2544 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE SUCCESS FileNameInformation 2545 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE SUCCESS FileNameInformation 2546 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\Prefetch\HP1006MC.EXE-1DFFDF4D.pf SUCCESS Options: Open Access: All 2547 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\Prefetch\HP1006MC.EXE-1DFFDF4D.pf SUCCESS Options: Open Access: All 2548 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\Prefetch\HP1006MC.EXE-1DFFDF4D.pf SUCCESS FileInternalInformation 2549 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\Prefetch\HP1006MC.EXE-1DFFDF4D.pf SUCCESS 2550 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\Prefetch\HP1006MC.EXE-1DFFDF4D.pf SUCCESS Length: 10180 2551 8:30:28 HP1006MC.EXE:2488 READ C:\WINDOWS\Prefetch\HP1006MC.EXE-1DFFDF4D.pf SUCCESS Offset: 0 Length: 10180 2552 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\ SUCCESS Options: Open Directory Access: Traverse 2553 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE.Local NOT FOUND Attributes: Error 2554 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Attributes: A 2555 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\IMM32.DLL SUCCESS Options: Open Access: Execute 2556 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\IMM32.DLL SUCCESS Options: Open Access: All 2557 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS FileInternalInformation 2558 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\IMM32.DLL SUCCESS 2559 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Length: 110080 2560 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\IMM32.DLL SUCCESS 2561 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Attributes: A 2562 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\IMM32.DLL SUCCESS Options: Open Access: Execute 2563 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\IMM32.DLL SUCCESS Options: Open Access: All 2564 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS FileInternalInformation 2565 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\IMM32.DLL SUCCESS 2566 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Length: 110080 2567 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\IMM32.DLL SUCCESS 2568 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Attributes: A 2569 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\IMM32.DLL SUCCESS Options: Open Access: Execute 2570 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\IMM32.DLL SUCCESS Options: Open Access: All 2571 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS FileInternalInformation 2572 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\IMM32.DLL SUCCESS 2573 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\IMM32.DLL SUCCESS 2574 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Attributes: A 2575 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\IMM32.DLL SUCCESS Attributes: A 2576 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE BUFFER OVERFLOW FileNameInformation 2577 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE SUCCESS FileNameInformation 2578 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\rpcss.dll SUCCESS Attributes: A 2579 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\rpcss.dll SUCCESS Options: Open Access: Execute 2580 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\rpcss.dll SUCCESS Options: Open Access: All 2581 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\rpcss.dll SUCCESS FileInternalInformation 2582 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\rpcss.dll SUCCESS 2583 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\rpcss.dll SUCCESS Length: 401408 2584 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\rpcss.dll SUCCESS 2585 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\MSCTF.dll SUCCESS Attributes: A 2586 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\MSCTF.dll SUCCESS Options: Open Access: Execute 2587 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\MSCTF.dll SUCCESS Options: Open Access: All 2588 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\MSCTF.dll SUCCESS FileInternalInformation 2589 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\MSCTF.dll SUCCESS 2590 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\MSCTF.dll SUCCESS Length: 297984 2591 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\MSCTF.dll SUCCESS 2592 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\MSCTF.dll SUCCESS Attributes: A 2593 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\MSCTF.dll SUCCESS Options: Open Access: Execute 2594 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\MSCTF.dll SUCCESS Options: Open Access: All 2595 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\MSCTF.dll SUCCESS FileInternalInformation 2596 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\MSCTF.dll SUCCESS 2597 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\MSCTF.dll SUCCESS 2598 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\ntdll.dll SUCCESS Attributes: A 2599 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\imm32.dll SUCCESS Attributes: A 2600 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\KERNEL32.dll SUCCESS Attributes: A 2601 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\winlogon.exe SUCCESS Attributes: A 2602 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\winlogon.exe SUCCESS Options: Open Access: Execute 2603 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\winlogon.exe SUCCESS Options: Open Access: All 2604 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\winlogon.exe SUCCESS FileInternalInformation 2605 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\winlogon.exe SUCCESS 2606 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\winlogon.exe SUCCESS Length: 507904 2607 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\winlogon.exe SUCCESS 2608 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\xpsp2res.dll NOT FOUND Attributes: Error 2609 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\xpsp2res.dll SUCCESS Attributes: A 2610 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\xpsp2res.dll SUCCESS Options: Open Access: Execute 2611 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\xpsp2res.dll SUCCESS Options: Open Access: All 2612 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\xpsp2res.dll SUCCESS FileInternalInformation 2613 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\xpsp2res.dll SUCCESS 2614 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\xpsp2res.dll SUCCESS 2615 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CLBCATQ.DLL NOT FOUND Attributes: Error 2616 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\CLBCATQ.DLL SUCCESS Attributes: A 2617 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\CLBCATQ.DLL SUCCESS Options: Open Access: Execute 2618 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\CLBCATQ.DLL SUCCESS Options: Open Access: All 2619 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\CLBCATQ.DLL SUCCESS FileInternalInformation 2620 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\CLBCATQ.DLL SUCCESS 2621 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\CLBCATQ.DLL SUCCESS 2622 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\COMRes.dll NOT FOUND Attributes: Error 2623 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\COMRes.dll SUCCESS Attributes: A 2624 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\COMRes.dll SUCCESS Options: Open Access: Execute 2625 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\system32\COMRes.dll SUCCESS Options: Open Access: All 2626 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\COMRes.dll SUCCESS FileInternalInformation 2627 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\COMRes.dll SUCCESS 2628 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\system32\COMRes.dll SUCCESS 2629 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\Registration SUCCESS Attributes: D 2630 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\Registration\R000000000007.clb SUCCESS Options: Open Access: All 2631 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\Registration\R000000000007.clb SUCCESS Options: Open Access: All 2632 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\Registration\R000000000007.clb SUCCESS FileInternalInformation 2633 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\Registration\R000000000007.clb SUCCESS 2634 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\Registration\R000000000007.clb SUCCESS Length: 22708 2635 8:30:28 HP1006MC.EXE:2488 READ C:\WINDOWS\Registration\R000000000007.clb SUCCESS Offset: 0 Length: 22708 2636 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\Registration\R000000000007.clb SUCCESS 2637 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Attributes: A 2638 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Options: Open Access: Execute 2639 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Options: Open Access: All 2640 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS FileInternalInformation 2641 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS 2642 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Length: 6144 2643 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS 2644 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Attributes: A 2645 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Attributes: A 2646 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Options: Open Access: Execute 2647 8:30:28 HP1006MC.EXE:2488 OPEN C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS Options: Open Access: All 2648 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS FileInternalInformation 2649 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS 2650 8:30:28 HP1006MC.EXE:2488 CLOSE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MP.DLL SUCCESS 2651 8:30:28 HP1006MC.EXE:2488 QUERY INFORMATION C:\WINDOWS\system32\rpcrt4.dll SUCCESS Attributes: A