"Time of Day","Process Name","PID","Operation","Path","Result","Detail"
"13:34:02.3421508","_INS5576._MP","4732","RegOpenKey","HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer","REPARSE","Desired Access: Query Value"
"13:34:02.3421985","_INS5576._MP","4732","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations","NAME NOT FOUND","Length: 144"
"13:34:02.3422393","_INS5576._MP","4732","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NAME NOT FOUND","Desired Access: Query Value"
"13:34:02.3433885","_INS5576._MP","4732","RegOpenKey","HKLM\SOFTWARE\Wow6432Node\Microsoft\CTF\KnownClasses","NAME NOT FOUND","Desired Access: Read"
"13:34:02.3561582","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3561796","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3561998","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3562192","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3562381","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3562570","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3562761","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3562947","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3563136","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3563320","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3563501","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3563677","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3563856","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3564029","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3564203","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3564376","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3564550","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3564720","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3564891","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3565060","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3565223","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3565386","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3565550","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3565710","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3565869","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3566024","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.3566101","_INS5576._MP","4732","ReadFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_ISTMP0.DIR\license.txt","END OF FILE","Offset: 3,242, Length: 4,096"
"13:34:02.7895917","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:02.7896404","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:02.7899599","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:02.7901479","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:02.7919891","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:05.7888660","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:05.7889760","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:05.7896843","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:05.7900058","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:05.7933447","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:08.7996001","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:08.7996986","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:08.8003855","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:08.8007021","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:08.8040155","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:11.8104112","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:11.8105212","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:11.8112308","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:11.8115536","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:11.8149987","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:14.8211514","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:14.8212594","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:14.8219613","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:14.8222841","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:14.8256582","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:17.8319294","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:17.8320386","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:17.8327232","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:17.8330462","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:17.8363995","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:19.5623649","_INS5576._MP","4732","RegOpenKey","HKLM\SOFTWARE\Wow6432Node\Microsoft\CTF\KnownClasses","NAME NOT FOUND","Desired Access: Read"
"13:34:19.5651644","_INS5576._MP","4732","RegOpenKey","HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths","REPARSE","Desired Access: Maximum Allowed"
"13:34:19.5652142","_INS5576._MP","4732","RegOpenKey","HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE","REPARSE","Desired Access: Maximum Allowed"
"13:34:19.5657679","_INS5576._MP","4732","CreateFileMapping","C:\Program Files\Internet Explorer\iexplore.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
"13:34:19.5703349","_INS5576._MP","4732","CreateFileMapping","C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
"13:34:19.5710195","_INS5576._MP","4732","CreateFileMapping","C:\Program Files\Internet Explorer\iexplore.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
"13:34:19.5713744","_INS5576._MP","4732","CreateFileMapping","C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
"13:34:19.5729045","_INS5576._MP","4732","RegOpenKey","HKLM\SOFTWARE\Wow6432Node\Microsoft\CTF\KnownClasses","NAME NOT FOUND","Desired Access: Read"
"13:34:20.8494575","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:20.8495595","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:20.8502201","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:20.8505396","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:20.8538515","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"
"13:34:23.8550446","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a"
"13:34:23.8551405","_ISDEL.EXE","3440","CreateFile","C:\stopthis.now","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:23.8557794","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:23.8560764","_ISDEL.EXE","3440","CreateFile","C:\Windows\_INS33IS._MP","NAME NOT FOUND","Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"13:34:23.8591268","_ISDEL.EXE","3440","CreateFile","C:\Users\Westyfield2\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP","SHARING VIOLATION","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: n/a"