" "19:13:37,3880610","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 350 370, Length: 997" "19:13:37,3880992","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 351 367, Length: 997" "19:13:37,3881377","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 352 364, Length: 982" "19:13:37,3881755","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 353 346, Length: 981" "19:13:37,3882137","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 354 327, Length: 1 000" "19:13:37,3882522","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 355 327, Length: 1 000" "19:13:37,3882900","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 356 327, Length: 986" "19:13:37,3883285","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 357 313, Length: 986" "19:13:37,3883654","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 358 299, Length: 975" "19:13:37,3884026","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 359 274, Length: 1 000" "19:13:37,3884401","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 360 274, Length: 998" "19:13:37,3884991","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 361 272, Length: 994" "19:13:37,3885565","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 362 266, Length: 989" "19:13:37,3885963","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 363 255, Length: 995" "19:13:37,3886345","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 364 250, Length: 980" "19:13:37,3886733","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 365 230, Length: 990" "19:13:37,3887121","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 366 220, Length: 992" "19:13:37,3887496","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 367 212, Length: 977" "19:13:37,3887884","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 368 189, Length: 992" "19:13:37,3888272","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 369 181, Length: 972" "19:13:37,3888644","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 370 153, Length: 979" "19:13:37,3889026","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 371 132, Length: 983" "19:13:37,3889408","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 372 115, Length: 994" "19:13:37,3889793","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 373 109, Length: 996" "19:13:37,3890168","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 374 105, Length: 984" "19:13:37,3890549","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 375 089, Length: 972" "19:13:37,3890928","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 376 061, Length: 991" "19:13:37,3891335","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 377 052, Length: 1 000" "19:13:37,3891733","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 378 052, Length: 976" "19:13:37,3892336","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 379 028, Length: 996" "19:13:37,3892923","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 380 024, Length: 998" "19:13:37,3893394","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 381 022, Length: 984" "19:13:37,3893808","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 382 006, Length: 999" "19:13:37,3894206","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 005, Length: 988" "19:13:37,3894539","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 993, Length: 988" "19:13:37,3894918","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 384 981, Length: 996" "19:13:37,3895303","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 385 977, Length: 976" "19:13:37,3895675","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 386 953, Length: 983" "19:13:37,3896043","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 387 936, Length: 986" "19:13:37,3896425","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 388 922, Length: 1 000" "19:13:37,3896794","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 389 922, Length: 971" "19:13:37,3897188","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 390 893, Length: 999" "19:13:37,3897583","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 391 892, Length: 999" "19:13:37,3897968","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 392 891, Length: 994" "19:13:37,3898366","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 393 885, Length: 994" "19:13:37,3898754","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 394 879, Length: 986" "19:13:37,3899116","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 395 865, Length: 1 000" "19:13:37,3899511","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 396 865, Length: 999" "19:13:37,3899892","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 397 864, Length: 996" "19:13:37,3900251","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 398 860, Length: 974" "19:13:37,3900623","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 399 834, Length: 991" "19:13:37,3901198","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 400 825, Length: 985" "19:13:37,3901586","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 401 810, Length: 968" "19:13:37,3902150","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 402 778, Length: 994" "19:13:37,3902522","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 403 772, Length: 992" "19:13:37,3902881","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 404 764, Length: 992" "19:13:37,3903269","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 405 756, Length: 980" "19:13:37,3903638","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 406 736, Length: 986" "19:13:37,3903978","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 407 722, Length: 990" "19:13:37,3904325","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 408 712, Length: 1 000" "19:13:37,3904742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 409 712, Length: 998" "19:13:37,3905130","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 410 710, Length: 985" "19:13:37,3905540","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 411 695, Length: 979" "19:13:37,3905906","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 412 674, Length: 977" "19:13:37,3906284","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 413 651, Length: 983" "19:13:37,3906669","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 414 634, Length: 973" "19:13:37,3907051","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 415 607, Length: 976" "19:13:37,3907449","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 416 583, Length: 995" "19:13:37,3907843","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 417 578, Length: 978" "19:13:37,3908238","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 418 556, Length: 963" "19:13:37,3908635","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 419 519, Length: 1 000" "19:13:37,3909033","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 420 519, Length: 982" "19:13:37,3909639","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 421 501, Length: 991" "19:13:37,3910046","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 422 492, Length: 979" "19:13:37,3910617","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 423 471, Length: 992" "19:13:37,3911018","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 424 463, Length: 997" "19:13:37,3911416","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 425 460, Length: 988" "19:13:37,3911826","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 426 448, Length: 986" "19:13:37,3912211","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 427 434, Length: 991" "19:13:37,3912609","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 428 425, Length: 987" "19:13:37,3913004","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 429 412, Length: 967" "19:13:37,3913408","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 430 379, Length: 980" "19:13:37,3913789","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 431 359, Length: 971" "19:13:37,3914193","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 432 330, Length: 983" "19:13:37,3914601","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 433 313, Length: 980" "19:13:37,3914998","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 434 293, Length: 988" "19:13:37,3915172","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 435 281, Length: 980" "19:13:37,3915310","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 436 261, Length: 974" "19:13:37,3915557","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 437 235, Length: 989" "19:13:37,3915919","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 438 224, Length: 981" "19:13:37,3916265","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 439 205, Length: 301" "19:13:37,3916509","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","" "19:13:37,4170932","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 5932, User Time: 0.0156250, Kernel Time: 0.0000000" "19:13:37,6196158","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:37,6196379","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:37,6196549","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:37,6196757","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:37,6198707","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 6472" "19:13:37,6224895","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6225254","R5Apex.exe","3708","QueryInformationVolume","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","VolumeCreationTime: 2020. 01. 09. 5:05:42, VolumeSerialNumber: 22AE-2966, SupportsObjects: True, VolumeLabel: HDD" "19:13:37,6225373","R5Apex.exe","3708","QueryAllInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","BUFFER OVERFLOW","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI, AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x400000000102e, EaSize: 0, Access: Read Attributes, Synchronize, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Long" "19:13:37,6225552","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:37,6226299","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe.eac","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a" "19:13:37,6227021","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6227252","R5Apex.exe","3708","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: game.bin, 2: game.bin" "19:13:37,6227505","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates","SUCCESS","" "19:13:37,6228086","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6228285","R5Apex.exe","3708","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\*.bin","SUCCESS","FileInformationClass: FileBothDirectoryInformation, Filter: *.bin, 2: game.bin" "19:13:37,6228596","R5Apex.exe","3708","QueryDirectory","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates","NO MORE FILES","FileInformationClass: FileBothDirectoryInformation" "19:13:37,6228698","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates","SUCCESS","" "19:13:37,6229276","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6229516","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","AllocationSize: 1 441 792, EndOfFile: 1 434 482, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,6244093","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 5004, User Time: 1.0781250, Kernel Time: 5.8750000" "19:13:37,6245379","EasyAntiCheat_launcher.exe","6076","NotifyChangeDirectory","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My","CANCELLED","Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_DIR_NAME" "19:13:37,6266900","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","Offset: 0, Length: 1 434 482, Priority: Normal" "19:13:37,6270884","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","" "19:13:37,6273844","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6274123","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","AllocationSize: 1 441 792, EndOfFile: 1 434 482, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,6309336","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","Offset: 0, Length: 1 434 482, Priority: Normal" "19:13:37,6311639","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.bin","SUCCESS","" "19:13:37,6312572","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.cer","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6312816","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.cer","SUCCESS","AllocationSize: 65 536, EndOfFile: 1 345, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,6312950","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.cer","SUCCESS","Offset: 0, Length: 1 345, Priority: Normal" "19:13:37,6313149","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\EasyAntiCheat\Certificates\game.cer","SUCCESS","" "19:13:37,6874040","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,6874383","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:37,6881869","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 0, Length: 4 194 304, Priority: Normal" "19:13:37,7130840","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 4 194 304, Length: 4 194 304" "19:13:37,7378393","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 8 388 608, Length: 4 194 304" "19:13:37,7625754","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 12 582 912, Length: 4 194 304" "19:13:37,7873035","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 16 777 216, Length: 4 194 304" "19:13:37,8121162","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 20 971 520, Length: 4 194 304" "19:13:37,8368693","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 25 165 824, Length: 4 194 304" "19:13:37,8615877","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 29 360 128, Length: 4 194 304" "19:13:37,8864915","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 33 554 432, Length: 153 848" "19:13:37,8874932","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:37,8882360","R5Apex.exe","3708","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,8882947","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\kernel32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,8883088","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\kernel32.dll","SUCCESS","AllocationSize: 704 512, EndOfFile: 702 568, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,8883274","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\kernel32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,8883585","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\kernel32.dll","SUCCESS","AllocationSize: 704 512, EndOfFile: 702 568, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,8904872","R5Apex.exe","3708","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "19:13:37,9911345","R5Apex.exe","3708","CreateFile","C:\Windows\System32\apphelp.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:37,9911769","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:37,9911884","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\apphelp.dll","SUCCESS","AllocationSize: 536 576, EndOfFile: 533 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,9912048","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\apphelp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:37,9912285","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\apphelp.dll","SUCCESS","AllocationSize: 536 576, EndOfFile: 533 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:37,9928482","R5Apex.exe","3708","CloseFile","C:\Windows\System32\apphelp.dll","SUCCESS","" "19:13:38,0175955","R5Apex.exe","3708","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,0176359","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\user32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,0176465","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\user32.dll","SUCCESS","AllocationSize: 1 634 304, EndOfFile: 1 633 744, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,0176632","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\user32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,0176869","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\user32.dll","SUCCESS","AllocationSize: 1 634 304, EndOfFile: 1 633 744, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,0226181","R5Apex.exe","3708","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "19:13:38,0741605","R5Apex.exe","3708","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,0742003","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,0742112","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\shell32.dll","SUCCESS","AllocationSize: 21 356 544, EndOfFile: 21 352 688, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,0742276","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\shell32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,0742519","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\shell32.dll","SUCCESS","AllocationSize: 21 356 544, EndOfFile: 21 352 688, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,1391267","R5Apex.exe","3708","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "19:13:38,5712677","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 5680" "19:13:38,5716706","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 5540" "19:13:38,5720256","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 5736" "19:13:38,5723733","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 7064" "19:13:38,5727149","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 412" "19:13:38,5735520","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 4828" "19:13:38,5754689","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,5755110","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ntoskrnl.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,5755222","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","AllocationSize: 8 593 408, EndOfFile: 8 592 280, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,5755392","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ntoskrnl.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:38,5755632","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","AllocationSize: 8 593 408, EndOfFile: 8 592 280, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,6015787","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ntoskrnl.exe","SUCCESS","" "19:13:38,7882759","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winload.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,7883173","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winload.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,7883285","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winload.exe","SUCCESS","AllocationSize: 1 208 320, EndOfFile: 1 208 184, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,7883449","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winload.exe","SUCCESS","SyncType: SyncTypeOther" "19:13:38,7883695","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winload.exe","SUCCESS","AllocationSize: 1 208 320, EndOfFile: 1 208 184, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,7920438","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winload.exe","SUCCESS","" "19:13:38,8301446","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 4440" "19:13:38,8307245","R5Apex.exe","3708","CreateFile","C:\Windows\System32\apphelp.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8307645","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\apphelp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8307758","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\apphelp.dll","SUCCESS","AllocationSize: 536 576, EndOfFile: 533 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8307921","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\apphelp.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8308152","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\apphelp.dll","SUCCESS","AllocationSize: 536 576, EndOfFile: 533 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8324099","R5Apex.exe","3708","CloseFile","C:\Windows\System32\apphelp.dll","SUCCESS","" "19:13:38,8567168","R5Apex.exe","3708","CloseFile","C:\Windows\System32\apphelp.dll","SUCCESS","" "19:13:38,8568233","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\8ccca27d-f1d8-4dda-b5dd-339aee937731","NAME NOT FOUND","Length: 524" "19:13:38,8569048","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","Desired Access: Query Value" "19:13:38,8569237","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LogFlags","NAME NOT FOUND","Length: 20" "19:13:38,8569413","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","" "19:13:38,8569683","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\18608e62-a628-49d9-8c02-55972e097d24","NAME NOT FOUND","Length: 524" "19:13:38,8570507","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","Desired Access: Query Value" "19:13:38,8570645","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\ShowDebugInfo","NAME NOT FOUND","Length: 20" "19:13:38,8570786","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags","SUCCESS","" "19:13:38,8571633","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8571870","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","BUFFER OVERFLOW","Information: Owner" "19:13:38,8571976","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Owner" "19:13:38,8572075","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:38,8572964","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ntdll.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8573278","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ntdll.dll","BUFFER OVERFLOW","Information: Owner" "19:13:38,8573384","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ntdll.dll","SUCCESS","Information: Owner" "19:13:38,8573487","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ntdll.dll","SUCCESS","" "19:13:38,8574298","R5Apex.exe","3708","CreateFile","C:\Windows\System32\kernel32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8574580","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\kernel32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:38,8574680","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\kernel32.dll","SUCCESS","Information: Owner" "19:13:38,8574779","R5Apex.exe","3708","CloseFile","C:\Windows\System32\kernel32.dll","SUCCESS","" "19:13:38,8575565","R5Apex.exe","3708","CreateFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8575757","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\KernelBase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:38,8575857","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\KernelBase.dll","SUCCESS","Information: Owner" "19:13:38,8575953","R5Apex.exe","3708","CloseFile","C:\Windows\System32\KernelBase.dll","SUCCESS","" "19:13:38,8576787","R5Apex.exe","3708","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8577076","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8577178","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8577297","R5Apex.exe","3708","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8577403","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","AllocationSize: 3 952 640, EndOfFile: 3 950 042, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8577563","R5Apex.exe","3708","CreateFileMapping","C:\Windows\apppatch\sysmain.sdb","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8579032","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8579394","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:38,8579580","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:38,8579766","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:38,8579927","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:38,8580610","R5Apex.exe","3708","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8580879","R5Apex.exe","3708","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:38,8580969","R5Apex.exe","3708","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:38,8581694","R5Apex.exe","3708","CreateFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8581941","R5Apex.exe","3708","QueryBasicInformationFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","CreationTime: 2017. 09. 29. 15:42:04, LastAccessTime: 2021. 02. 07. 17:37:54, LastWriteTime: 2017. 09. 29. 15:42:04, ChangeTime: 2020. 01. 09. 4:40:37, FileAttributes: A" "19:13:38,8582018","R5Apex.exe","3708","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:38,8582252","R5Apex.exe","3708","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI" "19:13:38,8582541","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:38,8583099","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8583365","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value" "19:13:38,8583525","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 130, Data: C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache" "19:13:38,8583686","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","" "19:13:38,8583836","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label, Attribute, Process Trust Label, 0x100" "19:13:38,8583952","R5Apex.exe","3708","QueryBasicInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI" "19:13:38,8584141","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","" "19:13:38,8585600","R5Apex.exe","3708","CloseFile","C:\Windows\apppatch\sysmain.sdb","SUCCESS","" "19:13:38,8589603","R5Apex.exe","3708","Load Image","C:\Windows\System32\shell32.dll","SUCCESS","Image Base: 0x7ffdd0b50000, Image Size: 0x1437000" "19:13:38,8591358","R5Apex.exe","3708","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8591726","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\shell32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8591826","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\shell32.dll","SUCCESS","AllocationSize: 21 356 544, EndOfFile: 21 352 688, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8591986","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\shell32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8592217","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\shell32.dll","SUCCESS","AllocationSize: 21 356 544, EndOfFile: 21 352 688, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8886741","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 407, Length: 101" "19:13:38,8887443","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:38,8888248","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8888691","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8888835","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8889332","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8889887","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:38,8891058","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:38,8891779","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8892107","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8892219","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8892395","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8892854","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:38,8894448","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:38,8896837","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8898149","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8898319","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8898579","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8899240","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:38,8900468","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:38,8901231","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8901549","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8901658","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8901834","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8902197","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:38,8903255","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:38,8904063","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8904378","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8904477","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8904637","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8905260","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:38,8906533","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:38,8907203","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8907623","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8907736","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8908092","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8908512","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:38,8910734","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:38,8913024","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:38,8913884","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:38,8914577","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8914923","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8915055","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8915234","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8915767","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:38,8917171","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:38,8918185","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8918506","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8918615","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8918781","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8919141","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:38,8921299","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:38,8922050","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8922358","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8922476","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8922646","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8923009","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:38,8923884","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:38,8924542","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8924821","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8924920","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8925087","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8925430","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:38,8927345","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:38,8928076","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8928746","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8928846","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8929083","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8930049","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:38,8933942","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:38,8934042","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\3e0e3a92-b00b-4456-9dee-f40aba77f00e","NAME NOT FOUND","Length: 524" "19:13:38,8934933","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8935783","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8936360","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8936665","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8937069","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 508, Length: 45" "19:13:38,8937319","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:38,8938638","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:38,8939507","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 5880, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:38,8941441","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8941810","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8941925","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8942098","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8942458","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:38,8943372","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:38,8944055","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8944337","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8944433","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8944590","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8944905","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:38,8945755","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:38,8946399","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8946678","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8946771","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8946928","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8947275","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:38,8948179","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:38,8949052","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8949392","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8949501","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8949671","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8950043","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:38,8950950","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:38,8951727","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:38,8952448","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:38,8953102","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8953394","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8953497","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8953657","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8954010","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:38,8954812","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:38,8955543","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8955841","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8955976","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8956140","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8956486","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:38,8957381","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:38,8958042","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8958334","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8958430","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8958584","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8958940","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:38,8959767","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:38,8960444","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8960717","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:38,8960810","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:38,8960963","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:38,8961284","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:38,8963616","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:38,8963725","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:38,8963872","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:38,8964030","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SYSTEM\Setup","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:38,8964116","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:38,8964331","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:38,8971621","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:38,8971884","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 0, Length: 2, Priority: Normal" "19:13:38,8972173","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2, Length: 998" "19:13:38,8972336","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 000, Length: 962" "19:13:38,8972474","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 1 962, Length: 963" "19:13:38,8972609","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 2 925, Length: 979" "19:13:38,8972962","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 3 904, Length: 995" "19:13:38,8973334","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 4 899, Length: 995" "19:13:38,8973748","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 5 894, Length: 986" "19:13:38,8974149","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 6 880, Length: 980" "19:13:38,8974540","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 7 860, Length: 976" "19:13:38,8974934","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 8 836, Length: 989" "19:13:38,8975130","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 9 825, Length: 968" "19:13:38,8975303","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 10 793, Length: 980" "19:13:38,8975669","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 11 773, Length: 961" "19:13:38,8975925","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 12 734, Length: 985" "19:13:38,8976313","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 13 719, Length: 986" "19:13:38,8976702","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 14 705, Length: 970" "19:13:38,8977109","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 15 675, Length: 987" "19:13:38,8977718","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 16 662, Length: 982" "19:13:38,8978142","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 17 644, Length: 992" "19:13:38,8978549","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 18 636, Length: 985" "19:13:38,8978911","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 19 621, Length: 999" "19:13:38,8979309","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 20 620, Length: 1 000" "19:13:38,8979694","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 21 620, Length: 982" "19:13:38,8980079","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 22 602, Length: 972" "19:13:38,8980448","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 23 574, Length: 995" "19:13:38,8980839","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 24 569, Length: 974" "19:13:38,8981221","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 25 543, Length: 997" "19:13:38,8981602","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 26 540, Length: 999" "19:13:38,8981936","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 27 539, Length: 960" "19:13:38,8982260","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 28 499, Length: 960" "19:13:38,8982587","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 29 459, Length: 987" "19:13:38,8982975","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 30 446, Length: 974" "19:13:38,8983363","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 31 420, Length: 994" "19:13:38,8983751","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 32 414, Length: 987" "19:13:38,8984120","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 33 401, Length: 998" "19:13:38,8984607","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 34 399, Length: 982" "19:13:38,8985259","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 35 381, Length: 992" "19:13:38,8985720","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 36 373, Length: 989" "19:13:38,8986131","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 37 362, Length: 971" "19:13:38,8986519","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 38 333, Length: 973" "19:13:38,8986939","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 39 306, Length: 1 000" "19:13:38,8987427","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 40 306, Length: 1 000" "19:13:38,8988123","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 41 306, Length: 991" "19:13:38,8988751","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 42 297, Length: 996" "19:13:38,8989386","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 43 293, Length: 992" "19:13:38,8989803","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 44 285, Length: 990" "19:13:38,8990336","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 45 275, Length: 976" "19:13:38,8990769","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 46 251, Length: 993" "19:13:38,8991166","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 47 244, Length: 976" "19:13:38,8991554","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 48 220, Length: 981" "19:13:38,8991943","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 49 201, Length: 996" "19:13:38,8992334","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 50 197, Length: 990" "19:13:38,8992709","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 51 187, Length: 1 000" "19:13:38,8993088","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 52 187, Length: 987" "19:13:38,8993463","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 53 174, Length: 981" "19:13:38,8993835","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 54 155, Length: 1 000" "19:13:38,8994207","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 55 155, Length: 998" "19:13:38,8994579","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 56 153, Length: 977" "19:13:38,8994957","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 57 130, Length: 971" "19:13:38,8995361","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 58 101, Length: 986" "19:13:38,8995740","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 59 087, Length: 987" "19:13:38,8996122","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 60 074, Length: 998" "19:13:38,8996519","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 61 072, Length: 1 000" "19:13:38,8996911","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 62 072, Length: 990" "19:13:38,8997401","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 63 062, Length: 997" "19:13:38,8997770","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 64 059, Length: 982" "19:13:38,8998136","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 65 041, Length: 1 000" "19:13:38,8998505","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 66 041, Length: 983" "19:13:38,8998889","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 67 024, Length: 996" "19:13:38,8999249","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 020, Length: 966" "19:13:38,8999656","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 68 986, Length: 986" "19:13:38,9000060","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 69 972, Length: 997" "19:13:38,9000442","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 70 969, Length: 981" "19:13:38,9000846","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 71 950, Length: 989" "19:13:38,9001231","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 72 939, Length: 992" "19:13:38,9001625","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 73 931, Length: 983" "19:13:38,9002020","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 74 914, Length: 975" "19:13:38,9002405","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 75 889, Length: 987" "19:13:38,9002793","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 76 876, Length: 981" "19:13:38,9003171","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 77 857, Length: 973" "19:13:38,9003556","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 78 830, Length: 988" "19:13:38,9003922","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 79 818, Length: 982" "19:13:38,9004323","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 80 800, Length: 988" "19:13:38,9004717","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 81 788, Length: 993" "19:13:38,9005131","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 82 781, Length: 991" "19:13:38,9005509","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 83 772, Length: 986" "19:13:38,9005907","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 84 758, Length: 1 000" "19:13:38,9006317","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 85 758, Length: 996" "19:13:38,9006718","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 86 754, Length: 990" "19:13:38,9007110","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 87 744, Length: 996" "19:13:38,9007501","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 88 740, Length: 986" "19:13:38,9007873","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 89 726, Length: 959" "19:13:38,9008245","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 90 685, Length: 933" "19:13:38,9008601","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 91 618, Length: 1 000" "19:13:38,9008992","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 92 618, Length: 992" "19:13:38,9009374","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 93 610, Length: 989" "19:13:38,9009752","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 94 599, Length: 979" "19:13:38,9010141","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 95 578, Length: 974" "19:13:38,9010519","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 96 552, Length: 979" "19:13:38,9010894","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 97 531, Length: 987" "19:13:38,9011270","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 98 518, Length: 999" "19:13:38,9011632","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 99 517, Length: 991" "19:13:38,9012026","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 100 508, Length: 998" "19:13:38,9012415","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 101 506, Length: 971" "19:13:38,9012787","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 102 477, Length: 990" "19:13:38,9013165","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 103 467, Length: 1 000" "19:13:38,9013531","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 104 467, Length: 986" "19:13:38,9013922","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 105 453, Length: 994" "19:13:38,9014300","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 106 447, Length: 988" "19:13:38,9014682","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 107 435, Length: 992" "19:13:38,9015073","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 108 427, Length: 992" "19:13:38,9015452","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 109 419, Length: 992" "19:13:38,9015827","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 110 411, Length: 978" "19:13:38,9016199","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 111 389, Length: 996" "19:13:38,9016562","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 112 385, Length: 986" "19:13:38,9016924","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 113 371, Length: 991" "19:13:38,9017248","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 114 362, Length: 981" "19:13:38,9017610","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 115 343, Length: 997" "19:13:38,9017976","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 116 340, Length: 998" "19:13:38,9018358","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 117 338, Length: 997" "19:13:38,9018720","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 118 335, Length: 997" "19:13:38,9019102","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 119 332, Length: 987" "19:13:38,9019474","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 120 319, Length: 986" "19:13:38,9019833","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 121 305, Length: 965" "19:13:38,9020215","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 122 270, Length: 1 000" "19:13:38,9020590","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 123 270, Length: 992" "19:13:38,9020952","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 124 262, Length: 994" "19:13:38,9021315","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 125 256, Length: 992" "19:13:38,9021680","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 126 248, Length: 969" "19:13:38,9022052","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 127 217, Length: 962" "19:13:38,9022428","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 128 179, Length: 999" "19:13:38,9022809","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 129 178, Length: 1 000" "19:13:38,9023169","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 130 178, Length: 972" "19:13:38,9023541","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 131 150, Length: 981" "19:13:38,9023909","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 132 131, Length: 979" "19:13:38,9024278","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 133 110, Length: 996" "19:13:38,9024650","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 134 106, Length: 973" "19:13:38,9025032","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 135 079, Length: 981" "19:13:38,9025414","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 136 060, Length: 1 000" "19:13:38,9025571","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 137 060, Length: 986" "19:13:38,9025991","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 138 046, Length: 977" "19:13:38,9026405","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 139 023, Length: 999" "19:13:38,9026796","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 140 022, Length: 983" "19:13:38,9027206","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 005, Length: 977" "19:13:38,9027611","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 141 982, Length: 988" "19:13:38,9028021","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 142 970, Length: 982" "19:13:38,9028422","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 143 952, Length: 972" "19:13:38,9028820","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 144 924, Length: 984" "19:13:38,9029227","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 145 908, Length: 994" "19:13:38,9029625","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 146 902, Length: 978" "19:13:38,9030026","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 147 880, Length: 981" "19:13:38,9030430","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 148 861, Length: 996" "19:13:38,9030827","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 149 857, Length: 986" "19:13:38,9031212","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 150 843, Length: 990" "19:13:38,9031604","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 151 833, Length: 984" "19:13:38,9031992","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 152 817, Length: 1 000" "19:13:38,9032370","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 153 817, Length: 990" "19:13:38,9032774","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 154 807, Length: 980" "19:13:38,9033182","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 155 787, Length: 982" "19:13:38,9033592","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 156 769, Length: 1 000" "19:13:38,9033964","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 157 769, Length: 994" "19:13:38,9034355","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 158 763, Length: 995" "19:13:38,9034756","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 159 758, Length: 984" "19:13:38,9035177","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 160 742, Length: 999" "19:13:38,9035577","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 161 741, Length: 973" "19:13:38,9035978","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 162 714, Length: 999" "19:13:38,9036376","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 163 713, Length: 989" "19:13:38,9036771","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 164 702, Length: 984" "19:13:38,9037159","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 165 686, Length: 989" "19:13:38,9037540","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 166 675, Length: 982" "19:13:38,9037928","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 167 657, Length: 987" "19:13:38,9038323","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 168 644, Length: 1 000" "19:13:38,9038705","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 169 644, Length: 971" "19:13:38,9039089","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 170 615, Length: 985" "19:13:38,9039477","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 171 600, Length: 993" "19:13:38,9039869","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 172 593, Length: 997" "19:13:38,9040266","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 173 590, Length: 988" "19:13:38,9040658","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 174 578, Length: 988" "19:13:38,9041052","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 175 566, Length: 994" "19:13:38,9041444","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 176 560, Length: 991" "19:13:38,9041828","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 177 551, Length: 987" "19:13:38,9042216","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 178 538, Length: 998" "19:13:38,9042595","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 179 536, Length: 983" "19:13:38,9042983","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 180 519, Length: 998" "19:13:38,9043371","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 181 517, Length: 981" "19:13:38,9043769","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 182 498, Length: 999" "19:13:38,9044167","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 183 497, Length: 1 000" "19:13:38,9044564","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 184 497, Length: 997" "19:13:38,9044946","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 185 494, Length: 991" "19:13:38,9045340","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 186 485, Length: 975" "19:13:38,9045728","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 187 460, Length: 988" "19:13:38,9046123","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 188 448, Length: 985" "19:13:38,9046511","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 189 433, Length: 993" "19:13:38,9046889","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 190 426, Length: 976" "19:13:38,9047284","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 191 402, Length: 995" "19:13:38,9047659","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 192 397, Length: 969" "19:13:38,9048034","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 193 366, Length: 987" "19:13:38,9048419","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 194 353, Length: 993" "19:13:38,9048791","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 195 346, Length: 997" "19:13:38,9049167","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 196 343, Length: 975" "19:13:38,9049535","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 197 318, Length: 975" "19:13:38,9049924","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 198 293, Length: 986" "19:13:38,9050305","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 199 279, Length: 990" "19:13:38,9050719","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 200 269, Length: 997" "19:13:38,9051126","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 201 266, Length: 987" "19:13:38,9051534","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 202 253, Length: 987" "19:13:38,9051938","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 203 240, Length: 977" "19:13:38,9052332","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 204 217, Length: 978" "19:13:38,9052727","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 205 195, Length: 978" "19:13:38,9053128","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 206 173, Length: 990" "19:13:38,9053529","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 207 163, Length: 995" "19:13:38,9053929","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 208 158, Length: 1 000" "19:13:38,9054318","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 209 158, Length: 989" "19:13:38,9054693","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 210 147, Length: 966" "19:13:38,9055094","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 211 113, Length: 994" "19:13:38,9055482","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 212 107, Length: 986" "19:13:38,9055879","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 213 093, Length: 978" "19:13:38,9056303","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 214 071, Length: 999" "19:13:38,9056697","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 215 070, Length: 984" "19:13:38,9057085","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 216 054, Length: 986" "19:13:38,9057477","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 217 040, Length: 1 000" "19:13:38,9057865","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 218 040, Length: 978" "19:13:38,9058253","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 018, Length: 971" "19:13:38,9058651","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 219 989, Length: 982" "19:13:38,9059055","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 220 971, Length: 1 000" "19:13:38,9059449","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 221 971, Length: 990" "19:13:38,9059853","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 222 961, Length: 990" "19:13:38,9060277","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 223 951, Length: 996" "19:13:38,9060674","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 224 947, Length: 976" "19:13:38,9061072","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 225 923, Length: 980" "19:13:38,9061470","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 226 903, Length: 998" "19:13:38,9061880","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 227 901, Length: 997" "19:13:38,9062284","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 228 898, Length: 998" "19:13:38,9062679","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 229 896, Length: 986" "19:13:38,9063077","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 230 882, Length: 996" "19:13:38,9063474","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 231 878, Length: 984" "19:13:38,9063872","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 232 862, Length: 1 000" "19:13:38,9064254","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 233 862, Length: 994" "19:13:38,9064648","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 234 856, Length: 981" "19:13:38,9065043","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 235 837, Length: 989" "19:13:38,9065444","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 236 826, Length: 999" "19:13:38,9065835","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 237 825, Length: 974" "19:13:38,9066245","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 238 799, Length: 990" "19:13:38,9066646","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 239 789, Length: 986" "19:13:38,9067041","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 240 775, Length: 992" "19:13:38,9067429","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 241 767, Length: 998" "19:13:38,9067833","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 242 765, Length: 994" "19:13:38,9068237","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 243 759, Length: 976" "19:13:38,9068628","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 244 735, Length: 979" "19:13:38,9069020","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 245 714, Length: 982" "19:13:38,9069417","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 246 696, Length: 1 000" "19:13:38,9069821","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 247 696, Length: 985" "19:13:38,9070222","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 248 681, Length: 978" "19:13:38,9070623","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 249 659, Length: 993" "19:13:38,9071011","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 250 652, Length: 983" "19:13:38,9071396","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 251 635, Length: 993" "19:13:38,9071797","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 252 628, Length: 989" "19:13:38,9072172","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 253 617, Length: 980" "19:13:38,9072551","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 254 597, Length: 990" "19:13:38,9072945","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 255 587, Length: 988" "19:13:38,9073327","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 256 575, Length: 998" "19:13:38,9073715","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 257 573, Length: 979" "19:13:38,9074119","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 258 552, Length: 984" "19:13:38,9074520","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 259 536, Length: 996" "19:13:38,9074924","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 260 532, Length: 996" "19:13:38,9075335","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 261 528, Length: 998" "19:13:38,9075742","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 262 526, Length: 972" "19:13:38,9076149","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 263 498, Length: 974" "19:13:38,9076541","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 264 472, Length: 993" "19:13:38,9076938","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 265 465, Length: 970" "19:13:38,9077326","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 266 435, Length: 993" "19:13:38,9077705","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 267 428, Length: 974" "19:13:38,9078103","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 268 402, Length: 998" "19:13:38,9078484","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 269 400, Length: 981" "19:13:38,9078882","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 270 381, Length: 969" "19:13:38,9079286","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 271 350, Length: 1 000" "19:13:38,9079684","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 272 350, Length: 1 000" "19:13:38,9080107","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 273 350, Length: 1 000" "19:13:38,9080492","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 274 350, Length: 973" "19:13:38,9080890","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 275 323, Length: 992" "19:13:38,9081284","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 276 315, Length: 979" "19:13:38,9081695","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 277 294, Length: 983" "19:13:38,9082092","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 278 277, Length: 984" "19:13:38,9082484","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 279 261, Length: 981" "19:13:38,9082878","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 280 242, Length: 989" "19:13:38,9083263","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 281 231, Length: 988" "19:13:38,9083658","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 282 219, Length: 984" "19:13:38,9084046","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 283 203, Length: 1 000" "19:13:38,9084440","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 284 203, Length: 1 000" "19:13:38,9084838","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 285 203, Length: 1 000" "19:13:38,9085248","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 286 203, Length: 986" "19:13:38,9085643","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 287 189, Length: 980" "19:13:38,9086044","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 288 169, Length: 993" "19:13:38,9086432","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 289 162, Length: 992" "19:13:38,9086820","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 290 154, Length: 985" "19:13:38,9087221","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 291 139, Length: 980" "19:13:38,9087615","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 292 119, Length: 990" "19:13:38,9088016","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 293 109, Length: 978" "19:13:38,9088411","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 294 087, Length: 988" "19:13:38,9088792","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 295 075, Length: 978" "19:13:38,9089193","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 296 053, Length: 993" "19:13:38,9089594","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 297 046, Length: 1 000" "19:13:38,9089989","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 298 046, Length: 984" "19:13:38,9090370","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 299 030, Length: 976" "19:13:38,9090771","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 006, Length: 988" "19:13:38,9091179","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 300 994, Length: 989" "19:13:38,9091583","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 301 983, Length: 997" "19:13:38,9091977","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 302 980, Length: 985" "19:13:38,9092333","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 303 965, Length: 990" "19:13:38,9092686","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 304 955, Length: 990" "19:13:38,9093087","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 305 945, Length: 974" "19:13:38,9093498","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 306 919, Length: 1 000" "19:13:38,9093911","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 307 919, Length: 995" "19:13:38,9094299","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 308 914, Length: 996" "19:13:38,9094700","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 309 910, Length: 998" "19:13:38,9095108","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 310 908, Length: 993" "19:13:38,9095499","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 311 901, Length: 986" "19:13:38,9095877","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 312 887, Length: 976" "19:13:38,9096294","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 313 863, Length: 991" "19:13:38,9096698","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 314 854, Length: 990" "19:13:38,9097099","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 315 844, Length: 990" "19:13:38,9097481","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 316 834, Length: 985" "19:13:38,9097872","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 317 819, Length: 986" "19:13:38,9098248","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 318 805, Length: 979" "19:13:38,9098639","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 319 784, Length: 998" "19:13:38,9099043","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 320 782, Length: 976" "19:13:38,9099441","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 321 758, Length: 992" "19:13:38,9099825","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 322 750, Length: 983" "19:13:38,9100242","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 323 733, Length: 990" "19:13:38,9100637","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 324 723, Length: 977" "19:13:38,9101019","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 325 700, Length: 981" "19:13:38,9101420","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 326 681, Length: 999" "19:13:38,9101817","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 327 680, Length: 985" "19:13:38,9102228","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 328 665, Length: 996" "19:13:38,9102635","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 329 661, Length: 1 000" "19:13:38,9103036","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 330 661, Length: 999" "19:13:38,9103427","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 331 660, Length: 988" "19:13:38,9103828","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 332 648, Length: 983" "19:13:38,9104219","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 333 631, Length: 974" "19:13:38,9104604","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 334 605, Length: 976" "19:13:38,9105005","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 335 581, Length: 989" "19:13:38,9105413","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 336 570, Length: 990" "19:13:38,9105820","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 337 560, Length: 992" "19:13:38,9106214","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 338 552, Length: 990" "19:13:38,9106622","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 339 542, Length: 978" "19:13:38,9107007","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 340 520, Length: 971" "19:13:38,9107398","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 341 491, Length: 982" "19:13:38,9107805","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 342 473, Length: 997" "19:13:38,9108196","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 343 470, Length: 991" "19:13:38,9108585","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 344 461, Length: 985" "19:13:38,9108995","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 345 446, Length: 998" "19:13:38,9109390","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 346 444, Length: 976" "19:13:38,9109784","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 347 420, Length: 981" "19:13:38,9110223","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 348 401, Length: 990" "19:13:38,9110618","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 349 391, Length: 979" "19:13:38,9111012","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 350 370, Length: 997" "19:13:38,9111397","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 351 367, Length: 997" "19:13:38,9111779","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 352 364, Length: 982" "19:13:38,9112157","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 353 346, Length: 981" "19:13:38,9112542","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 354 327, Length: 1 000" "19:13:38,9112930","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 355 327, Length: 1 000" "19:13:38,9113328","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 356 327, Length: 986" "19:13:38,9113703","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 357 313, Length: 986" "19:13:38,9114072","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 358 299, Length: 975" "19:13:38,9114444","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 359 274, Length: 1 000" "19:13:38,9114816","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 360 274, Length: 998" "19:13:38,9115192","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 361 272, Length: 994" "19:13:38,9115564","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 362 266, Length: 989" "19:13:38,9115936","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 363 255, Length: 995" "19:13:38,9116314","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 364 250, Length: 980" "19:13:38,9116696","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 365 230, Length: 990" "19:13:38,9117077","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 366 220, Length: 992" "19:13:38,9117453","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 367 212, Length: 977" "19:13:38,9117838","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 368 189, Length: 992" "19:13:38,9118206","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 369 181, Length: 972" "19:13:38,9118582","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 370 153, Length: 979" "19:13:38,9118960","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 371 132, Length: 983" "19:13:38,9119339","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 372 115, Length: 994" "19:13:38,9119717","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 373 109, Length: 996" "19:13:38,9120099","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 374 105, Length: 984" "19:13:38,9120477","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 375 089, Length: 972" "19:13:38,9120856","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 376 061, Length: 991" "19:13:38,9121250","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 377 052, Length: 1 000" "19:13:38,9121645","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 378 052, Length: 976" "19:13:38,9122039","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 379 028, Length: 996" "19:13:38,9122430","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 380 024, Length: 998" "19:13:38,9122854","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 381 022, Length: 984" "19:13:38,9123264","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 382 006, Length: 999" "19:13:38,9123659","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 005, Length: 988" "19:13:38,9123989","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 383 993, Length: 988" "19:13:38,9124368","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 384 981, Length: 996" "19:13:38,9124743","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 385 977, Length: 976" "19:13:38,9125121","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 386 953, Length: 983" "19:13:38,9125487","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 387 936, Length: 986" "19:13:38,9125853","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 388 922, Length: 1 000" "19:13:38,9126212","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 389 922, Length: 971" "19:13:38,9126603","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 390 893, Length: 999" "19:13:38,9126994","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 391 892, Length: 999" "19:13:38,9127376","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 392 891, Length: 994" "19:13:38,9127758","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 393 885, Length: 994" "19:13:38,9128143","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 394 879, Length: 986" "19:13:38,9128505","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 395 865, Length: 1 000" "19:13:38,9128893","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 396 865, Length: 999" "19:13:38,9129268","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 397 864, Length: 996" "19:13:38,9129631","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 398 860, Length: 974" "19:13:38,9130009","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 399 834, Length: 991" "19:13:38,9130372","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 400 825, Length: 985" "19:13:38,9130737","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 401 810, Length: 968" "19:13:38,9131100","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 402 778, Length: 994" "19:13:38,9131459","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 403 772, Length: 992" "19:13:38,9131815","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 404 764, Length: 992" "19:13:38,9132184","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 405 756, Length: 980" "19:13:38,9132552","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 406 736, Length: 986" "19:13:38,9132883","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 407 722, Length: 990" "19:13:38,9133232","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 408 712, Length: 1 000" "19:13:38,9133640","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 409 712, Length: 998" "19:13:38,9134025","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 410 710, Length: 985" "19:13:38,9134413","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 411 695, Length: 979" "19:13:38,9134778","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 412 674, Length: 977" "19:13:38,9135163","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 413 651, Length: 983" "19:13:38,9135538","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 414 634, Length: 973" "19:13:38,9135917","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 415 607, Length: 976" "19:13:38,9136311","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 416 583, Length: 995" "19:13:38,9136703","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 417 578, Length: 978" "19:13:38,9137081","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 418 556, Length: 963" "19:13:38,9137476","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 419 519, Length: 1 000" "19:13:38,9137873","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 420 519, Length: 982" "19:13:38,9138265","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 421 501, Length: 991" "19:13:38,9138650","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 422 492, Length: 979" "19:13:38,9139015","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 423 471, Length: 992" "19:13:38,9139400","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 424 463, Length: 997" "19:13:38,9139791","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 425 460, Length: 988" "19:13:38,9140195","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 426 448, Length: 986" "19:13:38,9140577","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 427 434, Length: 991" "19:13:38,9140968","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 428 425, Length: 987" "19:13:38,9141360","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 429 412, Length: 967" "19:13:38,9141745","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 430 379, Length: 980" "19:13:38,9142123","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 431 359, Length: 971" "19:13:38,9142527","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 432 330, Length: 983" "19:13:38,9142934","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 433 313, Length: 980" "19:13:38,9143323","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 434 293, Length: 988" "19:13:38,9143493","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 435 281, Length: 980" "19:13:38,9143624","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 436 261, Length: 974" "19:13:38,9143868","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 437 235, Length: 989" "19:13:38,9144233","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 438 224, Length: 981" "19:13:38,9144570","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","Offset: 439 205, Length: 301" "19:13:38,9144820","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\System32\drivers\etc\hosts","SUCCESS","" "19:13:38,9145911","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 10" "19:13:38,9146228","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Query: HandleTags, HandleTags: 0x400" "19:13:38,9146373","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000A","NAME NOT FOUND","Desired Access: Read" "19:13:38,9275353","R5Apex.exe","3708","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "19:13:39,2573807","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 5064, User Time: 0.0156250, Kernel Time: 0.0156250" "19:13:39,2575789","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0, OpenResult: Created" "19:13:39,2576870","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Offset: 0, Length: 4 563 888, Priority: Normal" "19:13:39,2591630","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","" "19:13:39,2593519","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2593798","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","AllocationSize: 4 567 040, EndOfFile: 4 563 888, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:39,2605530","EasyAntiCheat_launcher.exe","6076","ReadFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","Offset: 0, Length: 4 563 888, Priority: Normal" "19:13:39,2618921","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac","SUCCESS","" "19:13:39,2619543","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:39,2619652","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:39,2619870","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","Desired Access: Read" "19:13:39,2620136","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:39,2620252","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:39,2620431","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:39,2620566","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:39,2620675","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name","SUCCESS","Type: REG_SZ, Length: 80, Data: Microsoft Strong Cryptographic Provider" "19:13:39,2620819","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 001","SUCCESS","" "19:13:39,2620932","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:39,2620996","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:39,2621131","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","Desired Access: Read" "19:13:39,2621278","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:39,2621355","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:39,2621480","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:39,2621592","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:39,2621708","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:39,2621814","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\rsaenh.dll" "19:13:39,2623196","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:39,2623940","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2624364","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2624495","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2624687","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2625178","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:39,2626041","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:39,2626798","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2627080","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2627176","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2627333","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2627641","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:39,2628498","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:39,2629149","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2629428","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2629524","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2629681","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2630060","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:39,2630871","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:39,2631500","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2631769","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2631862","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2632016","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2632346","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:39,2633139","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:39,2633767","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2634037","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2634130","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2634287","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2634598","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:39,2635374","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:39,2636003","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2636259","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2636352","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2636506","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2636795","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:39,2637590","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:39,2638322","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:39,2639021","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:39,2639653","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2639932","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2640025","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2640182","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2640496","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:39,2641269","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:39,2641888","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2642151","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2642244","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2642398","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2642690","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:39,2643521","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:39,2644156","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2644435","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2644528","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2644685","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2645006","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:39,2645807","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:39,2646426","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2646689","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2646782","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2646936","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2647225","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:39,2648097","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:39,2648197","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\Microsoft\Cryptography","SUCCESS","Desired Access: Read" "19:13:39,2648331","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:39,2648421","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:39,2648553","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:39,2648662","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:39,2648797","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid","SUCCESS","Type: REG_SZ, Length: 74, Data: 79f2c6fd-7ad0-4683-a9c4-a7b82aed4fd8" "19:13:39,2648941","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography","SUCCESS","" "19:13:39,2649076","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:39,2649146","EasyAntiCheat_launcher.exe","6076","RegQueryKey","HKLM","SUCCESS","Query: Name" "19:13:39,2649281","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Cryptography\Offload","NAME NOT FOUND","Desired Access: Read" "19:13:39,2649563","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\WOW6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider","SUCCESS","" "19:13:39,2794413","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Created" "19:13:39,2795564","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Offset: 0, Length: 47, Priority: Normal" "19:13:39,2796235","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","Offset: 47, Length: 41, Priority: Normal" "19:13:39,2796453","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\easyanticheat_wow64_x64.eac.metadata","SUCCESS","" "19:13:39,2801527","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\154\loader.log","SUCCESS","" "19:13:39,2804388","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 553, Length: 28" "19:13:39,2814205","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 3932, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2817454","EasyAntiCheat_launcher.exe","6076","WriteFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","Offset: 2 581, Length: 14" "19:13:39,2817791","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\EasyAntiCheat\gamelauncher.log","SUCCESS","" "19:13:39,2819683","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:39,2820430","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2820819","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2820947","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2821126","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2821476","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:39,2822345","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:09, LastAccessTime: 2021. 02. 13. 21:47:21, LastWriteTime: 2017. 09. 29. 15:42:09, ChangeTime: 2020. 01. 09. 4:47:23, AllocationSize: 593 920, EndOfFile: 590 392, FileAttributes: A" "19:13:39,2822996","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2823275","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2823372","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","AllocationSize: 593 920, EndOfFile: 590 392, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2823529","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2823827","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\dxgi.dll","SUCCESS","" "19:13:39,2824683","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:39,2825338","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2825636","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2825732","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2825892","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2826210","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:39,2827127","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 19:43:53, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 1 478 656, EndOfFile: 1 474 680, FileAttributes: A" "19:13:39,2827759","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2828025","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2828118","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","AllocationSize: 1 478 656, EndOfFile: 1 474 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2828272","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2828567","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d9.dll","SUCCESS","" "19:13:39,2829359","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:39,2829991","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2830258","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2830351","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2830517","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2830816","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:39,2831598","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 716 800, EndOfFile: 713 216, FileAttributes: A" "19:13:39,2832224","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2832487","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2832576","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","AllocationSize: 716 800, EndOfFile: 713 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2832730","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2833013","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\d3d8.dll","SUCCESS","" "19:13:39,2833802","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:39,2834616","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\d3d.dll","NAME NOT FOUND","" "19:13:39,2835319","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:39,2835963","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2836239","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2836335","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2836492","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2836794","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:39,2837573","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:14, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:42:14, ChangeTime: 2020. 01. 09. 4:43:21, AllocationSize: 532 480, EndOfFile: 531 456, FileAttributes: A" "19:13:39,2838192","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2838455","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2838545","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","AllocationSize: 532 480, EndOfFile: 531 456, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2838722","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2839010","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\ddraw.dll","SUCCESS","" "19:13:39,2839812","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:39,2840457","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2840736","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2840829","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2840986","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2841300","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:39,2842086","EasyAntiCheat_launcher.exe","6076","QueryOpen","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:42:22, LastAccessTime: 2021. 02. 13. 19:43:41, LastWriteTime: 2017. 09. 29. 15:42:22, ChangeTime: 2020. 01. 09. 4:43:33, AllocationSize: 778 240, EndOfFile: 777 216, FileAttributes: A" "19:13:39,2842708","EasyAntiCheat_launcher.exe","6076","CreateFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:39,2842971","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,2843064","EasyAntiCheat_launcher.exe","6076","QueryStandardInformationFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","AllocationSize: 778 240, EndOfFile: 777 216, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,2843215","EasyAntiCheat_launcher.exe","6076","CreateFileMapping","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,2843500","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\opengl32.dll","SUCCESS","" "19:13:39,2844405","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 6300, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2844421","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 4140, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2844681","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 1524, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2844703","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 2664, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2844896","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 196, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2844905","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 2936, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2845110","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 2028, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2845200","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 616, User Time: 0.0156250, Kernel Time: 0.0000000" "19:13:39,2845322","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 5700, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:39,2848488","EasyAntiCheat_launcher.exe","6076","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 919, Length: 66" "19:13:39,2852028","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","" "19:13:39,2881519","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes\Local Settings\Software\Microsoft","SUCCESS","" "19:13:39,2881673","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes\Local Settings","SUCCESS","" "19:13:39,2881782","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:39,2881869","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM","SUCCESS","" "19:13:39,2882536","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","REPARSE","Desired Access: Read" "19:13:39,2882767","EasyAntiCheat_launcher.exe","6076","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","Desired Access: Read" "19:13:39,2882921","EasyAntiCheat_launcher.exe","6076","RegSetInfoKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:39,2883011","EasyAntiCheat_launcher.exe","6076","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20" "19:13:39,2883187","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","" "19:13:39,2883441","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\Fonts\StaticCache.dat","SUCCESS","" "19:13:39,2884765","EasyAntiCheat_launcher.exe","6076","Thread Exit","","SUCCESS","Thread ID: 4348, User Time: 0.1093750, Kernel Time: 0.0937500" "19:13:39,2893136","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\sfc.dll","SUCCESS","Name: \Windows\SysWOW64\sfc.dll" "19:13:39,2893338","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\System32\wow64cpu.dll","SUCCESS","Name: \Windows\System32\wow64cpu.dll" "19:13:39,2893463","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\System32\wow64win.dll","SUCCESS","Name: \Windows\System32\wow64win.dll" "19:13:39,2893579","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\System32\wow64.dll","SUCCESS","Name: \Windows\System32\wow64.dll" "19:13:39,2893688","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\apphelp.dll","SUCCESS","Name: \Windows\SysWOW64\apphelp.dll" "19:13:39,2893819","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll","SUCCESS","Name: \Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b\GdiPlus.dll" "19:13:39,2893951","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\gpapi.dll","SUCCESS","Name: \Windows\SysWOW64\gpapi.dll" "19:13:39,2894069","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\FWPUCLNT.DLL","SUCCESS","Name: \Windows\SysWOW64\FWPUCLNT.DLL" "19:13:39,2894182","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\winnsi.dll","SUCCESS","Name: \Windows\SysWOW64\winnsi.dll" "19:13:39,2894294","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\dnsapi.dll","SUCCESS","Name: \Windows\SysWOW64\dnsapi.dll" "19:13:39,2894406","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\rasadhlp.dll","SUCCESS","Name: \Windows\SysWOW64\rasadhlp.dll" "19:13:39,2894515","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\rsaenh.dll","SUCCESS","Name: \Windows\SysWOW64\rsaenh.dll" "19:13:39,2894627","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\cryptnet.dll","SUCCESS","Name: \Windows\SysWOW64\cryptnet.dll" "19:13:39,2894743","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\cryptsp.dll","SUCCESS","Name: \Windows\SysWOW64\cryptsp.dll" "19:13:39,2894852","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\WinTypes.dll","SUCCESS","Name: \Windows\SysWOW64\WinTypes.dll" "19:13:39,2894964","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ntmarta.dll","SUCCESS","Name: \Windows\SysWOW64\ntmarta.dll" "19:13:39,2895070","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\CoreUIComponents.dll","SUCCESS","Name: \Windows\SysWOW64\CoreUIComponents.dll" "19:13:39,2895176","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\CoreMessaging.dll","SUCCESS","Name: \Windows\SysWOW64\CoreMessaging.dll" "19:13:39,2895282","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\TextInputFramework.dll","SUCCESS","Name: \Windows\SysWOW64\TextInputFramework.dll" "19:13:39,2895388","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\dhcpcsvc6.dll","SUCCESS","Name: \Windows\SysWOW64\dhcpcsvc6.dll" "19:13:39,2895509","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll","SUCCESS","Name: \Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223\comctl32.dll" "19:13:39,2895622","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\mswsock.dll","SUCCESS","Name: \Windows\SysWOW64\mswsock.dll" "19:13:39,2895728","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\bcrypt.dll","SUCCESS","Name: \Windows\SysWOW64\bcrypt.dll" "19:13:39,2895833","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\winmmbase.dll","SUCCESS","Name: \Windows\SysWOW64\winmmbase.dll" "19:13:39,2895939","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\dhcpcsvc.dll","SUCCESS","Name: \Windows\SysWOW64\dhcpcsvc.dll" "19:13:39,2896042","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\secur32.dll","SUCCESS","Name: \Windows\SysWOW64\secur32.dll" "19:13:39,2896151","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ncryptsslp.dll","SUCCESS","Name: \Windows\SysWOW64\ncryptsslp.dll" "19:13:39,2896254","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ntasn1.dll","SUCCESS","Name: \Windows\SysWOW64\ntasn1.dll" "19:13:39,2896356","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\DWrite.dll","SUCCESS","Name: \Windows\SysWOW64\DWrite.dll" "19:13:39,2896465","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ncrypt.dll","SUCCESS","Name: \Windows\SysWOW64\ncrypt.dll" "19:13:39,2896577","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\WindowsCodecs.dll","SUCCESS","Name: \Windows\SysWOW64\WindowsCodecs.dll" "19:13:39,2896680","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\IPHLPAPI.DLL","SUCCESS","Name: \Windows\SysWOW64\IPHLPAPI.DLL" "19:13:39,2896786","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\winmm.dll","SUCCESS","Name: \Windows\SysWOW64\winmm.dll" "19:13:39,2896885","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\mskeyprotect.dll","SUCCESS","Name: \Windows\SysWOW64\mskeyprotect.dll" "19:13:39,2896994","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\schannel.dll","SUCCESS","Name: \Windows\SysWOW64\schannel.dll" "19:13:39,2897123","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\sfc_os.dll","SUCCESS","Name: \Windows\SysWOW64\sfc_os.dll" "19:13:39,2897225","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\winspool.drv","SUCCESS","Name: \Windows\SysWOW64\winspool.drv" "19:13:39,2897334","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\AcLayers.dll","SUCCESS","Name: \Windows\SysWOW64\AcLayers.dll" "19:13:39,2897440","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\msimg32.dll","SUCCESS","Name: \Windows\SysWOW64\msimg32.dll" "19:13:39,2897546","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\mpr.dll","SUCCESS","Name: \Windows\SysWOW64\mpr.dll" "19:13:39,2897649","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\dwmapi.dll","SUCCESS","Name: \Windows\SysWOW64\dwmapi.dll" "19:13:39,2897755","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\uxtheme.dll","SUCCESS","Name: \Windows\SysWOW64\uxtheme.dll" "19:13:39,2897857","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\cryptbase.dll","SUCCESS","Name: \Windows\SysWOW64\cryptbase.dll" "19:13:39,2897960","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\sspicli.dll","SUCCESS","Name: \Windows\SysWOW64\sspicli.dll" "19:13:39,2898062","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\sechost.dll","SUCCESS","Name: \Windows\SysWOW64\sechost.dll" "19:13:39,2898175","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\msctf.dll","SUCCESS","Name: \Windows\SysWOW64\msctf.dll" "19:13:39,2898284","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\win32u.dll","SUCCESS","Name: \Windows\SysWOW64\win32u.dll" "19:13:39,2898383","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\bcryptprimitives.dll","SUCCESS","Name: \Windows\SysWOW64\bcryptprimitives.dll" "19:13:39,2898486","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\msasn1.dll","SUCCESS","Name: \Windows\SysWOW64\msasn1.dll" "19:13:39,2898588","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\nsi.dll","SUCCESS","Name: \Windows\SysWOW64\nsi.dll" "19:13:39,2898691","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\imagehlp.dll","SUCCESS","Name: \Windows\SysWOW64\imagehlp.dll" "19:13:39,2898794","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\cfgmgr32.dll","SUCCESS","Name: \Windows\SysWOW64\cfgmgr32.dll" "19:13:39,2898896","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\msvcrt.dll","SUCCESS","Name: \Windows\SysWOW64\msvcrt.dll" "19:13:39,2899002","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\imm32.dll","SUCCESS","Name: \Windows\SysWOW64\imm32.dll" "19:13:39,2899105","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\psapi.dll","SUCCESS","Name: \Windows\SysWOW64\psapi.dll" "19:13:39,2899207","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\shlwapi.dll","SUCCESS","Name: \Windows\SysWOW64\shlwapi.dll" "19:13:39,2899310","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\advapi32.dll","SUCCESS","Name: \Windows\SysWOW64\advapi32.dll" "19:13:39,2899410","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\gdi32full.dll","SUCCESS","Name: \Windows\SysWOW64\gdi32full.dll" "19:13:39,2899512","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ole32.dll","SUCCESS","Name: \Windows\SysWOW64\ole32.dll" "19:13:39,2899612","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\user32.dll","SUCCESS","Name: \Windows\SysWOW64\user32.dll" "19:13:39,2899714","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\KernelBase.dll","SUCCESS","Name: \Windows\SysWOW64\KernelBase.dll" "19:13:39,2899826","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\SHCore.dll","SUCCESS","Name: \Windows\SysWOW64\SHCore.dll" "19:13:39,2899932","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\kernel32.dll","SUCCESS","Name: \Windows\SysWOW64\kernel32.dll" "19:13:39,2900035","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\rpcrt4.dll","SUCCESS","Name: \Windows\SysWOW64\rpcrt4.dll" "19:13:39,2900138","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\crypt32.dll","SUCCESS","Name: \Windows\SysWOW64\crypt32.dll" "19:13:39,2900243","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\wintrust.dll","SUCCESS","Name: \Windows\SysWOW64\wintrust.dll" "19:13:39,2900346","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ucrtbase.dll","SUCCESS","Name: \Windows\SysWOW64\ucrtbase.dll" "19:13:39,2900449","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\powrprof.dll","SUCCESS","Name: \Windows\SysWOW64\powrprof.dll" "19:13:39,2900571","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\profapi.dll","SUCCESS","Name: \Windows\SysWOW64\profapi.dll" "19:13:39,2900680","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\gdi32.dll","SUCCESS","Name: \Windows\SysWOW64\gdi32.dll" "19:13:39,2900782","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\msvcp_win.dll","SUCCESS","Name: \Windows\SysWOW64\msvcp_win.dll" "19:13:39,2901048","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\kernel.appcore.dll","SUCCESS","Name: \Windows\SysWOW64\kernel.appcore.dll" "19:13:39,2901186","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\combase.dll","SUCCESS","Name: \Windows\SysWOW64\combase.dll" "19:13:39,2901302","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\setupapi.dll","SUCCESS","Name: \Windows\SysWOW64\setupapi.dll" "19:13:39,2901414","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\oleaut32.dll","SUCCESS","Name: \Windows\SysWOW64\oleaut32.dll" "19:13:39,2901520","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\windows.storage.dll","SUCCESS","Name: \Windows\SysWOW64\windows.storage.dll" "19:13:39,2901626","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\shell32.dll","SUCCESS","Name: \Windows\SysWOW64\shell32.dll" "19:13:39,2901738","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ws2_32.dll","SUCCESS","Name: \Windows\SysWOW64\ws2_32.dll" "19:13:39,2901995","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\SysWOW64\ntdll.dll","SUCCESS","Name: \Windows\SysWOW64\ntdll.dll" "19:13:39,2902113","EasyAntiCheat_launcher.exe","6076","QueryNameInformationFile","C:\Windows\System32\ntdll.dll","SUCCESS","Name: \Windows\System32\ntdll.dll" "19:13:39,2902745","EasyAntiCheat_launcher.exe","6076","Process Exit","","SUCCESS","Exit Status: 0, User Time: 1.2500000 seconds, Kernel Time: 6.0312500 seconds, Private Bytes: 16 945 152, Peak Private Bytes: 32 526 336, Working Set: 28 962 816, Peak Working Set: 64 602 112" "19:13:39,2903159","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows","SUCCESS","" "19:13:39,2903431","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:39,2903688","EasyAntiCheat_launcher.exe","6076","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends","SUCCESS","" "19:13:39,2904015","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS","" "19:13:39,2904079","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","" "19:13:39,2904137","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","" "19:13:39,2904217","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM","SUCCESS","" "19:13:39,2904346","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder","SUCCESS","" "19:13:39,2904413","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\NetworkProvider\ProviderOrder","SUCCESS","" "19:13:39,2904580","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:39,2904666","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.16299.15_none_9407a1354a2a1e4b","SUCCESS","" "19:13:39,2904884","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:39,2904945","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Ids","SUCCESS","" "19:13:39,2905000","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer","SUCCESS","" "19:13:39,2905106","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.16299.15_none_1440321736920223","SUCCESS","" "19:13:39,2905272","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Classes","SUCCESS","" "19:13:39,2905385","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","" "19:13:39,2905462","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","" "19:13:39,2906629","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","SUCCESS","" "19:13:39,2906687","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","SUCCESS","" "19:13:39,2906741","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","SUCCESS","" "19:13:39,2906799","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:39,2906882","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:39,2907004","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS","" "19:13:39,2907088","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKU","SUCCESS","" "19:13:39,2907155","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS","" "19:13:39,2907232","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\System\CurrentControlSet\Services\crypt32","SUCCESS","" "19:13:39,2907354","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:39,2907421","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:39,2907492","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS","" "19:13:39,2907578","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Windows\SysWOW64\en-US\crypt32.dll.mui","SUCCESS","" "19:13:39,2907768","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS","" "19:13:39,2907835","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS","" "19:13:39,2907899","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS","" "19:13:39,2907967","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS","" "19:13:39,2908034","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS","" "19:13:39,2908101","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS","" "19:13:39,2908278","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","" "19:13:39,2908345","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:39,2908409","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS","" "19:13:39,2908460","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:39,2908521","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS","" "19:13:39,2908586","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS","" "19:13:39,2908733","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:39,2908784","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU","SUCCESS","" "19:13:39,2908845","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS","" "19:13:39,2908909","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS","" "19:13:39,2909009","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates","SUCCESS","" "19:13:39,2909131","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates","SUCCESS","" "19:13:39,2909314","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS","" "19:13:39,2909394","EasyAntiCheat_launcher.exe","6076","CloseFile","C:\Users\Administrator\AppData\Roaming\Microsoft\SystemCertificates\My","SUCCESS","" "19:13:39,2909615","EasyAntiCheat_launcher.exe","6076","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion","SUCCESS","" "19:13:39,3785749","R5Apex.exe","3708","Load Image","C:\Windows\System32\msvcrt.dll","SUCCESS","Image Base: 0x7ffdcfae0000, Image Size: 0x9d000" "19:13:39,3788154","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,3788664","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvcrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,3788799","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msvcrt.dll","SUCCESS","AllocationSize: 630 784, EndOfFile: 630 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,3788985","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvcrt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,3789245","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msvcrt.dll","SUCCESS","AllocationSize: 630 784, EndOfFile: 630 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,3808498","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "19:13:39,4112313","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 5492" "19:13:39,4114770","R5Apex.exe","3708","Load Image","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Image Base: 0x7ffdcf240000, Image Size: 0x4a000" "19:13:39,4116954","R5Apex.exe","3708","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,4117435","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\cfgmgr32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,4117570","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","AllocationSize: 290 816, EndOfFile: 287 944, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,4117746","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\cfgmgr32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,4118000","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","AllocationSize: 290 816, EndOfFile: 287 944, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,4126957","R5Apex.exe","3708","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "19:13:39,4367352","R5Apex.exe","3708","Load Image","C:\Windows\System32\ucrtbase.dll","SUCCESS","Image Base: 0x7ffdced10000, Image Size: 0xf6000" "19:13:39,4369280","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,4369668","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ucrtbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,4369774","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","AllocationSize: 1 003 520, EndOfFile: 1 003 104, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,4369931","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ucrtbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,4370168","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","AllocationSize: 1 003 520, EndOfFile: 1 003 104, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,4400554","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "19:13:39,4756654","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 3012" "19:13:39,4759008","R5Apex.exe","3708","Load Image","C:\Windows\System32\SHCore.dll","SUCCESS","Image Base: 0x7ffdd0970000, Image Size: 0xa6000" "19:13:39,4760846","R5Apex.exe","3708","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,4761247","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\SHCore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,4761353","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\SHCore.dll","SUCCESS","AllocationSize: 671 744, EndOfFile: 671 024, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,4761516","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\SHCore.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,4761757","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\SHCore.dll","SUCCESS","AllocationSize: 671 744, EndOfFile: 671 024, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,4782120","R5Apex.exe","3708","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS","" "19:13:39,5063907","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:39,5064080","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:39,5064247","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:39,5064424","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:39,5066200","R5Apex.exe","3708","Load Image","C:\Windows\System32\rpcrt4.dll","SUCCESS","Image Base: 0x7ffdcf870000, Image Size: 0x11f000" "19:13:39,5067981","R5Apex.exe","3708","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,5068381","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\rpcrt4.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,5068487","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","AllocationSize: 1 175 552, EndOfFile: 1 173 576, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,5068648","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\rpcrt4.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,5068885","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","AllocationSize: 1 175 552, EndOfFile: 1 173 576, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,5104338","R5Apex.exe","3708","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "19:13:39,5491722","R5Apex.exe","3708","Load Image","C:\Windows\System32\combase.dll","SUCCESS","Image Base: 0x7ffdd0540000, Image Size: 0x308000" "19:13:39,5493611","R5Apex.exe","3708","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,5494009","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\combase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,5494118","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\combase.dll","SUCCESS","AllocationSize: 3 182 592, EndOfFile: 3 180 720, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,5494278","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\combase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,5494522","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\combase.dll","SUCCESS","AllocationSize: 3 182 592, EndOfFile: 3 180 720, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,5591702","R5Apex.exe","3708","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "19:13:39,6410140","R5Apex.exe","3708","Load Image","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Image Base: 0x7ffdce3f0000, Image Size: 0x72000" "19:13:39,6412401","R5Apex.exe","3708","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,6412754","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,6412879","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","AllocationSize: 466 944, EndOfFile: 464 408, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,6413065","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,6413325","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","AllocationSize: 466 944, EndOfFile: 464 408, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,6427540","R5Apex.exe","3708","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "19:13:39,6700385","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 676" "19:13:39,6702611","R5Apex.exe","3708","Load Image","C:\Windows\System32\windows.storage.dll","SUCCESS","Image Base: 0x7ffdce520000, Image Size: 0x747000" "19:13:39,6704558","R5Apex.exe","3708","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,6704860","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\windows.storage.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,6704965","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\windows.storage.dll","SUCCESS","AllocationSize: 7 675 904, EndOfFile: 7 675 408, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,6705123","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\windows.storage.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,6705370","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\windows.storage.dll","SUCCESS","AllocationSize: 7 675 904, EndOfFile: 7 675 408, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,6939042","R5Apex.exe","3708","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS","" "19:13:39,8400262","R5Apex.exe","3708","Load Image","C:\Windows\System32\advapi32.dll","SUCCESS","Image Base: 0x7ffdcfe50000, Image Size: 0xa1000" "19:13:39,8402238","R5Apex.exe","3708","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,8402648","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\advapi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,8402757","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\advapi32.dll","SUCCESS","AllocationSize: 651 264, EndOfFile: 649 296, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,8402921","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\advapi32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,8403168","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\advapi32.dll","SUCCESS","AllocationSize: 651 264, EndOfFile: 649 296, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,8423030","R5Apex.exe","3708","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "19:13:39,8715444","R5Apex.exe","3708","Load Image","C:\Windows\System32\sechost.dll","SUCCESS","Image Base: 0x7ffdd0af0000, Image Size: 0x5b000" "19:13:39,8717663","R5Apex.exe","3708","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,8718542","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\sechost.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,8718680","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\sechost.dll","SUCCESS","AllocationSize: 372 736, EndOfFile: 371 424, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,8718863","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\sechost.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,8719119","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\sechost.dll","SUCCESS","AllocationSize: 372 736, EndOfFile: 371 424, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,8731669","R5Apex.exe","3708","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "19:13:39,9005913","R5Apex.exe","3708","Load Image","C:\Windows\System32\shlwapi.dll","SUCCESS","Image Base: 0x7ffdcfb80000, Image Size: 0x51000" "19:13:39,9008110","R5Apex.exe","3708","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,9008550","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\shlwapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,9008672","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\shlwapi.dll","SUCCESS","AllocationSize: 327 680, EndOfFile: 327 008, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,9008842","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\shlwapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,9009085","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\shlwapi.dll","SUCCESS","AllocationSize: 327 680, EndOfFile: 327 008, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,9019182","R5Apex.exe","3708","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "19:13:39,9268432","R5Apex.exe","3708","Load Image","C:\Windows\System32\gdi32.dll","SUCCESS","Image Base: 0x7ffdd1f90000, Image Size: 0x28000" "19:13:39,9270327","R5Apex.exe","3708","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,9270719","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\gdi32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,9270824","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\gdi32.dll","SUCCESS","AllocationSize: 155 648, EndOfFile: 154 008, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,9270988","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\gdi32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,9271229","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\gdi32.dll","SUCCESS","AllocationSize: 155 648, EndOfFile: 154 008, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,9276187","R5Apex.exe","3708","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "19:13:39,9472052","R5Apex.exe","3708","Load Image","C:\Windows\System32\gdi32full.dll","SUCCESS","Image Base: 0x7ffdcee10000, Image Size: 0x191000" "19:13:39,9473764","R5Apex.exe","3708","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:39,9474040","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\gdi32full.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:39,9474137","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\gdi32full.dll","SUCCESS","AllocationSize: 1 634 304, EndOfFile: 1 631 320, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,9474307","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\gdi32full.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:39,9474537","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\gdi32full.dll","SUCCESS","AllocationSize: 1 634 304, EndOfFile: 1 631 320, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:39,9523865","R5Apex.exe","3708","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "19:13:40,0002961","R5Apex.exe","3708","Load Image","C:\Windows\System32\msvcp_win.dll","SUCCESS","Image Base: 0x7ffdcec70000, Image Size: 0x9b000" "19:13:40,0004956","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,0005254","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvcp_win.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,0005357","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","AllocationSize: 630 784, EndOfFile: 628 632, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,0005517","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvcp_win.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,0005758","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","AllocationSize: 630 784, EndOfFile: 628 632, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,0024873","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "19:13:40,0334933","R5Apex.exe","3708","Load Image","C:\Windows\System32\user32.dll","SUCCESS","Image Base: 0x7ffdcf4c0000, Image Size: 0x18e000" "19:13:40,0336758","R5Apex.exe","3708","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,0337140","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\user32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,0337245","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\user32.dll","SUCCESS","AllocationSize: 1 634 304, EndOfFile: 1 633 744, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,0337403","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\user32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,0337637","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\user32.dll","SUCCESS","AllocationSize: 1 634 304, EndOfFile: 1 633 744, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,0386669","R5Apex.exe","3708","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "19:13:40,0900872","R5Apex.exe","3708","Load Image","C:\Windows\System32\win32u.dll","SUCCESS","Image Base: 0x7ffdcefb0000, Image Size: 0x20000" "19:13:40,0902838","R5Apex.exe","3708","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,0903242","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\win32u.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,0903351","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\win32u.dll","SUCCESS","AllocationSize: 122 880, EndOfFile: 119 440, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,0903515","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\win32u.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,0903759","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\win32u.dll","SUCCESS","AllocationSize: 122 880, EndOfFile: 119 440, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,0907675","R5Apex.exe","3708","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "19:13:40,1108068","R5Apex.exe","3708","Load Image","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Image Base: 0x7ffdce3d0000, Image Size: 0x11000" "19:13:40,1109944","R5Apex.exe","3708","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,1110249","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\kernel.appcore.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,1110358","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","AllocationSize: 57 344, EndOfFile: 54 368, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1110522","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\kernel.appcore.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,1110753","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","AllocationSize: 57 344, EndOfFile: 54 368, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1112709","R5Apex.exe","3708","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "19:13:40,1298391","R5Apex.exe","3708","Load Image","C:\Windows\System32\powrprof.dll","SUCCESS","Image Base: 0x7ffdce340000, Image Size: 0x4c000" "19:13:40,1300691","R5Apex.exe","3708","CreateFile","C:\Windows\System32\powrprof.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,1301165","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\powrprof.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,1301290","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\powrprof.dll","SUCCESS","AllocationSize: 303 104, EndOfFile: 299 688, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1301463","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\powrprof.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,1301730","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\powrprof.dll","SUCCESS","AllocationSize: 303 104, EndOfFile: 299 688, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1310954","R5Apex.exe","3708","CloseFile","C:\Windows\System32\powrprof.dll","SUCCESS","" "19:13:40,1555486","R5Apex.exe","3708","Load Image","C:\Windows\System32\profapi.dll","SUCCESS","Image Base: 0x7ffdce390000, Image Size: 0x1b000" "19:13:40,1557766","R5Apex.exe","3708","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,1558241","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\profapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,1558369","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\profapi.dll","SUCCESS","AllocationSize: 94 208, EndOfFile: 93 640, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1558549","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\profapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,1558805","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\profapi.dll","SUCCESS","AllocationSize: 94 208, EndOfFile: 93 640, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1561936","R5Apex.exe","3708","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS","" "19:13:40,1779424","R5Apex.exe","3708","Load Image","C:\Windows\System32\ole32.dll","SUCCESS","Image Base: 0x7ffdcf990000, Image Size: 0x149000" "19:13:40,1781598","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,1782092","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ole32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,1782221","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ole32.dll","SUCCESS","AllocationSize: 1 339 392, EndOfFile: 1 336 344, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1782410","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ole32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,1782673","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ole32.dll","SUCCESS","AllocationSize: 1 339 392, EndOfFile: 1 336 344, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,1823068","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "19:13:40,2245697","R5Apex.exe","3708","Load Image","C:\Windows\System32\imm32.dll","SUCCESS","Image Base: 0x7ffdcf840000, Image Size: 0x2d000" "19:13:40,2247573","R5Apex.exe","3708","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2247968","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\imm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2248080","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\imm32.dll","SUCCESS","AllocationSize: 176 128, EndOfFile: 173 640, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2248237","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\imm32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2248484","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\imm32.dll","SUCCESS","AllocationSize: 176 128, EndOfFile: 173 640, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2254020","R5Apex.exe","3708","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "19:13:40,2464555","R5Apex.exe","3708","Load Image","C:\Windows\System32\ws2_32.dll","SUCCESS","Image Base: 0x7ffdcf750000, Image Size: 0x6c000" "19:13:40,2466399","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ws2_32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2466813","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ws2_32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2466922","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ws2_32.dll","SUCCESS","AllocationSize: 430 080, EndOfFile: 428 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2467079","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ws2_32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2467316","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ws2_32.dll","SUCCESS","AllocationSize: 430 080, EndOfFile: 428 352, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2480431","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ws2_32.dll","SUCCESS","" "19:13:40,2750640","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value" "19:13:40,2750820","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value" "19:13:40,2750980","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode","NAME NOT FOUND","Length: 16" "19:13:40,2751958","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\AVIFIL32.dll","NAME NOT FOUND","" "19:13:40,2751971","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bcrypt.dll","NAME NOT FOUND","" "19:13:40,2752003","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\IPHLPAPI.DLL","NAME NOT FOUND","" "19:13:40,2752359","R5Apex.exe","3708","Load Image","C:\Windows\System32\Wldap32.dll","SUCCESS","Image Base: 0x7ffdcf6f0000, Image Size: 0x5e000" "19:13:40,2753033","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\avifil32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 19:44:42, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:41:40, AllocationSize: 114 688, EndOfFile: 113 664, FileAttributes: A" "19:13:40,2753042","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\bcrypt.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:41:41, AllocationSize: 139 264, EndOfFile: 137 544, FileAttributes: A" "19:13:40,2753062","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:45:19, AllocationSize: 225 280, EndOfFile: 221 696, FileAttributes: A" "19:13:40,2754309","R5Apex.exe","3708","CreateFile","C:\Windows\System32\avifil32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2754319","R5Apex.exe","3708","CreateFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2754345","R5Apex.exe","3708","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2754402","R5Apex.exe","3708","CreateFile","C:\Windows\System32\Wldap32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2754742","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avifil32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2754765","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2754806","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2754829","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\Wldap32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2754935","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\Wldap32.dll","SUCCESS","AllocationSize: 360 448, EndOfFile: 358 912, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2754973","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\bcrypt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2755021","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2755150","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\Wldap32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2755230","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avifil32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2755403","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\Wldap32.dll","SUCCESS","AllocationSize: 360 448, EndOfFile: 358 912, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2756275","R5Apex.exe","3708","Load Image","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","Image Base: 0x7ffdcd880000, Image Size: 0x39000" "19:13:40,2756468","R5Apex.exe","3708","Load Image","C:\Windows\System32\avifil32.dll","SUCCESS","Image Base: 0x7ffdc9620000, Image Size: 0x1f000" "19:13:40,2758081","R5Apex.exe","3708","CreateFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2758456","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2758559","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","AllocationSize: 225 280, EndOfFile: 221 696, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2758633","R5Apex.exe","3708","CreateFile","C:\Windows\System32\avifil32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2758716","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2759056","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avifil32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2759098","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","AllocationSize: 225 280, EndOfFile: 221 696, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2759156","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\avifil32.dll","SUCCESS","AllocationSize: 114 688, EndOfFile: 113 664, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2759332","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avifil32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2759566","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\avifil32.dll","SUCCESS","AllocationSize: 114 688, EndOfFile: 113 664, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2763434","R5Apex.exe","3708","CloseFile","C:\Windows\System32\avifil32.dll","SUCCESS","" "19:13:40,2766346","R5Apex.exe","3708","CloseFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","" "19:13:40,2766978","R5Apex.exe","3708","CloseFile","C:\Windows\System32\Wldap32.dll","SUCCESS","" "19:13:40,2767081","R5Apex.exe","3708","Load Image","C:\Windows\System32\bcrypt.dll","SUCCESS","Image Base: 0x7ffdcddc0000, Image Size: 0x25000" "19:13:40,2768668","R5Apex.exe","3708","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2768999","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\bcrypt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2769088","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\bcrypt.dll","SUCCESS","AllocationSize: 139 264, EndOfFile: 137 544, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2769236","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\bcrypt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2769448","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\bcrypt.dll","SUCCESS","AllocationSize: 139 264, EndOfFile: 137 544, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2774255","R5Apex.exe","3708","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS","" "19:13:40,2941893","R5Apex.exe","3708","CloseFile","C:\Windows\System32\avifil32.dll","SUCCESS","" "19:13:40,2942730","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\d3d11.dll","NAME NOT FOUND","" "19:13:40,2943686","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d11.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:27, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:27, ChangeTime: 2020. 01. 09. 4:47:20, AllocationSize: 3 014 656, EndOfFile: 3 011 272, FileAttributes: A" "19:13:40,2944430","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d11.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2944770","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2944975","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d11.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2946380","R5Apex.exe","3708","Load Image","C:\Windows\System32\d3d11.dll","SUCCESS","Image Base: 0x7ffdcb880000, Image Size: 0x2e2000" "19:13:40,2948173","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d11.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,2948522","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d11.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,2948619","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d11.dll","SUCCESS","AllocationSize: 3 014 656, EndOfFile: 3 011 272, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,2948773","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d11.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,2949013","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d11.dll","SUCCESS","AllocationSize: 3 014 656, EndOfFile: 3 011 272, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3040469","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d11.dll","SUCCESS","" "19:13:40,3154949","R5Apex.exe","3708","Load Image","C:\Windows\System32\normaliz.dll","SUCCESS","Image Base: 0x7ffdd0520000, Image Size: 0x8000" "19:13:40,3156876","R5Apex.exe","3708","CreateFile","C:\Windows\System32\normaliz.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3157319","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\normaliz.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3157425","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\normaliz.dll","SUCCESS","AllocationSize: 8 192, EndOfFile: 5 632, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3157617","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\normaliz.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3157880","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\normaliz.dll","SUCCESS","AllocationSize: 8 192, EndOfFile: 5 632, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3158345","R5Apex.exe","3708","CloseFile","C:\Windows\System32\normaliz.dll","SUCCESS","" "19:13:40,3351231","R5Apex.exe","3708","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS","" "19:13:40,3352145","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\D3DCOMPILER_43.dll","NAME NOT FOUND","" "19:13:40,3352995","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","CreationTime: 2020. 01. 10. 5:49:28, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2010. 05. 26. 21:41:02, ChangeTime: 2021. 02. 07. 17:14:45, AllocationSize: 2 527 232, EndOfFile: 2 526 056, FileAttributes: ANCI" "19:13:40,3353777","R5Apex.exe","3708","CreateFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3354047","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\D3DCompiler_43.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3354246","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3355698","R5Apex.exe","3708","Load Image","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Image Base: 0x7ffdb6130000, Image Size: 0x26f000" "19:13:40,3357713","R5Apex.exe","3708","CreateFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3357988","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\D3DCompiler_43.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3358085","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","AllocationSize: 2 527 232, EndOfFile: 2 526 056, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,3358235","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3358476","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","AllocationSize: 2 527 232, EndOfFile: 2 526 056, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,3437282","R5Apex.exe","3708","CloseFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","" "19:13:40,3554559","R5Apex.exe","3708","CloseFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","" "19:13:40,3555470","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:29, AllocationSize: 720 896, EndOfFile: 718 848, FileAttributes: ANCI" "19:13:40,3556002","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3556275","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3557070","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3558590","R5Apex.exe","3708","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Image Base: 0x7ffdb3330000, Image Size: 0xb7000" "19:13:40,3559739","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3560316","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3560544","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","AllocationSize: 720 896, EndOfFile: 718 848, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,3562080","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Offset: 0, Length: 718 848, Priority: Normal" "19:13:40,3605295","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","" "19:13:40,3606578","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","AllocationSize: 720 896, EndOfFile: 718 848, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,3607947","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Offset: 0, Length: 718 848, Priority: Normal" "19:13:40,3650145","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","" "19:13:40,3653192","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","" "19:13:40,3653952","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","CreationTime: 2021. 04. 11. 21:49:19, LastAccessTime: 2021. 04. 11. 21:49:19, LastWriteTime: 2021. 04. 11. 21:49:19, ChangeTime: 2021. 04. 12. 10:14:29, AllocationSize: 262 144, EndOfFile: 198 656, FileAttributes: ANCI" "19:13:40,3654465","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3654748","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3655392","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3656826","R5Apex.exe","3708","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Image Base: 0x7ffdb7f10000, Image Size: 0x36000" "19:13:40,3658179","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3658824","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3659045","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","AllocationSize: 262 144, EndOfFile: 198 656, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,3659549","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Offset: 0, Length: 198 656, Priority: Normal" "19:13:40,3671445","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","" "19:13:40,3671682","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","AllocationSize: 262 144, EndOfFile: 198 656, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,3671781","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Offset: 0, Length: 198 656, Priority: Normal" "19:13:40,3683340","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","" "19:13:40,3685034","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","" "19:13:40,3685659","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WINMM.dll","NAME NOT FOUND","" "19:13:40,3686500","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmm.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 126 976, EndOfFile: 123 072, FileAttributes: A" "19:13:40,3687224","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmm.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3687564","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmm.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3687750","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmm.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3688937","R5Apex.exe","3708","Load Image","C:\Windows\System32\winmm.dll","SUCCESS","Image Base: 0x7ffdcb120000, Image Size: 0x23000" "19:13:40,3690435","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmm.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3690772","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmm.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3690868","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmm.dll","SUCCESS","AllocationSize: 126 976, EndOfFile: 123 072, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3691015","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmm.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3691250","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmm.dll","SUCCESS","AllocationSize: 126 976, EndOfFile: 123 072, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3694790","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmm.dll","SUCCESS","" "19:13:40,3739708","R5Apex.exe","3708","Load Image","C:\Windows\System32\crypt32.dll","SUCCESS","Image Base: 0x7ffdcf2f0000, Image Size: 0x1ce000" "19:13:40,3741501","R5Apex.exe","3708","CreateFile","C:\Windows\System32\crypt32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,3741899","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\crypt32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,3742024","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\crypt32.dll","SUCCESS","AllocationSize: 1 875 968, EndOfFile: 1 873 944, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3742255","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\crypt32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,3742524","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\crypt32.dll","SUCCESS","AllocationSize: 1 875 968, EndOfFile: 1 873 944, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,3802535","R5Apex.exe","3708","CloseFile","C:\Windows\System32\crypt32.dll","SUCCESS","" "19:13:40,4100651","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d11.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,4101084","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d11.dll","SUCCESS","AllocationSize: 3 014 656, EndOfFile: 3 011 272, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,4173678","R5Apex.exe","3708","ReadFile","C:\Windows\System32\d3d11.dll","SUCCESS","Offset: 0, Length: 3 011 272, Priority: Normal" "19:13:40,4181914","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d11.dll","SUCCESS","" "19:13:40,4444298","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d11.dll","SUCCESS","" "19:13:40,4445497","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\MSVFW32.dll","NAME NOT FOUND","" "19:13:40,4446366","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\msvfw32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 19:44:42, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:42:02, AllocationSize: 143 360, EndOfFile: 142 848, FileAttributes: A" "19:13:40,4447220","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvfw32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,4447652","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvfw32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,4448073","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvfw32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,4449705","R5Apex.exe","3708","Load Image","C:\Windows\System32\msvfw32.dll","SUCCESS","Image Base: 0x7ffdbad30000, Image Size: 0x29000" "19:13:40,4451508","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvfw32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,4451860","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvfw32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,4451969","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msvfw32.dll","SUCCESS","AllocationSize: 143 360, EndOfFile: 142 848, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,4452133","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msvfw32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,4452377","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msvfw32.dll","SUCCESS","AllocationSize: 143 360, EndOfFile: 142 848, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,4456947","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvfw32.dll","SUCCESS","" "19:13:40,4999460","R5Apex.exe","3708","CreateFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,4999804","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","AllocationSize: 2 527 232, EndOfFile: 2 526 056, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,5061418","R5Apex.exe","3708","ReadFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Offset: 0, Length: 2 526 056, Priority: Normal" "19:13:40,5067852","R5Apex.exe","3708","CloseFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","" "19:13:40,5170103","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmm.dll","SUCCESS","" "19:13:40,5170956","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\MSACM32.dll","NAME NOT FOUND","" "19:13:40,5171829","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\msacm32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:23, LastAccessTime: 2021. 02. 13. 20:39:01, LastWriteTime: 2017. 09. 29. 15:41:23, ChangeTime: 2020. 01. 09. 4:47:21, AllocationSize: 106 496, EndOfFile: 106 472, FileAttributes: A" "19:13:40,5172634","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msacm32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5172983","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msacm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5173439","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msacm32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5174908","R5Apex.exe","3708","Load Image","C:\Windows\System32\msacm32.dll","SUCCESS","Image Base: 0x7ffdbf390000, Image Size: 0x1c000" "19:13:40,5177076","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msacm32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5177429","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msacm32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5177528","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msacm32.dll","SUCCESS","AllocationSize: 106 496, EndOfFile: 106 472, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5177682","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msacm32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5177926","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msacm32.dll","SUCCESS","AllocationSize: 106 496, EndOfFile: 106 472, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5181528","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msacm32.dll","SUCCESS","" "19:13:40,5293343","R5Apex.exe","3708","CloseFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","" "19:13:40,5294250","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WINMM.dll","NAME NOT FOUND","" "19:13:40,5295097","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmm.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 126 976, EndOfFile: 123 072, FileAttributes: A" "19:13:40,5296694","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WINMM.dll","NAME NOT FOUND","" "19:13:40,5297486","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmm.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 126 976, EndOfFile: 123 072, FileAttributes: A" "19:13:40,5298051","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\AVRT.dll","NAME NOT FOUND","" "19:13:40,5298776","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\avrt.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:23, LastAccessTime: 2021. 02. 13. 21:57:19, LastWriteTime: 2017. 09. 29. 15:41:23, ChangeTime: 2020. 01. 09. 4:45:21, AllocationSize: 32 768, EndOfFile: 30 048, FileAttributes: A" "19:13:40,5299488","R5Apex.exe","3708","CreateFile","C:\Windows\System32\avrt.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5299844","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5300043","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avrt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5301595","R5Apex.exe","3708","Load Image","C:\Windows\System32\avrt.dll","SUCCESS","Image Base: 0x7ffdc8f70000, Image Size: 0xa000" "19:13:40,5303404","R5Apex.exe","3708","CreateFile","C:\Windows\System32\avrt.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5303763","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avrt.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5303859","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\avrt.dll","SUCCESS","AllocationSize: 32 768, EndOfFile: 30 048, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5304020","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\avrt.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5304260","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\avrt.dll","SUCCESS","AllocationSize: 32 768, EndOfFile: 30 048, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5305335","R5Apex.exe","3708","CloseFile","C:\Windows\System32\avrt.dll","SUCCESS","" "19:13:40,5477883","R5Apex.exe","3708","Load Image","C:\Windows\System32\msasn1.dll","SUCCESS","Image Base: 0x7ffdce3b0000, Image Size: 0x12000" "19:13:40,5479666","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msasn1.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5480048","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msasn1.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5480153","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msasn1.dll","SUCCESS","AllocationSize: 65 536, EndOfFile: 65 176, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5480311","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\msasn1.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5480541","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\msasn1.dll","SUCCESS","AllocationSize: 65 536, EndOfFile: 65 176, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5482559","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msasn1.dll","SUCCESS","" "19:13:40,5636790","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots","NAME NOT FOUND","Desired Access: Enumerate Sub Keys" "19:13:40,5637534","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe.local","NAME INVALID","" "19:13:40,5638471","R5Apex.exe","3708","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc","SUCCESS","Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5639038","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvfw32.dll","SUCCESS","" "19:13:40,5640026","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\dxgi.dll","NAME NOT FOUND","" "19:13:40,5640815","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:40,5641514","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dxgi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5641851","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5642053","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5643413","R5Apex.exe","3708","Load Image","C:\Windows\System32\dxgi.dll","SUCCESS","Image Base: 0x7ffdcd160000, Image Size: 0xaf000" "19:13:40,5645004","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dxgi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5645344","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dxgi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5645440","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dxgi.dll","SUCCESS","AllocationSize: 704 512, EndOfFile: 702 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5645597","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dxgi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5645831","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dxgi.dll","SUCCESS","AllocationSize: 704 512, EndOfFile: 702 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5666566","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dxgi.dll","SUCCESS","" "19:13:40,5800813","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msacm32.dll","SUCCESS","" "19:13:40,5801641","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WINMMBASE.dll","NAME NOT FOUND","" "19:13:40,5802526","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 159 744, EndOfFile: 159 680, FileAttributes: A" "19:13:40,5803273","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5803527","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5803722","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5805098","R5Apex.exe","3708","Load Image","C:\Windows\System32\winmmbase.dll","SUCCESS","Image Base: 0x7ffdcb0c0000, Image Size: 0x2a000" "19:13:40,5806891","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5807164","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5807257","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmmbase.dll","SUCCESS","AllocationSize: 159 744, EndOfFile: 159 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5807417","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5807651","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmmbase.dll","SUCCESS","AllocationSize: 159 744, EndOfFile: 159 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5812735","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,5960417","R5Apex.exe","3708","CloseFile","C:\Windows\System32\avrt.dll","SUCCESS","" "19:13:40,5961424","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 159 744, EndOfFile: 159 680, FileAttributes: A" "19:13:40,5962312","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5962562","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5962764","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5964156","R5Apex.exe","3708","Load Image","C:\Windows\System32\winmmbase.dll","SUCCESS","Image Base: 0x19999560000, Image Size: 0x2a000" "19:13:40,5965792","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,5966052","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,5966154","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmmbase.dll","SUCCESS","AllocationSize: 159 744, EndOfFile: 159 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5966305","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,5966526","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmmbase.dll","SUCCESS","AllocationSize: 159 744, EndOfFile: 159 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,5971581","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,6151795","R5Apex.exe","3708","Load Image","C:\Windows\System32\oleaut32.dll","SUCCESS","Image Base: 0x7ffdd0a20000, Image Size: 0xc5000" "19:13:40,6153648","R5Apex.exe","3708","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6154078","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\oleaut32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6154187","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\oleaut32.dll","SUCCESS","AllocationSize: 794 624, EndOfFile: 793 960, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,6154348","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\oleaut32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6154591","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\oleaut32.dll","SUCCESS","AllocationSize: 794 624, EndOfFile: 793 960, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,6179489","R5Apex.exe","3708","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS","" "19:13:40,6375264","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dxgi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6375713","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dxgi.dll","SUCCESS","AllocationSize: 704 512, EndOfFile: 702 504, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,6392821","R5Apex.exe","3708","ReadFile","C:\Windows\System32\dxgi.dll","SUCCESS","Offset: 0, Length: 702 504, Priority: Normal" "19:13:40,6394091","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dxgi.dll","SUCCESS","" "19:13:40,6455238","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dxgi.dll","SUCCESS","" "19:13:40,6456280","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 159 744, EndOfFile: 159 680, FileAttributes: A" "19:13:40,6457031","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6457316","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6457518","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6459176","R5Apex.exe","3708","Load Image","C:\Windows\System32\winmmbase.dll","SUCCESS","Image Base: 0x19999590000, Image Size: 0x2a000" "19:13:40,6460947","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6461245","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6461341","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmmbase.dll","SUCCESS","AllocationSize: 159 744, EndOfFile: 159 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,6461514","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winmmbase.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6461761","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winmmbase.dll","SUCCESS","AllocationSize: 159 744, EndOfFile: 159 680, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,6467352","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,6553213","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,6554724","R5Apex.exe","3708","QueryOpen","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:57, LastAccessTime: 2021. 02. 13. 20:18:25, LastWriteTime: 2017. 09. 29. 15:41:57, ChangeTime: 2020. 01. 09. 4:53:02, AllocationSize: 663 552, EndOfFile: 661 912, FileAttributes: A" "19:13:40,6555875","R5Apex.exe","3708","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6556462","R5Apex.exe","3708","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6556684","R5Apex.exe","3708","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6558223","R5Apex.exe","3708","Load Image","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","Image Base: 0x7ffdba6e0000, Image Size: 0xa6000" "19:13:40,6559994","R5Apex.exe","3708","CreateFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6560359","R5Apex.exe","3708","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6560459","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","AllocationSize: 663 552, EndOfFile: 661 912, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,6560613","R5Apex.exe","3708","CreateFileMapping","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6560863","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","AllocationSize: 663 552, EndOfFile: 661 912, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,6582310","R5Apex.exe","3708","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","" "19:13:40,6735249","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,6737006","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 159 744, EndOfFile: 159 680, FileAttributes: A" "19:13:40,6737882","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winmmbase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:25, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:25, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 159 744, EndOfFile: 159 680, FileAttributes: A" "19:13:40,6740743","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, AllocationSize: 327 680, EndOfFile: 289 568, FileAttributes: ANCI" "19:13:40,6741435","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6741708","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6742545","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6744239","R5Apex.exe","3708","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Image Base: 0x7ffdb32e0000, Image Size: 0x4b000" "19:13:40,6745515","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6746118","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6746342","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","AllocationSize: 327 680, EndOfFile: 289 568, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,6747003","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Offset: 0, Length: 289 568, Priority: Normal" "19:13:40,6764332","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","" "19:13:40,6764614","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","AllocationSize: 327 680, EndOfFile: 289 568, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,6764723","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Offset: 0, Length: 289 568, Priority: Normal" "19:13:40,6781408","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","" "19:13:40,6782479","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","" "19:13:40,6783152","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:29, AllocationSize: 458 752, EndOfFile: 423 936, FileAttributes: ANCI" "19:13:40,6783649","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6783884","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6784342","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6785503","R5Apex.exe","3708","Load Image","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Image Base: 0x7ffdb3260000, Image Size: 0x72000" "19:13:40,6786488","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6787052","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6787293","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","AllocationSize: 458 752, EndOfFile: 423 936, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,6787665","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Offset: 0, Length: 423 936, Priority: Normal" "19:13:40,6813407","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","" "19:13:40,6813791","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","AllocationSize: 458 752, EndOfFile: 423 936, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,6813916","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Offset: 0, Length: 423 936, Priority: Normal" "19:13:40,6838394","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","" "19:13:40,6840030","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","" "19:13:40,6954421","R5Apex.exe","3708","Load Image","C:\Windows\System32\setupapi.dll","SUCCESS","Image Base: 0x7ffdcff00000, Image Size: 0x44e000" "19:13:40,6956345","R5Apex.exe","3708","CreateFile","C:\Windows\System32\setupapi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,6956778","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\setupapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,6956887","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\setupapi.dll","SUCCESS","AllocationSize: 4 538 368, EndOfFile: 4 537 040, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,6957047","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\setupapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,6957413","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\setupapi.dll","SUCCESS","AllocationSize: 4 538 368, EndOfFile: 4 537 040, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,7095287","R5Apex.exe","3708","CloseFile","C:\Windows\System32\setupapi.dll","SUCCESS","" "19:13:40,7123210","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,7351407","R5Apex.exe","3708","CloseFile","C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.15_none_e47c14a8033886fc\comctl32.dll","SUCCESS","" "19:13:40,8163466","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\HID.DLL","NAME NOT FOUND","" "19:13:40,8164033","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\WININET.dll","NAME NOT FOUND","" "19:13:40,8164383","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\hid.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:49, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:49, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 36 864, EndOfFile: 34 816, FileAttributes: A" "19:13:40,8165114","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\wininet.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:49, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:49, ChangeTime: 2020. 01. 09. 4:47:22, AllocationSize: 3 334 144, EndOfFile: 3 334 144, FileAttributes: A" "19:13:40,8165227","R5Apex.exe","3708","CreateFile","C:\Windows\System32\hid.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8165714","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\hid.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,8165942","R5Apex.exe","3708","CreateFile","C:\Windows\System32\wininet.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8165951","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\hid.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,8166288","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\wininet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,8166484","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\wininet.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,8167465","R5Apex.exe","3708","Load Image","C:\Windows\System32\hid.dll","SUCCESS","Image Base: 0x7ffdcd0d0000, Image Size: 0xc000" "19:13:40,8167715","R5Apex.exe","3708","Load Image","C:\Windows\System32\wininet.dll","SUCCESS","Image Base: 0x7ffdc7f70000, Image Size: 0x334000" "19:13:40,8169329","R5Apex.exe","3708","CreateFile","C:\Windows\System32\hid.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8169351","R5Apex.exe","3708","CreateFile","C:\Windows\System32\wininet.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8169685","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\hid.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,8169704","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\wininet.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:40,8169791","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\hid.dll","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 816, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,8169800","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\wininet.dll","SUCCESS","AllocationSize: 3 334 144, EndOfFile: 3 334 144, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,8169973","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\wininet.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,8169977","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\hid.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,8170246","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\hid.dll","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 816, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,8170256","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\wininet.dll","SUCCESS","AllocationSize: 3 334 144, EndOfFile: 3 334 144, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:40,8171503","R5Apex.exe","3708","CloseFile","C:\Windows\System32\hid.dll","SUCCESS","" "19:13:40,8271849","R5Apex.exe","3708","CloseFile","C:\Windows\System32\wininet.dll","SUCCESS","" "19:13:40,8351563","R5Apex.exe","3708","CloseFile","C:\Windows\System32\hid.dll","SUCCESS","" "19:13:40,8871115","R5Apex.exe","3708","CloseFile","C:\Windows\System32\wininet.dll","SUCCESS","" "19:13:40,8874226","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8874659","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msvcrt.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8874800","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msvcrt.dll","SUCCESS","Information: Owner" "19:13:40,8874919","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvcrt.dll","SUCCESS","" "19:13:40,8876250","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8876571","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ucrtbase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8876689","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","Information: Owner" "19:13:40,8876795","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ucrtbase.dll","SUCCESS","" "19:13:40,8878280","R5Apex.exe","3708","CreateFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8878607","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\cfgmgr32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8878966","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","Information: Owner" "19:13:40,8879079","R5Apex.exe","3708","CloseFile","C:\Windows\System32\cfgmgr32.dll","SUCCESS","" "19:13:40,8880291","R5Apex.exe","3708","CreateFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8880599","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\rpcrt4.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8880711","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","Information: Owner" "19:13:40,8880817","R5Apex.exe","3708","CloseFile","C:\Windows\System32\rpcrt4.dll","SUCCESS","" "19:13:40,8882039","R5Apex.exe","3708","CreateFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8882263","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\bcryptprimitives.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8882372","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","Information: Owner" "19:13:40,8882475","R5Apex.exe","3708","CloseFile","C:\Windows\System32\bcryptprimitives.dll","SUCCESS","" "19:13:40,8883585","R5Apex.exe","3708","CreateFile","C:\Windows\System32\combase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8883883","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\combase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8883995","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\combase.dll","SUCCESS","Information: Owner" "19:13:40,8884098","R5Apex.exe","3708","CloseFile","C:\Windows\System32\combase.dll","SUCCESS","" "19:13:40,8885358","R5Apex.exe","3708","CreateFile","C:\Windows\System32\SHCore.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8885913","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\SHCore.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8886026","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\SHCore.dll","SUCCESS","Information: Owner" "19:13:40,8886128","R5Apex.exe","3708","CloseFile","C:\Windows\System32\SHCore.dll","SUCCESS","" "19:13:40,8887581","R5Apex.exe","3708","CreateFile","C:\Windows\System32\sechost.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8887883","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\sechost.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8887998","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\sechost.dll","SUCCESS","Information: Owner" "19:13:40,8888097","R5Apex.exe","3708","CloseFile","C:\Windows\System32\sechost.dll","SUCCESS","" "19:13:40,8889268","R5Apex.exe","3708","CreateFile","C:\Windows\System32\advapi32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8889557","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\advapi32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8889669","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\advapi32.dll","SUCCESS","Information: Owner" "19:13:40,8889768","R5Apex.exe","3708","CloseFile","C:\Windows\System32\advapi32.dll","SUCCESS","" "19:13:40,8891093","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8891305","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msvcp_win.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8891411","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","Information: Owner" "19:13:40,8891513","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvcp_win.dll","SUCCESS","" "19:13:40,8892912","R5Apex.exe","3708","CreateFile","C:\Windows\System32\win32u.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8893236","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\win32u.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8893348","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\win32u.dll","SUCCESS","Information: Owner" "19:13:40,8893691","R5Apex.exe","3708","CloseFile","C:\Windows\System32\win32u.dll","SUCCESS","" "19:13:40,8894749","R5Apex.exe","3708","CreateFile","C:\Windows\System32\user32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8895035","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\user32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8895147","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\user32.dll","SUCCESS","Information: Owner" "19:13:40,8895246","R5Apex.exe","3708","CloseFile","C:\Windows\System32\user32.dll","SUCCESS","" "19:13:40,8896658","R5Apex.exe","3708","CreateFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8896866","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\gdi32full.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8896969","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\gdi32full.dll","SUCCESS","Information: Owner" "19:13:40,8897071","R5Apex.exe","3708","CloseFile","C:\Windows\System32\gdi32full.dll","SUCCESS","" "19:13:40,8898518","R5Apex.exe","3708","CreateFile","C:\Windows\System32\gdi32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8898800","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\gdi32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8898909","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\gdi32.dll","SUCCESS","Information: Owner" "19:13:40,8899012","R5Apex.exe","3708","CloseFile","C:\Windows\System32\gdi32.dll","SUCCESS","" "19:13:40,8900401","R5Apex.exe","3708","CreateFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8900705","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\shlwapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8901032","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\shlwapi.dll","SUCCESS","Information: Owner" "19:13:40,8901164","R5Apex.exe","3708","CloseFile","C:\Windows\System32\shlwapi.dll","SUCCESS","" "19:13:40,8902450","R5Apex.exe","3708","CreateFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8902678","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\kernel.appcore.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8902784","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","Information: Owner" "19:13:40,8902883","R5Apex.exe","3708","CloseFile","C:\Windows\System32\kernel.appcore.dll","SUCCESS","" "19:13:40,8904073","R5Apex.exe","3708","CreateFile","C:\Windows\System32\powrprof.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8904384","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\powrprof.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8904493","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\powrprof.dll","SUCCESS","Information: Owner" "19:13:40,8904596","R5Apex.exe","3708","CloseFile","C:\Windows\System32\powrprof.dll","SUCCESS","" "19:13:40,8905693","R5Apex.exe","3708","CreateFile","C:\Windows\System32\profapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8905975","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\profapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8906087","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\profapi.dll","SUCCESS","Information: Owner" "19:13:40,8906183","R5Apex.exe","3708","CloseFile","C:\Windows\System32\profapi.dll","SUCCESS","" "19:13:40,8907287","R5Apex.exe","3708","CreateFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8907495","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\windows.storage.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8907707","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\windows.storage.dll","SUCCESS","Information: Owner" "19:13:40,8907813","R5Apex.exe","3708","CloseFile","C:\Windows\System32\windows.storage.dll","SUCCESS","" "19:13:40,8909775","R5Apex.exe","3708","CreateFile","C:\Windows\System32\shell32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8910067","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\shell32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8910176","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\shell32.dll","SUCCESS","Information: Owner" "19:13:40,8910279","R5Apex.exe","3708","CloseFile","C:\Windows\System32\shell32.dll","SUCCESS","" "19:13:40,8911815","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ole32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8912097","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ole32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8912207","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ole32.dll","SUCCESS","Information: Owner" "19:13:40,8912306","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ole32.dll","SUCCESS","" "19:13:40,8913666","R5Apex.exe","3708","CreateFile","C:\Windows\System32\imm32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8913945","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\imm32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8914054","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\imm32.dll","SUCCESS","Information: Owner" "19:13:40,8914153","R5Apex.exe","3708","CloseFile","C:\Windows\System32\imm32.dll","SUCCESS","" "19:13:40,8915330","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ws2_32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8915616","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ws2_32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8915725","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\ws2_32.dll","SUCCESS","Information: Owner" "19:13:40,8915821","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ws2_32.dll","SUCCESS","" "19:13:40,8916947","R5Apex.exe","3708","CreateFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8917229","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\bcrypt.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8917354","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\bcrypt.dll","SUCCESS","Information: Owner" "19:13:40,8917450","R5Apex.exe","3708","CloseFile","C:\Windows\System32\bcrypt.dll","SUCCESS","" "19:13:40,8919622","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8919840","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\winmmbase.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8919946","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\winmmbase.dll","SUCCESS","Information: Owner" "19:13:40,8920045","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmmbase.dll","SUCCESS","" "19:13:40,8921142","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winmm.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8921427","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\winmm.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8921540","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\winmm.dll","SUCCESS","Information: Owner" "19:13:40,8921639","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winmm.dll","SUCCESS","" "19:13:40,8922771","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msvfw32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8923057","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msvfw32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8923166","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msvfw32.dll","SUCCESS","Information: Owner" "19:13:40,8923265","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msvfw32.dll","SUCCESS","" "19:13:40,8924407","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msacm32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8924699","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msacm32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8924808","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msacm32.dll","SUCCESS","Information: Owner" "19:13:40,8924904","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msacm32.dll","SUCCESS","" "19:13:40,8926530","R5Apex.exe","3708","CreateFile","C:\Windows\System32\avifil32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8926841","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\avifil32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8926954","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\avifil32.dll","SUCCESS","Information: Owner" "19:13:40,8927053","R5Apex.exe","3708","CloseFile","C:\Windows\System32\avifil32.dll","SUCCESS","" "19:13:40,8928179","R5Apex.exe","3708","CreateFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8928458","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\IPHLPAPI.DLL","BUFFER OVERFLOW","Information: Owner" "19:13:40,8928567","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","Information: Owner" "19:13:40,8928666","R5Apex.exe","3708","CloseFile","C:\Windows\System32\IPHLPAPI.DLL","SUCCESS","" "19:13:40,8929741","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dxgi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8930023","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\dxgi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8930132","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\dxgi.dll","SUCCESS","Information: Owner" "19:13:40,8930228","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dxgi.dll","SUCCESS","" "19:13:40,8931344","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d11.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8931627","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\d3d11.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8931736","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\d3d11.dll","SUCCESS","Information: Owner" "19:13:40,8931835","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d11.dll","SUCCESS","" "19:13:40,8932993","R5Apex.exe","3708","CreateFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8933208","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\D3DCompiler_43.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8933310","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","Information: Owner" "19:13:40,8933410","R5Apex.exe","3708","CloseFile","C:\Windows\System32\D3DCompiler_43.dll","SUCCESS","" "19:13:40,8935007","R5Apex.exe","3708","CreateFile","C:\Windows\System32\avrt.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8935299","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\avrt.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8935408","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\avrt.dll","SUCCESS","Information: Owner" "19:13:40,8935507","R5Apex.exe","3708","CloseFile","C:\Windows\System32\avrt.dll","SUCCESS","" "19:13:40,8936425","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8936636","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8936733","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","Information: Owner" "19:13:40,8936826","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\mileswin64.dll","SUCCESS","" "19:13:40,8937698","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8937897","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8937990","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","Information: Owner" "19:13:40,8938083","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\binkawin64.dll","SUCCESS","" "19:13:40,8939122","R5Apex.exe","3708","CreateFile","C:\Windows\System32\Wldap32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8939401","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\Wldap32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8939507","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\Wldap32.dll","SUCCESS","Information: Owner" "19:13:40,8939606","R5Apex.exe","3708","CloseFile","C:\Windows\System32\Wldap32.dll","SUCCESS","" "19:13:40,8940671","R5Apex.exe","3708","CreateFile","C:\Windows\System32\normaliz.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8941210","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\normaliz.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8941325","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\normaliz.dll","SUCCESS","Information: Owner" "19:13:40,8941425","R5Apex.exe","3708","CloseFile","C:\Windows\System32\normaliz.dll","SUCCESS","" "19:13:40,8942714","R5Apex.exe","3708","CreateFile","C:\Windows\System32\msasn1.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8942996","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msasn1.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8943109","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\msasn1.dll","SUCCESS","Information: Owner" "19:13:40,8943208","R5Apex.exe","3708","CloseFile","C:\Windows\System32\msasn1.dll","SUCCESS","" "19:13:40,8944254","R5Apex.exe","3708","CreateFile","C:\Windows\System32\crypt32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8944533","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\crypt32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8944645","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\crypt32.dll","SUCCESS","Information: Owner" "19:13:40,8944738","R5Apex.exe","3708","CloseFile","C:\Windows\System32\crypt32.dll","SUCCESS","" "19:13:40,8945799","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8946002","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8946095","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","Information: Owner" "19:13:40,8946188","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steam_api64.dll","SUCCESS","" "19:13:40,8947111","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8947313","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8947403","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","Information: Owner" "19:13:40,8947496","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\bink2w64.dll","SUCCESS","" "19:13:40,8948590","R5Apex.exe","3708","CreateFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8949113","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\oleaut32.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8949247","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\oleaut32.dll","SUCCESS","Information: Owner" "19:13:40,8949347","R5Apex.exe","3708","CloseFile","C:\Windows\System32\oleaut32.dll","SUCCESS","" "19:13:40,8950752","R5Apex.exe","3708","CreateFile","C:\Windows\System32\setupapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8951034","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\setupapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8951143","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\setupapi.dll","SUCCESS","Information: Owner" "19:13:40,8951242","R5Apex.exe","3708","CloseFile","C:\Windows\System32\setupapi.dll","SUCCESS","" "19:13:40,8952423","R5Apex.exe","3708","CreateFile","C:\Windows\System32\hid.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8952708","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\hid.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8952817","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\hid.dll","SUCCESS","Information: Owner" "19:13:40,8952916","R5Apex.exe","3708","CloseFile","C:\Windows\System32\hid.dll","SUCCESS","" "19:13:40,8953949","R5Apex.exe","3708","CreateFile","C:\Windows\System32\wininet.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8954225","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\wininet.dll","BUFFER OVERFLOW","Information: Owner" "19:13:40,8954334","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\wininet.dll","SUCCESS","Information: Owner" "19:13:40,8954430","R5Apex.exe","3708","CloseFile","C:\Windows\System32\wininet.dll","SUCCESS","" "19:13:40,8957721","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:40,8957942","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:40,8958122","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:40,8958324","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:40,8958776","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","REPARSE","Desired Access: Read" "19:13:40,8958901","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS","Desired Access: Read" "19:13:40,8959087","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default)","SUCCESS","Type: REG_SZ, Length: 18, Data: 0006020E" "19:13:40,8961932","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","REPARSE","Desired Access: Query Value" "19:13:40,8962057","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","Desired Access: Query Value" "19:13:40,8962198","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:40,8962349","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","REPARSE","Desired Access: Query Value" "19:13:40,8962708","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","Desired Access: Query Value" "19:13:40,8962853","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","NAME NOT FOUND","Length: 20" "19:13:40,8962978","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled","NAME NOT FOUND","Length: 20" "19:13:40,8963103","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy","SUCCESS","" "19:13:40,8963417","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Lsa","SUCCESS","" "19:13:40,8963526","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","REPARSE","Desired Access: Query Value" "19:13:40,8963638","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration","NAME NOT FOUND","Desired Access: Query Value" "19:13:40,8964819","R5Apex.exe","3708","RegOpenKey","HKLM","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:40,8964982","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:40,8965088","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLE","SUCCESS","Desired Access: Read" "19:13:40,8965232","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorUseSystemHeap","NAME NOT FOUND","Length: 144" "19:13:40,8965409","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:40,8965499","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:40,8965595","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLE","SUCCESS","Desired Access: Read" "19:13:40,8965710","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\PageAllocatorSystemHeapIsPrivate","NAME NOT FOUND","Length: 144" "19:13:40,8965832","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:40,8965915","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:40,8966009","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLE","SUCCESS","Desired Access: Read" "19:13:40,8966134","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Ole\AggressiveMTATesting","NAME NOT FOUND","Length: 144" "19:13:40,8966255","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Ole","SUCCESS","" "19:13:40,8966836","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:40,8966942","R5Apex.exe","3708","RegOpenKey","HKLM","SUCCESS","Desired Access: Read" "19:13:40,8967060","R5Apex.exe","3708","RegSetInfoKey","HKLM","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:40,8967224","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8967323","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:40,8967490","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8967599","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:40,8967747","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8967843","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Ole","SUCCESS","Desired Access: Read" "19:13:40,8968254","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:40,8968420","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:40,8968517","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Classes\Local Settings","REPARSE","Desired Access: Read" "19:13:40,8968629","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Classes\Local Settings","SUCCESS","Desired Access: Read" "19:13:40,8968767","R5Apex.exe","3708","RegSetInfoKey","HKCU\Software\Classes\Local Settings","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:40,8969091","R5Apex.exe","3708","RegCloseKey","HKCU","SUCCESS","" "19:13:40,8969216","R5Apex.exe","3708","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8969322","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:40,8969456","R5Apex.exe","3708","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8969553","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole\FeatureDevelopmentProperties","NAME NOT FOUND","Desired Access: Read" "19:13:40,8969883","R5Apex.exe","3708","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8969992","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft\Ole","NAME NOT FOUND","Desired Access: Read" "19:13:40,8970098","R5Apex.exe","3708","RegQueryKey","HKCU\Software\Classes\Local Settings","SUCCESS","Query: HandleTags, HandleTags: 0x100" "19:13:40,8970194","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Classes\Local Settings\Software\Microsoft","SUCCESS","Desired Access: Read" "19:13:40,8970714","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:40,8970816","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read" "19:13:40,8971268","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be","NAME NOT FOUND","Length: 524" "19:13:40,8971833","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f0558438-f56a-5987-47da-040ca75aef05","NAME NOT FOUND","Length: 524" "19:13:40,8973565","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:40,8978754","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\imm32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:44:59, AllocationSize: 176 128, EndOfFile: 173 640, FileAttributes: A" "19:13:40,8981496","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\imm32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 20:08:57, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:44:59, AllocationSize: 176 128, EndOfFile: 173 640, FileAttributes: A" "19:13:40,8981808","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument\","REPARSE","Desired Access: Read" "19:13:40,8981987","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Error Message Instrument","NAME NOT FOUND","Desired Access: Read" "19:13:40,8982356","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f25bcd2e-2690-55dc-3bc4-07b65b1b41c9","NAME NOT FOUND","Length: 524" "19:13:40,8982831","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Display","NAME NOT FOUND","Desired Access: Read" "19:13:40,8983013","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:40,8983241","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Display","NAME NOT FOUND","Desired Access: Read" "19:13:40,8983539","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","Desired Access: Read" "19:13:40,8983735","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20" "19:13:40,8983899","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","" "19:13:40,8984280","R5Apex.exe","3708","RegOpenKey","HKCU\Control Panel\Desktop","SUCCESS","Desired Access: Read" "19:13:40,8984434","R5Apex.exe","3708","RegQueryValue","HKCU\Control Panel\Desktop\EnablePerProcessSystemDPI","NAME NOT FOUND","Length: 520" "19:13:40,8984617","R5Apex.exe","3708","RegCloseKey","HKCU\Control Panel\Desktop","SUCCESS","" "19:13:40,8985201","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32","SUCCESS","Desired Access: Read" "19:13:40,8985467","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\R5Apex","NAME NOT FOUND","Length: 172" "19:13:40,8985663","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32","SUCCESS","" "19:13:40,8985804","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility","NAME NOT FOUND","Desired Access: Read" "19:13:40,8990483","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:40,8990721","R5Apex.exe","3708","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration","NAME NOT FOUND","Desired Access: Read" "19:13:40,8990910","R5Apex.exe","3708","RegCloseKey","HKCU","SUCCESS","" "19:13:40,8991051","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:40,8991247","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:40,8991407","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "19:13:40,8991567","R5Apex.exe","3708","RegOpenKey","HKCU\Control Panel\Desktop\LanguageConfiguration","SUCCESS","Desired Access: Read" "19:13:40,8991734","R5Apex.exe","3708","RegEnumValue","HKCU\Control Panel\Desktop\LanguageConfiguration","NO MORE ENTRIES","Index: 0, Length: 512" "19:13:40,8991869","R5Apex.exe","3708","RegCloseKey","HKCU\Control Panel\Desktop\LanguageConfiguration","SUCCESS","" "19:13:40,8991984","R5Apex.exe","3708","RegCloseKey","HKCU","SUCCESS","" "19:13:40,8992138","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:40,8992308","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:40,8992462","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Policies\Microsoft\Control Panel\Desktop","NAME NOT FOUND","Desired Access: Read" "19:13:40,8992622","R5Apex.exe","3708","RegOpenKey","HKCU\Control Panel\Desktop","SUCCESS","Desired Access: Read" "19:13:40,8992760","R5Apex.exe","3708","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","BUFFER OVERFLOW","Length: 12" "19:13:40,8992940","R5Apex.exe","3708","RegQueryValue","HKCU\Control Panel\Desktop\PreferredUILanguages","SUCCESS","Type: REG_MULTI_SZ, Length: 12, Data: en-US" "19:13:40,8993126","R5Apex.exe","3708","RegCloseKey","HKCU\Control Panel\Desktop","SUCCESS","" "19:13:40,8993238","R5Apex.exe","3708","RegCloseKey","HKCU","SUCCESS","" "19:13:40,8993360","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\MUI\Settings","NAME NOT FOUND","Desired Access: Read" "19:13:40,8993530","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:40,8993681","R5Apex.exe","3708","RegOpenKey","HKCU\Control Panel\Desktop\MuiCached","SUCCESS","Desired Access: Read" "19:13:40,8993825","R5Apex.exe","3708","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","BUFFER OVERFLOW","Length: 12" "19:13:40,8993973","R5Apex.exe","3708","RegQueryValue","HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages","SUCCESS","Type: REG_MULTI_SZ, Length: 14, Data: en-US" "19:13:40,8994136","R5Apex.exe","3708","RegCloseKey","HKCU\Control Panel\Desktop\MuiCached","SUCCESS","" "19:13:40,8994249","R5Apex.exe","3708","RegCloseKey","HKCU","SUCCESS","" "19:13:40,8995807","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","Desired Access: Read" "19:13:40,8995958","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs","BUFFER TOO SMALL","Length: 0" "19:13:40,8996080","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:40,8996192","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows","SUCCESS","" "19:13:40,8997337","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,8997703","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:40,8997815","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","AllocationSize: 1 835 008, EndOfFile: 1 809 640, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,8997972","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,8998200","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","AllocationSize: 1 835 008, EndOfFile: 1 809 640, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,9052903","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","" "19:13:40,9885755","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","CreationTime: 2021. 04. 13. 19:00:26, LastAccessTime: 2021. 04. 13. 19:00:26, LastWriteTime: 2021. 04. 12. 22:03:30, ChangeTime: 2021. 04. 13. 19:00:28, AllocationSize: 1 835 008, EndOfFile: 1 809 640, FileAttributes: ANCI" "19:13:40,9886316","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:40,9886630","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,9887179","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:40,9888404","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,9889911","R5Apex.exe","3708","Load Image","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","Image Base: 0x7ffdaab20000, Image Size: 0x1ea000" "19:13:40,9891502","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:40,9891759","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:40,9891845","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","AllocationSize: 1 835 008, EndOfFile: 1 809 640, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,9891983","R5Apex.exe","3708","CreateFileMapping","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:40,9892204","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","AllocationSize: 1 835 008, EndOfFile: 1 809 640, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:40,9946269","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","" "19:13:41,0759864","R5Apex.exe","3708","Load Image","C:\Windows\System32\psapi.dll","SUCCESS","Image Base: 0x7ffdd0530000, Image Size: 0x8000" "19:13:41,0761927","R5Apex.exe","3708","CreateFile","C:\Windows\System32\psapi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,0762366","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\psapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,0762485","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\psapi.dll","SUCCESS","AllocationSize: 20 480, EndOfFile: 18 712, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,0762658","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\psapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,0762914","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\psapi.dll","SUCCESS","AllocationSize: 20 480, EndOfFile: 18 712, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,0763777","R5Apex.exe","3708","CloseFile","C:\Windows\System32\psapi.dll","SUCCESS","" "19:13:41,0931508","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","" "19:13:41,0932663","R5Apex.exe","3708","CreateFile","C:\Windows\System32\psapi.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,0933025","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\psapi.dll","BUFFER OVERFLOW","Information: Owner" "19:13:41,0933153","R5Apex.exe","3708","QuerySecurityFile","C:\Windows\System32\psapi.dll","SUCCESS","Information: Owner" "19:13:41,0933272","R5Apex.exe","3708","CloseFile","C:\Windows\System32\psapi.dll","SUCCESS","" "19:13:41,0934401","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","Desired Access: Read Control, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,0934619","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","BUFFER OVERFLOW","Information: Owner" "19:13:41,0934718","R5Apex.exe","3708","QuerySecurityFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","Information: Owner" "19:13:41,0934821","R5Apex.exe","3708","CloseFile","D:\Program Files (x86)\Steam\GameOverlayRenderer64.dll","SUCCESS","" "19:13:41,0939978","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,0942926","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:41,0943147","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,0943272","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:41,0943445","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\pid","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4576" "19:13:41,0943676","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:41,0946486","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,0946611","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Read" "19:13:41,0946746","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\SteamClientDll","SUCCESS","Type: REG_SZ, Length: 90, Data: D:\Program Files (x86)\Steam\steamclient.dll" "19:13:41,0946925","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:41,0947586","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Overwritten" "19:13:41,0948785","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 0, Length: 105, Priority: Normal" "19:13:41,0949453","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 105, Length: 74" "19:13:41,1046793","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 179, Length: 55" "19:13:41,1073420","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 234, Length: 105" "19:13:41,1130484","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1130958","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 339, Length: 83" "19:13:41,1137004","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1137800","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1138268","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,1138419","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1138643","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1139079","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1139971","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1140776","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1141533","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1142226","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1142559","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,1142668","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1142867","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1143268","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1144121","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1144811","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1145141","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,1145247","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1145426","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1145808","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1167015","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 422, Length: 144" "19:13:41,1170029","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\0e0fe12b-e926-44d2-8cf1-8a62a6d44036","NAME NOT FOUND","Length: 524" "19:13:41,1186136","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1187108","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1187878","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1188256","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,1188391","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1188606","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1189029","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1189915","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1190797","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1191634","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1192355","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1193128","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,1193253","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1193455","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1193866","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1194748","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1195434","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1195761","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ" "19:13:41,1195877","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1196069","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1196467","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1197590","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 566, Length: 144" "19:13:41,1199075","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\steamcompat.inf","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a" "19:13:41,1199421","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 710, Length: 74" "19:13:41,1201236","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 784, Length: 88" "19:13:41,1201567","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 872, Length: 87" "19:13:41,1201868","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 959, Length: 90" "19:13:41,1202166","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 049, Length: 92" "19:13:41,1202461","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 141, Length: 89" "19:13:41,1202795","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 230, Length: 89" "19:13:41,1203096","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 319, Length: 88" "19:13:41,1203388","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 407, Length: 90" "19:13:41,1203674","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 497, Length: 90" "19:13:41,1203962","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 587, Length: 88" "19:13:41,1204251","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 675, Length: 88" "19:13:41,1204540","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 763, Length: 89" "19:13:41,1204828","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 852, Length: 98" "19:13:41,1205143","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 1 950, Length: 97" "19:13:41,1205431","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 047, Length: 90" "19:13:41,1205720","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 137, Length: 89" "19:13:41,1206002","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 226, Length: 89" "19:13:41,1206288","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 315, Length: 87" "19:13:41,1206576","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 402, Length: 91" "19:13:41,1206862","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 493, Length: 91" "19:13:41,1207147","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 584, Length: 88" "19:13:41,1207462","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 672, Length: 88" "19:13:41,1207753","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 760, Length: 96" "19:13:41,1208055","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 856, Length: 90" "19:13:41,1208340","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 2 946, Length: 89" "19:13:41,1208623","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 035, Length: 87" "19:13:41,1208911","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 122, Length: 87" "19:13:41,1209197","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 209, Length: 88" "19:13:41,1209482","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 297, Length: 90" "19:13:41,1209800","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 387, Length: 89" "19:13:41,1210127","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 476, Length: 88" "19:13:41,1210444","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 564, Length: 90" "19:13:41,1210762","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 654, Length: 92" "19:13:41,1211076","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 746, Length: 92" "19:13:41,1211461","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 838, Length: 90" "19:13:41,1211785","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 3 928, Length: 87" "19:13:41,1212904","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 015, Length: 87" "19:13:41,1213498","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 102, Length: 96" "19:13:41,1213953","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 198, Length: 89" "19:13:41,1214299","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 287, Length: 89" "19:13:41,1214623","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 376, Length: 89" "19:13:41,1214944","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 465, Length: 86" "19:13:41,1215258","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 551, Length: 88" "19:13:41,1215598","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 639, Length: 86" "19:13:41,1215913","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 725, Length: 91" "19:13:41,1216227","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 816, Length: 93" "19:13:41,1216535","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 909, Length: 90" "19:13:41,1217083","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 4 999, Length: 90" "19:13:41,1217555","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 089, Length: 90" "19:13:41,1218007","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 179, Length: 90" "19:13:41,1218366","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 269, Length: 85" "19:13:41,1218681","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 354, Length: 89" "19:13:41,1218988","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 443, Length: 103" "19:13:41,1220034","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 546, Length: 87" "19:13:41,1220429","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 633, Length: 61" "19:13:41,1221227","R5Apex.exe","3708","CreateFile","C:\Playkey\CloudServerService\CloudServer\","PATH NOT FOUND","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a" "19:13:41,1224460","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1226269","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1228213","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1231846","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108","NAME NOT FOUND","Length: 524" "19:13:41,1232565","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033","NAME NOT FOUND","Length: 524" "19:13:41,1233017","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\a40b455c-253c-4311-ac6d-6e667edccefc","NAME NOT FOUND","Length: 524" "19:13:41,1233418","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:41,1233845","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:41,1235002","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1237677","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\30336ed4-e327-447c-9de0-51b652c86108","NAME NOT FOUND","Length: 524" "19:13:41,1238178","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\b87cf16b-0bf8-4492-a510-d5f59626b033","NAME NOT FOUND","Length: 524" "19:13:41,1238585","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\32980f26-c8f5-5767-6b26-635b3fa83c61","NAME NOT FOUND","Length: 524" "19:13:41,1238957","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\703fcc13-b66f-5868-ddd9-e2db7f381ffb","NAME NOT FOUND","Length: 524" "19:13:41,1239618","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,1239749","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\OLE\Tracing","NAME NOT FOUND","Desired Access: Read" "19:13:41,1240131","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\1aff6089-e863-4d36-bdfd-3581f07440be","NAME NOT FOUND","Length: 524" "19:13:41,1240509","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f0558438-f56a-5987-47da-040ca75aef05","NAME NOT FOUND","Length: 524" "19:13:41,1241584","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\oleaut32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 794 624, EndOfFile: 793 960, FileAttributes: A" "19:13:41,1242629","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\d0f1a5c6-fc43-48ae-99bf-efb1c38be9d1","NAME NOT FOUND","Length: 524" "19:13:41,1243344","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\f3a71a4b-6118-4257-8ccb-39a33ba059d4","NAME NOT FOUND","Length: 524" "19:13:41,1244871","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1245035","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1245195","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:41,1245365","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:41,1246693","R5Apex.exe","3708","RegOpenKey","HKCU","SUCCESS","Desired Access: Read" "19:13:41,1247097","R5Apex.exe","3708","RegCloseKey","HKCU","SUCCESS","" "19:13:41,1247976","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1249111","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1250028","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1250753","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1251186","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1251331","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1251536","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1251966","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1252841","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1253617","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1254368","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1255035","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1255359","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1255468","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1255651","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1256036","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1256873","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1257543","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1257877","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1257982","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1258159","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1258534","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1259666","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 694, Length: 144" "19:13:41,1261215","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\03bbe5b8-c788-4d0b-b47e-5b5731398a89","NAME NOT FOUND","Length: 524" "19:13:41,1262392","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1263101","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1263428","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1263544","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1263723","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1264115","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1264945","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1265686","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1266414","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1267069","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1267380","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1267486","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1267659","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1268040","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1268855","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1269513","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1269817","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1269920","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1270093","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1270459","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1271479","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 838, Length: 144" "19:13:41,1272842","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\CMF\Config","REPARSE","Desired Access: Read" "19:13:41,1272993","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","Desired Access: Read" "19:13:41,1273159","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\CMF\Config\SYSTEM","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,1273326","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\CMF\Config","SUCCESS","" "19:13:41,1274096","R5Apex.exe","3708","CreateFile","C:\Windows\System32\en-US\msvfw32.dll.mui","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1274356","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\en-US\msvfw32.dll.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1274461","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\en-US\msvfw32.dll.mui","SUCCESS","AllocationSize: 8 192, EndOfFile: 7 168, NumberOfLinks: 4, DeletePending: False, Directory: False" "19:13:41,1274635","R5Apex.exe","3708","CreateFileMapping","C:\Windows\SysWOW64\en-US\msvfw32.dll.mui","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1274994","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,1275116","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\VFW","NAME NOT FOUND","Desired Access: Query Value" "19:13:41,1276838","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\86cc27ea-6f87-47f7-8b43-3473527d4a87","NAME NOT FOUND","Length: 524" "19:13:41,1278907","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1279051","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1279192","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:41,1279369","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:41,1280972","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1281097","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1281229","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:41,1281376","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:41,1282172","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,1282284","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\LDAP","REPARSE","Desired Access: Read" "19:13:41,1282387","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\LDAP","SUCCESS","Desired Access: Read" "19:13:41,1282563","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\ldap\LdapClientIntegrity","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,1282711","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\ldap","SUCCESS","" "19:13:41,1282807","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,1282903","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\LDAP","REPARSE","Desired Access: Read" "19:13:41,1282996","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\LDAP","SUCCESS","Desired Access: Read" "19:13:41,1283108","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\ldap\UseOldHostResolutionOrder","NAME NOT FOUND","Length: 144" "19:13:41,1283230","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\ldap","SUCCESS","" "19:13:41,1283314","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,1283403","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\LDAP","REPARSE","Desired Access: Read" "19:13:41,1283493","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\LDAP","SUCCESS","Desired Access: Read" "19:13:41,1283602","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\ldap\UseHostnameAsAlias","NAME NOT FOUND","Length: 144" "19:13:41,1283718","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\ldap","SUCCESS","" "19:13:41,1284757","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1286681","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1287589","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1288330","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1288686","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1288811","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1289000","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1289401","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1290248","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1291001","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1291736","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1292400","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1292714","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1292833","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1293016","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1293391","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1294295","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1295036","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1295347","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1295456","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1295633","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1296005","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1297082","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 5 982, Length: 144" "19:13:41,1298449","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1299302","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1299969","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1300280","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1300386","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1300565","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1300937","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1301752","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1302483","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1303211","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1303866","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1304167","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1304273","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1304449","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1304818","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1305623","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1306355","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1306656","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1306762","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1306938","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1307301","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1308462","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 126, Length: 144" "19:13:41,1310001","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1310838","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1311493","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1311804","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1311910","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1312089","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1312458","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1313279","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1314068","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1314780","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1315431","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1315733","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1315838","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1316015","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1316409","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1317227","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1317891","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1318196","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1318302","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1318478","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1318840","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1319860","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 270, Length: 144" "19:13:41,1321143","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1321977","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1322635","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1322952","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1323058","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1323238","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1323622","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1324421","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1325143","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1325855","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1326503","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1326807","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1326913","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1327090","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1327455","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1328273","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1328927","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1329229","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1329331","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1329505","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1329867","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1330887","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 414, Length: 144" "19:13:41,1332417","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1333283","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1333950","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1334261","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1334376","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1334562","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1334944","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1335762","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1336490","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1337215","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1337885","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1338193","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1338305","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1338491","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1338867","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1339685","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1340345","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1340650","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1340759","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1340942","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1341311","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1342347","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 558, Length: 144" "19:13:41,1343668","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1345499","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Control\Session Manager","REPARSE","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1345689","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,1345855","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\Session Manager\ResourcePolicies","NAME NOT FOUND","Length: 24" "19:13:41,1346045","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS","" "19:13:41,1347995","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1349127","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ole32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:41, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:41, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 1 339 392, EndOfFile: 1 336 344, FileAttributes: A" "19:13:41,1349964","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,1350147","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Microsoft\OLEAUT","NAME NOT FOUND","Desired Access: Query Value" "19:13:41,1351330","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\KernelBase.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:11:01, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:00, AllocationSize: 2 514 944, EndOfFile: 2 514 944, FileAttributes: A" "19:13:41,1356824","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1357674","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1358418","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1359089","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1359220","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1359624","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1360067","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1360962","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1361741","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1362472","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1363146","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1363466","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1363572","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1363742","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1364111","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1365195","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1366167","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1366491","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1366594","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1366757","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1367126","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1367793","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 702, Length: 144" "19:13:41,1566490","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 6164" "19:13:41,1571413","R5Apex.exe","3708","Thread Exit","","SUCCESS","Thread ID: 5680, User Time: 0.0000000, Kernel Time: 0.0000000" "19:13:41,1581699","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1582667","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1583479","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1583960","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1584107","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1584329","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1584839","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1585859","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1586869","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1587966","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1588091","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\nvapi64.dll","NAME NOT FOUND","" "19:13:41,1589027","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1589428","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1589557","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1589765","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1590262","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1591247","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1592090","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1592443","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1592552","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1592729","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1593335","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1594342","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 846, Length: 144" "19:13:41,1596067","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\nvapi64.dll","SUCCESS","CreationTime: 2021. 04. 08. 22:17:02, LastAccessTime: 2021. 04. 08. 22:17:02, LastWriteTime: 2021. 03. 26. 11:06:28, ChangeTime: 2021. 04. 08. 22:17:57, AllocationSize: 7 208 960, EndOfFile: 7 207 552, FileAttributes: ANCI" "19:13:41,1596228","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1597116","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1597639","R5Apex.exe","3708","CreateFile","C:\Windows\System32\nvapi64.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1597886","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1597985","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nvapi64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1598229","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nvapi64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1598239","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1598357","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1598534","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1599069","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1599923","R5Apex.exe","3708","Load Image","C:\Windows\System32\nvapi64.dll","SUCCESS","Image Base: 0x7ffdbe2f0000, Image Size: 0x707000" "19:13:41,1599958","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1600833","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1601610","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1602312","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1602645","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1602755","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1602941","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1603390","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1604432","R5Apex.exe","3708","CreateFile","C:\Windows\System32\nvapi64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1604448","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1604730","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nvapi64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1604833","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nvapi64.dll","SUCCESS","AllocationSize: 7 208 960, EndOfFile: 7 207 552, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:41,1605025","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nvapi64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1605186","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1605356","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nvapi64.dll","SUCCESS","AllocationSize: 7 208 960, EndOfFile: 7 207 552, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:41,1605519","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1605615","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1605782","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1606250","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1606991","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 6 990, Length: 144" "19:13:41,1608775","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1609721","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1610494","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1610869","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1610997","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1611196","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1611664","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1612598","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1613428","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1614233","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1615927","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1616331","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1616453","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1616867","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1617370","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1618326","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1619038","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1619381","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1619490","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1619666","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1620151","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1620917","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 134, Length: 144" "19:13:41,1624760","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1625876","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1626694","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1627088","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1627216","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1627415","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1627977","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1629032","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1629866","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1630683","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1631395","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1631755","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1631867","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1632047","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1632787","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1634006","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1634750","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1635093","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1635203","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1635382","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1635809","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1636562","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 278, Length: 144" "19:13:41,1637592","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1638413","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1639131","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1639754","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1639869","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1640042","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1640716","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1641591","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1642396","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1643189","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1643888","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1644221","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1644327","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1644497","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1644965","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1645857","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1646813","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1647175","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1647281","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1647695","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1648157","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1648869","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 422, Length: 144" "19:13:41,1649943","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1650790","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1651874","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1652281","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1652416","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1652650","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1653154","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1654218","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1655158","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1656063","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1656829","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1657188","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1657301","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1657474","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1657984","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1658923","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1659722","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1660068","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1660174","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1660360","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1660771","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1661502","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 566, Length: 144" "19:13:41,1662503","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1663260","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1663924","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1664235","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1664334","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1664495","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1664892","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1665768","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1666499","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1667211","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1667849","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1668164","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1668260","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1668420","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1669103","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1669969","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1670627","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1670925","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1671021","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1671178","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1671557","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1672182","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 710, Length: 144" "19:13:41,1673363","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1674081","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1674723","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1675027","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1675123","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1675277","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1675698","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1676499","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1677221","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1678029","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1678677","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1678972","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1679065","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1679222","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1679610","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1680476","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1681124","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1681422","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1681519","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1681669","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1682038","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1682779","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 854, Length: 144" "19:13:41,1683854","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,1684572","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,1685213","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1685515","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1685611","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1685765","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1686192","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,1686997","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,1687712","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,1688443","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,1689088","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1689386","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1689479","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1689636","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1690018","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,1690813","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,1691458","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1691750","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,1691843","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,1691997","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,1692372","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,1693244","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 7 998, Length: 144" "19:13:41,1699473","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1699739","R5Apex.exe","3708","QueryInformationVolume","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","VolumeCreationTime: 2020. 01. 09. 5:05:42, VolumeSerialNumber: 22AE-2966, SupportsObjects: True, VolumeLabel: HDD" "19:13:41,1699845","R5Apex.exe","3708","QueryAllInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","BUFFER OVERFLOW","CreationTime: 2021. 04. 11. 18:48:56, LastAccessTime: 2021. 04. 11. 18:48:56, LastWriteTime: 2021. 04. 11. 18:48:56, ChangeTime: 2021. 04. 12. 10:14:30, FileAttributes: ANCI, AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False, IndexNumber: 0x400000000102e, EaSize: 0, Access: Generic Read, Position: 0, Mode: Synchronous IO Non-Alert, AlignmentRequirement: Long" "19:13:41,1700317","R5Apex.exe","3708","CreateFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,1700599","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:41,1777618","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 0, Length: 33 708 280, Priority: Normal" "19:13:41,1872881","R5Apex.exe","3708","CloseFile","C:\Windows\System32\nvapi64.dll","SUCCESS","" "19:13:41,4306080","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,4306270","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:41,4306670","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Read" "19:13:41,4306895","R5Apex.exe","3708","RegSetInfoKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:41,4306998","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\pid","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4576" "19:13:41,4307219","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:41,4307588","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,4307665","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:41,4307783","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Read" "19:13:41,4307899","R5Apex.exe","3708","RegSetInfoKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:41,4307992","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\SteamClientDll","SUCCESS","Type: REG_SZ, Length: 90, Data: D:\Program Files (x86)\Steam\steamclient.dll" "19:13:41,4308187","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:41,4308412","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,4308486","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:41,4308601","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Read" "19:13:41,4308710","R5Apex.exe","3708","RegSetInfoKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:41,4308794","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\SteamClientDll64","SUCCESS","Type: REG_SZ, Length: 94, Data: D:\Program Files (x86)\Steam\steamclient64.dll" "19:13:41,4308922","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:41,4309009","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,4309079","R5Apex.exe","3708","RegQueryKey","HKCU","SUCCESS","Query: Name" "19:13:41,4309207","R5Apex.exe","3708","RegOpenKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","Desired Access: Read" "19:13:41,4309313","R5Apex.exe","3708","RegSetInfoKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0" "19:13:41,4309390","R5Apex.exe","3708","RegQueryValue","HKCU\Software\Valve\Steam\ActiveProcess\pid","SUCCESS","Type: REG_DWORD, Length: 4, Data: 4576" "19:13:41,4309509","R5Apex.exe","3708","RegCloseKey","HKCU\Software\Valve\Steam\ActiveProcess","SUCCESS","" "19:13:41,5816099","R5Apex.exe","3708","CreateFile","C:\Windows\System32\nvapi64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,5816465","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nvapi64.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,5816593","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nvapi64.dll","SUCCESS","AllocationSize: 7 208 960, EndOfFile: 7 207 552, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:41,5816769","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nvapi64.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,5817039","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nvapi64.dll","SUCCESS","AllocationSize: 7 208 960, EndOfFile: 7 207 552, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:41,6244388","R5Apex.exe","3708","CloseFile","C:\Windows\System32\nvapi64.dll","SUCCESS","" "19:13:41,6246197","R5Apex.exe","3708","CreateFile","C:\Windows\System32\nvapi64.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6246502","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nvapi64.dll","SUCCESS","AllocationSize: 7 208 960, EndOfFile: 7 207 552, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:13:41,6420464","R5Apex.exe","3708","ReadFile","C:\Windows\System32\nvapi64.dll","SUCCESS","Offset: 0, Length: 7 207 552, Priority: Normal" "19:13:41,6441347","R5Apex.exe","3708","CloseFile","C:\Windows\System32\nvapi64.dll","SUCCESS","" "19:13:41,6611631","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,6612554","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,6613282","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6613757","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,6613898","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6614094","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,6614620","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,6615467","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,6616252","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,6616996","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,6617660","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6617978","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,6618080","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6618244","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,6618664","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,6619495","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,6620162","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6620473","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,6620569","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6620733","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,6621095","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,6621955","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 8 142, Length: 144" "19:13:41,6622914","R5Apex.exe","3708","QueryOpen","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\dnsapi.dll","NAME NOT FOUND","" "19:13:41,6623652","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dnsapi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:41:20, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:19, AllocationSize: 741 376, EndOfFile: 738 808, FileAttributes: A" "19:13:41,6624341","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dnsapi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6624668","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dnsapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,6624861","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dnsapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,6626599","R5Apex.exe","3708","Load Image","C:\Windows\System32\dnsapi.dll","SUCCESS","Image Base: 0x7ffdcd8c0000, Image Size: 0xb6000" "19:13:41,6628604","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dnsapi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6628998","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dnsapi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,6629107","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dnsapi.dll","SUCCESS","AllocationSize: 741 376, EndOfFile: 738 808, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6629267","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dnsapi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,6629518","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dnsapi.dll","SUCCESS","AllocationSize: 741 376, EndOfFile: 738 808, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6651959","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dnsapi.dll","SUCCESS","" "19:13:41,6990518","R5Apex.exe","3708","Load Image","C:\Windows\System32\nsi.dll","SUCCESS","Image Base: 0x7ffdd0960000, Image Size: 0x8000" "19:13:41,6992443","R5Apex.exe","3708","CreateFile","C:\Windows\System32\nsi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,6992837","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,6992943","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nsi.dll","SUCCESS","AllocationSize: 24 576, EndOfFile: 23 992, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6993107","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\nsi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,6993347","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\nsi.dll","SUCCESS","AllocationSize: 24 576, EndOfFile: 23 992, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,6994309","R5Apex.exe","3708","CloseFile","C:\Windows\System32\nsi.dll","SUCCESS","" "19:13:41,7186358","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dnsapi.dll","SUCCESS","" "19:13:41,7188086","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\WMI\Security\9ca335ed-c0a6-4b4d-b084-9c9b5143aff0","NAME NOT FOUND","Length: 524" "19:13:41,7190277","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,7191124","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,7191842","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7192205","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7192317","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7192496","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7192901","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,7193741","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,7194520","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,7195255","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,7195925","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7196246","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7196345","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7196512","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7196894","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,7197727","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,7198401","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7198725","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7198821","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7198982","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7199347","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,7200123","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 8 286, Length: 144" "19:13:41,7200903","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7201037","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","REPARSE","Desired Access: All Access" "19:13:41,7201169","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Desired Access: All Access" "19:13:41,7201377","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 2.0" "19:13:41,7201525","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\WinSock_Registry_Version","SUCCESS","Type: REG_SZ, Length: 8, Data: 2.0" "19:13:41,7201698","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7201794","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","Desired Access: Read" "19:13:41,7202032","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7202121","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0D80486A-1A8B83A5","NAME NOT FOUND","Desired Access: Read" "19:13:41,7202234","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7202320","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog\0D80486A","NAME NOT FOUND","Desired Access: Read" "19:13:41,7202436","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\AppId_Catalog","SUCCESS","" "19:13:41,7202545","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout","SUCCESS","Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll" "19:13:41,7202663","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Callout","SUCCESS","Type: REG_EXPAND_SZ, Length: 70, Data: %SystemRoot%\System32\fwpuclnt.dll" "19:13:41,7202798","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7202888","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:41,7203010","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 10" "19:13:41,7203286","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 10" "19:13:41,7203414","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7203504","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000A","NAME NOT FOUND","Desired Access: Read" "19:13:41,7203619","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1013" "19:13:41,7203738","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries64","SUCCESS","Type: REG_DWORD, Length: 4, Data: 12" "19:13:41,7203847","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7203934","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:41,7204068","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7204155","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001","SUCCESS","Desired Access: Read" "19:13:41,7204306","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7204427","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7204572","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001","SUCCESS","" "19:13:41,7204665","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7204755","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002","SUCCESS","Desired Access: Read" "19:13:41,7204886","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7205002","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7205133","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002","SUCCESS","" "19:13:41,7205293","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7205383","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003","SUCCESS","Desired Access: Read" "19:13:41,7205518","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7205637","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7205771","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003","SUCCESS","" "19:13:41,7205858","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7205948","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004","SUCCESS","Desired Access: Read" "19:13:41,7206070","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7206185","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7206317","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004","SUCCESS","" "19:13:41,7206400","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7206487","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005","SUCCESS","Desired Access: Read" "19:13:41,7206612","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7206730","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7206859","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005","SUCCESS","" "19:13:41,7206993","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7207083","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006","SUCCESS","Desired Access: Read" "19:13:41,7207208","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7207324","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7207455","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006","SUCCESS","" "19:13:41,7207539","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7207625","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007","SUCCESS","Desired Access: Read" "19:13:41,7207747","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7207866","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7207994","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007","SUCCESS","" "19:13:41,7208077","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7208164","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008","SUCCESS","Desired Access: Read" "19:13:41,7208289","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7208404","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7208533","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008","SUCCESS","" "19:13:41,7208635","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7208722","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009","SUCCESS","Desired Access: Read" "19:13:41,7208847","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7208966","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7209091","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009","SUCCESS","" "19:13:41,7209222","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7209312","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010","SUCCESS","Desired Access: Read" "19:13:41,7209440","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7209556","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7209684","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010","SUCCESS","" "19:13:41,7209768","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7209854","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011","SUCCESS","Desired Access: Read" "19:13:41,7209979","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7210095","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7210223","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011","SUCCESS","" "19:13:41,7210306","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7210396","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012","SUCCESS","Desired Access: Read" "19:13:41,7210518","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012\PackedCatalogItem","BUFFER OVERFLOW","Length: 144" "19:13:41,7210637","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012\PackedCatalogItem","SUCCESS","Type: REG_BINARY, Length: 888, Data: 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73" "19:13:41,7210768","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012","SUCCESS","" "19:13:41,7210848","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64","SUCCESS","" "19:13:41,7211073","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7211166","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:41,7211278","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 20" "19:13:41,7211455","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num","SUCCESS","Type: REG_DWORD, Length: 4, Data: 20" "19:13:41,7211592","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7211679","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\00000014","NAME NOT FOUND","Desired Access: Read" "19:13:41,7211775","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries64","SUCCESS","Type: REG_DWORD, Length: 4, Data: 6" "19:13:41,7211888","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7211974","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access" "19:13:41,7212096","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7212183","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001","SUCCESS","Desired Access: Read" "19:13:41,7212314","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll" "19:13:41,7212439","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\napinsp.dll" "19:13:41,7212564","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:41,7212683","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:41,7212798","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:41,7212911","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\napinsp.dll,-1000" "19:13:41,7213029","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: A2 CB 4A 96 BC B2 EB 40 8C 6A A6 DB 40 16 1C AE" "19:13:41,7213148","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:41,7213267","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 37" "19:13:41,7213385","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7213501","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7213632","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7213751","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7213870","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7213995","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001","SUCCESS","" "19:13:41,7214085","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7214184","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002","SUCCESS","Desired Access: Read" "19:13:41,7214319","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:41,7214437","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:41,7214556","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:41,7214668","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:41,7214784","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:41,7214896","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1000" "19:13:41,7215015","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: CE 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D" "19:13:41,7215130","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:41,7215246","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 39" "19:13:41,7215361","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7215477","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7215592","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7215707","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7215823","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7215948","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002","SUCCESS","" "19:13:41,7216035","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7216124","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003","SUCCESS","Desired Access: Read" "19:13:41,7216253","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:41,7216371","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\system32\pnrpnsp.dll" "19:13:41,7216487","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:41,7216609","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:41,7216724","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:41,7216843","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString","SUCCESS","Type: REG_SZ, Length: 82, Data: @%SystemRoot%\system32\pnrpnsp.dll,-1001" "19:13:41,7216958","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: CD 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D" "19:13:41,7217074","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:41,7217186","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 38" "19:13:41,7217301","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7217414","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7217529","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7217645","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7217760","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7217882","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003","SUCCESS","" "19:13:41,7217969","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7218058","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004","SUCCESS","Desired Access: Read" "19:13:41,7218183","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll" "19:13:41,7218302","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\system32\NLAapi.dll" "19:13:41,7218418","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:41,7218530","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:41,7218655","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:41,7218767","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\system32\nlasvc.dll,-1000" "19:13:41,7218886","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: 3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83" "19:13:41,7219001","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:41,7219114","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 15" "19:13:41,7219229","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7219341","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7219457","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7219572","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7219688","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7219813","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004","SUCCESS","" "19:13:41,7219896","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7219986","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005","SUCCESS","Desired Access: Read" "19:13:41,7220108","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll" "19:13:41,7220226","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\LibraryPath","SUCCESS","Type: REG_SZ, Length: 68, Data: %SystemRoot%\System32\mswsock.dll" "19:13:41,7220342","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:41,7220457","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:41,7220570","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:41,7220778","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString","SUCCESS","Type: REG_SZ, Length: 86, Data: @%SystemRoot%\system32\wshtcpip.dll,-60103" "19:13:41,7220906","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: 40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B" "19:13:41,7221035","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:41,7221150","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 12" "19:13:41,7221266","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7221378","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7221493","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7221609","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7221721","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7221846","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005","SUCCESS","" "19:13:41,7221930","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7222019","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006","SUCCESS","Desired Access: Read" "19:13:41,7222144","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll" "19:13:41,7222263","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\LibraryPath","SUCCESS","Type: REG_SZ, Length: 66, Data: %SystemRoot%\System32\winrnr.dll" "19:13:41,7222379","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:41,7222500","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:41,7222622","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:41,7222735","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString","SUCCESS","Type: REG_SZ, Length: 80, Data: @%SystemRoot%\System32\winrnr.dll,-1000" "19:13:41,7222850","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\ProviderId","SUCCESS","Type: REG_BINARY, Length: 16, Data: EE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC" "19:13:41,7222965","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\AddressFamily","NAME NOT FOUND","Length: 144" "19:13:41,7223078","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\SupportedNameSpace","SUCCESS","Type: REG_DWORD, Length: 4, Data: 32" "19:13:41,7223193","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\Enabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7223305","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\Version","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7223418","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\StoresServiceClassInfo","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7223533","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7223658","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\ProviderInfo","SUCCESS","Type: REG_BINARY, Length: 0" "19:13:41,7223780","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006","SUCCESS","" "19:13:41,7223864","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64","SUCCESS","" "19:13:41,7223957","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","" "19:13:41,7224094","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7224184","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock2\Parameters","REPARSE","Desired Access: Query Value" "19:13:41,7224287","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Winsock2\Parameters","SUCCESS","Desired Access: Query Value" "19:13:41,7224406","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets","NAME NOT FOUND","Length: 144" "19:13:41,7224511","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Ws2_32SpinCount","NAME NOT FOUND","Length: 144" "19:13:41,7224620","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\WinSock2\Parameters","SUCCESS","" "19:13:41,7225195","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7225320","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:41,7225416","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:41,7225538","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7225624","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:41,7225717","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:41,7225836","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7225919","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:41,7226096","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:41,7226224","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:41,7226368","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:41,7226452","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:41,7226529","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:41,7226615","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7226708","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:41,7226798","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:41,7226901","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7226987","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:41,7227077","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:41,7227183","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7227270","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:41,7227388","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7227504","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7227587","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\System\DNSClient","NAME NOT FOUND","Desired Access: Query Value" "19:13:41,7227693","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7227805","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7227962","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:41,7228046","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:41,7228123","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:41,7228213","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7228302","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:41,7228389","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:41,7228488","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7228581","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:41,7228668","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:41,7228777","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7228860","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:41,7228969","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:41,7229082","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:41,7229194","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:41,7229274","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:41,7229351","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:41,7229441","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7229531","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:41,7229614","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:41,7229717","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7229800","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:41,7229887","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:41,7229993","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7230073","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:41,7230185","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7230278","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","REPARSE","Desired Access: Query Value" "19:13:41,7230368","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","NAME NOT FOUND","Desired Access: Query Value" "19:13:41,7230535","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7230647","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7230772","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7230881","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:41,7230980","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:41,7231077","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7231186","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:41,7231282","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:41,7231381","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:41,7231478","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:41,7231574","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:41,7231676","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:41,7231773","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:41,7231869","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:41,7231972","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:41,7232068","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:41,7232167","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:41,7232263","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:41,7232363","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:41,7232459","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:41,7232555","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:41,7232651","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:41,7232751","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7232847","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7232943","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:41,7233040","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:41,7233139","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:41,7233235","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:41,7233331","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns","NAME NOT FOUND","Length: 144" "19:13:41,7233428","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseEdns","NAME NOT FOUND","Length: 144" "19:13:41,7233524","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:41,7233633","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:41,7233732","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:41,7233829","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:41,7233934","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7234031","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7234127","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:41,7234226","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:41,7234326","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:41,7234422","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:41,7234518","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:41,7234618","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:41,7234714","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartNameResolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7234816","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:41,7234916","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:41,7235012","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:41,7235108","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:41,7235204","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:41,7235301","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:41,7235397","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:41,7235493","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:41,7235589","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:41,7235689","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:41,7235785","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:41,7235881","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:41,7235977","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:41,7236074","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:41,7236170","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:41,7236269","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:41,7236369","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7236465","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7236564","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:41,7236667","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:41,7236763","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:41,7236863","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7236959","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7237068","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7237174","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:41,7237270","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:41,7237369","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableReverseAddressRegistrations","NAME NOT FOUND","Length: 144" "19:13:41,7237472","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:41,7237568","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:41,7237664","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableWanDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:41,7237767","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:41,7237863","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:41,7237959","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationTTL","NAME NOT FOUND","Length: 144" "19:13:41,7238062","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:41,7238158","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:41,7238258","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:41,7238360","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7238457","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7238556","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:41,7238668","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:41,7238765","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:41,7238861","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:41,7238963","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:41,7239060","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:41,7239159","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:41,7239258","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:41,7239358","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:41,7239454","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:41,7239550","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:41,7239647","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:41,7239746","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7239842","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7239938","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7240035","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7240131","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:41,7240237","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:41,7240336","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:41,7240432","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:41,7240529","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:41,7240625","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:41,7240724","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:41,7240820","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:41,7240917","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7241013","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7241109","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7241205","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7241305","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7241401","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7241497","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:41,7241593","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:41,7241690","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsTest","NAME NOT FOUND","Length: 144" "19:13:41,7241783","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseCompartments","NAME NOT FOUND","Length: 144" "19:13:41,7241879","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\CacheAllCompartments","NAME NOT FOUND","Length: 144" "19:13:41,7241975","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseNewRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7242068","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7242164","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistrationOnly","NAME NOT FOUND","Length: 144" "19:13:41,7242260","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\NewDhcpSrvRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7242357","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessPreferLocal","NAME NOT FOUND","Length: 144" "19:13:41,7242453","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:41,7242549","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:41,7242645","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:41,7242742","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:41,7242838","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ShortnameProxyDefault","NAME NOT FOUND","Length: 144" "19:13:41,7242934","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength","NAME NOT FOUND","Length: 144" "19:13:41,7243033","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval","NAME NOT FOUND","Length: 144" "19:13:41,7243136","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7243229","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Query Value" "19:13:41,7243344","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7243473","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:41,7243553","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7243675","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7243787","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7243883","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7243999","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:41,7244079","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:41,7244153","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:41,7245667","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,7246484","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,7247261","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7247607","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7247726","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7247912","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7248332","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,7249207","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,7249968","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,7250705","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,7251379","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7251699","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7251808","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7251985","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7252367","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,7253220","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,7253909","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7254220","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7254326","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7254499","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7254868","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,7255539","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 8 430, Length: 144" "19:13:41,7255933","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7256065","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Rpc","SUCCESS","Desired Access: Read" "19:13:41,7256238","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize","NAME NOT FOUND","Length: 144" "19:13:41,7256398","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","" "19:13:41,7256783","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","REPARSE","Desired Access: Read" "19:13:41,7256905","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","Desired Access: Read" "19:13:41,7257046","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName","SUCCESS","Type: REG_SZ, Length: 18, Data: DEVLA-PC" "19:13:41,7257190","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName","SUCCESS","" "19:13:41,7257290","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:41,7257405","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\OOBEInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7257521","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:41,7257614","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:41,7257723","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7257835","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:41,7257950","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys" "19:13:41,7258739","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7258852","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\Rpc","NAME NOT FOUND","Desired Access: Read" "19:13:41,7259313","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7259413","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Microsoft\Rpc","SUCCESS","Desired Access: Query Value" "19:13:41,7259541","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Microsoft\Rpc\IdleTimerWindow","NAME NOT FOUND","Length: 144" "19:13:41,7259673","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Microsoft\Rpc","SUCCESS","" "19:13:41,7260952","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7261061","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:41,7261177","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7261305","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:41,7263833","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7263948","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","REPARSE","Desired Access: Query Value" "19:13:41,7264057","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","SUCCESS","Desired Access: Query Value" "19:13:41,7264192","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Control\SQMServiceList\SQMServiceList","SUCCESS","Type: REG_SZ, Length: 54, Data: netprofm,netman,dcomlaunch" "19:13:41,7264355","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Control\SQMServiceList","SUCCESS","" "19:13:41,7270042","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7270154","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:13:41,7270286","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7270375","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:13:41,7270481","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:13:41,7271129","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7271235","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:13:41,7271354","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7271488","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:41,7275908","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7276030","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","REPARSE","Desired Access: Read" "19:13:41,7276132","R5Apex.exe","3708","RegCreateKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","Desired Access: Read, Disposition: REG_OPENED_EXISTING_KEY" "19:13:41,7276254","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7276347","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","REPARSE","Desired Access: Read" "19:13:41,7276444","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters","SUCCESS","Desired Access: Read" "19:13:41,7276559","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7276649","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows NT\DnsClient","SUCCESS","Desired Access: Read" "19:13:41,7276777","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7276864","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","REPARSE","Desired Access: Query Value" "19:13:41,7276957","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DNS","NAME NOT FOUND","Desired Access: Query Value" "19:13:41,7277075","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7277200","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7277313","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7277428","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:41,7277534","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseDomainNameDevolution","NAME NOT FOUND","Length: 144" "19:13:41,7277637","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7277749","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:41,7277852","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DomainNameDevolutionLevel","NAME NOT FOUND","Length: 144" "19:13:41,7277954","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:41,7278057","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:41,7278159","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\PrioritizeRecordData","NAME NOT FOUND","Length: 144" "19:13:41,7278268","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:41,7278371","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:41,7278471","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\AllowUnqualifiedQuery","NAME NOT FOUND","Length: 144" "19:13:41,7278589","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:41,7278695","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AppendToMultiLabelName","NAME NOT FOUND","Length: 144" "19:13:41,7278798","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:41,7278900","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenBadTlds","NAME NOT FOUND","Length: 144" "19:13:41,7279003","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:41,7279106","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenUnreachableServers","NAME NOT FOUND","Length: 144" "19:13:41,7279208","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:41,7279320","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ScreenDefaultServers","NAME NOT FOUND","Length: 144" "19:13:41,7279423","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7279523","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DynamicServerQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7279628","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:41,7279731","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterClusterIp","NAME NOT FOUND","Length: 144" "19:13:41,7279830","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:41,7279933","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\WaitForNameErrorOnAll","NAME NOT FOUND","Length: 144" "19:13:41,7280036","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns","NAME NOT FOUND","Length: 144" "19:13:41,7280138","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseEdns","NAME NOT FOUND","Length: 144" "19:13:41,7280254","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:41,7280356","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsSecureNameQueryFallback","NAME NOT FOUND","Length: 144" "19:13:41,7280459","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:41,7280562","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableDAForAllNetworks","NAME NOT FOUND","Length: 144" "19:13:41,7280664","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7280764","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessQueryOrder","NAME NOT FOUND","Length: 144" "19:13:41,7280866","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:41,7280969","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryIpMatching","NAME NOT FOUND","Length: 144" "19:13:41,7281072","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:41,7281171","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseHostsFile","NAME NOT FOUND","Length: 144" "19:13:41,7281274","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:41,7281376","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AddrConfigControl","NAME NOT FOUND","Length: 144" "19:13:41,7281479","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartNameResolution","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7281585","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:41,7281687","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\PreferLocalOverLowerBindingDNS","NAME NOT FOUND","Length: 144" "19:13:41,7281793","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:41,7281893","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\QueryNetBTFQDN","NAME NOT FOUND","Length: 144" "19:13:41,7281995","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:41,7282098","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableSmartProtocolReordering","NAME NOT FOUND","Length: 144" "19:13:41,7282201","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:41,7282300","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UdpRecvBufferSize","NAME NOT FOUND","Length: 144" "19:13:41,7282403","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:41,7282505","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableParallelAandAAAA","NAME NOT FOUND","Length: 144" "19:13:41,7282614","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:41,7282717","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableCoalescing","NAME NOT FOUND","Length: 144" "19:13:41,7282816","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:41,7282919","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\FilterVPNTrigger","NAME NOT FOUND","Length: 144" "19:13:41,7283022","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:41,7283121","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMultiHomedRouteConflicts","NAME NOT FOUND","Length: 144" "19:13:41,7283224","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7283323","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7283426","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:41,7283535","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:41,7283644","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterPrimaryName","NAME NOT FOUND","Length: 144" "19:13:41,7283750","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7283849","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7283955","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7284067","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:41,7284167","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterReverseLookup","NAME NOT FOUND","Length: 144" "19:13:41,7284272","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableReverseAddressRegistrations","NAME NOT FOUND","Length: 144" "19:13:41,7284382","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:41,7284481","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegisterWanAdapters","NAME NOT FOUND","Length: 144" "19:13:41,7284584","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DisableWanDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:41,7284689","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:41,7284792","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationTtl","NAME NOT FOUND","Length: 144" "19:13:41,7284891","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationTTL","NAME NOT FOUND","Length: 144" "19:13:41,7285001","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:41,7285103","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:41,7285206","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DefaultRegistrationRefreshInterval","NAME NOT FOUND","Length: 144" "19:13:41,7285312","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7285414","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7285517","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:41,7285626","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:41,7285729","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:41,7285831","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\UpdateSecurityLevel","NAME NOT FOUND","Length: 144" "19:13:41,7285947","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:41,7286049","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UpdateTopLevelDomainZones","NAME NOT FOUND","Length: 144" "19:13:41,7286155","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:41,7286258","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy","NAME NOT FOUND","Length: 144" "19:13:41,7286360","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:41,7286463","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\RegistrationOverwrite","NAME NOT FOUND","Length: 144" "19:13:41,7286562","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:41,7286665","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheSize","NAME NOT FOUND","Length: 144" "19:13:41,7286768","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7286870","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7286970","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7287072","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxNegativeCacheTtl","NAME NOT FOUND","Length: 144" "19:13:41,7287172","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:41,7287274","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\AdapterTimeoutLimit","NAME NOT FOUND","Length: 144" "19:13:41,7287377","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:41,7287480","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ServerPriorityTimeLimit","NAME NOT FOUND","Length: 144" "19:13:41,7287579","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:41,7287682","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MaxCachedSockets","NAME NOT FOUND","Length: 144" "19:13:41,7287784","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:41,7287884","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableServerUnreachability","NAME NOT FOUND","Length: 144" "19:13:41,7287986","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7288086","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7288189","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7288291","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastResponderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7288391","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7288493","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderFlags","NAME NOT FOUND","Length: 144" "19:13:41,7288602","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:41,7288708","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\MulticastSenderMaxTimeout","NAME NOT FOUND","Length: 144" "19:13:41,7288808","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsTest","NAME NOT FOUND","Length: 144" "19:13:41,7288913","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseCompartments","NAME NOT FOUND","Length: 144" "19:13:41,7289013","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\CacheAllCompartments","NAME NOT FOUND","Length: 144" "19:13:41,7289112","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\UseNewRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7289225","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7289324","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ResolverRegistrationOnly","NAME NOT FOUND","Length: 144" "19:13:41,7289427","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\NewDhcpSrvRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7289526","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DirectAccessPreferLocal","NAME NOT FOUND","Length: 144" "19:13:41,7289625","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:41,7289728","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DisableIdnEncoding","NAME NOT FOUND","Length: 144" "19:13:41,7289827","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:41,7289930","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\EnableIdnMapping","NAME NOT FOUND","Length: 144" "19:13:41,7290030","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\ShortnameProxyDefault","NAME NOT FOUND","Length: 144" "19:13:41,7290132","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutHistoryLength","NAME NOT FOUND","Length: 144" "19:13:41,7290235","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\TestMode_AdaptiveTimeoutRecalculationInterval","NAME NOT FOUND","Length: 144" "19:13:41,7290344","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7290443","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Query Value" "19:13:41,7290549","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7290677","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:13:41,7290764","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7290870","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7290982","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7291085","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DnsQuickQueryTimeouts","NAME NOT FOUND","Length: 144" "19:13:41,7291197","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7291306","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7291396","R5Apex.exe","3708","RegOpenKey","HKLM\Software\Policies\Microsoft\System\DNSClient","NAME NOT FOUND","Desired Access: Query Value" "19:13:41,7291508","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7291620","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7291729","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:41,7291838","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname","SUCCESS","Type: REG_SZ, Length: 18, Data: Devla-PC" "19:13:41,7291976","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7292082","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7292191","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7293115","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:13:41,7294010","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:13:41,7294712","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7295052","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7295164","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7295350","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7295745","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:13:41,7296598","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:13:41,7297355","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:13:41,7298096","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:13:41,7298776","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7299093","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7299199","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7299376","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7299760","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:13:41,7300604","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:13:41,7301271","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7301579","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7301682","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7301852","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7302224","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:13:41,7302836","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 8 574, Length: 144" "19:13:41,7305447","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 20:41:20, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:45:19, AllocationSize: 69 632, EndOfFile: 67 072, FileAttributes: A" "19:13:41,7306188","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7306451","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7306669","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7308119","R5Apex.exe","3708","Load Image","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","Image Base: 0x7ffdc0b90000, Image Size: 0x16000" "19:13:41,7310001","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7310261","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7310354","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","AllocationSize: 69 632, EndOfFile: 67 072, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7310505","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7310736","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","AllocationSize: 69 632, EndOfFile: 67 072, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7313099","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","" "19:13:41,7511860","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dhcpcsvc6.dll","SUCCESS","" "19:13:41,7515344","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7515488","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7515639","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7515831","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7516017","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7516126","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7516226","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7516335","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7516479","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7516575","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7516678","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7516825","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7516973","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7517941","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:45:19, AllocationSize: 86 016, EndOfFile: 84 992, FileAttributes: A" "19:13:41,7518721","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7519099","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7519333","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7520767","R5Apex.exe","3708","Load Image","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","Image Base: 0x7ffdcb050000, Image Size: 0x1a000" "19:13:41,7522512","R5Apex.exe","3708","CreateFile","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7522877","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7522983","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","AllocationSize: 86 016, EndOfFile: 84 992, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7523144","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7523378","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","AllocationSize: 86 016, EndOfFile: 84 992, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7525956","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","" "19:13:41,7726350","R5Apex.exe","3708","CloseFile","C:\Windows\System32\dhcpcsvc.dll","SUCCESS","" "19:13:41,7729621","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7729766","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read" "19:13:41,7729900","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Desired Access: Read" "19:13:41,7730282","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7730391","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055b14ee-328a-11ea-a2f1-806e6f6e6963}","SUCCESS","Desired Access: Query Value" "19:13:41,7730539","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\EnableDhcp","NAME NOT FOUND","Length: 144" "19:13:41,7730731","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","" "19:13:41,7730827","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:41,7730930","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7731026","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","REPARSE","Desired Access: Read" "19:13:41,7731132","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Desired Access: Read" "19:13:41,7731411","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7731510","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","Desired Access: Query Value" "19:13:41,7731639","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\EnableDhcp","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7731793","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces","SUCCESS","" "19:13:41,7731882","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7731992","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7732088","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7732197","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7732357","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpRACoexistenceEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7732505","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7732710","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7732806","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7732915","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7733047","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7733188","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7733278","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7733371","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7733477","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7733608","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7733772","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7733861","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7733954","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7734057","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7734185","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7734314","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7734468","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7734593","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:41,7734721","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7734808","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7734901","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7735003","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7735176","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Dhcpv6Domain","NAME NOT FOUND","Length: 144" "19:13:41,7735311","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7735404","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7735500","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7735600","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7735728","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","NAME NOT FOUND","Length: 144" "19:13:41,7735853","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7735981","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7736071","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7736164","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7736264","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7736389","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7736520","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7736645","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7736767","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7736902","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7737027","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7737120","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7737219","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7737344","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7737470","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7737591","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7737713","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7737845","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7738005","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7738098","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7738198","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7738429","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7738525","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7738640","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7738769","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7738862","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7738961","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:41,7739089","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7739224","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:41,7739314","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7739404","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7739503","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:41,7739628","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7739769","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7739888","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\Domain","NAME NOT FOUND","Length: 144" "19:13:41,7740000","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:41,7740141","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:41,7740228","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7740318","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7740417","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7740542","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7740632","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7740731","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7740850","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7740940","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7741039","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:41,7741164","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7741289","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7741415","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7741533","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7741658","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:41,7741767","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7741860","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7741960","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:41,7742085","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7742207","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\NameServer","SUCCESS","Type: REG_SZ, Length: 0" "19:13:41,7742329","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\ProfileNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7742447","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpNameServer","NAME NOT FOUND","Length: 144" "19:13:41,7742572","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:41,7742729","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7742819","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7742919","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7743053","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DhcpRACoexistenceEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7743191","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7743365","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7743464","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7743567","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7743708","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7743842","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7743932","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7744022","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7744121","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7744247","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7744384","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7744474","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7744564","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7744663","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7744785","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegistrationEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7744920","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegisterAdapterName","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7745045","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7745164","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:41,7745295","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7745385","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7745478","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7745578","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7745703","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\NameServer","SUCCESS","Type: REG_SZ, Length: 32, Data: 1.1.1.1,1.1.0.0" "19:13:41,7745828","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\NameServer","SUCCESS","Type: REG_SZ, Length: 32, Data: 1.1.1.1,1.1.0.0" "19:13:41,7745962","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7747236","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7747345","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","REPARSE","Desired Access: Read" "19:13:41,7747451","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","SUCCESS","Desired Access: Read" "19:13:41,7747585","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7747723","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7747848","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7747967","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:41,7748086","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7748204","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7748323","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7748442","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:41,7748557","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7748711","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7748833","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7748958","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:41,7749090","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{100640f5-43bb-4570-82e6-bfaec0e2dfb8}","SUCCESS","" "19:13:41,7749224","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7749320","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\","REPARSE","Desired Access: Read" "19:13:41,7749423","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Desired Access: Read" "19:13:41,7749558","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7749644","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\{100640F5-43BB-4570-82E6-BFAEC0E2DFB8}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7749750","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","" "19:13:41,7750459","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7750562","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","REPARSE","Desired Access: Read" "19:13:41,7750664","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","SUCCESS","Desired Access: Read" "19:13:41,7750793","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7750924","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7751046","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegistrationEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1" "19:13:41,7751168","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegisterAdapterName","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:13:41,7751286","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7751405","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:41,7751527","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7751646","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7751768","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\Domain","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7751883","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:41,7752015","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8f1a33f8-1dad-40a1-86b8-61b18ee07147}","SUCCESS","" "19:13:41,7752108","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7752201","R5Apex.exe","3708","RegOpenKey","HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\","REPARSE","Desired Access: Read" "19:13:41,7752297","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Desired Access: Read" "19:13:41,7752412","R5Apex.exe","3708","RegQueryKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7752499","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters\{8F1A33F8-1DAD-40A1-86B8-61B18EE07147}","NAME NOT FOUND","Desired Access: Read" "19:13:41,7752601","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\InterfaceSpecificParameters","SUCCESS","" "19:13:41,7753137","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:13:41,7753233","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","REPARSE","Desired Access: Read" "19:13:41,7753336","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","Desired Access: Read" "19:13:41,7753461","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\QueryAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7753586","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DisableAdapterDomainName","NAME NOT FOUND","Length: 144" "19:13:41,7753737","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegistrationEnabled","NAME NOT FOUND","Length: 144" "19:13:41,7753852","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DisableDynamicUpdate","NAME NOT FOUND","Length: 144" "19:13:41,7753965","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegisterAdapterName","NAME NOT FOUND","Length: 144" "19:13:41,7754080","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\EnableAdapterDomainNameRegistration","NAME NOT FOUND","Length: 144" "19:13:41,7754195","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\RegistrationMaxAddressCount","NAME NOT FOUND","Length: 144" "19:13:41,7754311","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\MaxNumberOfAddressesToRegister","NAME NOT FOUND","Length: 144" "19:13:41,7754426","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\EnableMulticast","NAME NOT FOUND","Length: 144" "19:13:41,7754542","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\Domain","NAME NOT FOUND","Length: 144" "19:13:41,7754657","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}\DhcpDomain","NAME NOT FOUND","Length: 144" "19:13:41,7754782","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{055B14EE-328A-11EA-A2F1-806E6F6E6963}","SUCCESS","" "19:13:41,7755366","R5Apex.exe","3708","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList","NAME NOT FOUND","Length: 144" "19:13:41,7755504","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\SearchList","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7755623","R5Apex.exe","3708","RegQueryValue","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\SearchList","SUCCESS","Type: REG_SZ, Length: 2, Data: " "19:13:41,7755767","R5Apex.exe","3708","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient","SUCCESS","" "19:13:41,7755850","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Tcpip\Parameters","SUCCESS","" "19:13:41,7755937","R5Apex.exe","3708","RegCloseKey","HKLM\System\CurrentControlSet\Services\Dnscache\Parameters","SUCCESS","" "19:13:41,7757008","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\winnsi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:43, LastAccessTime: 2021. 02. 13. 20:48:19, LastWriteTime: 2017. 09. 29. 15:41:43, ChangeTime: 2020. 01. 09. 4:45:12, AllocationSize: 36 864, EndOfFile: 34 696, FileAttributes: A" "19:13:41,7757833","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winnsi.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7758217","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7758445","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winnsi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7759949","R5Apex.exe","3708","Load Image","C:\Windows\System32\winnsi.dll","SUCCESS","Image Base: 0x7ffdc1320000, Image Size: 0xb000" "19:13:41,7761710","R5Apex.exe","3708","CreateFile","C:\Windows\System32\winnsi.dll","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened" "19:13:41,7762076","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winnsi.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:13:41,7762178","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winnsi.dll","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 696, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7762336","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\winnsi.dll","SUCCESS","SyncType: SyncTypeOther" "19:13:41,7762576","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\winnsi.dll","SUCCESS","AllocationSize: 36 864, EndOfFile: 34 696, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:13:41,7763974","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winnsi.dll","SUCCESS","" "19:13:41,7959647","R5Apex.exe","3708","CloseFile","C:\Windows\System32\winnsi.dll","SUCCESS","" "19:13:41,7961866","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 6388" "19:14:00,9283637","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 6024" "19:14:00,9285145","EasyAntiCheat.exe","2900","Thread Create","","SUCCESS","Thread ID: 2596" "19:14:01,0499049","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 4728, User Time: 0.0000000, Kernel Time: 0.0000000" "19:14:08,5720449","R5Apex.exe","3708","QueryStandardInformationFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","AllocationSize: 33 751 040, EndOfFile: 33 708 280, NumberOfLinks: 1, DeletePending: False, Directory: False" "19:14:08,5729499","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 0, Length: 4 194 304, Priority: Very Low" "19:14:08,5977778","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 4 194 304, Length: 4 194 304" "19:14:08,6225373","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 8 388 608, Length: 4 194 304" "19:14:08,6483507","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 12 582 912, Length: 4 194 304" "19:14:08,6731640","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 16 777 216, Length: 4 194 304" "19:14:08,6979239","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 20 971 520, Length: 4 194 304" "19:14:08,7226683","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 25 165 824, Length: 4 194 304" "19:14:08,7474242","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 29 360 128, Length: 4 194 304" "19:14:08,7721517","R5Apex.exe","3708","ReadFile","D:\Program Files (x86)\Steam\steamapps\common\Apex Legends\r5apex.exe","SUCCESS","Offset: 33 554 432, Length: 153 848" "19:14:30,9197035","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 952, User Time: 0.0000000, Kernel Time: 0.0000000" "19:14:30,9197041","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 4236, User Time: 0.0000000, Kernel Time: 0.0000000" "19:14:30,9197067","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 6344, User Time: 0.0000000, Kernel Time: 0.0000000" "19:14:38,8592086","R5Apex.exe","3708","Thread Exit","","SUCCESS","Thread ID: 676, User Time: 0.0625000, Kernel Time: 0.0156250" "19:14:38,8592108","R5Apex.exe","3708","Thread Exit","","SUCCESS","Thread ID: 3012, User Time: 0.1250000, Kernel Time: 0.0000000" "19:14:38,8592114","R5Apex.exe","3708","Thread Exit","","SUCCESS","Thread ID: 5492, User Time: 0.0468750, Kernel Time: 0.0468750" "19:15:41,1573017","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:15:41,1573940","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:15:41,1574665","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:15:41,1575124","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:15:41,1575265","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:15:41,1575461","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:15:41,1575951","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:15:41,1576808","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:15:41,1577587","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:15:41,1578322","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:15:41,1578979","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:15:41,1579297","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:15:41,1579396","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:15:41,1579560","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:15:41,1579976","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:15:41,1580804","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:15:41,1581487","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:15:41,1581801","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:15:41,1581901","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:15:41,1582061","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:15:41,1582459","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:15:41,1583367","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 8 718, Length: 144" "19:15:41,1584358","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:15:41,1585079","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:15:41,1585727","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:15:41,1586025","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:15:41,1586125","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:15:41,1586292","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:15:41,1586715","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:15:41,1587510","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:15:41,1588229","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:15:41,1588938","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:15:41,1589579","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:15:41,1589877","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:15:41,1589974","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:15:41,1590128","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:15:41,1590500","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:15:41,1591308","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:15:41,1591959","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:15:41,1592251","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:15:41,1592344","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:15:41,1592498","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:15:41,1592899","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:15:41,1593473","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 8 862, Length: 144" "19:15:41,1595246","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:15:41,1595410","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:15:41,1595666","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:15:41,1595865","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:15:41,1601584","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:15:41,1601703","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:15:41,1601889","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:15:41,1601978","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:15:41,1602107","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:17:46,1605490","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:17:46,1606420","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:17:46,1607152","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:17:46,1607620","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:17:46,1607764","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:17:46,1607963","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:17:46,1608470","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:17:46,1609451","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:17:46,1610234","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:17:46,1611109","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:17:46,1611773","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:17:46,1612097","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:17:46,1612197","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:17:46,1612360","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:17:46,1612752","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:17:46,1613582","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:17:46,1614253","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:17:46,1614573","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:17:46,1614670","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:17:46,1614830","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:17:46,1615231","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:17:46,1616049","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 006, Length: 144" "19:17:46,1617059","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:17:46,1617784","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:17:46,1618435","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:17:46,1618743","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:17:46,1618839","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:17:46,1618993","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:17:46,1619391","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:17:46,1620199","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:17:46,1620924","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:17:46,1621652","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:17:46,1622293","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:17:46,1622595","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:17:46,1622691","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:17:46,1622848","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:17:46,1623214","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:17:46,1624019","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:17:46,1624673","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:17:46,1624975","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:17:46,1625071","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:17:46,1625225","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:17:46,1625638","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:17:46,1626248","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 150, Length: 144" "19:17:46,1627813","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:17:46,1628015","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:17:46,1628191","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:17:46,1628387","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:17:46,1634115","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:17:46,1634234","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:17:46,1634414","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:17:46,1634503","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:17:46,1634632","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:18:41,1231705","R5Apex.exe","3708","Thread Create","","SUCCESS","Thread ID: 4956" "19:19:51,1635129","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:19:51,1636094","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:19:51,1636851","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:19:51,1637323","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:19:51,1637470","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:19:51,1637669","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:19:51,1638201","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:19:51,1639077","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:19:51,1639888","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:19:51,1640944","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:19:51,1641902","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:19:51,1642233","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:19:51,1642339","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:19:51,1642502","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:19:51,1642929","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:19:51,1643779","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:19:51,1644462","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:19:51,1644776","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:19:51,1644876","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:19:51,1645036","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:19:51,1645440","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:19:51,1646274","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 294, Length: 144" "19:19:51,1647291","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:19:51,1648025","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:19:51,1648991","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:19:51,1649545","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:19:51,1649651","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:19:51,1649812","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:19:51,1650216","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:19:51,1651069","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:19:51,1651803","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:19:51,1652525","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:19:51,1653182","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:19:51,1653487","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:19:51,1653580","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:19:51,1653737","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:19:51,1654103","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:19:51,1654918","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:19:51,1655963","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:19:51,1656284","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:19:51,1656624","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:19:51,1656791","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:19:51,1657198","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:19:51,1657801","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 438, Length: 144" "19:19:51,1659376","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:19:51,1659575","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:19:51,1659751","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:19:51,1659947","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:19:51,1666255","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:19:51,1666371","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:19:51,1666554","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:19:51,1666643","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:19:51,1666765","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:21:56,1669697","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:21:56,1670636","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:21:56,1671368","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:21:56,1671833","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:21:56,1671974","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:21:56,1672166","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:21:56,1672718","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:21:56,1673574","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:21:56,1674360","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:21:56,1675213","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:21:56,1675890","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:21:56,1676204","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:21:56,1676300","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:21:56,1676464","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:21:56,1676859","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:21:56,1677680","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:21:56,1678347","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:21:56,1678664","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:21:56,1678760","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:21:56,1678918","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:21:56,1679319","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:21:56,1680127","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 582, Length: 144" "19:21:56,1681147","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:21:56,1681875","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:21:56,1682523","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:21:56,1682824","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:21:56,1682920","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:21:56,1683074","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:21:56,1683469","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:21:56,1684274","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:21:56,1684999","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:21:56,1685727","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:21:56,1686375","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:21:56,1686670","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:21:56,1686766","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:21:56,1686920","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:21:56,1687282","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:21:56,1688074","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:21:56,1688725","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:21:56,1689024","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:21:56,1689117","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:21:56,1689274","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:21:56,1689656","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:21:56,1690230","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 726, Length: 144" "19:21:56,1691817","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:21:56,1692023","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:21:56,1692199","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:21:56,1692391","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:21:56,1698678","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:21:56,1698793","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:21:56,1698979","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:21:56,1699069","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:21:56,1699194","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:24:01,1699390","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:24:01,1700426","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:24:01,1701253","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:24:01,1701705","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:24:01,1701850","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:24:01,1702045","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:24:01,1702578","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:24:01,1703424","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:24:01,1704191","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:24:01,1704909","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:24:01,1705647","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:24:01,1705958","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:24:01,1706058","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:24:01,1706221","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:24:01,1706606","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:24:01,1707427","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:24:01,1708085","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:24:01,1708389","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:24:01,1708485","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:24:01,1708643","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:24:01,1709031","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:24:01,1709810","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 9 870, Length: 144" "19:24:01,1710814","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:24:01,1711632","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:24:01,1712373","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:24:01,1712665","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:24:01,1712761","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:24:01,1712918","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:24:01,1713296","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:24:01,1714085","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:24:01,1714794","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:24:01,1715500","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:24:01,1716132","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:24:01,1716423","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:24:01,1716516","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:24:01,1716670","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:24:01,1717020","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:24:01,1717803","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:24:01,1718441","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:24:01,1718723","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:24:01,1718819","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:24:01,1718970","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:24:01,1719339","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:24:01,1719903","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 014, Length: 144" "19:24:01,1721443","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:24:01,1721629","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:24:01,1721792","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:24:01,1721975","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:24:01,1727495","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:24:01,1727607","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:24:01,1727787","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:24:01,1727873","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:24:01,1728002","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:26:06,1729217","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:26:06,1730272","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:26:06,1730994","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:26:06,1731446","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:26:06,1731587","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:26:06,1731783","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:26:06,1732354","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:26:06,1733204","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:26:06,1733970","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:26:06,1734705","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:26:06,1735372","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:26:06,1735683","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:26:06,1735786","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:26:06,1735949","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:26:06,1736337","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:26:06,1737158","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:26:06,1737819","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:26:06,1738127","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:26:06,1738223","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:26:06,1738384","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:26:06,1738778","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:26:06,1739574","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 158, Length: 144" "19:26:06,1741155","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:26:06,1741886","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:26:06,1742537","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:26:06,1742845","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:26:06,1742941","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:26:06,1743098","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:26:06,1743502","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:26:06,1744304","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:26:06,1745032","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:26:06,1745744","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:26:06,1746482","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:26:06,1746780","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:26:06,1746876","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:26:06,1747034","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:26:06,1747419","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:26:06,1748365","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:26:06,1749019","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:26:06,1749314","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:26:06,1749410","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:26:06,1749564","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:26:06,1749946","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:26:06,1750530","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 302, Length: 144" "19:26:06,1752085","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:26:06,1752239","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:26:06,1752412","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:26:06,1752598","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:26:06,1758185","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:26:06,1758298","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:26:06,1758474","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:26:06,1758561","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:26:06,1758686","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:28:11,1758846","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:28:11,1759811","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:28:11,1760543","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:28:11,1760998","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:28:11,1761139","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:28:11,1761335","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:28:11,1761845","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:28:11,1762688","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:28:11,1763461","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:28:11,1764183","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:28:11,1764844","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:28:11,1765155","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:28:11,1765254","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:28:11,1765418","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:28:11,1765803","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:28:11,1766617","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:28:11,1767272","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:28:11,1767576","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:28:11,1767672","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:28:11,1767830","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:28:11,1768214","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:28:11,1769013","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 446, Length: 144" "19:28:11,1770011","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:28:11,1770723","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:28:11,1771361","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:28:11,1771656","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:28:11,1771749","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:28:11,1771906","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:28:11,1772323","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:28:11,1773128","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:28:11,1773933","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:28:11,1774751","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:28:11,1775485","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:28:11,1775777","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:28:11,1775873","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:28:11,1776027","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:28:11,1776383","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:28:11,1777169","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:28:11,1777807","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:28:11,1778093","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:28:11,1778186","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:28:11,1778340","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:28:11,1778709","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:28:11,1779276","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 590, Length: 144" "19:28:11,1780816","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:28:11,1781011","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:28:11,1781181","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:28:11,1781374","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:28:11,1786746","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:28:11,1786858","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:28:11,1787035","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:28:11,1787121","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:28:11,1787246","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:30:16,1789103","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:30:16,1790046","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:30:16,1790774","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:30:16,1791243","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:30:16,1791384","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:30:16,1791579","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:30:16,1792048","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:30:16,1792910","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:30:16,1793696","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:30:16,1794437","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:30:16,1795107","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:30:16,1795425","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:30:16,1795524","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:30:16,1795691","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:30:16,1796079","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:30:16,1796907","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:30:16,1797574","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:30:16,1797885","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:30:16,1797981","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:30:16,1798138","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:30:16,1798536","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:30:16,1799338","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 734, Length: 144" "19:30:16,1800361","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:30:16,1801192","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:30:16,1801833","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:30:16,1802135","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:30:16,1802231","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:30:16,1802385","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:30:16,1802776","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:30:16,1803584","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:30:16,1804312","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:30:16,1805031","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:30:16,1805669","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:30:16,1805964","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:30:16,1806060","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:30:16,1806214","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:30:16,1806573","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:30:16,1807372","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:30:16,1808017","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:30:16,1808312","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:30:16,1808405","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:30:16,1808556","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:30:16,1808944","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:30:16,1809531","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 10 878, Length: 144" "19:30:16,1811086","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:30:16,1811288","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:30:16,1811468","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:30:16,1811660","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:30:16,1817331","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:30:16,1817443","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:30:16,1817622","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:30:16,1817709","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:30:16,1817837","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:32:21,1818331","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:32:21,1819287","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:32:21,1820009","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:32:21,1820464","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:32:21,1820605","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:32:21,1820801","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:32:21,1821304","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:32:21,1822154","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:32:21,1822934","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:32:21,1823662","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:32:21,1824335","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:32:21,1824650","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:32:21,1824749","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:32:21,1824916","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:32:21,1825297","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:32:21,1826128","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:32:21,1826792","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:32:21,1827103","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:32:21,1827199","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:32:21,1827360","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:32:21,1827751","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:32:21,1828543","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 11 022, Length: 144" "19:32:21,1829653","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\dxgi.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:28, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:28, ChangeTime: 2020. 01. 09. 4:45:11, AllocationSize: 704 512, EndOfFile: 702 504, FileAttributes: A" "19:32:21,1830371","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d9.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:45, LastAccessTime: 2021. 02. 13. 21:57:12, LastWriteTime: 2017. 09. 29. 15:41:45, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 1 646 592, EndOfFile: 1 643 032, FileAttributes: A" "19:32:21,1831016","R5Apex.exe","3708","CreateFile","C:\Windows\System32\d3d9.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:32:21,1831314","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:32:21,1831411","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\d3d9.dll","SUCCESS","AllocationSize: 1 646 592, EndOfFile: 1 643 032, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:32:21,1831571","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\d3d9.dll","SUCCESS","SyncType: SyncTypeOther" "19:32:21,1831962","R5Apex.exe","3708","CloseFile","C:\Windows\System32\d3d9.dll","SUCCESS","" "19:32:21,1832761","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d8.dll","NAME NOT FOUND","" "19:32:21,1833473","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\d3d.dll","NAME NOT FOUND","" "19:32:21,1834178","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\ddraw.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:44, LastAccessTime: 2021. 02. 13. 15:18:33, LastWriteTime: 2017. 09. 29. 15:41:44, ChangeTime: 2020. 01. 09. 4:41:47, AllocationSize: 573 440, EndOfFile: 572 928, FileAttributes: A" "19:32:21,1834839","R5Apex.exe","3708","CreateFile","C:\Windows\System32\ddraw.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:32:21,1835131","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:32:21,1835224","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\ddraw.dll","SUCCESS","AllocationSize: 573 440, EndOfFile: 572 928, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:32:21,1835384","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\ddraw.dll","SUCCESS","SyncType: SyncTypeOther" "19:32:21,1835740","R5Apex.exe","3708","CloseFile","C:\Windows\System32\ddraw.dll","SUCCESS","" "19:32:21,1836539","R5Apex.exe","3708","QueryOpen","C:\Windows\System32\opengl32.dll","SUCCESS","CreationTime: 2017. 09. 29. 15:41:56, LastAccessTime: 2021. 02. 13. 20:09:37, LastWriteTime: 2017. 09. 29. 15:41:56, ChangeTime: 2020. 01. 09. 4:42:05, AllocationSize: 1 036 288, EndOfFile: 1 034 752, FileAttributes: A" "19:32:21,1837184","R5Apex.exe","3708","CreateFile","C:\Windows\System32\opengl32.dll","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened" "19:32:21,1837472","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READ|PAGE_NOCACHE" "19:32:21,1837565","R5Apex.exe","3708","QueryStandardInformationFile","C:\Windows\System32\opengl32.dll","SUCCESS","AllocationSize: 1 036 288, EndOfFile: 1 034 752, NumberOfLinks: 2, DeletePending: False, Directory: False" "19:32:21,1837722","R5Apex.exe","3708","CreateFileMapping","C:\Windows\System32\opengl32.dll","SUCCESS","SyncType: SyncTypeOther" "19:32:21,1838120","R5Apex.exe","3708","CloseFile","C:\Windows\System32\opengl32.dll","SUCCESS","" "19:32:21,1838694","R5Apex.exe","3708","WriteFile","D:\Program Files (x86)\Steam\GameOverlayRenderer.log","SUCCESS","Offset: 11 166, Length: 144" "19:32:21,1840282","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:32:21,1840452","R5Apex.exe","3708","RegOpenKey","HKLM\System\Setup","SUCCESS","Desired Access: Read" "19:32:21,1840631","R5Apex.exe","3708","RegQueryValue","HKLM\SYSTEM\Setup\SystemSetupInProgress","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0" "19:32:21,1840817","R5Apex.exe","3708","RegCloseKey","HKLM\SYSTEM\Setup","SUCCESS","" "19:32:21,1846514","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:32:21,1846626","R5Apex.exe","3708","RegOpenKey","HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:32:21,1846805","R5Apex.exe","3708","RegQueryKey","HKLM","SUCCESS","Query: HandleTags, HandleTags: 0x0" "19:32:21,1846895","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","REPARSE","Desired Access: Read" "19:32:21,1847017","R5Apex.exe","3708","RegOpenKey","HKLM\System\CurrentControlSet\Services\DnsCache\Parameters\DnsPolicyConfig","NAME NOT FOUND","Desired Access: Read" "19:33:30,9184279","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 6024, User Time: 0.0000000, Kernel Time: 0.0000000" "19:33:30,9184347","EasyAntiCheat.exe","2900","Thread Exit","","SUCCESS","Thread ID: 2596, User Time: 0.0000000, Kernel Time: 0.0000000"