24790	2:50:03.2171957 PM	RA3Beta.exe	388	Process Start		SUCCESS	Parent PID: 600
24791	2:50:03.2171999 PM	RA3Beta.exe	388	Thread Create		SUCCESS	Thread ID: 2100
24798	2:50:03.2180712 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24820	2:50:03.2185777 PM	RA3Beta.exe	388	Load Image	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Image Base: 0x400000, Image Size: 0x468000
24842	2:50:03.2193146 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Image Base: 0x7c900000, Image Size: 0xaf000
24843	2:50:03.2193404 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24856	2:50:03.2196932 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened
24858	2:50:03.2198600 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	AllocationSize: 28,672, EndOfFile: 25,332, NumberOfLinks: 1, DeletePending: False, Directory: False
24859	2:50:03.2200094 PM	RA3Beta.exe	388	ReadFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Offset: 0, Length: 25,332
24869	2:50:03.2211738 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	
24870	2:50:03.2212420 PM	RA3Beta.exe	388	CreateFile	C:	SUCCESS	Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24871	2:50:03.2212940 PM	RA3Beta.exe	388	QueryInformationVolume	C:	SUCCESS	VolumeCreationTime: 4/3/2006 7:12:44 PM, VolumeSerialNumber: 081F-ADCB, SupportsObjects: True, VolumeLabel: 
24872	2:50:03.2213227 PM	RA3Beta.exe	388	FileSystemControl	C:	SUCCESS	Control: FSCTL_FILE_PREFETCH
24874	2:50:03.2214194 PM	RA3Beta.exe	388	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24881	2:50:03.2216532 PM	RA3Beta.exe	388	QueryDirectory	C:\	SUCCESS	0: boot.ini, 1: changes, 2: Documents and Settings, 3: Downloads, 4: IO.SYS, 5: Moo, 6: MSDOS.SYS, 7: NTDETECT.COM, 8: ntldr, 9: pagefile.sys, 10: Program Files, 11: RECYCLER, 12: System Volume Information, 13: WINDOWS
24882	2:50:03.2217971 PM	RA3Beta.exe	388	QueryDirectory	C:\	NO MORE FILES	
24883	2:50:03.2218423 PM	RA3Beta.exe	388	CloseFile	C:\	SUCCESS	
24885	2:50:03.2220119 PM	RA3Beta.exe	388	CreateFile	C:\PROGRAM FILES	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24886	2:50:03.2220664 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files	SUCCESS	0: ., 1: .., 2: Adaptec ASPI, 3: Adobe Fireworks CS3, 4: AIM, 5: Alesis, 6: ATI Technologies, 7: Avira, 8: BearShare, 9: BlueTooth, 10: CCleaner, 11: Common Files, 12: CVSNT, 13: Defraggler, 14: DOSBox-0.72, 15: Eraser, 16: filehippo.com, 17: FileZilla FTP Client, 18: Firefox, 19: Foxit Reader, 20: HashTab Shell Extension, 21: I8kfanGUI, 22: InstallShield Installation Information, 23: Intel, 24: Internet Explorer, 25: Java, 26: JkDefrag, 27: K-Lite Codec Pack, 28: Logitech, 29: Luminescence, 30: MagicDisc, 31: MagicISO, 32: Media Player Classic, 33: Microsoft CAPICOM 2.1.0.2, 34: microsoft frontpage, 35: movie maker, 36: Mozilla Thunderbird, 37: Mp3tag, 38: msn gaming zone, 39: MSXML 4.0, 40: MSXML 6.0, 41: Nero 8, 42: NetMeeting, 43: Notepad++, 44: outlook express, 45: PeerGuardian2, 46: PowerISO, 47: PowerMenu, 48: QuickTime Alternative, 49: Red Alert 3 Beta, 50: Reference Assemblies, 51: RegSupreme Pro, 52: Revo Uninstaller, 53: Security, 54: ShellNewARE, 55: Sigmatel, 56: SMPlayer, 57: Sony, 58: Spybot - ?azd
24888	2:50:03.2222924 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files	NO MORE FILES	
24889	2:50:03.2223391 PM	RA3Beta.exe	388	CloseFile	C:\Program Files	SUCCESS	
24892	2:50:03.2225335 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24894	2:50:03.2226581 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech	SUCCESS	0: ., 1: .., 2: SetPoint
24900	2:50:03.2229542 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech	NO MORE FILES	
24901	2:50:03.2230724 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech	SUCCESS	
24905	2:50:03.2234543 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24907	2:50:03.2236415 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech\SetPoint	SUCCESS	0: ., 1: .., 2: AdobeHookDll.dll, 3: AOLHookDll.dll, 4: AppCmd.xml, 5: Bluetooth Connection Assistant.lnk, 6: BTWizard, 7: config.ini, 8: Connect.exe, 9: contacts_warranties.chm, 10: default.xml, 11: externalapps.xml, 12: game.xml, 13: GameHook.dll, 14: gettingstarted.chm, 15: HelpLinks.xml, 16: highresolution.xml, 17: HookDll.dll, 18: Images, 19: IMHook.dll, 20: kbcplext.dll, 21: KEM.xml, 22: KEM.xmlres, 23: KEMHook.dll, 24: KEMMAPI.dll, 25: KemUI.dll, 26: KEMUI.xml, 27: KEMUI.xmlres, 28: keyboard_tp.chm, 29: KGame.dll, 30: Launcher.exe, 31: LBTWiz.exe, 32: LBTWizGI.dll, 33: LBTWizGI.xml, 34: LBTWizGI.xmlres, 35: LCabHandler.dll, 36: lcamera.exe, 37: lgscroll.dll, 38: LHelpBrowser.exe, 39: Logitech web site for Bluetooth.URL, 40: logo.gif, 41: LRFWiz.exe, 42: LRFWiz.xml, 43: LRFWiz.xmlres, 44: LU, 45: Macros, 46: mcplext.dll, 47: mediapad_tp.chm, 48: MessengerHook.dll, 49: mouse_tp.chm, 50: MX5000.dll, 51: MX5500.dll, 52: NonElevatedDll.dll, 53: players.ini, 54: Readme.htm, 55: recrlist.txt, 56: remote_tp.ch?azc ? 0: ., 1: .., 2: AdobeHookDll.dll, 3: AOLHookDll.dll, 4: AppCmd.xml, 5: Bluetooth Connection Assistant.lnk, 6: BTWizard, 7: config.ini, 8: Connect.exe, 9: contacts_warranties.chm, 10: default.xml, 11: externalapps.xml, 12: game.xml, 13: GameHook.dll, 14: gettingstarted.chm, 15: HelpLinks.xml, 16: highresolution.xml, 17: HookDll.dll, 18: Images, 19: IMHook.dll, 20: kbcplext.dll, 21: KEM.xml, 22: KEM.xmlres, 23: KEMHook.dll, 24: KEMMAPI.dll, 25: KemUI.dll, 26: KEMUI.xml, 27: KEMUI.xmlres, 28: keyboard_tp.chm, 29: KGame.dll, 30: Launcher.exe, 31: LBTWiz.exe, 32: LBTWizGI.dll, 33: LBTWizGI.xml, 34: LBTWizGI.xmlres, 35: LCabHandler.dll, 36: lcamera.exe, 37: lgscroll.dll, 38: LHelpBrowser.exe, 39: Logitech web site for Bluetooth.URL, 40: logo.gif, 41: LRFWiz.exe, 42: LRFWiz.xml, 43: LRFWiz.xmlres, 44: LU, 45: Macros, 46: mcplext.dll, 47: mediapad_tp.chm, 48: MessengerHook.dll, 49: mouse_tp.chm, 50: MX5000.dll, 51: MX5500.dll, 52: NonElevatedDll.dll, 53: players.ini, 54: Readme.htm, 55: recrlist.txt, 56: remote_tp.chm, 57: RunNE.exe, 58: Search.xml, 59: setpoint.chm, 60: SetPoint.exe, 61: SetPointCOM.dll, 62: SetPointCOMMM9.dll, 63: SetPointCOMWMP9.dll, 64: SetPointSummary_000.log, 65: SetPoint_000.log, 66: Sounds, 67: Strings.xml, 68: WebBrowserSupport.dll, 69: 
24910	2:50:03.2239228 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech\SetPoint	NO MORE FILES	
24915	2:50:03.2241211 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech\SetPoint	SUCCESS	
24919	2:50:03.2242429 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\RED ALERT 3 BETA	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24920	2:50:03.2242927 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta	SUCCESS	0: ., 1: .., 2: Core, 3: EnglishAudio, 4: Lang-english, 5: Launcher, 6: LauncherSupport.dat, 7: Maps, 8: Movies, 9: notepad-MCE.lnk, 10: notepad-MCE.png, 11: notepad-MCE.xml, 12: patchw32.dll, 13: ra3.ico, 14: RA3Beta.exe, 15: ra3_english_1.0.SkuDef, 16: RetailExe, 17: Support, 18: VistaShellSupport.dll
24921	2:50:03.2243907 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta	NO MORE FILES	
24923	2:50:03.2244362 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta	SUCCESS	
24926	2:50:03.2246371 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\Launcher	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24931	2:50:03.2247760 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\Launcher	SUCCESS	0: ., 1: .., 2: 480banner.bmp, 3: 640banner.bmp, 4: bfme2button.bmp, 5: bfme2thumb.jpg, 6: bordercenter.bmp, 7: bordercorner.bmp, 8: captioncenter.bmp, 9: captionend.bmp, 10: cnc.bmp, 11: english.csf, 12: icon.bmp, 13: rotwkbutton.bmp, 14: splash.bmp, 15: thumb.jpg, 16: Thumbs.db
24935	2:50:03.2249399 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\Launcher	NO MORE FILES	
24936	2:50:03.2252215 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\Launcher	SUCCESS	
24938	2:50:03.2253475 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RETAILEXE	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24939	2:50:03.2254009 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	0: ., 1: .., 2: 1.0
24940	2:50:03.2254872 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe	NO MORE FILES	
24941	2:50:03.2256171 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	
24943	2:50:03.2257951 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24944	2:50:03.2259255 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	0: ., 1: .., 2: config.txt, 3: data, 4: dbghelp.dll, 5: gl.ini, 6: paul.dll, 7: ra3game.dat, 8: winui.dll, 9: xinput1_3.dll
24945	2:50:03.2260851 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	NO MORE FILES	
24946	2:50:03.2261823 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	
24948	2:50:03.2263700 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24949	2:50:03.2264745 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS	SUCCESS	0: ., 1: .., 2: 003301_.tmp, 3: addins, 4: AppPatch, 5: aspack.ini, 6: assembly, 7: atid.ini, 8: BLDLITE.EXE, 9: bootstat.dat, 10: cdface32.ini, 11: ContextMenuExt.dll, 12: control.ini, 13: CSC, 14: Ctregrun.exe, 15: Cursors, 16: d3dx.dat, 17: d3dx9_29.dll, 18: Debug, 19: dellstat.ini, 20: desktop.ini, 21: diagerr.xml, 22: diagwrn.xml, 23: DirectX.log, 24: Downloaded Installations, 25: Downloaded Program Files, 26: Driver Cache, 27: dsdxirmv.exe, 28: ehome, 29: eReg.dat, 30: explorer.exe, 31: explorer.scf, 32: Fonts, 33: ftpcache, 34: help, 35: helpwrit.ini, 36: hh.exe, 37: ie8, 38: ie8updates, 39: ime, 40: inf, 41: INRES.DLL, 42: Installer, 43: IsUninst.exe, 44: iun6002.exe, 45: java, 46: KHALMNPR.Exe, 47: l2schemas, 48: lame_enc.dll, 49: LastGood, 50: libiconv2.dll, 51: libintl3.dll, 52: Logs, 53: Microsoft.NET, 54: Minidump, 55: mozver.dat, 56: msagent, 57: msapps, 58: msdfmap.ini, 59: msdownld.tmp, 60: msoffice.ini, 61: mui, 62: my.ini, 63: neo20.ini, 64: nero.INI, 65: NeroDigital.ini, 66: network diagnos?azc ? 0: ., 1: .., 2: 003301_.tmp, 3: addins, 4: AppPatch, 5: aspack.ini, 6: assembly, 7: atid.ini, 8: BLDLITE.EXE, 9: bootstat.dat, 10: cdface32.ini, 11: ContextMenuExt.dll, 12: control.ini, 13: CSC, 14: Ctregrun.exe, 15: Cursors, 16: d3dx.dat, 17: d3dx9_29.dll, 18: Debug, 19: dellstat.ini, 20: desktop.ini, 21: diagerr.xml, 22: diagwrn.xml, 23: DirectX.log, 24: Downloaded Installations, 25: Downloaded Program Files, 26: Driver Cache, 27: dsdxirmv.exe, 28: ehome, 29: eReg.dat, 30: explorer.exe, 31: explorer.scf, 32: Fonts, 33: ftpcache, 34: help, 35: helpwrit.ini, 36: hh.exe, 37: ie8, 38: ie8updates, 39: ime, 40: inf, 41: INRES.DLL, 42: Installer, 43: IsUninst.exe, 44: iun6002.exe, 45: java, 46: KHALMNPR.Exe, 47: l2schemas, 48: lame_enc.dll, 49: LastGood, 50: libiconv2.dll, 51: libintl3.dll, 52: Logs, 53: Microsoft.NET, 54: Minidump, 55: mozver.dat, 56: msagent, 57: msapps, 58: msdfmap.ini, 59: msdownld.tmp, 60: msoffice.ini, 61: mui, 62: my.ini, 63: neo20.ini, 64: nero.INI, 65: NeroDigital.ini, 66: network diagnostic, 67: notepad.exe, 68: notepro.ini, 69: nsreg.dat, 70: NSTSPPRT.INI, 71: occache, 72: ODBC.INI, 73: ODBCINST.INI, 74: Offline Web Pages, 75: OpenALwEAX.exe, 76: pchealth, 77: PDF2HTML.INI, 78: PeerNet, 79: Performance, 80: PIF, 81: pkzipw.ini, 82: Prefetch, 83: Provisioning, 84: pss, 85: radrun.exe, 86: regedit.exe, 87: RegisteredPackages, 88: Registration, 89: repair, 90: Resources, 91: rzrunins.exe, 92: SBWIN.INI, 93: SchedLgU.Txt, 94: security, 95: ServicePackFiles, 96: setpwrcg.exe, 97: Setup1.exe, 98: setupapi.log, 99: ShellNew, 100: slrundll.exe, 101: smscfg.ini, 102: snymsico.dll, 103: SoftwareDistribution, 104: srchasst, 105: ST6UNST.EXE, 106: Sti_Trace.log, 107: stsystra.exe, 108: Sun, 109: SxsCaPendDel, 110: system, 111: system.ini, 112: system32, 113: T30DebugLogFile.txt, 114: TASKMAN.EXE, 115: Tasks, 116: Temp, 117: tosOBEX.INI, 118: twain.dll, 119: twain_32, 120: twain_32.dll, 121: twunk_16.exe, 122: twunk_32.exe, 123: uedit32.ini, 124: UnDeploy.exe, 125: uninst.exe, 126: UNRecode.cfg, 127: UNRecode.exe, 128: UNWISE.EXE, 129: vb.ini, 130: vbaddin.ini, 131: vmmreg32.dll, 132: WBEM, 133: Web, 134: wiadebug.log, 135: wiaservc.log, 136: win.ini, 137: winamp_plugger.dll, 138: WindowsShell.Manifest, 139: WindowsUpdate.log, 140: winhelp.exe, 141: winhlp32.exe, 142: wininit.ini, 143: winnt.bmp, 144: winnt256.bmp, 145: winoncd.ini, 146: WinSxS, 147: WirelessFTP.INI, 148: wise.ini, 149: WMSysPr9.prx, 150: WORDPAD.INI, 151: xnview.ini, 152: _default.pif, 153
24950	2:50:03.2268377 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS	NO MORE FILES	
24951	2:50:03.2269670 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS	SUCCESS	
24953	2:50:03.2272120 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24954	2:50:03.2273741 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\AppPatch	SUCCESS	0: ., 1: .., 2: acadproc.dll, 3: acgenral.dll, 4: aclayers.dll, 5: aclua.dll, 6: acspecfc.dll, 7: acxtrnal.dll, 8: apphelp.sdb, 9: apph_sp.sdb, 10: drvmain.sdb, 11: msimain.sdb, 12: sysmain.sdb
24955	2:50:03.2276042 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\AppPatch	NO MORE FILES	
24956	2:50:03.2277518 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\AppPatch	SUCCESS	
24958	2:50:03.2280046 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24959	2:50:03.2281817 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: ., 1: .., 2: $ncsp$.inf, 3: $winnt$.inf, 4: 1025, 5: 1028, 6: 1031, 7: 1033, 8: 1037, 9: 1041, 10: 1042, 11: 1054, 12: 12520437.cpx, 13: 12520850.cpx, 14: 2052, 15: 3076, 16: 3com_dmi, 17: 6to4svc.dll, 18: a3d.dll, 19: aaaamon.dll, 20: aaclient.dll, 21: aamd532.dll, 22: ac3acm.acm, 23: access.cpl, 24: acctres.dll, 25: accwiz.exe, 26: acelpdec.ax, 27: acledit.dll, 28: aclui.dll, 29: activeds.dll, 30: activeds.tlb, 31: actmovie.exe, 32: actskn43.ocx, 33: actskn43.ocx.bak, 34: actxprxy.dll, 35: admparse.dll, 36: Adobe, 37: adptif.dll, 38: adsldp.dll, 39: adsldpc.dll, 40: adsmsext.dll, 41: adsnds.dll, 42: adsnt.dll, 43: adsnw.dll, 44: advapi32.dll, 45: advpack.dll, 46: advpack.dll.mui, 47: ahui.exe, 48: Alesisasio.dll, 49: AlesisFirewireAsio.dll, 50: alg.exe, 51: alrsvc.dll, 52: amcompat.tlb, 53: amstream.dll, 54: ansi.sys, 55: apcups.dll, 56: append.exe, 57: apphelp.dll, 58: appmgmt, 59: appmgmts.dll, 60: appmgr.dll, 61: appwiz.cpl, 62: arp.exe, 63: asctrls.ocx, 64: asferror.dll, 65: asr_fmt.exe, 66: asr_ldm.?azcŸ>u?24790	2:50:03.2171957 PM	RA3Beta.exe	388	Process Start		SUCCESS	Parent PID: 600
24791	2:50:03.2171999 PM	RA3Beta.exe	388	Thread Create		SUCCESS	Thread ID: 2100
24798	2:50:03.2180712 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24820	2:50:03.2185777 PM	RA3Beta.exe	388	Load Image	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Image Base: 0x400000, Image Size: 0x468000
24842	2:50:03.2193146 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Image Base: 0x7c900000, Image Size: 0xaf000
24843	2:50:03.2193404 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24856	2:50:03.2196932 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened
24858	2:50:03.2198600 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	AllocationSize: 28,672, EndOfFile: 25,332, NumberOfLinks: 1, DeletePending: False, Directory: False
24859	2:50:03.2200094 PM	RA3Beta.exe	388	ReadFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Offset: 0, Length: 25,332
24869	2:50:03.2211738 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	
24870	2:50:03.2212420 PM	RA3Beta.exe	388	CreateFile	C:	SUCCESS	Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24871	2:50:03.2212940 PM	RA3Beta.exe	388	QueryInformationVolume	C:	SUCCESS	VolumeCreationTime: 4/3/2006 7:12:44 PM, VolumeSerialNumber: 081F-ADCB, SupportsObjects: True, VolumeLabel: 
24872	2:50:03.2213227 PM	RA3Beta.exe	388	FileSystemControl	C:	SUCCESS	Control: FSCTL_FILE_PREFETCH
24874	2:50:03.2214194 PM	RA3Beta.exe	388	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24881	2:50:03.2216532 PM	RA3Beta.exe	388	QueryDirectory	C:\	SUCCESS	0: boot.ini, 1: changes, 2: Documents and Settings, 3: Downloads, 4: IO.SYS, 5: Moo, 6: MSDOS.SYS, 7: NTDETECT.COM, 8: ntldr, 9: pagefile.sys, 10: Program Files, 11: RECYCLER, 12: System Volume Information, 13: WINDOWS
24882	2:50:03.2217971 PM	RA3Beta.exe	388	QueryDirectory	C:\	NO MORE FILES	
24883	2:50:03.2218423 PM	RA3Beta.exe	388	CloseFile	C:\	SUCCESS	
24885	2:50:03.2220119 PM	RA3Beta.exe	388	CreateFile	C:\PROGRAM FILES	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24886	2:50:03.2220664 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files	SUCCESS	0: ., 1: .., 2: Adaptec ASPI, 3: Adobe Fireworks CS3, 4: AIM, 5: Alesis, 6: ATI Technologies, 7: Avira, 8: BearShare, 9: BlueTooth, 10: CCleaner, 11: Common Files, 12: CVSNT, 13: Defraggler, 14: DOSBox-0.72, 15: Eraser, 16: filehippo.com, 17: FileZilla FTP Client, 18: Firefox, 19: Foxit Reader, 20: HashTab Shell Extension, 21: I8kfanGUI, 22: InstallShield Installation Information, 23: Intel, 24: Internet Explorer, 25: Java, 26: JkDefrag, 27: K-Lite Codec Pack, 28: Logitech, 29: Luminescence, 30: MagicDisc, 31: MagicISO, 32: Media Player Classic, 33: Microsoft CAPICOM 2.1.0.2, 34: microsoft frontpage, 35: movie maker, 36: Mozilla Thunderbird, 37: Mp3tag, 38: msn gaming zone, 39: MSXML 4.0, 40: MSXML 6.0, 41: Nero 8, 42: NetMeeting, 43: Notepad++, 44: outlook express, 45: PeerGuardian2, 46: PowerISO, 47: PowerMenu, 48: QuickTime Alternative, 49: Red Alert 3 Beta, 50: Reference Assemblies, 51: RegSupreme Pro, 52: Revo Uninstaller, 53: Security, 54: ShellNewARE, 55: Sigmatel, 56: SMPlayer, 57: Sony, 58: Spybot - ?azd
24888	2:50:03.2222924 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files	NO MORE FILES	
24889	2:50:03.2223391 PM	RA3Beta.exe	388	CloseFile	C:\Program Files	SUCCESS	
24892	2:50:03.2225335 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24894	2:50:03.2226581 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech	SUCCESS	0: ., 1: .., 2: SetPoint
24900	2:50:03.2229542 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech	NO MORE FILES	
24901	2:50:03.2230724 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech	SUCCESS	
24905	2:50:03.2234543 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24907	2:50:03.2236415 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech\SetPoint	SUCCESS	0: ., 1: .., 2: AdobeHookDll.dll, 3: AOLHookDll.dll, 4: AppCmd.xml, 5: Bluetooth Connection Assistant.lnk, 6: BTWizard, 7: config.ini, 8: Connect.exe, 9: contacts_warranties.chm, 10: default.xml, 11: externalapps.xml, 12: game.xml, 13: GameHook.dll, 14: gettingstarted.chm, 15: HelpLinks.xml, 16: highresolution.xml, 17: HookDll.dll, 18: Images, 19: IMHook.dll, 20: kbcplext.dll, 21: KEM.xml, 22: KEM.xmlres, 23: KEMHook.dll, 24: KEMMAPI.dll, 25: KemUI.dll, 26: KEMUI.xml, 27: KEMUI.xmlres, 28: keyboard_tp.chm, 29: KGame.dll, 30: Launcher.exe, 31: LBTWiz.exe, 32: LBTWizGI.dll, 33: LBTWizGI.xml, 34: LBTWizGI.xmlres, 35: LCabHandler.dll, 36: lcamera.exe, 37: lgscroll.dll, 38: LHelpBrowser.exe, 39: Logitech web site for Bluetooth.URL, 40: logo.gif, 41: LRFWiz.exe, 42: LRFWiz.xml, 43: LRFWiz.xmlres, 44: LU, 45: Macros, 46: mcplext.dll, 47: mediapad_tp.chm, 48: MessengerHook.dll, 49: mouse_tp.chm, 50: MX5000.dll, 51: MX5500.dll, 52: NonElevatedDll.dll, 53: players.ini, 54: Readme.htm, 55: recrlist.txt, 56: remote_tp.ch?azc
24960	2:50:03.2287650 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: diactfrm.dll, 1: diantz.exe, 2: DiceAsio.dll, 3: DiceController.dll, 4: digest.dll, 5: dimap.dll, 6: dimsntfy.dll, 7: dimsroam.dll, 8: dinput.dll, 9: dinput8.dll, 10: DirectX, 11: diskcomp.com, 12: diskcopy.com, 13: diskcopy.dll, 14: diskmgmt.msc, 15: diskpart.exe, 16: diskperf.exe, 17: dispex.dll, 18: divx.dll, 19: dllcache, 20: dllhost.exe, 21: dllhst3g.exe, 22: DLPT2.sys, 23: dmadmin.exe, 24: dmband.dll, 25: dmcompos.dll, 26: dmconfig.dll, 27: dmdlgs.dll, 28: dmdskmgr.dll, 29: dmdskres.dll, 30: dmime.dll, 31: dmintf.dll, 32: dmloader.dll, 33: dmocx.dll, 34: dmremote.exe, 35: dmscript.dll, 36: dmserver.dll, 37: dmstyle.dll, 38: dmsynth.dll, 39: dmusic.dll, 40: dmutil.dll, 41: dmview.ocx, 42: dns-sd.exe, 43: dnsapi.dll, 44: dnsrslvr.dll, 45: dnssd.dll, 46: docprop.dll, 47: docprop2.dll, 48: doskey.exe, 49: dosx.exe, 50: dot3api.dll, 51: dot3cfg.dll, 52: dot3dlg.dll, 53: dot3gpclnt.dll, 54: dot3msm.dll, 55: dot3svc.dll, 56: dot3ui.dll, 57: dpcdll.dll, 58: dpl100.dll, 59: dplay.dll, 60: dplaysvr.exe, 61: dp?azc ? 0: diactfrm.dll, 1: diantz.exe, 2: DiceAsio.dll, 3: DiceController.dll, 4: digest.dll, 5: dimap.dll, 6: dimsntfy.dll, 7: dimsroam.dll, 8: dinput.dll, 9: dinput8.dll, 10: DirectX, 11: diskcomp.com, 12: diskcopy.com, 13: diskcopy.dll, 14: diskmgmt.msc, 15: diskpart.exe, 16: diskperf.exe, 17: dispex.dll, 18: divx.dll, 19: dllcache, 20: dllhost.exe, 21: dllhst3g.exe, 22: DLPT2.sys, 23: dmadmin.exe, 24: dmband.dll, 25: dmcompos.dll, 26: dmconfig.dll, 27: dmdlgs.dll, 28: dmdskmgr.dll, 29: dmdskres.dll, 30: dmime.dll, 31: dmintf.dll, 32: dmloader.dll, 33: dmocx.dll, 34: dmremote.exe, 35: dmscript.dll, 36: dmserver.dll, 37: dmstyle.dll, 38: dmsynth.dll, 39: dmusic.dll, 40: dmutil.dll, 41: dmview.ocx, 42: dns-sd.exe, 43: dnsapi.dll, 44: dnsrslvr.dll, 45: dnssd.dll, 46: docprop.dll, 47: docprop2.dll, 48: doskey.exe, 49: dosx.exe, 50: dot3api.dll, 51: dot3cfg.dll, 52: dot3dlg.dll, 53: dot3gpclnt.dll, 54: dot3msm.dll, 55: dot3svc.dll, 56: dot3ui.dll, 57: dpcdll.dll, 58: dpl100.dll, 59: dplay.dll, 60: dplaysvr.exe, 61: dplayx.dll, 62: dpmodemx.dll, 63: dpnaddr.dll, 64: dpnet.dll, 65: dpnhpast.dll, 66: dpnhupnp.dll, 67: dpnlobby.dll, 68: dpnmodem.dll, 69: dpnsvr.exe, 70: dpnwsock.dll, 71: dpserial.dll, 72: dpvacm.dll, 73: dpvoice.dll, 74: dpvsetup.exe, 75: dpvvox.dll, 76: dpwsock.dll, 77: dpwsockx.dll, 78: driverquery.exe, 79: d?O?A                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        
24961	2:50:03.2294819 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: JkDefragScreenSaver.scr, 1: jobexec.dll, 2: joy.cpl, 3: jscript.dll, 4: jsproxy.dll, 5: jupdate-1.4.2_03-b02.log, 6: jupdate-1.5.0_05-b05.log, 7: jupdate-1.5.0_06-b05.log, 8: jupdate-1.6.0_03-b05.log, 9: jupdate-1.6.0_04-b12.log, 10: jupdate-1.6.0_06-b02.log, 11: jupdate-1.6.0_07-b06.log, 12: kanji_1.uce, 13: kanji_2.uce, 14: kb16.com, 15: kbd106.dll, 16: KBDAL.DLL, 17: kbdaze.dll, 18: kbdazel.dll, 19: kbdbe.dll, 20: kbdbene.dll, 21: kbdbhc.dll, 22: kbdblr.dll, 23: kbdbr.dll, 24: kbdbu.dll, 25: kbdca.dll, 26: kbdcan.dll, 27: kbdcr.dll, 28: kbdcz.dll, 29: kbdcz1.dll, 30: kbdcz2.dll, 31: kbdda.dll, 32: kbddv.dll, 33: kbdes.dll, 34: kbdest.dll, 35: kbdfc.dll, 36: kbdfi.dll, 37: kbdfi1.dll, 38: kbdfo.dll, 39: kbdfr.dll, 40: kbdgae.dll, 41: kbdgkl.dll, 42: kbdgr.dll, 43: kbdgr1.dll, 44: kbdhe.dll, 45: kbdhe220.dll, 46: kbdhe319.dll, 47: kbdhela2.dll, 48: kbdhela3.dll, 49: kbdhept.dll, 50: kbdhu.dll, 51: kbdhu1.dll, 52: kbdic.dll, 53: kbdinbe1.dll, 54: kbdinben.dll, 55: kbdinmal.dll, 56: kbdir.dll, 57: kbdit.dll?azc ? 24790	2:50:03.2171957 PM	RA3Beta.exe	388	Process Start		SUCCESS	Parent PID: 600
24791	2:50:03.2171999 PM	RA3Beta.exe	388	Thread Create		SUCCESS	Thread ID: 2100
24798	2:50:03.2180712 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24820	2:50:03.2185777 PM	RA3Beta.exe	388	Load Image	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Image Base: 0x400000, Image Size: 0x468000
24842	2:50:03.2193146 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Image Base: 0x7c900000, Image Size: 0xaf000
24843	2:50:03.2193404 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24856	2:50:03.2196932 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened
24858	2:50:03.2198600 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	AllocationSize: 28,672, EndOfFile: 25,332, NumberOfLinks: 1, DeletePending: False, Directory: False
24859	2:50:03.2200094 PM	RA3Beta.exe	388	ReadFile	C:\WINDOWS\?O?A                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    
24962	2:50:03.2301118 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: msr2c.dll, 1: msr2cenu.dll, 2: msratelc.dll, 3: msrating.dll, 4: msrclr40.dll, 5: msrd2x40.dll, 6: msrd3x40.dll, 7: MSRDO20.DLL, 8: msrecr40.dll, 9: msrepl40.dll, 10: msrle32.dll, 11: mssap.dll, 12: msscds32.ax, 13: msscp.dll, 14: msscript.ocx, 15: mssha.dll, 16: msshavmsg.dll, 17: mssign32.dll, 18: mssip32.dll, 19: MSSTDFMT.DLL, 20: msstkprp.dll, 21: msswch.dll, 22: msswchx.exe, 23: mstask.dll, 24: mstext40.dll, 25: mstime.dll, 26: mstinit.exe, 27: mstlsapi.dll, 28: mstsc.exe, 29: mstscax.dll, 30: msutb.dll, 31: msv1_0.dll, 32: msvbvm50.dll, 33: msvbvm60.dll, 34: msvcirt.dll, 35: msvcp50.dll, 36: msvcp60.dll, 37: msvcp70.dll, 38: msvcp71.dll, 39: msvcp80.dll, 40: msvcr70.dll, 41: msvcr71.dll, 42: msvcr80.dll, 43: msvcrt.dll, 44: msvcrt20.dll, 45: msvcrt40.dll, 46: msvfw32.dll, 47: msvidc32.dll, 48: msvidctl.dll, 49: msvideo.dll, 50: msw3prt.dll, 51: mswdat10.dll, 52: mswebdvd.dll, 53: MSWINSCK.OCX, 54: mswmdm.dll, 55: mswsock.dll, 56: mswstr10.dll, 57: msxbde40.dll, 58: msxml.dll, 59: msxml2r.dll, 60: msx?azc ? 0: msr2c.dll, 1: msr2cenu.dll, 2: msratelc.dll, 3: msrating.dll, 4: msrclr40.dll, 5: msrd2x40.dll, 6: msrd3x40.dll, 7: MSRDO20.DLL, 8: msrecr40.dll, 9: msrepl40.dll, 10: msrle32.dll, 11: mssap.dll, 12: msscds32.ax, 13: msscp.dll, 14: msscript.ocx, 15: mssha.dll, 16: msshavmsg.dll, 17: mssign32.dll, 18: mssip32.dll, 19: MSSTDFMT.DLL, 20: msstkprp.dll, 21: msswch.dll, 22: msswchx.exe, 23: mstask.dll, 24: mstext40.dll, 25: mstime.dll, 26: mstinit.exe, 27: mstlsapi.dll, 28: mstsc.exe, 29: mstscax.dll, 30: msutb.dll, 31: msv1_0.dll, 32: msvbvm50.dll, 33: msvbvm60.dll, 34: msvcirt.dll, 35: msvcp50.dll, 36: msvcp60.dll, 37: msvcp70.dll, 38: msvcp71.dll, 39: msvcp80.dll, 40: msvcr70.dll, 41: msvcr71.dll, 42: msvcr80.dll, 43: msvcrt.dll, 44: msvcrt20.dll, 45: msvcrt40.dll, 46: msvfw32.dll, 47: msvidc32.dll, 48: msvidctl.dll, 49: msvideo.dll, 50: msw3prt.dll, 51: mswdat10.dll, 52: mswebdvd.dll, 53: MSWINSCK.OCX, 54: mswmdm.dll, 55: mswsock.dll, 56: mswstr10.dll, 57: msxbde40.dll, 58: msxml.dll, 59: msxml2r.dll, 60: msxml3.dll, 61: msxml3r.dll, 62: msxml4.dll, 63: msxml4r.dll, 64: msxml6.dll, 65: msxml6r.dll, 66: msxmlr.dll, 67: msyuv.dll, 68: mtxclu.dll, 69: mtxdm.dll, 70: mtxex.dll, 71: mtxlegih.dll, 72: mtxoci.dll, 73: mtxparhd.dll, 74: mucltui.dll, 75: mui, 76: muweb.dll, 77: mycomput.dll, 78: mydocs.dll, 79: napipsec.dll, 80: napmontr.dll, 81: napstat.exe, 82: narrator.exe, 83: narrhook.dll, 84: nbtstat.exe, 85: ncobjapi.dll, 86: ncpa.cpl, 87: ncpa.cpl.manifest, 88: ncxpnt.dll, 89: nddeapi.dll, 90: nddeapir.exe, 91: nddenb32.dll, 92: ndptsp.tsp, 93: net.exe, 94: net.hlp, 95: net1.exe, 96: netapi.dll, 97: netapi32.dll, 98: netcfgx.dll, 99: netdde.exe, 100: netevent.dll, 101: netfxperf.dll, 102: neth.dll, 103: netid.dll, 104: netlogon.dll, 105: netman.dll, 106: netmsg.dll, 107: netplwiz.dll, 108: netrap.dll, 109: netsetup.cpl, 110: netsetup.exe, 111: netsh.exe, 112: netshell.dll, 113: netstat.exe, 114: netui0.dll, 115: netui1.dll, 116: netui2.dll, 117: NETw3c32.dll, 118: NETw3r32.dll, 119: netware.drv, 120: newdev.dll, 121: nlhtml.dll, 122: nlsdl.dll, 123: nlsfunc.exe, 124: nmevtmsg.dll, 125: nmmkcert.dll, 126: noise.chs, 127: noise.cht, 128: noise.dat, 129: noise.deu, 130: noise.eng, 131: noise.enu, 132: noise.esn, 133: noise.fra, 134: noise.ita, 135: noise.nld, 136: noise.sve, 137: noise.tha, 138: normaliz.dll, 139: normidna.nls, 140: normnfc.nls, 141: normnfd.nls, 142: normnfkc.nls, 143: normnfkd.nls, 144: notepad.exe, 145: Npindeo.dll, 146: npp, 147: npptools.dll, 148: NPSWF32.dll, 149: NPSWF32_FlashUtil.exe, 150: npwmsdrm.dll, 151: NRad.dll, 152: nscompat.tlb, 153: nslookup.exe, 154: ntbackup.exe, 155: ntdll.dll, 156: ntdos.sys, 157: ntdos404.sys, 158: ntdos411.sys, 159: ntdos412.sys, 160: ntdos804.sys, 161: ntdsapi.dll, 162: ntdsbcli.dll, 163: ntimage.gif, 164: ntio.sys, 165: ntio404.sys, 166: ntio411.sys, 167: ntio412.sys, 168: ntio804.sys, 169: ntkrnlpa.exe, 170: ntlanman.dll, 171: ntlanui.dll, 172: ntlanui2.dll, 173: ntlsapi.dll, 174: ntmarta.dll, 175: ntmsapi.dll, 176: ntmsdba.dll, 177: ntmsevt.dll, 178: ntmsmgr.dll, 179: ntmsmgr.msc, 180: ntmsoprq.msc, 181: ntmssvc.dll, 182: ntoskrnl.exe, 183: ntprint.dll, 184: ntsd.exe, 185: ntsdexts.dll, 186: ntshrui.dll, 187: ntvdm.exe, 188: ntvdmd.dll, 189: nusrmgr.cpl, 190: nv4_disp.dll, 191: nw16.exe, 192: nwapi16.dll, 193: nwapi32.dll, 194: nwc.cpl, 195: nwc.cpl.manifest, 196: nwcfg.dll, 197: nwevent.dll, 198: nwprovau.dll, 199: nwscript.exe, 200: nwwks.dll, 201: oakley.dll, 202: objsel.dll, 203: occache.dll, 204: ocmanage.dll, 205: odbc16gt.dll, 206: odbc32.dll, 207: odbc32gt.dll, 208: odbcad32.exe, 209: odbcbcp.dll, 210: odbcconf.dll, 211: odbcconf.exe, 212: odbcconf.rsp, 213: odbccp32.cpl, 214: odbccp32.dll, 215: odbccr32.dll, 216: odbccu32.dll, 217: odbcint.dll, 218: odbcji32.dll, 219: odbcjt32.dll, 220: odbcp32r.dll, 221: odbctrac.dll, 222: oddbse32.dll, 223: odexl32.dll, 224: odfox32.dll, 225: odpdx32.dll, 226: odtext32.dll, 227: OEM.dll, 228: oembios.bin, 229: oembios.dat, 230: oembios.sig, 231: OEMBKGN1.BMP, 232: Oemdspif.dll, 233: OEMINFO.INI, 234: OEMINFO.PNF, 235: OEMLOGO.BMP, 236: offfilt.dll, 237: ole2.dll, 238: ole2disp.dll, 239: ole2nls.dll, 240: ole32.dll, 241: oleacc.dll, 242: oleaccrc.dll, 243: oleaut32.dll, 244: olecli.dll, 245: olecli32.dll, 246: olecnv32.dll, 247: oledlg.dll, 248: oleprn.dll, 249: olepro32.dll, 250: olesvr.dll, 251: olesvr32.dll, 252: olethk32.dll, 253: onex.dll, 254: oobe, 255: openfiles.exe, 256: opengl32.dll, 257: osk.exe, 258: osuninst.dll, 259: osuninst.exe, 260: p2p.dll, 261: p2pgasvc.dll, 262: p2pgraph.dll, 263: p2pnetsh.dll, 264: p2psvc.dll, 265: packager.exe, 266: pagefileconfig.vbs, 267: panmap.dll, 268: paqsp.dll, 269: pathping.exe, 270: pautoenr.dll, 271: PCCLPFR.DLL, 272: PCDLIB32.DLL, 273: pcl.sep, 274: pdf2html.dat, 275: pdh.dll, 276: pentnt.exe, 277: perfc009.dat, 278: perfci.h, 279: perfci.ini, 280: perfctrs.dll, 281: perfd009.dat, 282: perfdisk.dll, 283: perffilt.h, 284: perffilt.ini, 285: perfh009.dat, 286: perfi009.dat, 287: perfmon.exe, 288: perfmon.msc, 289: perfnet.dll, 290: perfnw.dll, 291: perfos.dll, 292: perfproc.dll, 293: PerfStringBackup.INI, 294: perfts.dll, 295: perfwci.h, 296: perfwci.ini, 297: photometadatahandler.dll, 298: photowiz.dll, 299: PICCLP32.OCX, 300: pid.dll, 301: pid.inf, 302: pidgen.dll, 303: pifmgr.dll, 304: ping.exe, 305: ping6.exe, 306: pintool.exe, 307: pjlmon.dll, 308: plustab.dll, 309: pmspl.dll, 310: pncrt.dll, 311: pndx5016.dll, 312: pndx5032.dll, 313: pngfilt.dll, 314: pnrpnsp.dll, 315: polstore.dll, 316: popup.ocx, 317: PortableDeviceApi.dll, 318: PortableDeviceClassExtension.dll, 319: PortableDeviceTypes.dll, 320: PortableDeviceWiaCompat.dll, 321: PortableDeviceWMDRM.dll, 322: powercfg.cpl, 323: powercfg.exe, 324: PowerToyReadme.htm, 325: powrprof.dll, 326: PreInstall, 327: PresentationCFFRasterizerNative_v0300.dll, 328: PresentationHost.exe, 329: PresentationHostProxy.dll, 330: PresentationNative_v0300.dll, 331: prflbmsg.dll, 332: Primomonnt.dll, 333: print.exe, 334: printui.dll, 335: prncnfg.vbs, 336: prndrvr.vbs, 337: prnjobs.vbs, 338: prnmngr.vbs, 339: prnport.vbs, 340: prnqctl.vbs, 341: prntvpt.dll, 342: Probe.inf, 343: proctexe.ocx, 344: prodspec.ini, 345: profmap.dll, 346: progman.exe, 347: PropertyGrid.ocx, 348: ProphetConnect4.ocx, 349: proquota.exe, 350: proxycfg.exe, 351: psapi.dll, 352: psbase.dll, 353: pschdcnt.h, 354: pschdprf.dll, 355: pschdprf.ini, 356: pscript.sep, 357: psisdecd.dll, 358: psisrndr.ax, 359: psnppagn.dll, 360: pstorec.dll, 361: pstorsvc.dll, 362: ptpusb.dll, 363: ptpusd.dll, 364: pubprn.vbs, 365: px.dll, 366: pxafs.dll, 367: pxcpya64.exe, 368: pxdrv.dll, 369: pxhpinst.exe, 370: pxinsa64.exe, 371: pxinsi64.exe, 372: pxmas.dll, 373: pxsfs.dll, 374: pxwave.dll, 375: qagent.dll, 376: qagentrt.dll, 377: qappsrv.exe, 378: qasf.dll, 379: qcap.dll, 380: qcliprov.dll, 381: qdiagd.ocx, 382: qdv.dll, 383: qdvd.dll, 384: qedit.dll, 385: qedwipes.dll, 386: qmgr.dll, 387: qmgrprxy.dll, 388: qosname.dll, 389: qprocess.exe, 390: qt-dx331.dll, 391: quartz.dll, 392: query.dll, 393: QuickTime.qts, 394: QuickTimeVR.qtx, 395: qutil.dll, 396: qwinsta.exe, 397: racpldlg.dll, 398: Rad.dll, 399: RadClkR.dll, 400: RadClock.exe, 401: RadEnu.dll, 402: RadEsp.dll, 403: RadExe.dll, 404: RadFra.dll, 405: RadHun.dll, 406: RadIta.dll, 407: RadNlb.dll, 408: RadPlk.dll, 409: RadProbe.sys, 410: RadType.dll, 411: ras, 412: rasadhlp.dll, 413: rasapi32.dll, 414: rasauto.dll, 415: rasautou.exe, 416: raschap.dll, 417: rasctrnm.h, 418: rasctrs.dll, 419: rasctrs.ini, 420: rasdial.exe, 421: rasdlg.dll, 422: rasman.dll, 423: rasmans.dll, 424: rasmontr.dll, 425: rasmxs.dll, 426: rasphone.exe, 427: rasppp.dll, 428: rasqec.dll, 429: rasrad.dll, 430
24963	2:50:03.2306465 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: rasser.dll, 1: rastapi.dll, 2: rastls.dll, 3: RBDELDRV.BAT, 4: rcbdyctl.dll, 5: rcimlby.exe, 6: rcp.exe, 7: rdchost.dll, 8: RDOCURS.DLL, 9: rdpcfgex.dll, 10: rdpclip.exe, 11: rdpdd.dll, 12: rdpsnd.dll, 13: rdpwsx.dll, 14: rdsaddin.exe, 15: rdshost.exe, 16: recover.exe, 17: redir.exe, 18: reg.exe, 19: regapi.dll, 20: regedt32.exe, 21: regini.exe, 22: regsvc.dll, 23: regsvr32.exe, 24: regwiz.exe, 25: regwizc.dll, 26: regxplor.dll, 27: ReinstallBackups, 28: relog.exe, 29: remotepg.dll, 30: remotesp.tsp, 31: rend.dll, 32: replace.exe, 33: reset.exe, 34: Restore, 35: results.txt, 36: resutils.dll, 37: rewire.dll, 38: REX Shared Library.dll, 39: rexec.exe, 40: ReyXpBasics.tlb, 41: rgb9rast_2.dll, 42: rhttpaa.dll, 43: riched20.dll, 44: riched32.dll, 45: richtx32.ocx, 46: rixdicon.dll, 47: RmActivate.exe, 48: RmActivate_isv.exe, 49: RmActivate_ssp.exe, 50: RmActivate_ssp_isv.exe, 51: rmc_fixasf.exe, 52: rmc_rtspdl.dll, 53: rmoc3260.dll, 54: RNBOSENT, 55: rnr20.dll, 56: RO5D3.tmp.LOG, 57: RO5D8.bac, 58: RO5D8.tmp.L?azc
24965	2:50:03.2315159 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: tmp31.tmp, 1: tmpE0.tmp, 2: toolhelp.dll, 3: TosAcpiAPI.dll, 4: TosAvAPI.dll, 5: TosAvctAPI.dll, 6: TosAvdtAPI.dll, 7: TosBdAPI.dll, 8: TosBtAcc.dll, 9: TosBtAerialAPI.dll, 10: TosBtAPI.dll, 11: TosBtCapApi.dll, 12: TosBtECCAPI.dll, 13: TosBtExt.dll, 14: TosBtHcrpAPI.dll, 15: TosBtHSPAPI.dll, 16: TosBtSDDB.dll, 17: tosBtShell.dll, 18: TosCommAPI.dll, 19: TosGnsAPI.dll, 20: TosHidAPI.dll, 21: TosLaneAPI.dll, 22: TosSndAPI.dll, 23: TosSndPlug.dll, 24: tourstart.exe, 25: tracerpt.exe, 26: tracert.exe, 27: tracert6.exe, 28: traffic.dll, 29: tree.com, 30: trkwks.dll, 31: tsappcmp.dll, 32: tsbyuv.dll, 33: tscfgwmi.dll, 34: tscon.exe, 35: tscupgrd.exe, 36: tsd32.dll, 37: tsddd.dll, 38: tsdiscon.exe, 39: tsgqec.dll, 40: tskill.exe, 41: tslabels.h, 42: tslabels.ini, 43: tspkg.dll, 44: tsshutdn.exe, 45: tssoft32.acm, 46: tswpfwrp.exe, 47: TWAIN_32.DLL, 48: TweakUI.exe, 49: twext.dll, 50: TwnLib4.dll, 51: TWUNK_16.EXE, 52: TWUNK_32.EXE, 53: txflog.dll, 54: typelib.dll, 55: typeperf.exe, 56: tzchange.exe, 57: TZLog.lo?azc ? 0: tmp31.tmp, 1: tmpE0.tmp, 2: toolhelp.dll, 3: TosAcpiAPI.dll, 4: TosAvAPI.dll, 5: TosAvctAPI.dll, 6: TosAvdtAPI.dll, 7: TosBdAPI.dll, 8: TosBtAcc.dll, 9: TosBtAerialAPI.dll, 10: TosBtAPI.dll, 11: TosBtCapApi.dll, 12: TosBtECCAPI.dll, 13: TosBtExt.dll, 14: TosBtHcrpAPI.dll, 15: TosBtHSPAPI.dll, 16: TosBtSDDB.dll, 17: tosBtShell.dll, 18: TosCommAPI.dll, 19: TosGnsAPI.dll, 20: TosHidAPI.dll, 21: TosLaneAPI.dll, 22: TosSndAPI.dll, 23: TosSndPlug.dll, 24: tourstart.exe, 25: tracerpt.exe, 26: tracert.exe, 27: tracert6.exe, 28: traffic.dll, 29: tree.com, 30: trkwks.dll, 31: tsappcmp.dll, 32: tsbyuv.dll, 33: tscfgwmi.dll, 34: tscon.exe, 35: tscupgrd.exe, 36: tsd32.dll, 37: tsddd.dll, 38: tsdiscon.exe, 39: tsgqec.dll, 40: tskill.exe, 41: tslabels.h, 42: tslabels.ini, 43: tspkg.dll, 44: tsshutdn.exe, 45: tssoft32.acm, 46: tswpfwrp.exe, 47: TWAIN_32.DLL, 48: TweakUI.exe, 49: twext.dll, 50: TwnLib4.dll, 51: TWUNK_16.EXE, 52: TWUNK_32.EXE, 53: txflog.dll, 54: typelib.dll, 55: typeperf.exe, 56: tzchange.exe, 57: TZLog.log, 58: uci100.dll, 59: udhisapi.dll, 60: ufat.dll, 61: UIAutomationCore.dll, 62: ulib.dll, 63: umandlg.dll, 64: umdmxfrm.dll, 65: umpnpmgr.dll, 66: unicode.nls, 67: unimdm.tsp, 68: unimdmat.dll, 69: uniplat.dll, 70: unlodctr.exe, 71: unrar.dll, 72: untfs.dll, 73: upnp.dll, 74: upnpcont.exe, 75: upnphost.dll, 76: upnpui.dll, 77: ups.exe, 78: ureg.dll, 79: url.dll, 80: urlmon.dll, 81: URTTemp, 82: usbmon.dll, 83: usbui.dll, 84: user.exe, 85: user32.dll, 86: userenv.dll, 87: userinit.exe, 88: usmt, 89: usp10.dll, 90: usrcntra.dll, 91: usrcoina.dll, 92: usrdpa.dll, 93: usrdtea.dll, 94: usrfaxa.dll, 95: usrlbva.dll, 96: usrlogon.cmd, 97: usrmlnka.exe, 98: usrprbda.exe, 99: usrrtosa.dll, 100: usrsdpia.dll, 101: usrshuta.exe, 102: usrsvpia.dll, 103: usrv42a.dll, 104: usrv80a.dll, 105: usrvoica.dll, 106: usrvpa.dll, 107: utildll.dll, 108: utilman.exe, 109: uwdf.exe, 110: uxtheme.dll, 111: v7vga.rom, 112: VB6FR.DLL, 113: VB6STKIT.DLL, 114: VBAEN32.OLB, 115: VBAEND32.OLB, 116: vbajet32.dll, 117: vbalProgBar6.ocx, 118: VBICodec.ax, 119: vbisurf.ax, 120: vbscript.dll, 121: vcdex.dll, 122: vdmdbg.dll, 123: vdmredir.dll, 124: VEN2232.OLB, 125: ver.dll, 126: verclsid.exe, 127: verifier.dll, 128: verifier.exe, 129: version.dll, 130: vfpodbc.dll, 131: vfwwdm32.dll, 132: vga.dll, 133: vga.drv, 134: vga256.dll, 135: vga64k.dll, 136: vidcap.ax, 137: View Channels.scf, 138: vjoy.dll, 139: VSFLEX3.OCX, 140: vssadmin.exe, 141: vssapi.dll, 142: vssvc.exe, 143: vss_ps.dll, 144: vwipxspx.dll, 145: vwipxspx.exe, 146: vxblock.dll, 147: w32time.dll, 148: w32tm.exe, 149: w32topl.dll, 150: w39MLRes.dll, 151: w39NCPA.dll, 152: w3ssl.dll, 153: watchdog.sys, 154: wavemsp.dll, 155: wbcache.deu, 156: wbcache.enu, 157: wbcache.esn, 158: wbcache.fra, 159: wbcache.ita, 160: wbcache.nld, 161: wbcache.sve, 162: wbdbase.deu, 163: wbdbase.enu, 164: wbdbase.esn, 165: wbdbase.fra, 166: wbdbase.ita, 167: wbdbase.nld, 168: wbdbase.sve, 169: wbem, 170: wdfapi.dll, 171: WdfCoInstaller01005.dll, 172: wdfmgr.exe, 173: wdigest.dll, 174: wdl.trm, 175: wdmaud.drv, 176: webcheck.dll, 177: webclnt.dll, 178: webfldrs.msi, 179: webhits.dll, 180: webvw.dll, 181: wextract.exe, 182: wfwnet.drv, 183: WgaLogon.dll, 184: WgaTray.exe, 185: wiaacmgr.exe, 186: wiadefui.dll, 187: wiadss.dll, 188: wiascr.dll, 189: wiaservc.dll, 190: wiasf.ax, 191: wiashext.dll, 192: wiavideo.dll, 193: wiavusd.dll, 194: wifeman.dll, 195: win.com, 196: win32k.sys, 197: win32spl.dll, 198: win87em.dll, 199: winbrand.dll, 200: winchat.exe, 201: windowscodecs.dll, 202: windowscodecsext.dll, 203: WindowsLogon.manifest, 204: WindowsUptime.exe, 205: winfax.dll, 206: WinFXDocObj.exe, 207: winhelp.hlp, 208: winhlp32.exe, 209: winhttp.dll, 210: wininet.dll, 211: winipsec.dll, 212: winlogon.exe, 213: winmine.exe, 214: winmm.dll, 215: winmsd.exe, 216: winnls.dll, 217: winntbbu.dll, 218: winoldap.mod, 219: winrnr.dll, 220: wins, 221: winscard.dll, 222: winshfhc.dll, 223: winsock.dll, 224: winspool.drv, 225: winspool.exe, 226: winsrv.dll, 227: winsta.dll, 228: winstrm.dll, 229: wintrust.dll, 230: winver.exe, 231: wkssvc.dll, 232: wlanapi.dll, 233: wldap32.dll, 234: wlnotify.dll, 235: WMADMOD.dll, 236: WMADMOE.dll, 237: wmasf.dll, 238: wmdmlog.dll, 239: wmdmps.dll, 240: wmdrmdev.dll, 241: wmdrmnet.dll, 242: wmdrmsdk.dll, 243: wmerrenu.dll, 244: wmerror.dll, 245: wmi.dll, 246: wmidx.dll, 247: wmidx.ocx, 248: wmimgmt.msc, 249: wmiprop.dll, 250: wmiscmgr.dll, 251: WMNetMgr.dll, 252: wmp.dll, 253: wmp.ocx, 254: wmpasf.dll, 255: wmpcd.dll, 256: wmpcore.dll, 257: wmpdxm.dll, 258: wmpeffects.dll, 259: wmpencen.dll, 260: wmphoto.dll, 261: wmploc.dll, 262: wmpmde.dll, 263: wmpps.dll, 264: wmpshell.dll, 265: wmpsrcwp.dll, 266: wmpui.dll, 267: wmsdmod.dll, 268: wmsdmoe.dll, 269: wmsdmoe2.dll, 270: WMSPDMOD.dll, 271: WMSPDMOE.dll, 272: wmstream.dll, 273: wmv8dmod.dll, 274: wmv8dmoe.dll, 275: wmv8ds32.ax, 276: WMVADVD.dll, 277: WMVADVE.DLL, 278: wmvcore.dll, 279: WMVDECOD.dll, 280: wmvdmod.dll, 281: wmvdmoe.dll, 282: wmvdmoe2.dll, 283: wmvds32.ax, 284: WMVENCOD.dll, 285: WMVSDECD.dll, 286: WMVSENCD.dll, 287: WMVXENCD.dll, 288: WNASPI32.DLL, 289: wow32.dll, 290: wowdeb.exe, 291: wowexec.exe, 292: wowfax.dll, 293: wowfaxui.dll, 294: wpa.dbl, 295: wpabaln.exe, 296: wpdconns.dll, 297: wpdmtp.dll, 298: wpdmtpdr.dll, 299: wpdmtpus.dll, 300: WpdShext.dll, 301: wpdshextautoplay.exe, 302: wpdshextres.dll, 303: WPDShServiceObj.dll, 304: wpdsp.dll, 305: wpdtrace.dll, 306: wpd_ci.dll, 307: wpnpinst.exe, 308: write.exe, 309: ws2help.dll, 310: ws2_32.dll, 311: wscntfy.exe, 312: wscript.exe, 313: wscsvc.dll, 314: wscui.cpl, 315: wsecedit.dll, 316: wshatm.dll, 317: wshbth.dll, 318: wshcon.dll, 319: wshext.dll, 320: wship6.dll, 321: wshisn.dll, 322: wshnetbs.dll, 323: wshom.ocx, 324: wshrm.dll, 325: wshtcpip.dll, 326: wsnmp32.dll, 327: wsock32.dll, 328: wstdecod.dll, 329: wstpager.ax, 330: wstrenderer.ax, 331: wtsapi32.dll, 332: wuapi.dll, 333: wuapi.dll.mui, 334: wuauclt.exe, 335: wuauclt1.exe, 336: wuaucpl.cpl, 337: wuaucpl.cpl.manifest, 338: wuaucpl.cpl.mui, 339: wuaueng.dll, 340: wuaueng.dll.mui, 341: wuaueng1.dll, 342: wuauserv.dll, 343: wucltui.dll, 344: wucltui.dll.mui, 345: WUDFCoinstaller.dll, 346: WudfHost.exe, 347: WudfPlatform.dll, 348: WudfSvc.dll, 349: WUDFx.dll, 350: wupdmgr.exe, 351: wups.dll, 352: wups2.dll, 353: wuweb.dll, 354: wzcdlg.dll, 355: wzcsapi.dll, 356: wzcsvc.dll, 357: x3daudio1_0.dll, 358: x3daudio1_1.dll, 359: X3DAudio1_2.dll, 360: X3DAudio1_3.dll, 361: X3DAudio1_4.dll, 362: xactengine2_0.dll, 363: xactengine2_1.dll, 364: xactengine2_10.dll, 365: xactengine2_2.dll, 366: xactengine2_3.dll, 367: xactengine2_4.dll, 368: xactengine2_5.dll, 369: xactengine2_6.dll, 370: xactengine2_7.dll, 371: xactengine2_8.dll, 372: xactengine2_9.dll, 373: xactengine3_0.dll, 374: xactengine3_1.dll, 375: xactengine3_2.dll, 376: xactsrv.dll, 377: XAPOFX1_0.dll, 378: XAPOFX1_1.dll, 379: XAudio2_0.dll, 380: XAudio2_1.dll, 381: XAudio2_2.dll, 382: xcopy.exe, 383: xenroll.dll, 384: xinput1_1.dll, 385: xinput1_2.dll, 386: xinput1_3.dll, 387: xinput9_1_0.dll, 388: xircom, 389: xlive.dll, 390: xlive.dll.cat, 391: xlivefnt.dll, 392: xmllite.dll, 393: xmlprov.dll, 394: xmlprovi.dll, 395: xolehlp.dll, 396: XPbuttons.ocx, 397: xpob2res.dll, 398: xpsp1res.dll, 399: xpsp2res.dll, 400: xpsp3res.dll, 401: XPSSHHDR.dll, 402: XpsSvcs.dll, 403: XPSViewer, 404: xvidcore.dll, 405: xvidvfw.dll, 406: yv12vfw.dll, 407: zipfldr.dll, 408: 
24972	2:50:03.2320431 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	NO MORE FILES	
24973	2:50:03.2321951 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32	SUCCESS	
24977	2:50:03.2324331 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24978	2:50:03.2325943 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS	SUCCESS	0: ., 1: .., 2: InstallTemp, 3: Manifests, 4: MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e, 5: Policies, 6: x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a, 7: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d, 8: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213, 9: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a, 10: x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7, 11: x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a, 12: x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841, 13: x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474, 14: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2, 15: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd, 16: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700, 17: x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0, ?azdŸ>??24790	2:50:03.2171957 PM	RA3Beta.exe	388	Process Start		SUCCESS	Parent PID: 600
24791	2:50:03.2171999 PM	RA3Beta.exe	388	Thread Create		SUCCESS	Thread ID: 2100
24798	2:50:03.2180712 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24820	2:50:03.2185777 PM	RA3Beta.exe	388	Load Image	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Image Base: 0x400000, Image Size: 0x468000
24842	2:50:03.2193146 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Image Base: 0x7c900000, Image Size: 0xaf000
24843	2:50:03.2193404 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
24856	2:50:03.2196932 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened
24858	2:50:03.2198600 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	AllocationSize: 28,672, EndOfFile: 25,332, NumberOfLinks: 1, DeletePending: False, Directory: False
24859	2:50:03.2200094 PM	RA3Beta.exe	388	ReadFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	Offset: 0, Length: 25,332
24869	2:50:03.2211738 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\Prefetch\RA3BETA.EXE-36984579.pf	SUCCESS	
24870	2:50:03.2212420 PM	RA3Beta.exe	388	CreateFile	C:	SUCCESS	Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24871	2:50:03.2212940 PM	RA3Beta.exe	388	QueryInformationVolume	C:	SUCCESS	VolumeCreationTime: 4/3/2006 7:12:44 PM, VolumeSerialNumber: 081F-ADCB, SupportsObjects: True, VolumeLabel: 
24872	2:50:03.2213227 PM	RA3Beta.exe	388	FileSystemControl	C:	SUCCESS	Control: FSCTL_FILE_PREFETCH
24874	2:50:03.2214194 PM	RA3Beta.exe	388	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24881	2:50:03.2216532 PM	RA3Beta.exe	388	QueryDirectory	C:\	SUCCESS	0: boot.ini, 1: changes, 2: Documents and Settings, 3: Downloads, 4: IO.SYS, 5: Moo, 6: MSDOS.SYS, 7: NTDETECT.COM, 8: ntldr, 9: pagefile.sys, 10: Program Files, 11: RECYCLER, 12: System Volume Information, 13: WINDOWS
24882	2:50:03.2217971 PM	RA3Beta.exe	388	QueryDirectory	C:\	NO MORE FILES	
24883	2:50:03.2218423 PM	RA3Beta.exe	388	CloseFile	C:\	SUCCESS	
24885	2:50:03.2220119 PM	RA3Beta.exe	388	CreateFile	C:\PROGRAM FILES	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24886	2:50:03.2220664 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files	SUCCESS	0: ., 1: .., 2: Adaptec ASPI, 3: Adobe Fireworks CS3, 4: AIM, 5: Alesis, 6: ATI Technologies, 7: Avira, 8: BearShare, 9: BlueTooth, 10: CCleaner, 11: Common Files, 12: CVSNT, 13: Defraggler, 14: DOSBox-0.72, 15: Eraser, 16: filehippo.com, 17: FileZilla FTP Client, 18: Firefox, 19: Foxit Reader, 20: HashTab Shell Extension, 21: I8kfanGUI, 22: InstallShield Installation Information, 23: Intel, 24: Internet Explorer, 25: Java, 26: JkDefrag, 27: K-Lite Codec Pack, 28: Logitech, 29: Luminescence, 30: MagicDisc, 31: MagicISO, 32: Media Player Classic, 33: Microsoft CAPICOM 2.1.0.2, 34: microsoft frontpage, 35: movie maker, 36: Mozilla Thunderbird, 37: Mp3tag, 38: msn gaming zone, 39: MSXML 4.0, 40: MSXML 6.0, 41: Nero 8, 42: NetMeeting, 43: Notepad++, 44: outlook express, 45: PeerGuardian2, 46: PowerISO, 47: PowerMenu, 48: QuickTime Alternative, 49: Red Alert 3 Beta, 50: Reference Assemblies, 51: RegSupreme Pro, 52: Revo Uninstaller, 53: Security, 54: ShellNewARE, 55: Sigmatel, 56: SMPlayer, 57: Sony, 58: Spybot - ?azd
24888	2:50:03.2222924 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files	NO MORE FILES	
24889	2:50:03.2223391 PM	RA3Beta.exe	388	CloseFile	C:\Program Files	SUCCESS	
24892	2:50:03.2225335 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24894	2:50:03.2226581 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech	SUCCESS	0: ., 1: .., 2: SetPoint
24900	2:50:03.2229542 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech	NO MORE FILES	
24901	2:50:03.2230724 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech	SUCCESS	
24905	2:50:03.2234543 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24907	2:50:03.2236415 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Logitech\SetPoint	SUCCESS	0: ., 1: .., 2: AdobeHookDll.dll, 3: AOLHookDll.dll, 4: AppCmd.xml, 5: Bluetooth Connection Assistant.lnk, 6: BTWizard, 7: config.ini, 8: Connect.exe, 9: contacts_warranties.chm, 10: default.xml, 11: externalapps.xml, 12: game.xml, 13: GameHook.dll, 14: gettingstarted.chm, 15: HelpLinks.xml, 16: highresolution.xml, 17: HookDll.dll, 18: Images, 19: IMHook.dll, 20: kbcplext.dll, 21: KEM.xml, 22: KEM.xmlres, 23: KEMHook.dll, 24: KEMMAPI.dll, 25: KemUI.dll, 26: KEMUI.xml, 27: KEMUI.xmlres, 28: keyboard_tp.chm, 29: KGame.dll, 30: Launcher.exe, 31: LBTWiz.exe, 32: LBTWizGI.dll, 33: LBTWizGI.xml, 34: LBTWizGI.xmlres, 35: LCabHandler.dll, 36: lcamera.exe, 37: lgscroll.dll, 38: LHelpBrowser.exe, 39: Logitech web site for Bluetooth.URL, 40: logo.gif, 41: LRFWiz.exe, 42: LRFWiz.xml, 43: LRFWiz.xmlres, 44: LU, 45: Macros, 46: mcplext.dll, 47: mediapad_tp.chm, 48: MessengerHook.dll, 49: mouse_tp.chm, 50: MX5000.dll, 51: MX5500.dll, 52: NonElevatedDll.dll, 53: players.ini, 54: Readme.htm, 55: recrlist.txt, 56: remote_tp.ch?azc
24980	2:50:03.2330672 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS	NO MORE FILES	
24982	2:50:03.2332530 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS	SUCCESS	
24989	2:50:03.2335050 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\X86_MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_8.0.50727.1433_X-WW_5CF844D2	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
24990	2:50:03.2336969 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	0: ., 1: .., 2: msvcm80.dll, 3: msvcp80.dll, 4: msvcr80.dll
24991	2:50:03.2339271 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	NO MORE FILES	
24996	2:50:03.2346915 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
25006	2:50:03.2349457 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25047	2:50:03.2365330 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	0: ., 1: .., 2: comctl32.dll
25048	2:50:03.2372876 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	NO MORE FILES	
25049	2:50:03.2374555 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
25051	2:50:03.2376874 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\X86_MICROSOFT.WINDOWS.GDIPLUS_6595B64144CCF1DF_1.0.2600.5512_X-WW_DFB54E0C	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25052	2:50:03.2378642 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c	SUCCESS	0: ., 1: .., 2: GdiPlus.dll
25053	2:50:03.2380547 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c	NO MORE FILES	
25054	2:50:03.2382067 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c	SUCCESS	
25056	2:50:03.2384942 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25058	2:50:03.2387453 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	AllocationSize: 708,608, EndOfFile: 706,048, NumberOfLinks: 1, DeletePending: False, Directory: False
25062	2:50:03.2390496 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25064	2:50:03.2392770 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	AllocationSize: 991,232, EndOfFile: 989,696, NumberOfLinks: 1, DeletePending: False, Directory: False
25068	2:50:03.2395795 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\unicode.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25070	2:50:03.2398203 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\unicode.nls	SUCCESS	AllocationSize: 90,112, EndOfFile: 89,588, NumberOfLinks: 1, DeletePending: False, Directory: False
25074	2:50:03.2401156 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\locale.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25076	2:50:03.2403413 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\locale.nls	SUCCESS	AllocationSize: 266,240, EndOfFile: 265,948, NumberOfLinks: 1, DeletePending: False, Directory: False
25080	2:50:03.2408344 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\sorttbls.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25082	2:50:03.2410615 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\sorttbls.nls	SUCCESS	AllocationSize: 24,576, EndOfFile: 23,044, NumberOfLinks: 1, DeletePending: False, Directory: False
25086	2:50:03.2412607 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25088	2:50:03.2413814 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	AllocationSize: 3,489,792, EndOfFile: 3,486,992, NumberOfLinks: 1, DeletePending: False, Directory: False
25092	2:50:03.2416912 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25094	2:50:03.2419184 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	AllocationSize: 618,496, EndOfFile: 617,472, NumberOfLinks: 1, DeletePending: False, Directory: False
25098	2:50:03.2422128 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25100	2:50:03.2424380 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	AllocationSize: 618,496, EndOfFile: 617,472, NumberOfLinks: 1, DeletePending: False, Directory: False
25104	2:50:03.2427486 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25106	2:50:03.2429755 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	AllocationSize: 585,728, EndOfFile: 584,704, NumberOfLinks: 1, DeletePending: False, Directory: False
25110	2:50:03.2432747 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25112	2:50:03.2434998 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	AllocationSize: 57,344, EndOfFile: 56,320, NumberOfLinks: 1, DeletePending: False, Directory: False
25116	2:50:03.2439058 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25118	2:50:03.2441326 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	AllocationSize: 286,720, EndOfFile: 285,184, NumberOfLinks: 1, DeletePending: False, Directory: False
25122	2:50:03.2444972 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\user32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25124	2:50:03.2449023 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\user32.dll	SUCCESS	AllocationSize: 581,632, EndOfFile: 578,560, NumberOfLinks: 1, DeletePending: False, Directory: False
25128	2:50:03.2452006 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25130	2:50:03.2454283 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	AllocationSize: 176,128, EndOfFile: 176,128, NumberOfLinks: 1, DeletePending: False, Directory: False
25134	2:50:03.2457387 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25136	2:50:03.2459650 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	AllocationSize: 147,456, EndOfFile: 146,432, NumberOfLinks: 1, DeletePending: False, Directory: False
25140	2:50:03.2462619 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25142	2:50:03.2465022 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	AllocationSize: 344,064, EndOfFile: 343,040, NumberOfLinks: 1, DeletePending: False, Directory: False
25146	2:50:03.2468042 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\comdlg32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25148	2:50:03.2470319 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\comdlg32.dll	SUCCESS	AllocationSize: 278,528, EndOfFile: 276,992, NumberOfLinks: 1, DeletePending: False, Directory: False
25152	2:50:03.2473288 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25154	2:50:03.2475674 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	AllocationSize: 8,462,336, EndOfFile: 8,461,312, NumberOfLinks: 1, DeletePending: False, Directory: False
25158	2:50:03.2478800 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25160	2:50:03.2481060 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	AllocationSize: 475,136, EndOfFile: 474,112, NumberOfLinks: 1, DeletePending: False, Directory: False
25164	2:50:03.2484007 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25166	2:50:03.2487983 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	AllocationSize: 1,290,240, EndOfFile: 1,287,168, NumberOfLinks: 1, DeletePending: False, Directory: False
25170	2:50:03.2490939 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25172	2:50:03.2493213 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	AllocationSize: 552,960, EndOfFile: 551,936, NumberOfLinks: 1, DeletePending: False, Directory: False
25176	2:50:03.2496439 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25178	2:50:03.2498722 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	AllocationSize: 1,724,416, EndOfFile: 1,724,416, NumberOfLinks: 1, DeletePending: False, Directory: False
25182	2:50:03.2501686 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25184	2:50:03.2504055 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	AllocationSize: 831,488, EndOfFile: 830,464, NumberOfLinks: 1, DeletePending: False, Directory: False
25188	2:50:03.2507013 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25190	2:50:03.2509287 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	AllocationSize: 24,576, EndOfFile: 23,552, NumberOfLinks: 1, DeletePending: False, Directory: False
25194	2:50:03.2512229 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25196	2:50:03.2514612 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	AllocationSize: 1,191,936, EndOfFile: 1,188,352, NumberOfLinks: 1, DeletePending: False, Directory: False
25200	2:50:03.2517565 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25202	2:50:03.2519830 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	AllocationSize: 270,336, EndOfFile: 268,800, NumberOfLinks: 1, DeletePending: False, Directory: False
25206	2:50:03.2522202 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\IESETTING.DLL	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25208	2:50:03.2525605 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\IESetting.dll	SUCCESS	AllocationSize: 143,360, EndOfFile: 142,848, NumberOfLinks: 1, DeletePending: False, Directory: False
25212	2:50:03.2528572 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25214	2:50:03.2530893 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	AllocationSize: 163,840, EndOfFile: 163,328, NumberOfLinks: 1, DeletePending: False, Directory: False
25218	2:50:03.2534078 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25220	2:50:03.2536355 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	AllocationSize: 413,696, EndOfFile: 413,696, NumberOfLinks: 1, DeletePending: False, Directory: False
25224	2:50:03.2539299 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25226	2:50:03.2541559 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	AllocationSize: 65,536, EndOfFile: 65,024, NumberOfLinks: 1, DeletePending: False, Directory: False
25230	2:50:03.2544747 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25232	2:50:03.2546968 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
25236	2:50:03.2549904 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25238	2:50:03.2552145 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 110,080, NumberOfLinks: 1, DeletePending: False, Directory: False
25242	2:50:03.2555181 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ctype.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25244	2:50:03.2557439 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\ctype.nls	SUCCESS	AllocationSize: 12,288, EndOfFile: 8,386, NumberOfLinks: 1, DeletePending: False, Directory: False
25248	2:50:03.2560380 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\sortkey.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25250	2:50:03.2564308 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\sortkey.nls	SUCCESS	AllocationSize: 266,240, EndOfFile: 262,148, NumberOfLinks: 1, DeletePending: False, Directory: False
25254	2:50:03.2567772 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25256	2:50:03.2570105 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	AllocationSize: 1,056,768, EndOfFile: 1,054,208, NumberOfLinks: 1, DeletePending: False, Directory: False
25260	2:50:03.2571968 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WINDOWSSHELL.MANIFEST	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25262	2:50:03.2573245 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
25266	2:50:03.2576209 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25268	2:50:03.2578508 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	AllocationSize: 20,480, EndOfFile: 16,896, NumberOfLinks: 1, DeletePending: False, Directory: False
25272	2:50:03.2581470 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25274	2:50:03.2583847 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	AllocationSize: 221,184, EndOfFile: 218,624, NumberOfLinks: 1, DeletePending: False, Directory: False
25278	2:50:03.2586873 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25280	2:50:03.2589116 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	AllocationSize: 49,152, EndOfFile: 45,584, NumberOfLinks: 1, DeletePending: False, Directory: False
25284	2:50:03.2592234 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25286	2:50:03.2594510 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	AllocationSize: 638,976, EndOfFile: 635,904, NumberOfLinks: 1, DeletePending: False, Directory: False
25290	2:50:03.2597477 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25292	2:50:03.2599748 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	AllocationSize: 118,784, EndOfFile: 118,784, NumberOfLinks: 1, DeletePending: False, Directory: False
25296	2:50:03.2604676 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25298	2:50:03.2606939 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	AllocationSize: 65,536, EndOfFile: 64,000, NumberOfLinks: 1, DeletePending: False, Directory: False
25302	2:50:03.2610051 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25304	2:50:03.2612440 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	AllocationSize: 172,032, EndOfFile: 172,032, NumberOfLinks: 1, DeletePending: False, Directory: False
25308	2:50:03.2615401 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\version.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25310	2:50:03.2617656 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\version.dll	SUCCESS	AllocationSize: 20,480, EndOfFile: 18,944, NumberOfLinks: 1, DeletePending: False, Directory: False
25314	2:50:03.2620620 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25316	2:50:03.2623014 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
25320	2:50:03.2626567 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25322	2:50:03.2628839 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	AllocationSize: 126,976, EndOfFile: 125,952, NumberOfLinks: 1, DeletePending: False, Directory: False
25326	2:50:03.2631482 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25328	2:50:03.2633267 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	AllocationSize: 12,288, EndOfFile: 8,494, NumberOfLinks: 1, DeletePending: False, Directory: False
25332	2:50:03.2634608 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3_ENGLISH_1.0.SKUDEF	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25334	2:50:03.2635323 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\ra3_english_1.0.SkuDef	SUCCESS	AllocationSize: 272, EndOfFile: 268, NumberOfLinks: 1, DeletePending: False, Directory: False
25338	2:50:03.2637815 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25340	2:50:03.2639561 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	AllocationSize: 15,884,288, EndOfFile: 15,881,488, NumberOfLinks: 1, DeletePending: False, Directory: False
25344	2:50:03.2643894 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25346	2:50:03.2645805 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	AllocationSize: 925,696, EndOfFile: 921,656, NumberOfLinks: 1, DeletePending: False, Directory: False
25350	2:50:03.2648816 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25352	2:50:03.2651166 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	AllocationSize: 159,744, EndOfFile: 159,232, NumberOfLinks: 1, DeletePending: False, Directory: False
25354	2:50:03.2655596 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	
25356	2:50:03.2657856 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	
25358	2:50:03.2660069 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\unicode.nls	SUCCESS	
25360	2:50:03.2662399 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\locale.nls	SUCCESS	
25362	2:50:03.2664553 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\sorttbls.nls	SUCCESS	
25364	2:50:03.2665718 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
25366	2:50:03.2667900 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	
25368	2:50:03.2670202 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	
25370	2:50:03.2672367 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	
25372	2:50:03.2674705 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	
25374	2:50:03.2676864 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	
25376	2:50:03.2679016 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\user32.dll	SUCCESS	
25378	2:50:03.2682899 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	
25380	2:50:03.2685072 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	
25382	2:50:03.2687234 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	
25384	2:50:03.2689394 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\comdlg32.dll	SUCCESS	
25386	2:50:03.2691724 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	
25388	2:50:03.2693889 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	
25390	2:50:03.2696040 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	
25392	2:50:03.2698194 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	
25394	2:50:03.2700842 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	
25396	2:50:03.2703027 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	
25398	2:50:03.2705195 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	
25400	2:50:03.2707340 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	
25402	2:50:03.2709609 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	
25404	2:50:03.2711229 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\IESetting.dll	SUCCESS	
25406	2:50:03.2713403 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	
25408	2:50:03.2715570 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	
25410	2:50:03.2717730 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	
25412	2:50:03.2721582 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
25414	2:50:03.2723739 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
25416	2:50:03.2725901 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ctype.nls	SUCCESS	
25418	2:50:03.2728058 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\sortkey.nls	SUCCESS	
25420	2:50:03.2730299 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
25422	2:50:03.2731436 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
25424	2:50:03.2733592 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	
25426	2:50:03.2735743 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
25428	2:50:03.2737917 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
25430	2:50:03.2740345 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	
25432	2:50:03.2742655 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	
25434	2:50:03.2744809 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	
25436	2:50:03.2746965 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	
25438	2:50:03.2749645 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\version.dll	SUCCESS	
25440	2:50:03.2751947 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
25442	2:50:03.2754145 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	
25444	2:50:03.2755835 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	
25446	2:50:03.2756456 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\ra3_english_1.0.SkuDef	SUCCESS	
25448	2:50:03.2758104 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	
25450	2:50:03.2759774 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	
25452	2:50:03.2761959 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	
25454	2:50:03.2764853 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25461	2:50:03.2770401 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25468	2:50:03.2774863 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25479	2:50:03.2781347 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25486	2:50:03.2786803 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25493	2:50:03.2792312 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25500	2:50:03.2799433 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25507	2:50:03.2804945 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25514	2:50:03.2810365 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\user32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25521	2:50:03.2816307 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25528	2:50:03.2821905 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25535	2:50:03.2827540 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25542	2:50:03.2833052 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\comdlg32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25549	2:50:03.2840162 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25556	2:50:03.2846048 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25563	2:50:03.2851406 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25570	2:50:03.2856926 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25577	2:50:03.2862352 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25584	2:50:03.2868090 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25591	2:50:03.2873456 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25598	2:50:03.2880485 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25605	2:50:03.2886008 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25612	2:50:03.2890785 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\IESETTING.DLL	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25619	2:50:03.2895680 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25626	2:50:03.2901013 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25633	2:50:03.2906475 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25640	2:50:03.2911783 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25647	2:50:03.2918887 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25654	2:50:03.2924494 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25661	2:50:03.2930014 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25668	2:50:03.2935503 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25675	2:50:03.2940909 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25682	2:50:03.2946466 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25689	2:50:03.2951774 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25696	2:50:03.2957199 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\version.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25703	2:50:03.2962524 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25710	2:50:03.2967963 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
25717	2:50:03.2974925 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	
25719	2:50:03.2977193 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	
25721	2:50:03.2978392 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
25723	2:50:03.2980576 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	
25725	2:50:03.2982741 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	
25727	2:50:03.2984926 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	
25729	2:50:03.2987239 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	
25731	2:50:03.2989569 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	
25733	2:50:03.2991726 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\user32.dll	SUCCESS	
25735	2:50:03.2993868 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	
25737	2:50:03.2996039 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	
25739	2:50:03.2998185 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	
25741	2:50:03.3000350 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\comdlg32.dll	SUCCESS	
25743	2:50:03.3002504 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	
25745	2:50:03.3004657 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	
25747	2:50:03.3006806 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	
25749	2:50:03.3008957 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	
25751	2:50:03.3011122 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	
25753	2:50:03.3013301 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	
25755	2:50:03.3015474 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	
25757	2:50:03.3017634 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	
25759	2:50:03.3019788 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	
25761	2:50:03.3021408 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\IESetting.dll	SUCCESS	
25763	2:50:03.3034700 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	
25765	2:50:03.3036882 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	
25767	2:50:03.3039050 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	
25769	2:50:03.3041204 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
25771	2:50:03.3043372 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
25773	2:50:03.3045540 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
25775	2:50:03.3047710 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
25777	2:50:03.3050395 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	
25779	2:50:03.3052602 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	
25781	2:50:03.3054773 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	
25783	2:50:03.3056927 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	
25785	2:50:03.3059069 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\version.dll	SUCCESS	
25787	2:50:03.3061248 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
25789	2:50:03.3063400 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	
25791	2:50:03.3063958 PM	RA3Beta.exe	388	CloseFile	C:	SUCCESS	
25795	2:50:03.3065947 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RA3Beta.exe	NAME NOT FOUND	Desired Access: Read
25799	2:50:03.3068786 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
25802	2:50:03.3072412 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\kernel32.dll	SUCCESS	Image Base: 0x7c800000, Image Size: 0xf6000
25803	2:50:03.3075734 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	Desired Access: Read
25804	2:50:03.3076382 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
25805	2:50:03.3076795 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	
25812	2:50:03.3082871 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Image Base: 0x5d090000, Image Size: 0x9a000
25815	2:50:03.3085908 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\advapi32.dll	SUCCESS	Image Base: 0x77dd0000, Image Size: 0x9b000
25818	2:50:03.3092018 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	Image Base: 0x77e70000, Image Size: 0x92000
25822	2:50:03.3096577 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\secur32.dll	SUCCESS	Image Base: 0x77fe0000, Image Size: 0x11000
25826	2:50:03.3099387 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\gdi32.dll	SUCCESS	Image Base: 0x77f10000, Image Size: 0x49000
25834	2:50:03.3103502 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\user32.dll	SUCCESS	Image Base: 0x7e410000, Image Size: 0x91000
25835	2:50:03.3105072 PM	RA3Beta.exe	388	FileSystemControl	C:\Program Files\Red Alert 3 Beta	SUCCESS	Control: FSCTL_IS_VOLUME_MOUNTED
25838	2:50:03.3106919 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\WINMM.dll	NAME NOT FOUND	
25839	2:50:03.3110118 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\winmm.dll	SUCCESS	CreationTime: 8/16/2005 5:18:45 AM, LastAccessTime: 6/5/2008 7:52:15 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 176,128, EndOfFile: 176,128, FileAttributes: A
25841	2:50:03.3113358 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
25854	2:50:03.3117309 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\SafeBoot\Option	NAME NOT FOUND	Desired Access: Query Value, Set Value
25855	2:50:03.3117733 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Query Value
25856	2:50:03.3118208 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
25857	2:50:03.3118566 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
25858	2:50:03.3118965 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	NAME NOT FOUND	Desired Access: Query Value
25861	2:50:03.3121678 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	
25865	2:50:03.3124773 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\winmm.dll	SUCCESS	Image Base: 0x76b40000, Image Size: 0x2d000
25873	2:50:03.3133632 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\WINSPOOL.DRV	NAME NOT FOUND	
25876	2:50:03.3136638 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\winspool.drv	SUCCESS	CreationTime: 8/16/2005 5:18:45 AM, LastAccessTime: 6/5/2008 7:51:59 AM, LastWriteTime: 4/14/2008 5:42:46 AM, ChangeTime: 6/5/2008 7:51:59 AM, AllocationSize: 147,456, EndOfFile: 146,432, FileAttributes: A
25878	2:50:03.3140094 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
25891	2:50:03.3145653 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\winspool.drv	SUCCESS	
25895	2:50:03.3148933 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\winspool.drv	SUCCESS	Image Base: 0x73000000, Image Size: 0x26000
25900	2:50:03.3153263 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	Image Base: 0x77c10000, Image Size: 0x58000
25905	2:50:03.3158562 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\comdlg32.dll	SUCCESS	Image Base: 0x763b0000, Image Size: 0x49000
25913	2:50:03.3161842 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\shell32.dll	SUCCESS	Image Base: 0x7c9c0000, Image Size: 0x817000
25918	2:50:03.3166767 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	Image Base: 0x77f60000, Image Size: 0x76000
25923	2:50:03.3172905 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\ole32.dll	SUCCESS	Image Base: 0x774e0000, Image Size: 0x13d000
25931	2:50:03.3176632 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	Image Base: 0x77120000, Image Size: 0x8b000
25932	2:50:03.3178177 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
25935	2:50:03.3179548 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe.Local	NAME NOT FOUND	
25937	2:50:03.3183750 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c	SUCCESS	CreationTime: 6/5/2008 7:56:31 AM, LastAccessTime: 6/5/2008 7:56:31 AM, LastWriteTime: 6/5/2008 7:56:31 AM, ChangeTime: 6/5/2008 7:56:31 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
25939	2:50:03.3186390 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
25945	2:50:03.3190980 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
25954	2:50:03.3196425 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	
25958	2:50:03.3199643 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll	SUCCESS	Image Base: 0x4ec50000, Image Size: 0x1a6000
25967	2:50:03.3206700 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\wininet.dll	SUCCESS	Image Base: 0x78050000, Image Size: 0xd0000
25973	2:50:03.3213553 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\normaliz.dll	SUCCESS	Image Base: 0x350000, Image Size: 0x9000
25983	2:50:03.3230697 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\urlmon.dll	SUCCESS	Image Base: 0x7f560000, Image Size: 0x12e000
26013	2:50:03.3277871 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\iertutil.dll	SUCCESS	Image Base: 0x5dca0000, Image Size: 0x45000
26018	2:50:03.3282514 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\IESetting.dll	SUCCESS	Image Base: 0x77270000, Image Size: 0x26000
26019	2:50:03.3290331 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\OLEACC.dll	NAME NOT FOUND	
26020	2:50:03.3293362 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\oleacc.dll	SUCCESS	CreationTime: 8/16/2005 5:18:32 AM, LastAccessTime: 4/9/2006 12:56:37 AM, LastWriteTime: 8/10/2004 6:00:00 AM, ChangeTime: 4/3/2006 7:14:08 PM, AllocationSize: 163,840, EndOfFile: 163,328, FileAttributes: A
26021	2:50:03.3296259 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26028	2:50:03.3301391 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleacc.dll	SUCCESS	
26031	2:50:03.3304573 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\oleacc.dll	SUCCESS	Image Base: 0x74c80000, Image Size: 0x2c000
26033	2:50:03.3307059 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\MSVCP60.dll	NAME NOT FOUND	
26034	2:50:03.3310263 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	CreationTime: 8/16/2005 5:18:27 AM, LastAccessTime: 6/5/2008 7:52:46 AM, LastWriteTime: 4/14/2008 5:42:02 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 413,696, EndOfFile: 413,696, FileAttributes: A
26036	2:50:03.3313870 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26049	2:50:03.3319667 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	
26055	2:50:03.3326564 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\msvcp60.dll	SUCCESS	Image Base: 0x76080000, Image Size: 0x65000
26056	2:50:03.3335166 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\ShimEng.dll	NAME NOT FOUND	
26058	2:50:03.3338823 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\shimeng.dll	SUCCESS	CreationTime: 8/16/2005 5:18:36 AM, LastAccessTime: 6/5/2008 7:52:26 AM, LastWriteTime: 4/14/2008 5:42:06 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 65,536, EndOfFile: 65,024, FileAttributes: A
26060	2:50:03.3341977 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26072	2:50:03.3347768 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	
26078	2:50:03.3350919 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Image Base: 0x5cb70000, Image Size: 0x26000
26079	2:50:03.3354923 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
26080	2:50:03.3357026 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
26082	2:50:03.3359082 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
26086	2:50:03.3361566 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
26088	2:50:03.3366064 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
26089	2:50:03.3366765 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
26090	2:50:03.3367033 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
26091	2:50:03.3367472 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
26092	2:50:03.3367838 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
26094	2:50:03.3372229 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
26096	2:50:03.3373850 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	Desired Access: Read
26098	2:50:03.3374425 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26099	2:50:03.3374752 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	
26105	2:50:03.3377582 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secur32.dll	NAME NOT FOUND	Desired Access: Read
26106	2:50:03.3378088 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll	NAME NOT FOUND	Desired Access: Read
26107	2:50:03.3378507 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll	NAME NOT FOUND	Desired Access: Read
26108	2:50:03.3378884 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	Desired Access: Read
26109	2:50:03.3379356 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26110	2:50:03.3379579 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26111	2:50:03.3379845 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	
26112	2:50:03.3380107 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon	SUCCESS	Desired Access: Read
26113	2:50:03.3380540 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LeakTrack	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26115	2:50:03.3380959 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon	SUCCESS	
26117	2:50:03.3381200 PM	RA3Beta.exe	388	RegOpenKey	HKLM	SUCCESS	Desired Access: Maximum Allowed
26118	2:50:03.3382038 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics	NAME NOT FOUND	Desired Access: Read
26119	2:50:03.3382446 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USER32.dll	NAME NOT FOUND	Desired Access: Read
26120	2:50:03.3383873 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	Desired Access: Query Value
26121	2:50:03.3384368 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode	NAME NOT FOUND	Length: 16
26122	2:50:03.3384669 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	
26123	2:50:03.3388234 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
26124	2:50:03.3391033 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26126	2:50:03.3393523 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 110,080, NumberOfLinks: 1, DeletePending: False, Directory: False
26130	2:50:03.3396934 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
26133	2:50:03.3400509 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
26134	2:50:03.3405055 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26136	2:50:03.3407885 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 110,080, NumberOfLinks: 1, DeletePending: False, Directory: False
26140	2:50:03.3410351 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
26142	2:50:03.3415458 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
26143	2:50:03.3418556 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26157	2:50:03.3425085 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
26160	2:50:03.3429460 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\imm32.dll	SUCCESS	Image Base: 0x76390000, Image Size: 0x1d000
26161	2:50:03.3430645 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.DLL	NAME NOT FOUND	Desired Access: Read
26164	2:50:03.3434030 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
26165	2:50:03.3434924 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll	NAME NOT FOUND	Desired Access: Read
26166	2:50:03.3435198 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernel32.dll	NAME NOT FOUND	Desired Access: Read
26167	2:50:03.3435422 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll	NAME NOT FOUND	Desired Access: Read
26168	2:50:03.3435645 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COMCTL32.dll	NAME NOT FOUND	Desired Access: Read
26169	2:50:03.3435888 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINMM.dll	NAME NOT FOUND	Desired Access: Read
26170	2:50:03.3436117 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvcrt.dll	NAME NOT FOUND	Desired Access: Read
26171	2:50:03.3436338 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINSPOOL.DRV	NAME NOT FOUND	Desired Access: Read
26172	2:50:03.3436559 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHLWAPI.dll	NAME NOT FOUND	Desired Access: Read
26173	2:50:03.3436779 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHELL32.dll	NAME NOT FOUND	Desired Access: Read
26174	2:50:03.3437000 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comdlg32.dll	NAME NOT FOUND	Desired Access: Read
26175	2:50:03.3437224 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll	NAME NOT FOUND	Desired Access: Read
26176	2:50:03.3437564 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLEAUT32.dll	NAME NOT FOUND	Desired Access: Read
26177	2:50:03.3437799 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gdiplus.dll	NAME NOT FOUND	Desired Access: Read
26178	2:50:03.3438020 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Normaliz.dll	NAME NOT FOUND	Desired Access: Read
26179	2:50:03.3438246 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IESetting.dll	NAME NOT FOUND	Desired Access: Read
26180	2:50:03.3438467 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iertutil.dll	NAME NOT FOUND	Desired Access: Read
26181	2:50:03.3438679 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\urlmon.dll	NAME NOT FOUND	Desired Access: Read
26182	2:50:03.3438900 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WININET.dll	NAME NOT FOUND	Desired Access: Read
26183	2:50:03.3439207 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSVCP60.dll	NAME NOT FOUND	Desired Access: Read
26184	2:50:03.3439431 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLEACC.dll	NAME NOT FOUND	Desired Access: Read
26185	2:50:03.3439654 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ShimEng.dll	NAME NOT FOUND	Desired Access: Read
26186	2:50:03.3444442 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
26187	2:50:03.3444755 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Error Message Instrument	NAME NOT FOUND	Desired Access: Read
26188	2:50:03.3445264 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	Desired Access: Read
26189	2:50:03.3445739 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles	NAME NOT FOUND	Length: 20
26190	2:50:03.3446071 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	
26191	2:50:03.3448370 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32	SUCCESS	Desired Access: Read
26192	2:50:03.3448789 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\RA3Beta	NAME NOT FOUND	Length: 172
26193	2:50:03.3449060 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32	SUCCESS	
26194	2:50:03.3449234 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility	SUCCESS	Desired Access: Read
26195	2:50:03.3449602 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IME Compatibility\RA3Beta	NAME NOT FOUND	Length: 172
26196	2:50:03.3449826 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IME Compatibility	SUCCESS	
26197	2:50:03.3452449 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	Desired Access: Read
26198	2:50:03.3452851 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs	SUCCESS	Type: REG_SZ, Length: 2, Data: 
26199	2:50:03.3453139 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
26201	2:50:03.3460187 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26202	2:50:03.3460629 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
26203	2:50:03.3460861 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26204	2:50:03.3461403 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
26205	2:50:03.3461721 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26206	2:50:03.3461970 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26208	2:50:03.3465400 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
26211	2:50:03.3468147 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	AllocationSize: 618,496, EndOfFile: 617,472, NumberOfLinks: 1, DeletePending: False, Directory: False
26220	2:50:03.3470926 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\COMCTL32.dll.124.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26221	2:50:03.3472119 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26222	2:50:03.3472530 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
26223	2:50:03.3472750 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26224	2:50:03.3473181 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
26225	2:50:03.3473435 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26226	2:50:03.3473675 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26229	2:50:03.3476251 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\COMCTL32.dll.124.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26239	2:50:03.3500765 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	
26241	2:50:03.3502777 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
26242	2:50:03.3503416 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26243	2:50:03.3503813 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\SmoothScroll	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26244	2:50:03.3504224 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26245	2:50:03.3504674 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26246	2:50:03.3509339 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32	SUCCESS	Desired Access: Read
26247	2:50:03.3509962 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26248	2:50:03.3510638 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26250	2:50:03.3511060 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26252	2:50:03.3511412 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26253	2:50:03.3511663 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26254	2:50:03.3511915 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26255	2:50:03.3512158 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26256	2:50:03.3512406 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26257	2:50:03.3512655 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26258	2:50:03.3512912 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26259	2:50:03.3513163 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26260	2:50:03.3513420 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26261	2:50:03.3513677 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26263	2:50:03.3514002 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26264	2:50:03.3514493 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26265	2:50:03.3514795 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26266	2:50:03.3515071 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26267	2:50:03.3515351 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26268	2:50:03.3515625 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26269	2:50:03.3515912 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26270	2:50:03.3516203 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26271	2:50:03.3516513 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26273	2:50:03.3516840 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26275	2:50:03.3517390 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26277	2:50:03.3518206 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26279	2:50:03.3518765 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26281	2:50:03.3519276 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26282	2:50:03.3519555 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26283	2:50:03.3519812 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26284	2:50:03.3520072 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26285	2:50:03.3520329 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26286	2:50:03.3520595 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26287	2:50:03.3520860 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26288	2:50:03.3521134 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26289	2:50:03.3521407 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26290	2:50:03.3521690 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26291	2:50:03.3521972 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26292	2:50:03.3522265 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26293	2:50:03.3522556 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26294	2:50:03.3522860 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26295	2:50:03.3523184 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26296	2:50:03.3523438 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26297	2:50:03.3523690 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26298	2:50:03.3523950 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26299	2:50:03.3524207 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26300	2:50:03.3524475 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26301	2:50:03.3524735 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26303	2:50:03.3525028 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26305	2:50:03.3525316 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26306	2:50:03.3525592 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26307	2:50:03.3526126 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26308	2:50:03.3526498 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26309	2:50:03.3526796 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26310	2:50:03.3527087 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26311	2:50:03.3527366 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux7	NAME NOT FOUND	Length: 536
26312	2:50:03.3527648 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux8	NAME NOT FOUND	Length: 536
26313	2:50:03.3527919 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux9	NAME NOT FOUND	Length: 536
26314	2:50:03.3528185 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm	SUCCESS	Desired Access: All Access
26315	2:50:03.3529040 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm\wheel	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
26316	2:50:03.3529629 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm	SUCCESS	
26317	2:50:03.3530171 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26318	2:50:03.3530529 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26319	2:50:03.3530850 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26320	2:50:03.3531101 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26321	2:50:03.3531375 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26322	2:50:03.3531627 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26323	2:50:03.3531875 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26324	2:50:03.3532132 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26325	2:50:03.3532387 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26326	2:50:03.3532652 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26327	2:50:03.3532940 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26328	2:50:03.3533211 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26329	2:50:03.3533482 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26330	2:50:03.3533758 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26331	2:50:03.3534035 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26332	2:50:03.3534339 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26333	2:50:03.3534627 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26334	2:50:03.3534923 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26335	2:50:03.3535219 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26336	2:50:03.3535527 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
26337	2:50:03.3539424 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Performance	NAME NOT FOUND	Desired Access: Maximum Allowed
26339	2:50:03.3541368 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\Setup	SUCCESS	Desired Access: Query Value
26340	2:50:03.3541810 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SYSTEM\Setup\SystemSetupInProgress	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26342	2:50:03.3542148 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SYSTEM\Setup	SUCCESS	
26343	2:50:03.3542804 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26344	2:50:03.3543240 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
26345	2:50:03.3543475 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26346	2:50:03.3543846 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
26347	2:50:03.3544139 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26348	2:50:03.3544380 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26354	2:50:03.3547282 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
26358	2:50:03.3549875 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	AllocationSize: 8,462,336, EndOfFile: 8,461,312, NumberOfLinks: 1, DeletePending: False, Directory: False
26362	2:50:03.3552540 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\SHELL32.dll.124.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26363	2:50:03.3555146 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\SHELL32.dll.124.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26463	2:50:03.3677212 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	
26465	2:50:03.3677994 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
26466	2:50:03.3678651 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe.Local	NAME NOT FOUND	
26467	2:50:03.3679863 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	CreationTime: 6/5/2008 7:56:33 AM, LastAccessTime: 6/5/2008 7:56:33 AM, LastWriteTime: 6/5/2008 7:56:33 AM, ChangeTime: 6/5/2008 7:56:33 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
26468	2:50:03.3680911 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
26469	2:50:03.3682366 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26471	2:50:03.3683593 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	AllocationSize: 1,056,768, EndOfFile: 1,054,208, NumberOfLinks: 1, DeletePending: False, Directory: False
26475	2:50:03.3684886 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
26478	2:50:03.3686719 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26485	2:50:03.3689376 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
26488	2:50:03.3691552 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Image Base: 0x773d0000, Image Size: 0x103000
26489	2:50:03.3693689 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll	NAME NOT FOUND	Desired Access: Read
26490	2:50:03.3694206 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26491	2:50:03.3694483 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
26492	2:50:03.3694625 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26493	2:50:03.3694854 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
26494	2:50:03.3695055 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26495	2:50:03.3695198 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26496	2:50:03.3696287 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	CreationTime: 8/16/2005 5:40:51 AM, LastAccessTime: 4/9/2006 1:04:37 AM, LastWriteTime: 8/16/2005 5:40:52 AM, ChangeTime: 8/4/2008 7:40:37 PM, AllocationSize: 4,096, EndOfFile: 749, FileAttributes: RHA
26497	2:50:03.3697131 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26499	2:50:03.3697776 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
26503	2:50:03.3698517 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
26506	2:50:03.3699810 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	CreationTime: 8/16/2005 5:40:51 AM, LastAccessTime: 4/9/2006 1:04:37 AM, LastWriteTime: 8/16/2005 5:40:52 AM, ChangeTime: 8/4/2008 7:40:37 PM, AllocationSize: 4,096, EndOfFile: 749, FileAttributes: RHA
26507	2:50:03.3700584 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26509	2:50:03.3701559 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
26513	2:50:03.3702282 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
26515	2:50:03.3703310 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
26517	2:50:03.3703922 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
26521	2:50:03.3704682 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
26522	2:50:03.3705375 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WindowsShell.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26579	2:50:03.3786640 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
26581	2:50:03.3787598 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
26582	2:50:03.3787975 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26583	2:50:03.3788198 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\SmoothScroll	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26584	2:50:03.3788447 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26585	2:50:03.3788793 PM	RA3Beta.exe	388	RegOpenKey	HKCU\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced	SUCCESS	Desired Access: Read
26586	2:50:03.3789182 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
26587	2:50:03.3789450 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced	SUCCESS	
26588	2:50:03.3789623 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26589	2:50:03.3789824 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack	SUCCESS	Desired Access: Query Value
26590	2:50:03.3790132 PM	RA3Beta.exe	388	RegEnumValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack	NO MORE ENTRIES	Index: 0, Length: 220
26591	2:50:03.3790271 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack	SUCCESS	
26592	2:50:03.3795529 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	BUFFER OVERFLOW	Name: \P
26593	2:50:03.3795786 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RA3Beta.exe
26594	2:50:03.3796563 PM	RA3Beta.exe	388	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: 67 0B FC A1 59 64 3C 41 9D CF B6 C5 88 9D 16 BA
26595	2:50:03.3798205 PM	RA3Beta.exe	388	SetEndOfFileInformationFile	C:\WINDOWS\system32\config\software.LOG	SUCCESS	EndOfFile: 16,384
26596	2:50:03.3800225 PM	RA3Beta.exe	388	SetEndOfFileInformationFile	C:\WINDOWS\system32\config\software.LOG	SUCCESS	EndOfFile: 16,384
26597	2:50:03.3801725 PM	RA3Beta.exe	388	SetEndOfFileInformationFile	C:\WINDOWS\system32\config\software.LOG	SUCCESS	EndOfFile: 24,576
26598	2:50:03.3802876 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Control\Session Manager	SUCCESS	Desired Access: Read
26599	2:50:03.3803279 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\CriticalSectionTimeout	SUCCESS	Type: REG_DWORD, Length: 4, Data: 2592000
26600	2:50:03.3803455 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	
26601	2:50:03.3803580 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Ole	SUCCESS	Desired Access: Read
26602	2:50:03.3803804 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Ole\RWLockResourceTimeOut	NAME NOT FOUND	Length: 144
26603	2:50:03.3803941 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Ole	SUCCESS	
26604	2:50:03.3804133 PM	RA3Beta.exe	388	RegOpenKey	HKCR\Interface	SUCCESS	Desired Access: Read
26605	2:50:03.3804418 PM	RA3Beta.exe	388	RegCloseKey	HKCR\Interface	SUCCESS	
26606	2:50:03.3804524 PM	RA3Beta.exe	388	RegOpenKey	HKCR\Interface\{00020400-0000-0000-C000-000000000046}	SUCCESS	Desired Access: Read
26607	2:50:03.3804804 PM	RA3Beta.exe	388	RegCloseKey	HKCR\Interface\{00020400-0000-0000-C000-000000000046}	SUCCESS	
26608	2:50:03.3805150 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\OLEAUT	NAME NOT FOUND	Desired Access: Query Value
26609	2:50:03.3805421 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\OLEAUT\UserEra	NAME NOT FOUND	Desired Access: Query Value, Enumerate Sub Keys
26610	2:50:03.3805550 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\OLEAUT	NAME NOT FOUND	Desired Access: Query Value
26611	2:50:03.3808620 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26612	2:50:03.3808832 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
26613	2:50:03.3808961 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26614	2:50:03.3809156 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
26615	2:50:03.3809318 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26616	2:50:03.3809444 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26617	2:50:03.3810698 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\urlmon.dll.123.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26618	2:50:03.3811989 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\urlmon.dll.123.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26703	2:50:03.3915617 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
26704	2:50:03.3916371 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe.Local	NAME NOT FOUND	
26705	2:50:03.3917975 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	CreationTime: 6/5/2008 7:56:33 AM, LastAccessTime: 6/5/2008 7:56:33 AM, LastWriteTime: 6/5/2008 7:56:33 AM, ChangeTime: 6/5/2008 7:56:33 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
26706	2:50:03.3919221 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
26707	2:50:03.3920416 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Classes	SUCCESS	Desired Access: Maximum Allowed
26708	2:50:03.3920724 PM	RA3Beta.exe	388	RegQueryKey	HKCU\Software\Classes	SUCCESS	Query: Name
26709	2:50:03.3920863 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Classes\PROTOCOLS\Name-Space Handler	NAME NOT FOUND	Desired Access: Maximum Allowed
26710	2:50:03.3920972 PM	RA3Beta.exe	388	RegOpenKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	Desired Access: Maximum Allowed
26711	2:50:03.3921271 PM	RA3Beta.exe	388	RegQueryKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	Query: Name
26712	2:50:03.3921486 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Classes\PROTOCOLS\Name-Space Handler	NAME NOT FOUND	Desired Access: Maximum Allowed
26713	2:50:03.3921637 PM	RA3Beta.exe	388	RegEnumKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	Index: 0, Name: mk
26714	2:50:03.3921891 PM	RA3Beta.exe	388	RegEnumKey	HKCR\PROTOCOLS\Name-Space Handler	NO MORE ENTRIES	Index: 1, Length: 288
26715	2:50:03.3922084 PM	RA3Beta.exe	388	RegCloseKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	
26716	2:50:03.3922308 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26717	2:50:03.3922551 PM	RA3Beta.exe	388	RegOpenKey	HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
26718	2:50:03.3922715 PM	RA3Beta.exe	388	RegOpenKey	HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
26719	2:50:03.3922841 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings	SUCCESS	Desired Access: Query Value
26720	2:50:03.3923190 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck	NAME NOT FOUND	Length: 144
26721	2:50:03.3923364 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings	SUCCESS	
26722	2:50:03.3923540 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
26723	2:50:03.3923869 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
26724	2:50:03.3923992 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
26725	2:50:03.3924137 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
26726	2:50:03.3924260 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
26727	2:50:03.3924470 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
26729	2:50:03.3924752 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915	NAME NOT FOUND	Desired Access: Query Value
26730	2:50:03.3924934 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915	NAME NOT FOUND	Desired Access: Query Value
26731	2:50:03.3925107 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
26732	2:50:03.3925280 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
26733	2:50:03.3925425 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains	NAME NOT FOUND	Desired Access: Read
26734	2:50:03.3925576 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains	NAME NOT FOUND	Desired Access: Read
26735	2:50:03.3925694 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains	NAME NOT FOUND	Desired Access: Read
26736	2:50:03.3925816 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges	NAME NOT FOUND	Desired Access: Read
26738	2:50:03.3926210 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges	NAME NOT FOUND	Desired Access: Read
26739	2:50:03.3926336 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges	NAME NOT FOUND	Desired Access: Read
26740	2:50:03.3926476 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
26741	2:50:03.3926587 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
26742	2:50:03.3926708 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
26743	2:50:03.3926819 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
26744	2:50:03.3927015 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
26747	2:50:03.3927272 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING	NAME NOT FOUND	Desired Access: Query Value
26749	2:50:03.3927557 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING	SUCCESS	Desired Access: Query Value
26750	2:50:03.3927864 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\RA3Beta.exe	NAME NOT FOUND	Length: 144
26751	2:50:03.3928021 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\*	NAME NOT FOUND	Length: 144
26752	2:50:03.3928188 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING	SUCCESS	
26754	2:50:03.3928560 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION	NAME NOT FOUND	Desired Access: Query Value
26756	2:50:03.3928923 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION	SUCCESS	Desired Access: Query Value
26757	2:50:03.3929144 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\RA3Beta.exe	NAME NOT FOUND	Length: 144
26758	2:50:03.3929275 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\*	NAME NOT FOUND	Length: 144
26759	2:50:03.3929420 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION	SUCCESS	
26760	2:50:03.3929574 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING	NAME NOT FOUND	Desired Access: Query Value
26761	2:50:03.3929728 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING	SUCCESS	Desired Access: Query Value
26762	2:50:03.3930049 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\RA3Beta.exe	NAME NOT FOUND	Length: 144
26763	2:50:03.3930175 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\*	NAME NOT FOUND	Length: 144
26764	2:50:03.3930317 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING	SUCCESS	
26765	2:50:03.3930468 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING	NAME NOT FOUND	Desired Access: Query Value
26766	2:50:03.3930800 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING	SUCCESS	Desired Access: Query Value
26767	2:50:03.3930999 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\RA3Beta.exe	NAME NOT FOUND	Length: 144
26768	2:50:03.3931124 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\*	NAME NOT FOUND	Length: 144
26769	2:50:03.3931267 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING	SUCCESS	
26770	2:50:03.3931418 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS	NAME NOT FOUND	Desired Access: Query Value
26771	2:50:03.3931552 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS	SUCCESS	Desired Access: Query Value
26772	2:50:03.3931753 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\RA3Beta.exe	NAME NOT FOUND	Length: 144
26774	2:50:03.3932083 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\*	NAME NOT FOUND	Length: 144
26776	2:50:03.3932393 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS	SUCCESS	
26777	2:50:03.3932563 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT	NAME NOT FOUND	Desired Access: Query Value
26778	2:50:03.3932697 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT	SUCCESS	Desired Access: Query Value
26779	2:50:03.3932898 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT\RA3Beta.exe	NAME NOT FOUND	Length: 144
26780	2:50:03.3933038 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT\*	NAME NOT FOUND	Length: 144
26781	2:50:03.3933178 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT	SUCCESS	
26782	2:50:03.3933326 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS	NAME NOT FOUND	Desired Access: Query Value
26783	2:50:03.3933457 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS	SUCCESS	Desired Access: Query Value
26784	2:50:03.3933647 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\RA3Beta.exe	NAME NOT FOUND	Length: 144
26785	2:50:03.3933778 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\*	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
26786	2:50:03.3933929 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS	SUCCESS	
26787	2:50:03.3934083 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL	NAME NOT FOUND	Desired Access: Query Value
26788	2:50:03.3934214 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL	SUCCESS	Desired Access: Query Value
26789	2:50:03.3934407 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\RA3Beta.exe	NAME NOT FOUND	Length: 144
26790	2:50:03.3934549 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\*	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
26791	2:50:03.3934700 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL	SUCCESS	
26792	2:50:03.3934868 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	Desired Access: Query Value
26793	2:50:03.3935108 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\RA3Beta.exe	NAME NOT FOUND	Length: 144
26794	2:50:03.3935245 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*	NAME NOT FOUND	Length: 144
26795	2:50:03.3935396 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	
26796	2:50:03.3935541 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	Desired Access: Query Value
26797	2:50:03.3936100 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\RA3Beta.exe	NAME NOT FOUND	Length: 144
26798	2:50:03.3936223 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*	NAME NOT FOUND	Length: 144
26799	2:50:03.3936368 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	
26800	2:50:03.3936533 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND	NAME NOT FOUND	Desired Access: Query Value
26801	2:50:03.3936664 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND	SUCCESS	Desired Access: Query Value
26802	2:50:03.3936854 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND\RA3Beta.exe	NAME NOT FOUND	Length: 144
26803	2:50:03.3936969 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND\*	NAME NOT FOUND	Length: 144
26804	2:50:03.3937108 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND	SUCCESS	
26805	2:50:03.3937259 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL	NAME NOT FOUND	Desired Access: Query Value
26806	2:50:03.3937393 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL	SUCCESS	Desired Access: Query Value
26807	2:50:03.3937589 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\RA3Beta.exe	NAME NOT FOUND	Length: 144
26808	2:50:03.3937701 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\*	NAME NOT FOUND	Length: 144
26809	2:50:03.3937838 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL	SUCCESS	
26810	2:50:03.3937991 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL	NAME NOT FOUND	Desired Access: Query Value
26811	2:50:03.3938122 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL	SUCCESS	Desired Access: Query Value
26812	2:50:03.3938312 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL\RA3Beta.exe	NAME NOT FOUND	Length: 144
26813	2:50:03.3938427 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL\*	NAME NOT FOUND	Length: 144
26814	2:50:03.3938572 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL	SUCCESS	
26815	2:50:03.3938737 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD	NAME NOT FOUND	Desired Access: Query Value
26816	2:50:03.3938868 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD	SUCCESS	Desired Access: Query Value
26817	2:50:03.3939061 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\RA3Beta.exe	NAME NOT FOUND	Length: 144
26818	2:50:03.3939176 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\*	NAME NOT FOUND	Length: 144
26819	2:50:03.3939315 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD	SUCCESS	
26820	2:50:03.3939466 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT	NAME NOT FOUND	Desired Access: Query Value
26821	2:50:03.3939598 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT	SUCCESS	Desired Access: Query Value
26822	2:50:03.3939799 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT\RA3Beta.exe	NAME NOT FOUND	Length: 144
26823	2:50:03.3939910 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT\*	NAME NOT FOUND	Length: 144
26824	2:50:03.3940044 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT	SUCCESS	
26825	2:50:03.3940190 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN	NAME NOT FOUND	Desired Access: Query Value
26826	2:50:03.3940321 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN	SUCCESS	Desired Access: Query Value
26827	2:50:03.3940511 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\RA3Beta.exe	NAME NOT FOUND	Length: 144
26828	2:50:03.3940628 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*	NAME NOT FOUND	Length: 144
26829	2:50:03.3940771 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN	SUCCESS	
26830	2:50:03.3940922 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE	NAME NOT FOUND	Desired Access: Query Value
26831	2:50:03.3941070 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE	SUCCESS	Desired Access: Query Value
26832	2:50:03.3941271 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\RA3Beta.exe	NAME NOT FOUND	Length: 144
26833	2:50:03.3941391 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*	NAME NOT FOUND	Length: 144
26834	2:50:03.3941542 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE	SUCCESS	
26835	2:50:03.3941696 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT	NAME NOT FOUND	Desired Access: Query Value
26836	2:50:03.3941830 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT	SUCCESS	Desired Access: Query Value
26837	2:50:03.3942022 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\RA3Beta.exe	NAME NOT FOUND	Length: 144
26838	2:50:03.3942143 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\*	NAME NOT FOUND	Length: 144
26839	2:50:03.3942291 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT	SUCCESS	
26840	2:50:03.3942453 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK	NAME NOT FOUND	Desired Access: Query Value
26841	2:50:03.3942581 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK	SUCCESS	Desired Access: Query Value
26842	2:50:03.3942774 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\RA3Beta.exe	NAME NOT FOUND	Length: 144
26843	2:50:03.3942894 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\*	NAME NOT FOUND	Length: 144
26844	2:50:03.3943031 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK	SUCCESS	
26845	2:50:03.3943182 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GET_URL_DOM_FILEPATH_UNENCODED	NAME NOT FOUND	Desired Access: Query Value
26846	2:50:03.3943313 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GET_URL_DOM_FILEPATH_UNENCODED	NAME NOT FOUND	Desired Access: Query Value
26847	2:50:03.3943450 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING	NAME NOT FOUND	Desired Access: Query Value
26848	2:50:03.3943573 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING	NAME NOT FOUND	Desired Access: Query Value
26849	2:50:03.3943707 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX	NAME NOT FOUND	Desired Access: Query Value
26850	2:50:03.3943835 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX	NAME NOT FOUND	Desired Access: Query Value
26851	2:50:03.3943972 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS	NAME NOT FOUND	Desired Access: Query Value
26852	2:50:03.3944098 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS	NAME NOT FOUND	Desired Access: Query Value
26853	2:50:03.3944235 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION	NAME NOT FOUND	Desired Access: Query Value
26854	2:50:03.3944361 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION	NAME NOT FOUND	Desired Access: Query Value
26855	2:50:03.3944512 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS	NAME NOT FOUND	Desired Access: Query Value
26856	2:50:03.3944637 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS	NAME NOT FOUND	Desired Access: Query Value
26857	2:50:03.3944771 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP	NAME NOT FOUND	Desired Access: Query Value
26858	2:50:03.3944897 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP	NAME NOT FOUND	Desired Access: Query Value
26859	2:50:03.3945031 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL	NAME NOT FOUND	Desired Access: Query Value
26860	2:50:03.3945160 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL	NAME NOT FOUND	Desired Access: Query Value
26861	2:50:03.3945297 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS	NAME NOT FOUND	Desired Access: Query Value
26862	2:50:03.3945428 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS	NAME NOT FOUND	Desired Access: Query Value
26863	2:50:03.3945554 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS	NAME NOT FOUND	Desired Access: Query Value
26864	2:50:03.3945676 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS	NAME NOT FOUND	Desired Access: Query Value
26865	2:50:03.3945808 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOMSTORAGE	NAME NOT FOUND	Desired Access: Query Value
26866	2:50:03.3945942 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOMSTORAGE	NAME NOT FOUND	Desired Access: Query Value
26867	2:50:03.3946068 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST	NAME NOT FOUND	Desired Access: Query Value
26868	2:50:03.3946196 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST	NAME NOT FOUND	Desired Access: Query Value
26869	2:50:03.3946341 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DATAURI	NAME NOT FOUND	Desired Access: Query Value
26870	2:50:03.3946462 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DATAURI	NAME NOT FOUND	Desired Access: Query Value
26871	2:50:03.3946596 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONSERVICES	NAME NOT FOUND	Desired Access: Query Value
26872	2:50:03.3946719 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONSERVICES	NAME NOT FOUND	Desired Access: Query Value
26873	2:50:03.3946881 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
26874	2:50:03.3947045 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
26875	2:50:03.3948476 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	Desired Access: Read, Maximum Allowed
26876	2:50:03.3948831 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\DF8480A1-7492-4F45-AB78-1084642581FB	NAME NOT FOUND	Length: 130
26877	2:50:03.3948973 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\00000000-0000-0000-0000-000000000000	NAME NOT FOUND	Length: 130
26878	2:50:03.3949096 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	
26879	2:50:03.3950269 PM	RA3Beta.exe	388	Thread Create		SUCCESS	Thread ID: 4052
26880	2:50:03.3953035 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	Desired Access: Read, Maximum Allowed
26881	2:50:03.3953401 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\DF8480A1-7492-4F45-AB78-1084642581FB	NAME NOT FOUND	Length: 130
26882	2:50:03.3953535 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\00000000-0000-0000-0000-000000000000	NAME NOT FOUND	Length: 130
26883	2:50:03.3953658 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	
26885	2:50:03.3954915 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
26886	2:50:03.3955150 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
26887	2:50:03.3955292 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
26889	2:50:03.3955552 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
26890	2:50:03.3955762 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
26891	2:50:03.3955898 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
26897	2:50:03.3957309 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\WININET.dll.123.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26898	2:50:03.3958879 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\WININET.dll.123.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
26983	2:50:03.4072802 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
26984	2:50:03.4073575 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe.Local	NAME NOT FOUND	
26985	2:50:03.4075070 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	CreationTime: 6/5/2008 7:56:33 AM, LastAccessTime: 6/5/2008 7:56:33 AM, LastWriteTime: 6/5/2008 7:56:33 AM, ChangeTime: 6/5/2008 7:56:33 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
26986	2:50:03.4076154 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
26987	2:50:03.4077137 PM	RA3Beta.exe	388	RegCreateKey	HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings	SUCCESS	Desired Access: Read/Write
26988	2:50:03.4079565 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\OLEACCRC.DLL	NAME NOT FOUND	
26989	2:50:03.4081046 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	CreationTime: 8/16/2005 5:18:32 AM, LastAccessTime: 4/9/2006 12:56:36 AM, LastWriteTime: 8/10/2004 6:00:00 AM, ChangeTime: 4/3/2006 7:14:08 PM, AllocationSize: 20,480, EndOfFile: 16,896, FileAttributes: A
26990	2:50:03.4082431 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
26992	2:50:03.4083711 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	AllocationSize: 20,480, EndOfFile: 16,896, NumberOfLinks: 1, DeletePending: False, Directory: False
26996	2:50:03.4085041 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\oleaccrc.dll	SUCCESS	
27008	2:50:03.4098911 PM	RA3Beta.exe	388	RegOpenKey	HKCU\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	Desired Access: Read
27009	2:50:03.4099277 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 16, Data: english
27010	2:50:03.4099506 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	
27011	2:50:03.4099934 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	Desired Access: Read
27012	2:50:03.4100241 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Package	NAME NOT FOUND	Length: 144
27013	2:50:03.4100425 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	
27014	2:50:03.4102967 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
27015	2:50:03.4104367 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27017	2:50:03.4105878 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	AllocationSize: 221,184, EndOfFile: 218,624, NumberOfLinks: 1, DeletePending: False, Directory: False
27021	2:50:03.4107370 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
27024	2:50:03.4109158 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
27025	2:50:03.4110980 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27032	2:50:03.4116667 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
27035	2:50:03.4118590 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Image Base: 0x5ad70000, Image Size: 0x38000
27036	2:50:03.4119531 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uxtheme.dll	NAME NOT FOUND	Desired Access: Read
27037	2:50:03.4120176 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Read/Write
27038	2:50:03.4120428 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager	SUCCESS	Desired Access: Query Value
27039	2:50:03.4120702 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager\Compositing	NAME NOT FOUND	Length: 144
27040	2:50:03.4120925 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager	SUCCESS	
27041	2:50:03.4121090 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
27042	2:50:03.4121344 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
27043	2:50:03.4121523 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Query Value
27044	2:50:03.4121724 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\LameButtonText	NAME NOT FOUND	Length: 144
27045	2:50:03.4121942 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
27046	2:50:03.4122084 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
27047	2:50:03.4126797 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
27055	2:50:03.4132776 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
27058	2:50:03.4135108 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
27059	2:50:03.4138852 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Hardware\DeviceMap\VIDEO	SUCCESS	Desired Access: Read, Maximum Allowed
27060	2:50:03.4139159 PM	RA3Beta.exe	388	RegQueryValue	HKLM\HARDWARE\DEVICEMAP\VIDEO\MaxObjectNumber	SUCCESS	Type: REG_DWORD, Length: 4, Data: 4
27061	2:50:03.4139310 PM	RA3Beta.exe	388	RegCloseKey	HKLM\HARDWARE\DEVICEMAP\VIDEO	SUCCESS	
27062	2:50:03.4139464 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\CURRENTCONTROLSET\ENUM	SUCCESS	Desired Access: Read
27063	2:50:03.4139743 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008	SUCCESS	Desired Access: Read
27064	2:50:03.4139997 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Enum	SUCCESS	
27065	2:50:03.4140157 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008\HardwareID	BUFFER OVERFLOW	Length: 48
27066	2:50:03.4140285 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008\HardwareID	SUCCESS	Type: REG_MULTI_SZ, Length: 292, Data: PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00, PCI\VEN_1002&DEV_7145&SUBSYS_20031028, PCI\VEN_1002&DEV_7145&CC_030000, PCI\VEN_1002&DEV_7145&CC_0300
27067	2:50:03.4140414 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008	SUCCESS	
27068	2:50:03.4140517 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\CURRENTCONTROLSET\ENUM	SUCCESS	Desired Access: Read
27069	2:50:03.4140721 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008	SUCCESS	Desired Access: Read
27070	2:50:03.4140925 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Enum	SUCCESS	
27071	2:50:03.4141059 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008\HardwareID	BUFFER OVERFLOW	Length: 48
27072	2:50:03.4141171 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008\HardwareID	SUCCESS	Type: REG_MULTI_SZ, Length: 292, Data: PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00, PCI\VEN_1002&DEV_7145&SUBSYS_20031028, PCI\VEN_1002&DEV_7145&CC_030000, PCI\VEN_1002&DEV_7145&CC_0300
27073	2:50:03.4141299 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_7145&SUBSYS_20031028&REV_00\4&1c9ec085&0&0008	SUCCESS	
27074	2:50:03.4141411 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Hardware\DeviceMap\Video	SUCCESS	Desired Access: Read
27075	2:50:03.4141581 PM	RA3Beta.exe	388	RegQueryValue	HKLM\HARDWARE\DEVICEMAP\VIDEO\\Device\Video0	SUCCESS	Type: REG_SZ, Length: 202, Data: \Registry\Machine\System\CurrentControlSet\Control\Video\{576CC490-7714-4B15-8219-9EB56ABCE7C0}\0000
27076	2:50:03.4141696 PM	RA3Beta.exe	388	RegCloseKey	HKLM\HARDWARE\DEVICEMAP\VIDEO	SUCCESS	
27077	2:50:03.4142975 PM	RA3Beta.exe	388	Thread Create		SUCCESS	Thread ID: 2864
27078	2:50:03.4147878 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	CreationTime: 7/25/2008 3:37:28 PM, LastAccessTime: 8/22/2008 2:42:14 PM, LastWriteTime: 7/25/2008 3:37:28 PM, ChangeTime: 8/22/2008 2:50:03 PM, AllocationSize: 3,489,792, EndOfFile: 3,486,992, FileAttributes: A
27079	2:50:03.4152172 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	Desired Access: Read
27080	2:50:03.4152530 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 24, Data: Engish (US)
27081	2:50:03.4152680 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 24, Data: Engish (US)
27082	2:50:03.4152868 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	
27083	2:50:03.4156902 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	CreationTime: 8/13/2008 10:34:00 AM, LastAccessTime: 8/13/2008 10:34:00 AM, LastWriteTime: 5/2/2008 2:42:50 AM, ChangeTime: 8/13/2008 10:34:01 AM, AllocationSize: 49,152, EndOfFile: 45,584, FileAttributes: A
27084	2:50:03.4158273 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27086	2:50:03.4159489 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	AllocationSize: 49,152, EndOfFile: 45,584, NumberOfLinks: 1, DeletePending: False, Directory: False
27090	2:50:03.4160204 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\lang\Engish (US).big	PATH NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
27091	2:50:03.4161802 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\Launcher	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27092	2:50:03.4162358 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\Launcher\*	SUCCESS	Filter: *, 1: .
27093	2:50:03.4163389 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
27096	2:50:03.4166157 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	CreationTime: 8/13/2008 10:34:00 AM, LastAccessTime: 8/13/2008 10:34:00 AM, LastWriteTime: 5/2/2008 2:42:50 AM, ChangeTime: 8/13/2008 10:34:01 AM, AllocationSize: 49,152, EndOfFile: 45,584, FileAttributes: A
27097	2:50:03.4167487 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	CreationTime: 8/13/2008 10:34:00 AM, LastAccessTime: 8/13/2008 10:34:00 AM, LastWriteTime: 5/2/2008 2:42:50 AM, ChangeTime: 8/13/2008 10:34:01 AM, AllocationSize: 49,152, EndOfFile: 45,584, FileAttributes: A
27098	2:50:03.4168791 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27099	2:50:03.4169423 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\Launcher	SUCCESS	0: .., 1: 480banner.bmp, 2: 640banner.bmp, 3: bfme2button.bmp, 4: bfme2thumb.jpg, 5: bordercenter.bmp, 6: bordercorner.bmp, 7: captioncenter.bmp, 8: captionend.bmp, 9: cnc.bmp, 10: english.csf, 11: icon.bmp, 12: rotwkbutton.bmp, 13: splash.bmp, 14: thumb.jpg, 15: Thumbs.db
27100	2:50:03.4170644 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\Launcher	NO MORE FILES	
27101	2:50:03.4171141 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\Launcher	SUCCESS	
27108	2:50:03.4175016 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
27111	2:50:03.4176999 PM	RA3Beta.exe	388	Load Image	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Image Base: 0x10100000, Image Size: 0xe000
27112	2:50:03.4177318 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
27113	2:50:03.4177600 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
27114	2:50:03.4177751 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
27115	2:50:03.4177977 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
27116	2:50:03.4178192 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
27117	2:50:03.4178332 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
27118	2:50:03.4179628 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll.2.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
27119	2:50:03.4181044 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll.2.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
27138	2:50:03.4194767 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
27139	2:50:03.4195767 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	AllocationSize: 12,288, EndOfFile: 8,494, NumberOfLinks: 1, DeletePending: False, Directory: False
27141	2:50:03.4196943 PM	RA3Beta.exe	388	ReadFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	Offset: 0, Length: 8,192
27147	2:50:03.4199390 PM	RA3Beta.exe	388	ReadFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	Offset: 8,192, Length: 302
27149	2:50:03.4200396 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\Launcher\english.csf	SUCCESS	
27182	2:50:03.4247746 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
27183	2:50:03.4248556 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe.Local	NAME NOT FOUND	
27184	2:50:03.4250014 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	CreationTime: 3/4/2008 4:56:27 AM, LastAccessTime: 3/4/2008 4:56:27 AM, LastWriteTime: 3/4/2008 4:56:27 AM, ChangeTime: 3/4/2008 4:56:27 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
27186	2:50:03.4251232 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27188	2:50:03.4252970 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27202	2:50:03.4261666 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	
27206	2:50:03.4264007 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Image Base: 0x78130000, Image Size: 0x9b000
27207	2:50:03.4266103 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSVCR80.dll	NAME NOT FOUND	Desired Access: Read
27208	2:50:03.4270455 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	CreationTime: 10/24/2007 2:47:56 AM, LastAccessTime: 3/4/2008 4:56:27 AM, LastWriteTime: 10/24/2007 2:47:56 AM, ChangeTime: 3/4/2008 4:56:27 AM, AllocationSize: 638,976, EndOfFile: 635,904, FileAttributes: A
27209	2:50:03.4270768 PM	RA3Beta.exe	388	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27210	2:50:03.4271011 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS	SUCCESS	Filter: WINDOWS, 1: WINDOWS
27211	2:50:03.4271271 PM	RA3Beta.exe	388	CloseFile	C:\	SUCCESS	
27213	2:50:03.4272260 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27214	2:50:03.4272788 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS	SUCCESS	Filter: WinSxS, 1: WinSxS
27215	2:50:03.4273347 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS	SUCCESS	
27217	2:50:03.4274551 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27218	2:50:03.4275355 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll	SUCCESS	Filter: MSVCR80.dll, 1: msvcr80.dll
27219	2:50:03.4276168 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
27221	2:50:03.4276531 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lgscroll.dll	NAME NOT FOUND	Desired Access: Read
27222	2:50:03.4278096 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\NTMARTA.DLL	NAME NOT FOUND	
27223	2:50:03.4279551 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	CreationTime: 8/16/2005 5:18:30 AM, LastAccessTime: 6/5/2008 7:52:40 AM, LastWriteTime: 4/14/2008 5:42:04 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 118,784, EndOfFile: 118,784, FileAttributes: A
27224	2:50:03.4280884 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27231	2:50:03.4284493 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	
27244	2:50:03.4298347 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Image Base: 0x77690000, Image Size: 0x21000
27245	2:50:03.4299721 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\SAMLIB.dll	NAME NOT FOUND	
27246	2:50:03.4301183 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\samlib.dll	SUCCESS	CreationTime: 8/16/2005 5:18:35 AM, LastAccessTime: 6/5/2008 7:52:01 AM, LastWriteTime: 4/14/2008 5:42:06 AM, ChangeTime: 6/5/2008 7:52:01 AM, AllocationSize: 65,536, EndOfFile: 64,000, FileAttributes: A
27247	2:50:03.4302518 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27254	2:50:03.4305155 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	
27258	2:50:03.4307155 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\samlib.dll	SUCCESS	Image Base: 0x71bf0000, Image Size: 0x13000
27261	2:50:03.4310675 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\wldap32.dll	SUCCESS	Image Base: 0x76f60000, Image Size: 0x2c000
27263	2:50:03.4311818 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAMLIB.dll	NAME NOT FOUND	Desired Access: Read
27264	2:50:03.4312100 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WLDAP32.dll	NAME NOT FOUND	Desired Access: Read
27265	2:50:03.4312402 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Services\LDAP	SUCCESS	Desired Access: Read
27267	2:50:03.4312874 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Services\ldap\LdapClientIntegrity	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27268	2:50:03.4313111 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Services\ldap	SUCCESS	
27269	2:50:03.4313237 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NTMARTA.DLL	NAME NOT FOUND	Desired Access: Read
27275	2:50:03.4314966 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM	SUCCESS	Desired Access: Maximum Allowed
27276	2:50:03.4315291 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM\Ime File	SUCCESS	Type: REG_SZ, Length: 26, Data: msctfime.ime
27277	2:50:03.4315458 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM	SUCCESS	
27282	2:50:03.4317182 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\version.dll	SUCCESS	Image Base: 0x77c00000, Image Size: 0x8000
27283	2:50:03.4317528 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\version.dll	NAME NOT FOUND	Desired Access: Read
27284	2:50:03.4319227 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27285	2:50:03.4321621 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27295	2:50:03.4329829 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
27299	2:50:03.4331374 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
27302	2:50:03.4333094 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27303	2:50:03.4334430 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27306	2:50:03.4336550 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
27310	2:50:03.4337835 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
27312	2:50:03.4339802 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27313	2:50:03.4341330 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27315	2:50:03.4342506 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
27319	2:50:03.4343772 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
27321	2:50:03.4345437 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27322	2:50:03.4346767 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27324	2:50:03.4347940 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
27328	2:50:03.4349208 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
27332	2:50:03.4351896 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\apphelp.dll	SUCCESS	Image Base: 0x77b40000, Image Size: 0x22000
27333	2:50:03.4352259 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apphelp.dll	NAME NOT FOUND	Desired Access: Read
27334	2:50:03.4352600 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility	SUCCESS	Desired Access: Query Value
27335	2:50:03.4353038 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility\DisableAppCompat	NAME NOT FOUND	Length: 20
27336	2:50:03.4353242 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility	SUCCESS	
27337	2:50:03.4355170 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
27339	2:50:03.4356544 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27342	2:50:03.4357888 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27351	2:50:03.4359170 PM	RA3Beta.exe	388	RegCreateKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders	SUCCESS	Desired Access: Maximum Allowed
27353	2:50:03.4360570 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal	SUCCESS	Type: REG_EXPAND_SZ, Length: 54, Data: %USERPROFILE%\My Documents
27355	2:50:03.4360930 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders	SUCCESS	
27356	2:50:03.4361836 PM	RA3Beta.exe	388	QueryOpen	C:\Documents and Settings\Owner\My Documents	SUCCESS	CreationTime: 4/8/2006 9:24:25 PM, LastAccessTime: 8/21/2008 4:08:48 PM, LastWriteTime: 8/21/2008 4:08:48 PM, ChangeTime: 8/21/2008 4:08:48 PM, AllocationSize: 0, EndOfFile: 0, FileAttributes: RD
27357	2:50:03.4362076 PM	RA3Beta.exe	388	RegCreateKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders	SUCCESS	Desired Access: Maximum Allowed
27358	2:50:03.4362364 PM	RA3Beta.exe	388	RegSetValue	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal	SUCCESS	Type: REG_SZ, Length: 90, Data: C:\Documents and Settings\Owner\My Documents
27359	2:50:03.4362567 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders	SUCCESS	
27360	2:50:03.4362741 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	Desired Access: Read
27361	2:50:03.4363059 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\UserDataLeafName	SUCCESS	Type: REG_SZ, Length: 34, Data: Red Alert 3 Beta
27362	2:50:03.4363255 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\UserDataLeafName	SUCCESS	Type: REG_SZ, Length: 34, Data: Red Alert 3 Beta
27363	2:50:03.4363433 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ScreenshotsFolderName	SUCCESS	Type: REG_SZ, Length: 24, Data: Screenshots
27364	2:50:03.4363562 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ScreenshotsFolderName	SUCCESS	Type: REG_SZ, Length: 24, Data: Screenshots
27365	2:50:03.4363674 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ReplayFolderName	SUCCESS	Type: REG_SZ, Length: 16, Data: Replays
27366	2:50:03.4363797 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ReplayFolderName	SUCCESS	Type: REG_SZ, Length: 16, Data: Replays
27367	2:50:03.4363911 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ProfileFolderName	SUCCESS	Type: REG_SZ, Length: 18, Data: Profiles
27368	2:50:03.4364034 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ProfileFolderName	SUCCESS	Type: REG_SZ, Length: 18, Data: Profiles
27369	2:50:03.4364154 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\SaveFolderName	SUCCESS	Type: REG_SZ, Length: 20, Data: SaveGames
27370	2:50:03.4364280 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\SaveFolderName	SUCCESS	Type: REG_SZ, Length: 20, Data: SaveGames
27372	2:50:03.4364408 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\UseLocalUserMaps	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27373	2:50:03.4364517 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\MapPackVersion	NAME NOT FOUND	Length: 144
27374	2:50:03.4364632 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Version	NAME NOT FOUND	Length: 144
27375	2:50:03.4364738 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Hash	NAME NOT FOUND	Length: 144
27376	2:50:03.4364839 PM	RA3Beta.exe	388	RegOpenKey	HKCU\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	Desired Access: Read
27377	2:50:03.4365093 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 16, Data: english
27378	2:50:03.4365221 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 16, Data: english
27379	2:50:03.4365347 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 16, Data: english
27380	2:50:03.4365470 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta\Language	SUCCESS	Type: REG_SZ, Length: 16, Data: english
27382	2:50:03.4365752 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	
27383	2:50:03.4365928 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\BaseURL	NAME NOT FOUND	Length: 144
27384	2:50:03.4366051 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Install Dir	SUCCESS	Type: REG_SZ, Length: 70, Data: C:\Program Files\Red Alert 3 Beta\
27385	2:50:03.4366182 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Install Dir	SUCCESS	Type: REG_SZ, Length: 70, Data: C:\Program Files\Red Alert 3 Beta\
27386	2:50:03.4366294 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Readme	SUCCESS	Type: REG_SZ, Length: 106, Data: C:\Program Files\Red Alert 3 Beta\Support\readme.txt
27387	2:50:03.4366417 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\Readme	SUCCESS	Type: REG_SZ, Length: 106, Data: C:\Program Files\Red Alert 3 Beta\Support\readme.txt
27388	2:50:03.4366560 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	
27389	2:50:03.4366685 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	Desired Access: Read
27393	2:50:03.4367054 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\DisplayName	SUCCESS	Type: REG_SZ, Length: 74, Data: Command & Conquer™ Red Alert™ 3 Beta
27394	2:50:03.4367264 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\DisplayName	SUCCESS	Type: REG_SZ, Length: 74, Data: Command & Conquer™ Red Alert™ 3 Beta
27395	2:50:03.4367417 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta	SUCCESS	
27396	2:50:03.4367543 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ergc	SUCCESS	Desired Access: Read
27397	2:50:03.4367794 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ergc\(Default)	SUCCESS	Type: REG_SZ, Length: 42, Data: ZXYGSVY5HW7CGDDH8DGW
27398	2:50:03.4367915 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ergc\(Default)	SUCCESS	Type: REG_SZ, Length: 42, Data: ZXYGSVY5HW7CGDDH8DGW
27399	2:50:03.4368035 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ergc\(Default)	SUCCESS	Type: REG_SZ, Length: 42, Data: ZXYGSVY5HW7CGDDH8DGW
27400	2:50:03.4368063 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27403	2:50:03.4369742 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
27404	2:50:03.4370049 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
27405	2:50:03.4370172 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
27408	2:50:03.4370434 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27409	2:50:03.4370602 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ergc\(Default)	SUCCESS	Type: REG_SZ, Length: 42, Data: ZXYGSVY5HW7CGDDH8DGW
27410	2:50:03.4370627 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
27411	2:50:03.4370798 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Electronic Arts\EA Games\Red Alert 3 Beta\ergc	SUCCESS	
27412	2:50:03.4371415 PM	RA3Beta.exe	388	CreateFile	C:\Documents and Settings\Owner\My Documents\Red Alert 3 Beta\Replays	PATH NOT FOUND	Desired Access: Read Data/List Directory, Synchronize, Disposition: Create, Options: Directory, Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, AllocationSize: 0
27413	2:50:03.4372018 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27414	2:50:03.4372848 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
27415	2:50:03.4373281 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27416	2:50:03.4373820 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32	SUCCESS	
27418	2:50:03.4375312 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27419	2:50:03.4375589 PM	RA3Beta.exe	388	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27420	2:50:03.4375832 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RA3_english_*.SkuDef	SUCCESS	Filter: RA3_english_*.SkuDef, 1: ra3_english_1.0.SkuDef
27421	2:50:03.4376268 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta	NO MORE FILES	
27422	2:50:03.4376466 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta	SUCCESS	
27423	2:50:03.4376695 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS	SUCCESS	Filter: WINDOWS, 1: WINDOWS
27425	2:50:03.4378106 PM	RA3Beta.exe	388	CloseFile	C:\	SUCCESS	
27427	2:50:03.4378307 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3_english_1.0.SkuDef	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
27428	2:50:03.4378690 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\ra3_english_1.0.SkuDef	SUCCESS	AllocationSize: 272, EndOfFile: 268, NumberOfLinks: 1, DeletePending: False, Directory: False
27429	2:50:03.4379005 PM	RA3Beta.exe	388	ReadFile	C:\Program Files\Red Alert 3 Beta\ra3_english_1.0.SkuDef	SUCCESS	Offset: 0, Length: 268
27432	2:50:03.4379762 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\ra3_english_1.0.SkuDef	SUCCESS	
27433	2:50:03.4379821 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27434	2:50:03.4380391 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	Filter: system32, 1: system32
27435	2:50:03.4380941 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS	SUCCESS	
27437	2:50:03.4382252 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\PROTECTED_FILE	NAME NOT FOUND	
27438	2:50:03.4382321 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27439	2:50:03.4382777 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	Desired Access: Query Value
27440	2:50:03.4383118 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\SafeProcessSearchMode	NAME NOT FOUND	Length: 16
27441	2:50:03.4383157 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
27442	2:50:03.4383333 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	
27443	2:50:03.4384081 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32	SUCCESS	
27445	2:50:03.4384386 PM	RA3Beta.exe	388	QueryOpen	C:\Program	NAME NOT FOUND	
27446	2:50:03.4384439 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
27447	2:50:03.4384718 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
27448	2:50:03.4384889 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
27449	2:50:03.4385123 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
27450	2:50:03.4385249 PM	RA3Beta.exe	388	QueryOpen	C:\Program.exe	NAME NOT FOUND	
27451	2:50:03.4385420 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
27452	2:50:03.4385579 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
27453	2:50:03.4385696 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\msctfime.ime	NAME NOT FOUND	Desired Access: Read, WOW64_64Key
27454	2:50:03.4386126 PM	RA3Beta.exe	388	CreateFile	C:\Program	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a
27455	2:50:03.4387034 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red	NAME NOT FOUND	
27456	2:50:03.4388004 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red.exe	NAME NOT FOUND	
27457	2:50:03.4388490 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
27459	2:50:03.4389009 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a
27460	2:50:03.4389976 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert	NAME NOT FOUND	
27461	2:50:03.4390621 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert.exe	NAME NOT FOUND	
27462	2:50:03.4391269 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a
27463	2:50:03.4391409 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27464	2:50:03.4392071 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3	NAME NOT FOUND	
27465	2:50:03.4392694 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3.exe	NAME NOT FOUND	
27466	2:50:03.4393200 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27467	2:50:03.4393393 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a
27469	2:50:03.4394639 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
27471	2:50:03.4394829 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	CreationTime: 7/25/2008 3:04:28 PM, LastAccessTime: 8/22/2008 2:42:16 PM, LastWriteTime: 7/25/2008 3:04:28 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 15,884,288, EndOfFile: 15,881,488, FileAttributes: A
27474	2:50:03.4396072 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	CreationTime: 7/25/2008 3:04:28 PM, LastAccessTime: 8/22/2008 2:42:16 PM, LastWriteTime: 7/25/2008 3:04:28 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 15,884,288, EndOfFile: 15,881,488, FileAttributes: A
27475	2:50:03.4396359 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
27477	2:50:03.4397991 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27478	2:50:03.4399332 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27485	2:50:03.4401910 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
27488	2:50:03.4404073 PM	RA3Beta.exe	388	Load Image	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Image Base: 0x755c0000, Image Size: 0x2e000
27489	2:50:03.4405978 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msctfime.ime	NAME NOT FOUND	Desired Access: Read
27492	2:50:03.4409490 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\ole32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:32 AM, LastAccessTime: 6/5/2008 7:52:37 AM, LastWriteTime: 4/14/2008 5:42:04 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 1,290,240, EndOfFile: 1,287,168, FileAttributes: A
27498	2:50:03.4411928 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
27501	2:50:03.4413574 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\ntdll.dll	SUCCESS	CreationTime: 8/16/2005 5:18:29 AM, LastAccessTime: 4/14/2008 5:41:26 AM, LastWriteTime: 4/14/2008 5:41:26 AM, ChangeTime: 6/5/2008 7:52:03 AM, AllocationSize: 708,608, EndOfFile: 706,048, FileAttributes: A
27502	2:50:03.4414485 PM	RA3Beta.exe	388	RegOpenKey	HKCU\SOFTWARE\Microsoft\CTF	SUCCESS	Desired Access: Maximum Allowed
27503	2:50:03.4414800 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\CTF\Disable Thread Input Manager	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27504	2:50:03.4415002 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\CTF	SUCCESS	
27505	2:50:03.4416672 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
27506	2:50:03.4417731 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27508	2:50:03.4418792 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27512	2:50:03.4420237 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27513	2:50:03.4421530 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
27514	2:50:03.4421743 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
27515	2:50:03.4421868 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
27516	2:50:03.4422078 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27517	2:50:03.4422223 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
27524	2:50:03.4426791 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls	NAME NOT FOUND	Desired Access: Query Value
27525	2:50:03.4427014 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility	SUCCESS	Desired Access: Query Value
27526	2:50:03.4427282 PM	RA3Beta.exe	388	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility\DisableAppCompat	NAME NOT FOUND	Length: 20
27527	2:50:03.4427439 PM	RA3Beta.exe	388	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility	SUCCESS	
27528	2:50:03.4429565 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\apphelp.dll	SUCCESS	CreationTime: 8/16/2005 5:18:04 AM, LastAccessTime: 6/5/2008 7:53:20 AM, LastWriteTime: 4/14/2008 5:41:50 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 126,976, EndOfFile: 125,952, FileAttributes: A
27529	2:50:03.4430079 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27530	2:50:03.4431604 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
27531	2:50:03.4431853 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
27532	2:50:03.4433088 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32	SUCCESS	
27534	2:50:03.4433666 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27535	2:50:03.4435158 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27537	2:50:03.4435331 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27539	2:50:03.4435507 PM	RA3Beta.exe	388	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27542	2:50:03.4435943 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS	SUCCESS	Filter: WINDOWS, 1: WINDOWS
27543	2:50:03.4436250 PM	RA3Beta.exe	388	CloseFile	C:\	SUCCESS	
27545	2:50:03.4437046 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
27546	2:50:03.4437496 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27547	2:50:03.4438041 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32	SUCCESS	Filter: system32, 1: system32
27548	2:50:03.4438588 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS	SUCCESS	
27550	2:50:03.4439938 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
27551	2:50:03.4440164 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
27552	2:50:03.4440217 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27553	2:50:03.4440292 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
27554	2:50:03.4440502 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27555	2:50:03.4440656 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
27556	2:50:03.4441041 PM	RA3Beta.exe	388	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
27557	2:50:03.4441726 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27558	2:50:03.4442033 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32	SUCCESS	
27560	2:50:03.4442371 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Filter: ra3game.dat, 1: ra3game.dat
27561	2:50:03.4442424 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
27562	2:50:03.4442728 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
27563	2:50:03.4442902 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
27564	2:50:03.4442969 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	
27566	2:50:03.4443511 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
27567	2:50:03.4443832 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
27568	2:50:03.4444005 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
27569	2:50:03.4444125 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\msctfime.ime	NAME NOT FOUND	Desired Access: Read, WOW64_64Key
27570	2:50:03.4445472 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	CreationTime: 7/25/2008 3:04:28 PM, LastAccessTime: 8/22/2008 2:42:16 PM, LastWriteTime: 7/25/2008 3:04:28 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 15,884,288, EndOfFile: 15,881,488, FileAttributes: A
27571	2:50:03.4446134 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27572	2:50:03.4446419 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Filter: 1.0, 1: 1.0
27573	2:50:03.4446693 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	
27574	2:50:03.4446830 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
27577	2:50:03.4447841 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27578	2:50:03.4448559 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Filter: ra3game.dat, 1: ra3game.dat
27579	2:50:03.4448849 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
27580	2:50:03.4449162 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	
27582	2:50:03.4449509 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
27583	2:50:03.4449766 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	NAME NOT FOUND	Length: 1,024
27584	2:50:03.4449944 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
27585	2:50:03.4450151 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
27586	2:50:03.4450403 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	NAME NOT FOUND	Length: 1,024
27587	2:50:03.4450562 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
27588	2:50:03.4450676 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ra3game.dat	NAME NOT FOUND	Desired Access: Read, WOW64_64Key
27589	2:50:03.4453269 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
27591	2:50:03.4453671 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\SafeBoot\Option	NAME NOT FOUND	Desired Access: Query Value, Set Value
27592	2:50:03.4453881 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Query Value
27593	2:50:03.4454118 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27594	2:50:03.4454250 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\AuthenticodeEnabled	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27595	2:50:03.4454395 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
27596	2:50:03.4454696 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\LevelObjects	NAME NOT FOUND	Desired Access: Read
27597	2:50:03.4454814 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Query Value
27598	2:50:03.4454998 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\Levels	NAME NOT FOUND	Length: 536
27599	2:50:03.4455143 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
27600	2:50:03.4455705 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths	SUCCESS	Desired Access: Read
27601	2:50:03.4455931 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths	SUCCESS	Index: 0, Name: {cd331470-db91-4a63-8ea4-c4f86a02fec1}
27602	2:50:03.4456093 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cd331470-db91-4a63-8ea4-c4f86a02fec1}	SUCCESS	Desired Access: Read
27603	2:50:03.4456392 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cd331470-db91-4a63-8ea4-c4f86a02fec1}\ItemData	NAME NOT FOUND	Length: 280
27604	2:50:03.4456998 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cd331470-db91-4a63-8ea4-c4f86a02fec1}	SUCCESS	
27605	2:50:03.4457160 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths	SUCCESS	Index: 1, Name: {dda3f824-d8cb-441b-834d-be2efd2c1a33}
27606	2:50:03.4457297 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}	SUCCESS	Desired Access: Read
27607	2:50:03.4457552 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ItemData	SUCCESS	Type: REG_EXPAND_SZ, Length: 190, Data: %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK*
27608	2:50:03.4457705 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27609	2:50:03.4457870 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}	SUCCESS	
27610	2:50:03.4458015 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths	NO MORE ENTRIES	Index: 2, Length: 280
27611	2:50:03.4458152 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths	SUCCESS	
27612	2:50:03.4458261 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	Desired Access: Read
27613	2:50:03.4458468 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	Index: 0, Name: {349d35ab-37b5-462f-9b89-edd5fbde1328}
27614	2:50:03.4458602 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}	SUCCESS	Desired Access: Read
27615	2:50:03.4458851 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ItemData	SUCCESS	Type: REG_BINARY, Length: 16, Data: 5E AB 30 4F 95 7A 49 89 6A 00 6C 1C 31 15 40 15
27616	2:50:03.4458996 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\HashAlg	SUCCESS	Type: REG_DWORD, Length: 4, Data: 32771
27617	2:50:03.4459124 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ItemSize	SUCCESS	Type: REG_QWORD, Length: 8, Data: 
27618	2:50:03.4459256 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27619	2:50:03.4459423 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}	SUCCESS	
27620	2:50:03.4459569 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	Index: 1, Name: {7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
27621	2:50:03.4459706 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}	SUCCESS	Desired Access: Read
27622	2:50:03.4459957 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ItemData	SUCCESS	Type: REG_BINARY, Length: 16, Data: 67 B0 D4 8B 34 3A 3F D3 BC E9 DC 64 67 04 F3 94
27623	2:50:03.4460099 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\HashAlg	SUCCESS	Type: REG_DWORD, Length: 4, Data: 32771
27624	2:50:03.4460231 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ItemSize	SUCCESS	Type: REG_QWORD, Length: 8, Data: 
27625	2:50:03.4460368 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27626	2:50:03.4460538 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}	SUCCESS	
27627	2:50:03.4460683 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	Index: 2, Name: {81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
27628	2:50:03.4460817 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}	SUCCESS	Desired Access: Read
27629	2:50:03.4461066 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ItemData	SUCCESS	Type: REG_BINARY, Length: 16, Data: 32 78 02 DC FE F8 C8 93 DC 8A B0 06 DD 84 7D 1D
27630	2:50:03.4461211 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\HashAlg	SUCCESS	Type: REG_DWORD, Length: 4, Data: 32771
27631	2:50:03.4461343 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ItemSize	SUCCESS	Type: REG_QWORD, Length: 8, Data: 
27632	2:50:03.4461474 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27633	2:50:03.4461644 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}	SUCCESS	
27634	2:50:03.4461792 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	Index: 3, Name: {94e3e076-8f53-42a5-8411-085bcc18a68d}
27635	2:50:03.4461926 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}	SUCCESS	Desired Access: Read
27636	2:50:03.4462175 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ItemData	SUCCESS	Type: REG_BINARY, Length: 16, Data: BD 9A 2A DB 42 EB D8 56 0E 25 0E 4D F8 16 2F 67
27637	2:50:03.4462320 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\HashAlg	SUCCESS	Type: REG_DWORD, Length: 4, Data: 32771
27638	2:50:03.4462449 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ItemSize	SUCCESS	Type: REG_QWORD, Length: 8, Data: 
27639	2:50:03.4462586 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27640	2:50:03.4462759 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}	SUCCESS	
27641	2:50:03.4462904 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	Index: 4, Name: {dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
27642	2:50:03.4463036 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}	SUCCESS	Desired Access: Read
27643	2:50:03.4463281 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ItemData	SUCCESS	Type: REG_BINARY, Length: 16, Data: 38 6B 08 5F 84 EC F6 69 D3 6B 95 6A 22 C0 1E 80
27644	2:50:03.4463452 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\HashAlg	SUCCESS	Type: REG_DWORD, Length: 4, Data: 32771
27645	2:50:03.4463619 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ItemSize	SUCCESS	Type: REG_QWORD, Length: 8, Data: 
27646	2:50:03.4463767 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27647	2:50:03.4463943 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}	SUCCESS	
27648	2:50:03.4464094 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	NO MORE ENTRIES	Index: 5, Length: 280
27649	2:50:03.4464234 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	SUCCESS	
27650	2:50:03.4464346 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones	NAME NOT FOUND	Desired Access: Read
27651	2:50:03.4464480 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths	NAME NOT FOUND	Desired Access: Read
27652	2:50:03.4464597 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes	NAME NOT FOUND	Desired Access: Read
27653	2:50:03.4464720 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones	NAME NOT FOUND	Desired Access: Read
27654	2:50:03.4464832 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths	NAME NOT FOUND	Desired Access: Read
27655	2:50:03.4464949 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes	NAME NOT FOUND	Desired Access: Read
27656	2:50:03.4465058 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones	NAME NOT FOUND	Desired Access: Read
27657	2:50:03.4465170 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths	NAME NOT FOUND	Desired Access: Read
27658	2:50:03.4465284 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes	NAME NOT FOUND	Desired Access: Read
27659	2:50:03.4465396 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones	NAME NOT FOUND	Desired Access: Read
27660	2:50:03.4465505 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	SUCCESS	Desired Access: Read
27661	2:50:03.4465712 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	SUCCESS	Index: 0, Name: {191cd7fa-f240-4a17-8986-94d480a6c8ca}
27662	2:50:03.4465854 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}	SUCCESS	Desired Access: Read
27664	2:50:03.4466304 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\ItemData	SUCCESS	Type: REG_EXPAND_SZ, Length: 154, Data: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%
27665	2:50:03.4466611 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27666	2:50:03.4466787 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}	SUCCESS	
27667	2:50:03.4466975 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	SUCCESS	Index: 1, Name: {7272edfb-af9f-4ddf-b65b-e4282f2deefc}
27668	2:50:03.4467111 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}	SUCCESS	Desired Access: Read
27669	2:50:03.4467368 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\ItemData	SUCCESS	Type: REG_EXPAND_SZ, Length: 164, Data: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe
27670	2:50:03.4467522 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27672	2:50:03.4467740 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}	SUCCESS	
27673	2:50:03.4467896 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	SUCCESS	Index: 2, Name: {8868b733-4b3a-48f8-9136-aa6d05d4fc83}
27674	2:50:03.4468036 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}	SUCCESS	Desired Access: Read
27675	2:50:03.4468299 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\ItemData	SUCCESS	Type: REG_EXPAND_SZ, Length: 182, Data: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe
27676	2:50:03.4468455 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27677	2:50:03.4468676 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}	SUCCESS	
27680	2:50:03.4469075 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	SUCCESS	Index: 3, Name: {d2c34ab2-529a-46b2-b293-fc853fce72ea}
27682	2:50:03.4469444 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}	SUCCESS	Desired Access: Read
27685	2:50:03.4469863 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\ItemData	SUCCESS	Type: REG_EXPAND_SZ, Length: 158, Data: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%
27686	2:50:03.4470344 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\SaferFlags	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27687	2:50:03.4470534 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}	SUCCESS	
27688	2:50:03.4470701 PM	RA3Beta.exe	388	RegEnumKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	NO MORE ENTRIES	Index: 4, Length: 280
27689	2:50:03.4470844 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	SUCCESS	
27690	2:50:03.4470961 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes	NAME NOT FOUND	Desired Access: Read
27691	2:50:03.4471092 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones	NAME NOT FOUND	Desired Access: Read
27692	2:50:03.4471322 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths	NAME NOT FOUND	Desired Access: Read
27693	2:50:03.4471562 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes	NAME NOT FOUND	Desired Access: Read
27695	2:50:03.4471785 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones	NAME NOT FOUND	Desired Access: Read
27697	2:50:03.4472000 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths	NAME NOT FOUND	Desired Access: Read
27698	2:50:03.4472215 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes	NAME NOT FOUND	Desired Access: Read
27699	2:50:03.4472417 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones	NAME NOT FOUND	Desired Access: Read
27700	2:50:03.4472618 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths	NAME NOT FOUND	Desired Access: Read
27701	2:50:03.4472816 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes	NAME NOT FOUND	Desired Access: Read
27702	2:50:03.4473012 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones	NAME NOT FOUND	Desired Access: Read
27703	2:50:03.4473210 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths	NAME NOT FOUND	Desired Access: Read
27704	2:50:03.4473411 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes	NAME NOT FOUND	Desired Access: Read
27705	2:50:03.4473615 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones	NAME NOT FOUND	Desired Access: Read
27706	2:50:03.4473816 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths	NAME NOT FOUND	Desired Access: Read
27707	2:50:03.4474017 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes	NAME NOT FOUND	Desired Access: Read
27708	2:50:03.4474219 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones	NAME NOT FOUND	Desired Access: Read
27709	2:50:03.4474341 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Read
27710	2:50:03.4474537 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\DefaultLevel	SUCCESS	Type: REG_DWORD, Length: 4, Data: 262144
27711	2:50:03.4474691 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
27712	2:50:03.4474881 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	NAME NOT FOUND	Desired Access: Read
27713	2:50:03.4475255 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Query Value
27714	2:50:03.4475448 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\PolicyScope	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
27715	2:50:03.4475596 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
27716	2:50:03.4477593 PM	RA3Beta.exe	388	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat
27717	2:50:03.4478722 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	CreationTime: 7/25/2008 3:04:28 PM, LastAccessTime: 8/22/2008 2:42:16 PM, LastWriteTime: 7/25/2008 3:04:28 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 15,884,288, EndOfFile: 15,881,488, FileAttributes: A
27718	2:50:03.4479311 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27719	2:50:03.4479563 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Filter: 1.0, 1: 1.0
27720	2:50:03.4479814 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	
27722	2:50:03.4480744 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
27723	2:50:03.4481387 PM	RA3Beta.exe	388	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Filter: ra3game.dat, 1: ra3game.dat
27724	2:50:03.4481926 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	
27726	2:50:03.4482829 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	AllocationSize: 15,884,288, EndOfFile: 15,881,488, NumberOfLinks: 1, DeletePending: False, Directory: False
27728	2:50:03.4483639 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	AllocationSize: 15,884,288, EndOfFile: 15,881,488, NumberOfLinks: 1, DeletePending: False, Directory: False
27732	2:50:03.4484209 PM	RA3Beta.exe	388	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
27733	2:50:03.4484418 PM	RA3Beta.exe	388	RegOpenKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders	SUCCESS	Desired Access: Read
27734	2:50:03.4484667 PM	RA3Beta.exe	388	RegCloseKey	HKCU	SUCCESS	
27735	2:50:03.4484860 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache	BUFFER OVERFLOW	Length: 144
27736	2:50:03.4485083 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache	SUCCESS	Type: REG_SZ, Length: 144, Data: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files
27737	2:50:03.4485267 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders	SUCCESS	
27738	2:50:03.4485494 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion	SUCCESS	Desired Access: Read
27739	2:50:03.4485748 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir	SUCCESS	Type: REG_SZ, Length: 34, Data: C:\Program Files
27740	2:50:03.4485902 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion	SUCCESS	
27741	2:50:03.4486052 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
27742	2:50:03.4486270 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot	SUCCESS	Type: REG_SZ, Length: 22, Data: C:\WINDOWS
27743	2:50:03.4486527 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
27744	2:50:03.4486673 PM	RA3Beta.exe	388	RegOpenKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
27745	2:50:03.4486879 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot	SUCCESS	Type: REG_SZ, Length: 22, Data: C:\WINDOWS
27746	2:50:03.4487025 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
27747	2:50:03.4487371 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Query Value
27748	2:50:03.4487581 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName	NAME NOT FOUND	Length: 536
27749	2:50:03.4487723 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
27750	2:50:03.4487824 PM	RA3Beta.exe	388	RegOpenKey	HKLM\System\CurrentControlSet\Control\SafeBoot\Option	NAME NOT FOUND	Desired Access: Query Value, Set Value
27751	2:50:03.4488329 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ra3game.dat	NAME NOT FOUND	Desired Access: Read
27752	2:50:03.4490148 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
27753	2:50:03.4491640 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
27754	2:50:03.4493221 PM	RA3Beta.exe	388	Process Create	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	PID: 3416, Command line: "C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat" -config "C:\Program Files\Red Alert 3 Beta\RA3_english_1.0.SkuDef" 
27755	2:50:03.4493254 PM	ra3game.dat	3416	Process Start		SUCCESS	Parent PID: 388
27756	2:50:03.4493282 PM	ra3game.dat	3416	Thread Create		SUCCESS	Thread ID: 2472
27817	2:50:03.4558648 PM	ra3game.dat	3416	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat
27824	2:50:03.4560699 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	
27826	2:50:03.4561735 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\PROTECTED_FILE	NAME NOT FOUND	
27827	2:50:03.4565339 PM	RA3Beta.exe	388	RegOpenKey	HKCU\SOFTWARE\Microsoft\CTF	SUCCESS	Desired Access: Maximum Allowed
27828	2:50:03.4565677 PM	RA3Beta.exe	388	RegQueryValue	HKCU\Software\Microsoft\CTF\Disable Thread Input Manager	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
27829	2:50:03.4565875 PM	RA3Beta.exe	388	RegCloseKey	HKCU\Software\Microsoft\CTF	SUCCESS	
27830	2:50:03.4566294 PM	ra3game.dat	3416	Load Image	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Image Base: 0x400000, Image Size: 0x14b1000
27832	2:50:03.4568060 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Image Base: 0x7c900000, Image Size: 0xaf000
27833	2:50:03.4568230 PM	ra3game.dat	3416	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat
27836	2:50:03.4569708 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\Prefetch\RA3GAME.DAT-05C3E16A.pf	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: None, AllocationSize: n/a, OpenResult: Opened
27838	2:50:03.4570694 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\Prefetch\RA3GAME.DAT-05C3E16A.pf	SUCCESS	AllocationSize: 49,152, EndOfFile: 49,130, NumberOfLinks: 1, DeletePending: False, Directory: False
27839	2:50:03.4571616 PM	ra3game.dat	3416	ReadFile	C:\WINDOWS\Prefetch\RA3GAME.DAT-05C3E16A.pf	SUCCESS	Offset: 0, Length: 49,130
27848	2:50:03.4575885 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\Prefetch\RA3GAME.DAT-05C3E16A.pf	SUCCESS	
27849	2:50:03.4576299 PM	ra3game.dat	3416	CreateFile	C:	SUCCESS	Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27850	2:50:03.4576611 PM	ra3game.dat	3416	QueryInformationVolume	C:	SUCCESS	VolumeCreationTime: 4/3/2006 7:12:44 PM, VolumeSerialNumber: 081F-ADCB, SupportsObjects: True, VolumeLabel: 
27851	2:50:03.4577008 PM	ra3game.dat	3416	FileSystemControl	C:	SUCCESS	Control: FSCTL_FILE_PREFETCH
27852	2:50:03.4578402 PM	ra3game.dat	3416	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27853	2:50:03.4579008 PM	ra3game.dat	3416	QueryDirectory	C:\	SUCCESS	0: boot.ini, 1: changes, 2: Documents and Settings, 3: Downloads, 4: IO.SYS, 5: Moo, 6: MSDOS.SYS, 7: NTDETECT.COM, 8: ntldr, 9: pagefile.sys, 10: Program Files, 11: RECYCLER, 12: System Volume Information, 13: WINDOWS
27854	2:50:03.4580123 PM	ra3game.dat	3416	QueryDirectory	C:\	NO MORE FILES	
27855	2:50:03.4581109 PM	ra3game.dat	3416	CloseFile	C:\	SUCCESS	
27857	2:50:03.4581757 PM	ra3game.dat	3416	CreateFile	C:\DOCUMENTS AND SETTINGS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27858	2:50:03.4582059 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings	SUCCESS	0: ., 1: .., 2: Administrator, 3: All Users, 4: Default User, 5: LocalService, 6: NetworkService, 7: Owner
27859	2:50:03.4582565 PM	RA3Beta.exe	388	QueryOpen	C:\Program Files\Red Alert 3 Beta\Launcher\english_splash.bmp	NAME NOT FOUND	
27861	2:50:03.4583517 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings	NO MORE FILES	
27862	2:50:03.4583755 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings	SUCCESS	
27864	2:50:03.4584395 PM	RA3Beta.exe	388	CreateFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
27866	2:50:03.4584716 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\ALL USERS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27867	2:50:03.4585004 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\All Users	SUCCESS	0: ., 1: .., 2: Application Data, 3: Desktop, 4: Documents, 5: DRM, 6: Favorites, 7: Microsoft, 8: NTUSER.DAT, 9: NTUSER.DAT.LOG, 10: ntuser.pol, 11: Start Menu, 12: Templates
27868	2:50:03.4585627 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\All Users	NO MORE FILES	
27870	2:50:03.4586769 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	AllocationSize: 925,696, EndOfFile: 921,656, NumberOfLinks: 1, DeletePending: False, Directory: False
27879	2:50:03.4608585 PM	RA3Beta.exe	388	ReadFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	Offset: 0, Length: 921,600
27881	2:50:03.4609046 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\All Users	SUCCESS	
27883	2:50:03.4609836 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\All Users\DOCUMENTS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27884	2:50:03.4610194 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\All Users\Documents	SUCCESS	0: ., 1: .., 2: default.ers, 3: desktop.ini, 4: schedlog.txt, 5: STALKER-SHOC
27885	2:50:03.4612851 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\All Users\Documents	NO MORE FILES	
27886	2:50:03.4613197 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\All Users\Documents	SUCCESS	
27888	2:50:03.4615421 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27889	2:50:03.4616044 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner	SUCCESS	0: ., 1: .., 2: .assistant, 3: .java, 4: .jpi_cache, 5: .plugin140.trace, 6: .recently-used.xbel, 7: .smplayer, 8: Application Data, 9: Contacts, 10: Cookies, 11: Desktop, 12: dwhelper, 13: Favorites, 14: Installer.log, 15: Local Settings, 16: My Documents, 17: NetHood, 18: ntuser.dat, 19: ntuser.dat.bak_jv16pt, 20: ntuser.dat.LOG, 21: ntuser.dat.tmp.LOG, 22: ntuser.ini, 23: ntuser.pol, 24: PrintHood, 25: Recent, 26: reg740.txt, 27: SendTo, 28: Start Menu, 29: Templates, 30: UserData, 31: WINDOWS
27890	2:50:03.4617142 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner	NO MORE FILES	
27891	2:50:03.4617734 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner	SUCCESS	
27893	2:50:03.4618636 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\LOCAL SETTINGS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27894	2:50:03.4619217 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings	SUCCESS	0: ., 1: .., 2: Application Data, 3: Apps, 4: desktop.ini, 5: History, 6: Temp, 7: Temporary Internet Files
27900	2:50:03.4631322 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings	NO MORE FILES	
27901	2:50:03.4631923 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings	SUCCESS	
27907	2:50:03.4635909 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27908	2:50:03.4636770 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	0: ., 1: .., 2: bye35.tmp, 3: CmdLineExt.dll, 4: drm_dialogs.dll, 5: is-O3M1T.tmp, 6: isp29.tmp, 7: isp33.tmp, 8: jar_cache4433.tmp, 9: java_install_reg.log, 10: Perflib_Perfdata_2cc.dat, 11: Perflib_Perfdata_ea4.dat, 12: set25.tmp, 13: set3D.tmp, 14: _iu14D2N.tmp
27909	2:50:03.4638047 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings\Temp	NO MORE FILES	
27910	2:50:03.4638938 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	
27912	2:50:03.4639840 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\MY DOCUMENTS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27913	2:50:03.4640421 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\My Documents	SUCCESS	0: ., 1: .., 2: backup.theme, 3: Data CD#1.dbr, 4: default.feq, 5: default.fgs, 6: Default.rdp, 7: desktop.ini, 8: filelib, 9: ISO1_DVD.nri, 10: Normal.Theme, 11: Standard 1280 x 800.theme
27914	2:50:03.4641413 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\My Documents	NO MORE FILES	
27915	2:50:03.4641944 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\My Documents	SUCCESS	
27917	2:50:03.4644249 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27918	2:50:03.4644846 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings	SUCCESS	0: ., 1: .., 2: Administrator, 3: All Users, 4: Default User, 5: LocalService, 6: NetworkService, 7: Owner
27919	2:50:03.4645704 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings	NO MORE FILES	
27920	2:50:03.4646902 PM	RA3Beta.exe	388	ReadFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	Offset: 921,600, Length: 56
27922	2:50:03.4648000 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta\Launcher\splash.bmp	SUCCESS	
27923	2:50:03.4654387 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings	SUCCESS	
27925	2:50:03.4655772 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27926	2:50:03.4656644 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner	SUCCESS	0: ., 1: .., 2: .assistant, 3: .java, 4: .jpi_cache, 5: .plugin140.trace, 6: .recently-used.xbel, 7: .smplayer, 8: Application Data, 9: Contacts, 10: Cookies, 11: Desktop, 12: dwhelper, 13: Favorites, 14: Installer.log, 15: Local Settings, 16: My Documents, 17: NetHood, 18: ntuser.dat, 19: ntuser.dat.bak_jv16pt, 20: ntuser.dat.LOG, 21: ntuser.dat.tmp.LOG, 22: ntuser.ini, 23: ntuser.pol, 24: PrintHood, 25: Recent, 26: reg740.txt, 27: SendTo, 28: Start Menu, 29: Templates, 30: UserData, 31: WINDOWS
27927	2:50:03.4658066 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner	NO MORE FILES	
27928	2:50:03.4658859 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner	SUCCESS	
27930	2:50:03.4660399 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27931	2:50:03.4661519 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings	SUCCESS	0: ., 1: .., 2: Application Data, 3: Apps, 4: desktop.ini, 5: History, 6: Temp, 7: Temporary Internet Files
27932	2:50:03.4663044 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings	NO MORE FILES	
27933	2:50:03.4714104 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings	SUCCESS	
27935	2:50:03.4716272 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27936	2:50:03.4717733 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	0: ., 1: .., 2: bye35.tmp, 3: CmdLineExt.dll, 4: drm_dialogs.dll, 5: is-O3M1T.tmp, 6: isp29.tmp, 7: isp33.tmp, 8: jar_cache4433.tmp, 9: java_install_reg.log, 10: Perflib_Perfdata_2cc.dat, 11: Perflib_Perfdata_ea4.dat, 12: set25.tmp, 13: set3D.tmp, 14: _iu14D2N.tmp
27937	2:50:03.4721543 PM	ra3game.dat	3416	QueryDirectory	C:\Documents and Settings\Owner\Local Settings\Temp	NO MORE FILES	
27938	2:50:03.4722898 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	
27940	2:50:03.4723571 PM	ra3game.dat	3416	CreateFile	C:\PROGRAM FILES	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27941	2:50:03.4723845 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files	SUCCESS	0: ., 1: .., 2: Adaptec ASPI, 3: Adobe Fireworks CS3, 4: AIM, 5: Alesis, 6: ATI Technologies, 7: Avira, 8: BearShare, 9: BlueTooth, 10: CCleaner, 11: Common Files, 12: CVSNT, 13: Defraggler, 14: DOSBox-0.72, 15: Eraser, 16: filehippo.com, 17: FileZilla FTP Client, 18: Firefox, 19: Foxit Reader, 20: HashTab Shell Extension, 21: I8kfanGUI, 22: InstallShield Installation Information, 23: Intel, 24: Internet Explorer, 25: Java, 26: JkDefrag, 27: K-Lite Codec Pack, 28: Logitech, 29: Luminescence, 30: MagicDisc, 31: MagicISO, 32: Media Player Classic, 33: Microsoft CAPICOM 2.1.0.2, 34: microsoft frontpage, 35: movie maker, 36: Mozilla Thunderbird, 37: Mp3tag, 38: msn gaming zone, 39: MSXML 4.0, 40: MSXML 6.0, 41: Nero 8, 42: NetMeeting, 43: Notepad++, 44: outlook express, 45: PeerGuardian2, 46: PowerISO, 47: PowerMenu, 48: QuickTime Alternative, 49: Red Alert 3 Beta, 50: Reference Assemblies, 51: RegSupreme Pro, 52: Revo Uninstaller, 53: Security, 54: ShellNewARE, 55: Sigmatel, 56: SMPlayer, 57: Sony, 58: Spybot - ?azc ? 0: ., 1: .., 2: Adaptec ASPI, 3: Adobe Fireworks CS3, 4: AIM, 5: Alesis, 6: ATI Technologies, 7: Avira, 8: BearShare, 9: BlueTooth, 10: CCleaner, 11: Common Files, 12: CVSNT, 13: Defraggler, 14: DOSBox-0.72, 15: Eraser, 16: filehippo.com, 17: FileZilla FTP Client, 18: Firefox, 19: Foxit Reader, 20: HashTab Shell Extension, 21: I8kfanGUI, 22: InstallShield Installation Information, 23: Intel, 24: Internet Explorer, 25: Java, 26: JkDefrag, 27: K-Lite Codec Pack, 28: Logitech, 29: Luminescence, 30: MagicDisc, 31: MagicISO, 32: Media Player Classic, 33: Microsoft CAPICOM 2.1.0.2, 34: microsoft frontpage, 35: movie maker, 36: Mozilla Thunderbird, 37: Mp3tag, 38: msn gaming zone, 39: MSXML 4.0, 40: MSXML 6.0, 41: Nero 8, 42: NetMeeting, 43: Notepad++, 44: outlook express, 45: PeerGuardian2, 46: PowerISO, 47: PowerMenu, 48: QuickTime Alternative, 49: Red Alert 3 Beta, 50: Reference Assemblies, 51: RegSupreme Pro, 52: Revo Uninstaller, 53: Security, 54: ShellNewARE, 55: Sigmatel, 56: SMPlayer, 57: Sony, 58: Spybot - Search & Destroy, 59: SpywareBlaster, 60: Synaptics, 61: Thunderbird-Tray, 62: TortoiseCVS, 63: Toshiba, 64: UltraExplorer, 65: Unlocker, 66: uTorrent, 67: VLC, 68: Winamp, 69: Windows Media Player, 70: Windows NT, 71: WinRAR, 72: 
27942	2:50:03.4724898 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files	NO MORE FILES	
27943	2:50:03.4726544 PM	ra3game.dat	3416	CloseFile	C:\Program Files	SUCCESS	
27945	2:50:03.4727536 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
27946	2:50:03.4728145 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Logitech	SUCCESS	0: ., 1: .., 2: SetPoint
27947	2:50:03.4729838 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Logitech	NO MORE FILES	
27948	2:50:03.4730388 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Logitech	SUCCESS	
28070	2:50:03.4761484 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28071	2:50:03.4762350 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Logitech\SetPoint	SUCCESS	0: ., 1: .., 2: AdobeHookDll.dll, 3: AOLHookDll.dll, 4: AppCmd.xml, 5: Bluetooth Connection Assistant.lnk, 6: BTWizard, 7: config.ini, 8: Connect.exe, 9: contacts_warranties.chm, 10: default.xml, 11: externalapps.xml, 12: game.xml, 13: GameHook.dll, 14: gettingstarted.chm, 15: HelpLinks.xml, 16: highresolution.xml, 17: HookDll.dll, 18: Images, 19: IMHook.dll, 20: kbcplext.dll, 21: KEM.xml, 22: KEM.xmlres, 23: KEMHook.dll, 24: KEMMAPI.dll, 25: KemUI.dll, 26: KEMUI.xml, 27: KEMUI.xmlres, 28: keyboard_tp.chm, 29: KGame.dll, 30: Launcher.exe, 31: LBTWiz.exe, 32: LBTWizGI.dll, 33: LBTWizGI.xml, 34: LBTWizGI.xmlres, 35: LCabHandler.dll, 36: lcamera.exe, 37: lgscroll.dll, 38: LHelpBrowser.exe, 39: Logitech web site for Bluetooth.URL, 40: logo.gif, 41: LRFWiz.exe, 42: LRFWiz.xml, 43: LRFWiz.xmlres, 44: LU, 45: Macros, 46: mcplext.dll, 47: mediapad_tp.chm, 48: MessengerHook.dll, 49: mouse_tp.chm, 50: MX5000.dll, 51: MX5500.dll, 52: NonElevatedDll.dll, 53: players.ini, 54: Readme.htm, 55: recrlist.txt, 56: remote_tp.ch?azc ? 0: ., 1: .., 2: Adaptec ASPI, 3: Adobe Fireworks CS3, 4: AIM, 5: Alesis, 6: ATI Technologies, 7: Avira, 8: BearShare, 9: BlueTooth, 10: CCleaner, 11: Common Files, 12: CVSNT, 13: Defraggler, 14: DOSBox-0.72, 15: Eraser, 16: filehippo.com, 17: FileZilla FTP Client, 18: Firefox, 19: Foxit Reader, 20: HashTab Shell Extension, 21: I8kfanGUI, 22: InstallShield Installation Information, 23: Intel, 24: Internet Explorer, 25: Java, 26: JkDefrag, 27: K-Lite Codec Pack, 28: Logitech, 29: Luminescence, 30: MagicDisc, 31: MagicISO, 32: Media Player Classic, 33: Microsoft CAPICOM 2.1.0.2, 34: microsoft frontpage, 35: movie maker, 36: Mozilla Thunderbird, 37: Mp3tag, 38: msn gaming zone, 39: MSXML 4.0, 40: MSXML 6.0, 41: Nero 8, 42: NetMeeting, 43: Notepad++, 44: outlook express, 45: PeerGuardian2, 46: PowerISO, 47: PowerMenu, 48: QuickTime Alternative, 49: Red Alert 3 Beta, 50: Reference Assemblies, 51: RegSupreme Pro, 52: Revo Uninstaller, 53: Security, 54: ShellNewARE, 55: Sigmatel, 56: SMPlayer, 57: Sony, 58: Spybot - ?azc
28072	2:50:03.4763836 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Logitech\SetPoint	NO MORE FILES	
28073	2:50:03.4766694 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Logitech\SetPoint	SUCCESS	
28075	2:50:03.4767415 PM	ra3game.dat	3416	CreateFile	C:\Program Files\RED ALERT 3 BETA	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28076	2:50:03.4767711 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Red Alert 3 Beta	SUCCESS	0: ., 1: .., 2: Core, 3: EnglishAudio, 4: Lang-english, 5: Launcher, 6: LauncherSupport.dat, 7: Maps, 8: Movies, 9: notepad-MCE.lnk, 10: notepad-MCE.png, 11: notepad-MCE.xml, 12: patchw32.dll, 13: ra3.ico, 14: RA3Beta.exe, 15: ra3_english_1.0.SkuDef, 16: RetailExe, 17: Support, 18: VistaShellSupport.dll
28077	2:50:03.4768843 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Red Alert 3 Beta	NO MORE FILES	
28078	2:50:03.4769122 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta	SUCCESS	
28080	2:50:03.4771128 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RETAILEXE	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28081	2:50:03.4771410 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	0: ., 1: .., 2: 1.0
28082	2:50:03.4771874 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe	NO MORE FILES	
28083	2:50:03.4773279 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe	SUCCESS	
28085	2:50:03.4774243 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28086	2:50:03.4774818 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	0: ., 1: .., 2: config.txt, 3: data, 4: dbghelp.dll, 5: gl.ini, 6: paul.dll, 7: ra3game.dat, 8: winui.dll, 9: xinput1_3.dll
28087	2:50:03.4775679 PM	ra3game.dat	3416	QueryDirectory	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	NO MORE FILES	
28088	2:50:03.4776212 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0	SUCCESS	
28090	2:50:03.4777137 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28091	2:50:03.4777676 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS	SUCCESS	0: ., 1: .., 2: 003301_.tmp, 3: addins, 4: AppPatch, 5: aspack.ini, 6: assembly, 7: atid.ini, 8: BLDLITE.EXE, 9: bootstat.dat, 10: cdface32.ini, 11: ContextMenuExt.dll, 12: control.ini, 13: CSC, 14: Ctregrun.exe, 15: Cursors, 16: d3dx.dat, 17: d3dx9_29.dll, 18: Debug, 19: dellstat.ini, 20: desktop.ini, 21: diagerr.xml, 22: diagwrn.xml, 23: DirectX.log, 24: Downloaded Installations, 25: Downloaded Program Files, 26: Driver Cache, 27: dsdxirmv.exe, 28: ehome, 29: eReg.dat, 30: explorer.exe, 31: explorer.scf, 32: Fonts, 33: ftpcache, 34: help, 35: helpwrit.ini, 36: hh.exe, 37: ie8, 38: ie8updates, 39: ime, 40: inf, 41: INRES.DLL, 42: Installer, 43: IsUninst.exe, 44: iun6002.exe, 45: java, 46: KHALMNPR.Exe, 47: l2schemas, 48: lame_enc.dll, 49: LastGood, 50: libiconv2.dll, 51: libintl3.dll, 52: Logs, 53: Microsoft.NET, 54: Minidump, 55: mozver.dat, 56: msagent, 57: msapps, 58: msdfmap.ini, 59: msdownld.tmp, 60: msoffice.ini, 61: mui, 62: my.ini, 63: neo20.ini, 64: nero.INI, 65: NeroDigital.ini, 66: network diagnos?azc ? 0: ., 1: .., 2: 003301_.tmp, 3: addins, 4: AppPatch, 5: aspack.ini, 6: assembly, 7: atid.ini, 8: BLDLITE.EXE, 9: bootstat.dat, 10: cdface32.ini, 11: ContextMenuExt.dll, 12: control.ini, 13: CSC, 14: Ctregrun.exe, 15: Cursors, 16: d3dx.dat, 17: d3dx9_29.dll, 18: Debug, 19: dellstat.ini, 20: desktop.ini, 21: diagerr.xml, 22: diagwrn.xml, 23: DirectX.log, 24: Downloaded Installations, 25: Downloaded Program Files, 26: Driver Cache, 27: dsdxirmv.exe, 28: ehome, 29: eReg.dat, 30: explorer.exe, 31: explorer.scf, 32: Fonts, 33: ftpcache, 34: help, 35: helpwrit.ini, 36: hh.exe, 37: ie8, 38: ie8updates, 39: ime, 40: inf, 41: INRES.DLL, 42: Installer, 43: IsUninst.exe, 44: iun6002.exe, 45: java, 46: KHALMNPR.Exe, 47: l2schemas, 48: lame_enc.dll, 49: LastGood, 50: libiconv2.dll, 51: libintl3.dll, 52: Logs, 53: Microsoft.NET, 54: Minidump, 55: mozver.dat, 56: msagent, 57: msapps, 58: msdfmap.ini, 59: msdownld.tmp, 60: msoffice.ini, 61: mui, 62: my.ini, 63: neo20.ini, 64: nero.INI, 65: NeroDigital.ini, 66: network diagnostic, 67: notepad.exe, 68: notepro.ini, 69: nsreg.dat, 70: NSTSPPRT.INI, 71: occache, 72: ODBC.INI, 73: ODBCINST.INI, 74: Offline Web Pages, 75: OpenALwEAX.exe, 76: pchealth, 77: PDF2HTML.INI, 78: PeerNet, 79: Performance, 80: PIF, 81: pkzipw.ini, 82: Prefetch, 83: Provisioning, 84: pss, 85: radrun.exe, 86: regedit.exe, 87: RegisteredPackages, 88: Registration, 89: repair, 90: Resources, 91: rzrunins.exe, 92: SBWIN.INI, 93: SchedLgU.Txt, 94: security, 95: ServicePackFiles, 96: setpwrcg.exe, 97: Setup1.exe, 98: setupapi.log, 99: ShellNew, 100: slrundll.exe, 101: smscfg.ini, 102: snymsico.dll, 103: SoftwareDistribution, 104: srchasst, 105: ST6UNST.EXE, 106: Sti_Trace.log, 107: stsystra.exe, 108: Sun, 109: SxsCaPendDel, 110: system, 111: system.ini, 112: system32, 113: T30DebugLogFile.txt, 114: TASKMAN.EXE, 115: Tasks, 116: Temp, 117: tosOBEX.INI, 118: twain.dll, 119: twain_32, 120: twain_32.dll, 121: twunk_16.exe, 122: twunk_32.exe, 123: uedit32.ini, 124: UnDeploy.exe, 125: uninst.exe, 126: UNRecode.cfg, 127: UNRecode.exe, 128: UNWISE.EXE, 129: vb.ini, 130: vbaddin.ini, 131: vmmreg32.dll, 132: WBEM, 133: Web, 134: wiadebug.log, 135: wiaservc.log, 136: win.ini, 137: winamp_plugger.dll, 138: WindowsShell.Manifest, 139: WindowsUpdate.log, 140: winhelp.exe, 141: winhlp32.exe, 142: wininit.ini, 143: winnt.bmp, 144: winnt256.bmp, 145: winoncd.ini, 146: WinSxS, 147: WirelessFTP.INI, 148: wise.ini, 149: WMSysPr9.prx, 150: WORDPAD.INI, 151: xnview.ini, 152: _default.pif, 153: _delis32.ini
28092	2:50:03.4779165 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS	NO MORE FILES	
28093	2:50:03.4779866 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS	SUCCESS	
28095	2:50:03.4781392 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28096	2:50:03.4781579 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msimtf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:48 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 159,744, EndOfFile: 159,232, FileAttributes: A
28097	2:50:03.4782319 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\AppPatch	SUCCESS	0: ., 1: .., 2: acadproc.dll, 3: acgenral.dll, 4: aclayers.dll, 5: aclua.dll, 6: acspecfc.dll, 7: acxtrnal.dll, 8: apphelp.sdb, 9: apph_sp.sdb, 10: drvmain.sdb, 11: msimain.sdb, 12: sysmain.sdb
28098	2:50:03.4783417 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
28099	2:50:03.4783526 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\AppPatch	NO MORE FILES	
28100	2:50:03.4784465 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\AppPatch	SUCCESS	
28103	2:50:03.4784912 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	AllocationSize: 159,744, EndOfFile: 159,232, NumberOfLinks: 1, DeletePending: False, Directory: False
28105	2:50:03.4786722 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28106	2:50:03.4787535 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: ., 1: .., 2: $ncsp$.inf, 3: $winnt$.inf, 4: 1025, 5: 1028, 6: 1031, 7: 1033, 8: 1037, 9: 1041, 10: 1042, 11: 1054, 12: 12520437.cpx, 13: 12520850.cpx, 14: 2052, 15: 3076, 16: 3com_dmi, 17: 6to4svc.dll, 18: a3d.dll, 19: aaaamon.dll, 20: aaclient.dll, 21: aamd532.dll, 22: ac3acm.acm, 23: access.cpl, 24: acctres.dll, 25: accwiz.exe, 26: acelpdec.ax, 27: acledit.dll, 28: aclui.dll, 29: activeds.dll, 30: activeds.tlb, 31: actmovie.exe, 32: actskn43.ocx, 33: actskn43.ocx.bak, 34: actxprxy.dll, 35: admparse.dll, 36: Adobe, 37: adptif.dll, 38: adsldp.dll, 39: adsldpc.dll, 40: adsmsext.dll, 41: adsnds.dll, 42: adsnt.dll, 43: adsnw.dll, 44: advapi32.dll, 45: advpack.dll, 46: advpack.dll.mui, 47: ahui.exe, 48: Alesisasio.dll, 49: AlesisFirewireAsio.dll, 50: alg.exe, 51: alrsvc.dll, 52: amcompat.tlb, 53: amstream.dll, 54: ansi.sys, 55: apcups.dll, 56: append.exe, 57: apphelp.dll, 58: appmgmt, 59: appmgmts.dll, 60: appmgr.dll, 61: appwiz.cpl, 62: arp.exe, 63: asctrls.ocx, 64: asferror.dll, 65: asr_fmt.exe, 66: asr_ldm.?azc ? 0: ., 1: .., 2: $ncsp$.inf, 3: $winnt$.inf, 4: 1025, 5: 1028, 6: 1031, 7: 1033, 8: 1037, 9: 1041, 10: 1042, 11: 1054, 12: 12520437.cpx, 13: 12520850.cpx, 14: 2052, 15: 3076, 16: 3com_dmi, 17: 6to4svc.dll, 18: a3d.dll, 19: aaaamon.dll, 20: aaclient.dll, 21: aamd532.dll, 22: ac3acm.acm, 23: access.cpl, 24: acctres.dll, 25: accwiz.exe, 26: acelpdec.ax, 27: acledit.dll, 28: aclui.dll, 29: activeds.dll, 30: activeds.tlb, 31: actmovie.exe, 32: actskn43.ocx, 33: actskn43.ocx.bak, 34: actxprxy.dll, 35: admparse.dll, 36: Adobe, 37: adptif.dll, 38: adsldp.dll, 39: adsldpc.dll, 40: adsmsext.dll, 41: adsnds.dll, 42: adsnt.dll, 43: adsnw.dll, 44: advapi32.dll, 45: advpack.dll, 46: advpack.dll.mui, 47: ahui.exe, 48: Alesisasio.dll, 49: AlesisFirewireAsio.dll, 50: alg.exe, 51: alrsvc.dll, 52: amcompat.tlb, 53: amstream.dll, 54: ansi.sys, 55: apcups.dll, 56: append.exe, 57: apphelp.dll, 58: appmgmt, 59: appmgmts.dll, 60: appmgr.dll, 61: appwiz.cpl, 62: arp.exe, 63: asctrls.ocx, 64: asferror.dll, 65: asr_fmt.exe, 66: asr_ldm.exe, 67: asr_pfu.exe, 68: asycfilt.dll, 69: at.exe, 70: atfenuxx.hlp, 71: ati2cqag.dll, 72: ati2dvaa.dll, 73: ati2dvag.dll, 74: ati2edxx.dll, 75: ati2evxx.dll, 76: ati2evxx.exe, 77: Ati2mdxx.exe, 78: ati3d1ag.dll, 79: ati3duag.dll, 80: ATIDDC.DLL, 81: ATIDEMGR.dll, 82: atifglpf.xml, 83: atiicdxx.dat, 84: atiiiexx.dll, 85: atikvmag.dll, 86: atioglx1.dll, 87: atioglxx.dll, 88: atipdlxx.dll, 89: atitvo32.dll, 90: ativcoxx.dll, 91: ativdaxx.ax, 92: ativmvxx.ax, 93: ativtmxx.dll, 94: ativvaxx.dll, 95: atkctrs.dll, 96: atl.dll, 97: atl71.dll, 98: atmadm.exe, 99: atmenuxx.hlp, 100: atmfd.dll, 101: atmlib.dll, 102: atmpvcno.dll, 103: attenuxx.hlp, 104: attrib.exe, 105: audiodev.dll, 106: AUDIOGENIE2.DLL, 107: audiosrv.dll, 108: auditusr.exe, 109: authz.dll, 110: autochk.exe, 111: autoconv.exe, 112: autodisc.dll, 113: AUTOEXEC.NT, 114: autofmt.exe, 115: autolfn.exe, 116: avicap.dll, 117: avicap32.dll, 118: avifil32.dll, 119: avifile.dll, 120: avmeter.dll, 121: avtapi.dll, 122: avwav.dll, 123: axaltocm.dll, 124: azroles.dll, 125: basecsp.dll, 126: basesrv.dll, 127: BASSMOD.dll,bak, 128: batmeter.dll, 129: batt.dll, 130: bcshellext.dll, 131: bcsprsrc.dll, 132: bfdadcb8_d.ocx, 133: bidispl.dll, 134: bios1.rom, 135: bios4.rom, 136: bits, 137: bitsprx2.dll, 138: bitsprx3.dll, 139: bitsprx4.dll, 140: blackbox.dll, 141: blastcln.exe, 142: Bliss.avi, 143: Bliss.exe, 144: BMAPI.dll, 145: bootcfg.exe, 146: bootok.exe, 147: bootvid.dll, 148: bootvrfy.exe, 149: bopomofo.uce, 150: BReWErS.dll, 151: browselc.dll, 152: browser.dll, 153: browseui.dll, 154: browsewm.dll, 155: BtCoreIf.dll, 156: bthci.dll, 157: bthprops.cpl, 158: bthserv.dll, 159: BTMIGetKey.dll, 160: btpanui.dll, 161: cabinet.dll, 162: cabview.dll, 163: cacls.exe, 164: calc.exe, 165: camocx.dll, 166: capesnpn.dll, 167: capicom.dll, 168: cards.dll, 169: CatRoot, 170: CatRoot2, 171: catsrv.dll, 172: catsrvps.dll, 173: catsrvut.dll, 174: ccfgnt.dll, 175: CDDBControlSony.dll, 176: CddbLinkSony.dll, 177: CddbMusicIDSony.dll, 178: CddbPlaylist2Sony.dll, 179: CDDBUISony.dll, 180: cdfview.dll, 181: cdm.dll, 182: cdmodem.dll, 183: cdosys.dll, 184: cdplayer.exe.manifest, 185: certcli.dll, 186: certmgr.dll, 187: certmgr.msc, 188: cewmdm.dll, 189: cfgbkend.dll, 190: cfgmgr32.dll, 191: cfperfmon_mx.dll, 192: charmap.exe, 193: chcp.com, 194: chkdsk.exe, 195: chkntfs.exe, 196: ciadmin.dll, 197: ciadv.msc, 198: cic.dll, 199: cidaemon.exe, 200: ciodm.dll, 201: cipher.exe, 202: cisvc.exe, 203: ckcnv.exe, 204: clb.dll, 205: clbcatex.dll, 206: clbcatq.dll, 207: cleanmgr.exe, 208: cliconf.chm, 209: cliconfg.dll, 210: cliconfg.exe, 211: cliconfg.rll, 212: clipsrv.exe, 213: clusapi.dll, 214: cmcfg32.dll, 215: cmd.exe, 216: cmdial32.dll, 217: cmdl32.exe, 218: CMDLGFR.DLL, 219: cmdlib.wsc, 220: CmdLineExt.dll, 221: CmdLineExt03.dll, 222: cmmgr32.hlp, 223: cmmon32.exe, 224: cmos.ram, 225: cmpbk32.dll, 226: cmprops.dll, 227: cmsetacl.dll, 228: cmstp.exe, 229: cmutil.dll, 230: cnbjmon.dll, 231: cnetcfg.dll, 232: cnvfat.dll, 233: colbact.dll, 234: Com, 235: comaddin.dll, 236: comcat.dll, 237: comctl32.dll, 238: comctl32.ocx, 239: comdlg32.dll, 240: comdlg32.ocx, 241: comm.drv, 242: command.com, 243: commdlg.dll, 244: comp.exe, 245: compact.exe, 246: compatui.dll, 247: compmgmt.msc, 248: compobj.dll, 249: compstui.dll, 250: comrepl.dll, 251: comres.dll, 252: comsdupd.exe, 253: comsnap.dll, 254: comsvcs.dll, 255: comuid.dll, 256: config, 257: config.hsp, 258: CONFIG.NT, 259: CONFIG.TMP, 260: confmsp.dll, 261: conime.exe, 262: console.dll, 263: Contig.exe, 264: ContigEula.txt, 265: control.exe, 266: ControlSubX.ocx, 267: convert.exe, 268: corpol.dll, 269: country.sys, 270: cpuinf32.dll, 271: credssp.dll, 272: credui.dll, 273: crtdll.dll, 274: crypt32.dll, 275: cryptdlg.dll, 276: cryptdll.dll, 277: cryptext.dll, 278: cryptnet.dll, 279: cryptsvc.dll, 280: cryptui.dll, 281: cscdll.dll, 282: cscript.exe, 283: cscui.dll, 284: csrsrv.dll, 285: csrss.exe, 286: csseqchk.dll, 287: Ct1mgm.rom, 288: ctfmon.exe, 289: ctl3d32.dll, 290: ctl3dv2.dll, 291: ctype.nls, 292: c_037.nls, 293: c_10000.nls, 294: c_10006.nls, 295: c_10007.nls, 296: c_10010.nls, 297: c_10017.nls, 298: c_10029.nls, 299: c_10079.nls, 300: c_10081.nls, 301: c_10082.nls, 302: c_1026.nls, 303: c_1250.nls, 304: c_1251.nls, 305: c_1252.nls, 306: c_1253.nls, 307: c_1254.nls, 308: c_1255.nls, 309: c_1256.nls, 310: c_1257.nls, 311: c_1258.nls, 312: c_20127.nls, 313: c_20261.nls, 314: c_20866.nls, 315: c_20905.nls, 316: c_21866.nls, 317: c_28591.nls, 318: c_28592.nls, 319: c_28593.nls, 320: C_28594.NLS, 321: C_28595.NLS, 322: C_28597.NLS, 323: c_28598.nls, 324: c_28599.nls, 325: c_28603.nls, 326: c_28605.nls, 327: c_437.nls, 328: c_500.nls, 329: c_737.nls, 330: c_775.nls, 331: c_850.nls, 332: c_852.nls, 333: c_855.nls, 334: c_857.nls, 335: c_860.nls, 336: c_861.nls, 337: c_863.nls, 338: c_865.nls, 339: c_866.nls, 340: c_869.nls, 341: c_874.nls, 342: c_875.nls, 343: c_932.nls, 344: c_936.nls, 345: c_949.nls, 346: c_950.nls, 347: d3d8.dll, 348: d3d8thk.dll, 349: d3d9.dll, 350: d3d9caps.dat, 351: D3DCompiler_33.dll, 352: D3DCompiler_34.dll, 353: D3DCompiler_35.dll, 354: D3DCompiler_36.dll, 355: D3DCompiler_37.dll, 356: D3DCompiler_38.dll, 357: D3DCompiler_39.dll, 358: d3dim.dll, 359: d3dim700.dll, 360: d3dpmesh.dll, 361: d3dramp.dll, 362: d3drm.dll, 363: d3dx10_33.dll, 364: d3dx10_34.dll, 365: d3dx10_35.dll, 366: d3dx10_36.dll, 367: d3dx10_37.dll, 368: d3dx10_38.dll, 369: d3dx10_39.dll, 370: d3dx9_24.dll, 371: d3dx9_25.dll, 372: d3dx9_26.dll, 373: d3dx9_27.dll, 374: d3dx9_28.dll, 375: d3dx9_29.dll, 376: d3dx9_30.dll, 377: d3dx9_31.dll, 378: d3dx9_32.dll, 379: d3dx9_33.dll, 380: d3dx9_34.dll, 381: d3dx9_35.dll, 382: d3dx9_36.dll, 383: D3DX9_37.dll, 384: D3DX9_38.dll, 385: D3DX9_39.dll, 386: d3dxof.dll, 387: danim.dll, 388: Data, 389: dataclen.dll, 390: datime.dll, 391: davclnt.dll, 392: daxctle.ocx, 393: dbgeng.dll, 394: dbghelp.dll, 395: dbmsrpcn.dll, 396: dbnetlib.dll, 397: dbnmpntw.dll, 398: dcache.bin, 399: dciman32.dll, 400: dcomcnfg.exe, 401: ddeml.dll, 402: ddeshare.exe, 403: DDMI2.sys, 404: ddraw.dll, 405: ddrawex.dll, 406: debug.exe, 407: Default.sfm, 408: Default4.sfm, 409: Default8.sfm, 410: default_user_class.dat, 411: default_user_class.dat.LOG, 412: defrag.exe, 413: DellSys.dll, 414: DELLWALL.BMP, 415: desk.cpl, 416: deskadp.dll, 417: deskmon.dll, 418: deskperf.dll, 419: desktop.ini, 420: devenum.dll, 421: devmgmt.msc, 422: devmgr.dll, 423: dfrg.msc, 424: dfrgfat.exe, 425: dfrgntfs.exe, 426: dfrgres.dll, 427: dfrgsnap.dll, 428: dfrgui.dll, 429: dfshim.dll, 430: dfsshlex.dll, 431: dgnet.dll, 432: dgrpsetu.dll, 433: dgsetup.dll, 434: dhcp, 435: dhcpcsvc.dll, 436: dhcpmon.dll, 437: dhcpqec.dll, 438
28107	2:50:03.4790245 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	
28109	2:50:03.4790837 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: diactfrm.dll, 1: diantz.exe, 2: DiceAsio.dll, 3: DiceController.dll, 4: digest.dll, 5: dimap.dll, 6: dimsntfy.dll, 7: dimsroam.dll, 8: dinput.dll, 9: dinput8.dll, 10: DirectX, 11: diskcomp.com, 12: diskcopy.com, 13: diskcopy.dll, 14: diskmgmt.msc, 15: diskpart.exe, 16: diskperf.exe, 17: dispex.dll, 18: divx.dll, 19: dllcache, 20: dllhost.exe, 21: dllhst3g.exe, 22: DLPT2.sys, 23: dmadmin.exe, 24: dmband.dll, 25: dmcompos.dll, 26: dmconfig.dll, 27: dmdlgs.dll, 28: dmdskmgr.dll, 29: dmdskres.dll, 30: dmime.dll, 31: dmintf.dll, 32: dmloader.dll, 33: dmocx.dll, 34: dmremote.exe, 35: dmscript.dll, 36: dmserver.dll, 37: dmstyle.dll, 38: dmsynth.dll, 39: dmusic.dll, 40: dmutil.dll, 41: dmview.ocx, 42: dns-sd.exe, 43: dnsapi.dll, 44: dnsrslvr.dll, 45: dnssd.dll, 46: docprop.dll, 47: docprop2.dll, 48: doskey.exe, 49: dosx.exe, 50: dot3api.dll, 51: dot3cfg.dll, 52: dot3dlg.dll, 53: dot3gpclnt.dll, 54: dot3msm.dll, 55: dot3svc.dll, 56: dot3ui.dll, 57: dpcdll.dll, 58: dpl100.dll, 59: dplay.dll, 60: dplaysvr.exe, 61: dp?azc ? 0: diactfrm.dll, 1: diantz.exe, 2: DiceAsio.dll, 3: DiceController.dll, 4: digest.dll, 5: dimap.dll, 6: dimsntfy.dll, 7: dimsroam.dll, 8: dinput.dll, 9: dinput8.dll, 10: DirectX, 11: diskcomp.com, 12: diskcopy.com, 13: diskcopy.dll, 14: diskmgmt.msc, 15: diskpart.exe, 16: diskperf.exe, 17: dispex.dll, 18: divx.dll, 19: dllcache, 20: dllhost.exe, 21: dllhst3g.exe, 22: DLPT2.sys, 23: dmadmin.exe, 24: dmband.dll, 25: dmcompos.dll, 26: dmconfig.dll, 27: dmdlgs.dll, 28: dmdskmgr.dll, 29: dmdskres.dll, 30: dmime.dll, 31: dmintf.dll, 32: dmloader.dll, 33: dmocx.dll, 34: dmremote.exe, 35: dmscript.dll, 36: dmserver.dll, 37: dmstyle.dll, 38: dmsynth.dll, 39: dmusic.dll, 40: dmutil.dll, 41: dmview.ocx, 42: dns-sd.exe, 43: dnsapi.dll, 44: dnsrslvr.dll, 45: dnssd.dll, 46: docprop.dll, 47: docprop2.dll, 48: doskey.exe, 49: dosx.exe, 50: dot3api.dll, 51: dot3cfg.dll, 52: dot3dlg.dll, 53: dot3gpclnt.dll, 54: dot3msm.dll, 55: dot3svc.dll, 56: dot3ui.dll, 57: dpcdll.dll, 58: dpl100.dll, 59: dplay.dll, 60: dplaysvr.exe, 61: dplayx.dll, 62: dpmodemx.dll, 63: dpnaddr.dll, 64: dpnet.dll, 65: dpnhpast.dll, 66: dpnhupnp.dll, 67: dpnlobby.dll, 68: dpnmodem.dll, 69: dpnsvr.exe, 70: dpnwsock.dll, 71: dpserial.dll, 72: dpvacm.dll, 73: dpvoice.dll, 74: dpvsetup.exe, 75: dpvvox.dll, 76: dpwsock.dll, 77: dpwsockx.dll, 78: driverquery.exe, 79: drivers, 80: DRM, 81: drmclien.dll, 82: drmstor.dll, 83: drmupgds.exe, 84: drmv2clt.dll, 85: drprov.dll, 86: DRVSTORE, 87: drwatson.exe, 88: drwtsn32.exe, 89: ds16gt.dLL, 90: ds32gt.dll, 91: dsauth.dll, 92: dsdmo.dll, 93: dsdmoprp.dll, 94: dskquota.dll, 95: dskquoui.dll, 96: dsound.dll, 97: dsound.vxd, 98: dsound3d.dll, 99: dsprop.dll, 100: dsprpres.dll, 101: dsquery.dll, 102: dssec.dat, 103: dssec.dll, 104: dssenh.dll, 105: dsuiext.dll, 106: dswave.dll, 107: dumprep.exe, 108: duser.dll, 109: dvdplay.exe, 110: dvdupgrd.exe, 111: dwwin.exe, 112: dx7vb.dll, 113: dx8vb.dll, 114: dxdiag.exe, 115: dxdiagn.dll, 116: dxmasf.dll, 117: dxtmsft.dll, 118: dxtrans.dll, 119: dxva2.dll, 120: eapolqec.dll, 121: eapp3hst.dll, 122: eappcfg.dll, 123: eappgnui.dll, 124: eapphost.dll, 125: eappprxy.dll, 126: eapqec.dll, 127: eapsvc.dll, 128: ebfbebda1_d.dll, 129: edit.com, 130: edit.hlp, 131: edlin.exe, 132: efsadu.dll, 133: ega.cpi, 134: els.dll, 135: emptyregdb.dat, 136: en, 137: en-US, 138: encapi.dll, 139: encdec.dll, 140: EqnClass.Dll, 141: eraser.dll, 142: ersvc.dll, 143: es.dll, 144: esent.dll, 145: esent97.dll, 146: esentprf.dll, 147: esentprf.hxx, 148: esentprf.ini, 149: esentutl.exe, 150: eudcedit.exe, 151: eula.txt, 152: eventcls.dll, 153: eventcreate.exe, 154: eventlog.dll, 155: eventquery.vbs, 156: eventtriggers.exe, 157: eventvwr.exe, 158: eventvwr.msc, 159: evr.dll, 160: exe2bin.exe, 161: expand.exe, 162: export, 163: expsrv.dll, 164: extmgr.dll, 165: extrac32.exe, 166: exts.dll, 167: fastopen.exe, 168: faultrep.dll, 169: faxpatch.exe, 170: fc.exe, 171: fde.dll, 172: fdeploy.dll, 173: feclient.dll, 174: ff_vfw.dll, 175: ff_vfw.dll.manifest, 176: filemgmt.dll, 177: FileOps.exe, 178: find.exe, 179: findstr.exe, 180: finger.exe, 181: firewall.cpl, 182: fixmapi.exe, 183: fldrclnr.dll, 184: fltlib.dll, 185: fltmc.exe, 186: FM20.DLL, 187: FM20ENU.DLL, 188: fmifs.dll, 189: FNTCACHE.DAT, 190: fontext.dll, 191: fontsub.dll, 192: fontview.exe, 193: forcedos.exe, 194: format.com, 195: framebuf.dll, 196: fsdbcrpt.kar.{fbdfea4c-c65a-477f-864c-f28667e6277a}, 197: fsmgmt.msc, 198: fsquirt.exe, 199: fsusd.dll, 200: fsutil.exe, 201: ftp.exe, 202: ftsrch.dll, 203: fwcfg.dll, 204: FXAB32.DLL, 205: Fxdb.dll, 206: fxsapi.dll, 207: fxscfgwz.dll, 208: fxsclnt.exe, 209: fxsclntR.dll, 210: fxscom.dll, 211: fxscomex.dll, 212: fxscount.h, 213: fxscover.exe, 214: fxsdrv.dll, 215: fxsevent.dll, 216: fxsext32.dll, 217: fxsmon.dll, 218: fxsperf.dll, 219: fxsperf.ini, 220: fxsres.dll, 221: fxsroute.dll, 222: fxssend.exe, 223: fxsst.dll, 224: fxssvc.exe, 225: fxst30.dll, 226: fxstiff.dll, 227: FxsTmp, 228: fxsui.dll, 229: fxswzrd.dll, 230: fxsxp32.dll, 231: g711codc.ax, 232: gb2312.uce, 233: gbaudmgr.ax, 234: gbclcnvt.ax, 235: gbcpntfy.ax, 236: gbproppg.ax, 237: gbtvrate.dll, 238: gcdef.dll, 239: gdi.exe, 240: gdi32.dll, 241: geo.nls, 242: getmac.exe, 243: getuname.dll, 244: giveio.sys, 245: glmf32.dll, 246: glu32.dll, 247: GPCIEnum.sys, 248: gpedit.dll, 249: gpedit.msc, 250: gpkcsp.dll, 251: gpkrsrc.dll, 252: gpresult.exe, 253: gptext.dll, 254: gpupdate.exe, 255: graftabl.com, 256: graphics.com, 257: graphics.pro, 258: GroupPolicy, 259: grpconv.exe, 260: GTKCMOS.sys, 261: h323.tsp, 262: h323log.txt, 263: h323msp.dll, 264: HAL.DLL, 265: haspdos.sys, 266: haspvdd.dll, 267: hccoin.dll, 268: Hdaudprop.dll, 269: Hdaudpropres.dll, 270: Hdaudpropshortcut.exe, 271: hdwwiz.cpl, 272: help.exe, 273: hhctrl.ocx, 274: hhsetup.dll, 275: hid.dll, 276: hidphone.tsp, 277: hidserv.dll, 278: himem.sys, 279: hlink.dll, 280: hnetcfg.dll, 281: hnetmon.dll, 282: hnetwiz.dll, 283: homepage.inf, 284: hostname.exe, 285: hotplug.dll, 286: hsfcisp2.dll, 287: hticons.dll, 288: html.iec, 289: httpapi.dll, 290: htui.dll, 291: hypertrm.dll, 292: iac25_32.ax, 293: ias, 294: iasacct.dll, 295: iasads.dll, 296: iashlpr.dll, 297: iasnap.dll, 298: iaspolcy.dll, 299: iasrad.dll, 300: iasrecst.dll, 301: iassam.dll, 302: iassdo.dll, 303: iassvcs.dll, 304: icaapi.dll, 305: icardagt.exe, 306: icardie.dll, 307: icardres.dll, 308: icardres.dll.mui, 309: iccvid.dll, 310: icfgnt5.dll, 311: icm32.dll, 312: icmp.dll, 313: icmui.dll, 314: icrav03.rat, 315: icsxml, 316: icwdial.dll, 317: icwphbk.dll, 318: ideograf.uce, 319: idndl.dll, 320: idq.dll, 321: ie4uinit.exe, 322: IE7Eula.rtf, 323: IE8Eula.rtf, 324: ieakeng.dll, 325: ieaksie.dll, 326: ieakui.dll, 327: ieapfltr.dat, 328: ieapfltr.dll, 329: iedkcs32.dll, 330: ieencode.dll, 331: ieframe.dll, 332: ieframe.dll.mui, 333: iepeers.dll, 334: iernonce.dll, 335: iertutil.dll, 336: IESetting.dll, 337: iesetup.dll, 338: ieudinit.exe, 339: ieui.dll, 340: ieuinit.inf, 341: iexpress.exe, 342: ifmon.dll, 343: ifsutil.dll, 344: ifxcardm.dll, 345: igdetect.dll, 346: igmpagnt.dll, 347: iissuba.dll, 348: ils.dll, 349: imaadp32.acm, 350: imagehlp.dll, 351: imagX7.dll, 352: imagXpr7.dll, 353: imagXR7.dll, 354: imagXRA7.dll, 355: imapi.exe, 356: imapi2.dll, 357: imapi2fs.dll, 358: IMC32.acm, 359: IME, 360: imeshare.dll, 361: imgutil.dll, 362: imm32.dll, 363: indounin.dll, 364: inetcfg.dll, 365: inetcomm0.dll, 366: inetcpl.cpl, 367: inetcplc.dll, 368: inetmib1.dll, 369: inetpp.dll, 370: inetppui.dll, 371: inetres.dll, 372: inetsrv, 373: Inetwh32.dll, 374: infocardapi.dll, 375: infocardcpl.cpl, 376: infosoft.dll, 377: initdebug.nfo, 378: initpki.dll, 379: input.dll, 380: inseng.dll, 381: inst.apf, 382: instcat.sql, 383: intl.cpl, 384: iologmsg.dll, 385: ipconf.tsp, 386: ipconfig.exe, 387: iphlpapi.dll, 388: ipmontr.dll, 389: ipnathlp.dll, 390: ippromon.dll, 391: iprop.dll, 392: iprtprio.dll, 393: iprtrmgr.dll, 394: ipsec6.exe, 395: ipsecsnp.dll, 396: ipsecsvc.dll, 397: ipsink.ax, 398: ipsmsnap.dll, 399: ipv6.exe, 400: ipv6mon.dll, 401: ipxmontr.dll, 402: ipxpromn.dll, 403: ipxrip.dll, 404: ipxroute.exe, 405: ipxrtmgr.dll, 406: ipxsap.dll, 407: ipxwan.dll, 408: ir32_32.dll, 409: ir41_32.ax, 410: ir41_qc.dll, 411: ir41_qcx.dll, 412: ir50_32.dll, 413: ir50_qc.dll, 414: ir50_qcx.dll, 415: irclass.dll, 416: irprops.cpl, 417: isign32.dll, 418: isrdbg32.dll, 419: ISUSPM.cpl, 420: itircl.dll, 421: itss.dll, 422: iuengine.dll, 423: ivfsrc.ax, 424: ixsso.dll, 425: iyuv_32.dll, 426: Iyvu9_32.dll, 427: java.exe, 428: javacpl.cpl, 429: javaw.exe, 430: javaws.exe, 431: jet500.dll, 432: Jgaw400.dll, 433: jgdw400.dll, 434: Jgmd400.dll, 435: jgpl400.dll, 436: Jgsd400.dll, 437: Jgsh400.dll, 438: JkDefragScreenSaver.exe, 439
28110	2:50:03.4793684 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: JkDefragScreenSaver.scr, 1: jobexec.dll, 2: joy.cpl, 3: jscript.dll, 4: jsproxy.dll, 5: jupdate-1.4.2_03-b02.log, 6: jupdate-1.5.0_05-b05.log, 7: jupdate-1.5.0_06-b05.log, 8: jupdate-1.6.0_03-b05.log, 9: jupdate-1.6.0_04-b12.log, 10: jupdate-1.6.0_06-b02.log, 11: jupdate-1.6.0_07-b06.log, 12: kanji_1.uce, 13: kanji_2.uce, 14: kb16.com, 15: kbd106.dll, 16: KBDAL.DLL, 17: kbdaze.dll, 18: kbdazel.dll, 19: kbdbe.dll, 20: kbdbene.dll, 21: kbdbhc.dll, 22: kbdblr.dll, 23: kbdbr.dll, 24: kbdbu.dll, 25: kbdca.dll, 26: kbdcan.dll, 27: kbdcr.dll, 28: kbdcz.dll, 29: kbdcz1.dll, 30: kbdcz2.dll, 31: kbdda.dll, 32: kbddv.dll, 33: kbdes.dll, 34: kbdest.dll, 35: kbdfc.dll, 36: kbdfi.dll, 37: kbdfi1.dll, 38: kbdfo.dll, 39: kbdfr.dll, 40: kbdgae.dll, 41: kbdgkl.dll, 42: kbdgr.dll, 43: kbdgr1.dll, 44: kbdhe.dll, 45: kbdhe220.dll, 46: kbdhe319.dll, 47: kbdhela2.dll, 48: kbdhela3.dll, 49: kbdhept.dll, 50: kbdhu.dll, 51: kbdhu1.dll, 52: kbdic.dll, 53: kbdinbe1.dll, 54: kbdinben.dll, 55: kbdinmal.dll, 56: kbdir.dll, 57: kbdit.dll?azd ? 0: JkDefragScreenSaver.scr, 1: jobexec.dll, 2: joy.cpl, 3: jscript.dll, 4: jsproxy.dll, 5: jupdate-1.4.2_03-b02.log, 6: jupdate-1.5.0_05-b05.log, 7: jupdate-1.5.0_06-b05.log, 8: jupdate-1.6.0_03-b05.log, 9: jupdate-1.6.0_04-b12.log, 10: jupdate-1.6.0_06-b02.log, 11: jupdate-1.6.0_07-b06.log, 12: kanji_1.uce, 13: kanji_2.uce, 14: kb16.com, 15: kbd106.dll, 16: KBDAL.DLL, 17: kbdaze.dll, 18: kbdazel.dll, 19: kbdbe.dll, 20: kbdbene.dll, 21: kbdbhc.dll, 22: kbdblr.dll, 23: kbdbr.dll, 24: kbdbu.dll, 25: kbdca.dll, 26: kbdcan.dll, 27: kbdcr.dll, 28: kbdcz.dll, 29: kbdcz1.dll, 30: kbdcz2.dll, 31: kbdda.dll, 32: kbddv.dll, 33: kbdes.dll, 34: kbdest.dll, 35: kbdfc.dll, 36: kbdfi.dll, 37: kbdfi1.dll, 38: kbdfo.dll, 39: kbdfr.dll, 40: kbdgae.dll, 41: kbdgkl.dll, 42: kbdgr.dll, 43: kbdgr1.dll, 44: kbdhe.dll, 45: kbdhe220.dll, 46: kbdhe319.dll, 47: kbdhela2.dll, 48: kbdhela3.dll, 49: kbdhept.dll, 50: kbdhu.dll, 51: kbdhu1.dll, 52: kbdic.dll, 53: kbdinbe1.dll, 54: kbdinben.dll, 55: kbdinmal.dll, 56: kbdir.dll, 57: kbdit.dll, 58: kbdit142.dll, 59: kbdiultn.dll, 60: kbdjpn.dll, 61: kbdkaz.dll, 62: kbdkyr.dll, 63: kbdla.dll, 64: kbdlt.dll, 65: kbdlt1.dll, 66: kbdlv.dll, 67: kbdlv1.dll, 68: kbdmac.dll, 69: kbdmaori.dll, 70: kbdmlt47.dll, 71: kbdmlt48.dll, 72: kbdmon.dll, 73: kbdne.dll, 74: kbdnec.dll, 75: kbdnepr.dll, 76: kbdno.dll, 77: kbdno1.dll, 78: kbdpash.dll, 79: kbdpl.dll, 80: kbdpl1.dll, 81: kbdpo.dll, 82: kbdro.dll, 83: kbdru.dll, 84: kbdru1.dll, 85: kbdsf.dll, 86: kbdsg.dll, 87: kbdsl.dll, 88: kbdsl1.dll, 89: kbdsmsfi.dll, 90: kbdsmsno.dll, 91: kbdsp.dll, 92: kbdsw.dll, 93: kbdtat.dll, 94: kbdtuf.dll, 95: kbdtuq.dll, 96: kbduk.dll, 97: kbdukx.dll, 98: kbdur.dll, 99: kbdus.dll, 100: kbdusl.dll, 101: kbdusr.dll, 102: kbdusx.dll, 103: kbduzb.dll, 104: kbdycc.dll, 105: kbdycl.dll, 106: kd1394.dll, 107: kdcom.dll, 108: kemutb.dll, 109: KemUtil.dll, 110: KemWnd.dll, 111: KemXML.dll, 112: kerberos.dll, 113: kernel32.dll, 114: key01.sys, 115: keyboard.drv, 116: keyboard.sys, 117: keymgr.dll, 118: KeyRemap.VXD, 119: kmddsp.tsp, 120: kmsvc.dll, 121: korean.uce, 122: KPower.dll, 123: krnl386.exe, 124: ksproxy.ax, 125: kstvtune.ax, 126: ksuser.dll, 127: kswdmcap.ax, 128: ksxbar.ax, 129: l2gpstore.dll, 130: l3codeca.acm, 131: l3codecp.acm, 132: l3codecx.ax, 133: label.exe, 134: lameACM.acm, 135: lame_acm.xml, 136: lame_enc.dll, 137: langwrbk.dll, 138: lanman.drv, 139: LAPRXY.dll, 140: LAYOUT.DLL, 141: LCWizard.dll, 142: LegitCheckControl.dll, 143: LEX2KUSB.DLL, 144: LEXBCE.DLL, 145: LEXBCES.EXE, 146: lexlmpm.dll, 147: LEXP2P32.DLL, 148: LEXPPS.EXE, 149: lfbmp11n.dll, 150: LFCMP11n.DLL, 151: lfeps11n.dll, 152: lffax11n.dll, 153: lfgif11n.dll, 154: lfpcd11n.dll, 155: lfpcx11n.dll, 156: Lfpng11n.dll, 157: lfpsd11n.dll, 158: lftga11n.dll, 159: lftif11n.dll, 160: lfwmf11n.dll, 161: libexpat.dll, 162: licdll.dll, 163: licmgr10.dll, 164: licwmi.dll, 165: lights.exe, 166: linkinfo.dll, 167: lmhsvc.dll, 168: lmrt.dll, 169: lnkstub.exe, 170: loadfix.com, 171: loadperf.dll, 172: LocalCOM.cpl, 173: locale.nls, 174: localsec.dll, 175: localspl.dll, 176: localui.dll, 177: locator.exe, 178: lodctr.exe, 179: logagent.exe, 180: LogFiles, 181: loghours.dll, 182: login.cmd, 183: logman.exe, 184: logoff.exe, 185: logon.scr, 186: logonui.exe, 187: logonui.exe.manifest, 188: lpk.dll, 189: lpq.exe, 190: lpr.exe, 191: lprhelp.dll, 192: lprmonui.dll, 193: lsasrv.dll, 194: lsass.exe, 195: LTDIS11n.dll, 196: ltfil11n.DLL, 197: ltimg11n.dll, 198: ltkrn11n.dll, 199: Ltwvc11n.dll, 200: lusrmgr.msc, 201: lz32.dll, 202: lzexpand.dll, 203: l_except.nls, 204: l_intl.nls, 205: Macromed, 206: magnify.exe, 207: mag_hook.dll, 208: main.cpl, 209: makecab.exe, 210: mapi32.dll, 211: mapistub.dll, 212: mapisvc.inf, 213: mcastmib.dll, 214: mcd32.dll, 215: mcdsrv32.dll, 216: mchgrcoi.dll, 217: mciavi.drv, 218: mciavi32.dll, 219: mcicda.dll, 220: mciole16.dll, 221: mciole32.dll, 222: mciqtz32.dll, 223: mciseq.dll, 224: mciseq.drv, 225: mciwave.dll, 226: mciwave.drv, 227: mdhcp.dll, 228: mdminst.dll, 229: mdmxsdk.dll, 230: mdwmdmsp.dll, 231: mem.exe, 232: mf3216.dll, 233: MFC40.DLL, 234: mfc40u.dll, 235: mfc42.dll, 236: MFC42ENU.DLL, 237: mfc42u.dll, 238: MFC71.dll, 239: MFC71CHS.DLL, 240: MFC71CHT.DLL, 241: MFC71DEU.DLL, 242: MFC71ENU.DLL, 243: MFC71ESP.DLL, 244: MFC71FRA.DLL, 245: MFC71ITA.DLL, 246: MFC71JPN.DLL, 247: MFC71KOR.DLL, 248: MFC71u.dll, 249: MFCANS32.DLL, 250: mfcsubs.dll, 251: mfcuia32.dll, 252: MFPLAT.dll, 253: mgmtapi.dll, 254: mhn.dll, 255: mib.bin, 256: Microsoft, 257: microsoft.managementconsole.dll, 258: midas.dll, 259: midas.jdbg, 260: midimap.dll, 261: miglibnt.dll, 262: migpwd.exe, 263: milcore.dll, 264: mimefilt.dll, 265: mkcHyperlink.ocx, 266: mlang.dat, 267: mlang.dll, 268: mlfcache.dat, 269: mll_hp.dll, 270: mll_mtf.dll, 271: mll_qic.dll, 272: mmc.exe, 273: mmcbase.dll, 274: mmcex.dll, 275: mmcfxcommon.dll, 276: mmcndmgr.dll, 277: mmcperf.exe, 278: mmcshext.dll, 279: mmdriver.inf, 280: mmdrv.dll, 281: mmfutil.dll, 282: mmsys.cpl, 283: mmsystem.dll, 284: mmtask.tsk, 285: mmutilse.dll, 286: mnmdd.dll, 287: mnmsrvc.exe, 288: mobsync.dll, 289: mobsync.exe, 290: mode.com, 291: modemui.dll, 292: modex.dll, 293: more.com, 294: moricons.dll, 295: mountvol.exe, 296: mouse.drv, 297: MP43DECD.dll, 298: MP43DMOD.dll, 299: MP4SDECD.dll, 300: MP4SDMOD.dll, 301: mpeg2data.ax, 302: mpg2splt.ax, 303: MPG4DECD.dll, 304: MPG4DMOD.dll, 305: mpg4ds32.ax, 306: mplay32.exe, 307: mpnotify.exe, 308: mpr.dll, 309: mprapi.dll, 310: mprddm.dll, 311: mprdim.dll, 312: mprmsg.dll, 313: mprui.dll, 314: mqad.dll, 315: mqbkup.exe, 316: mqcertui.dll, 317: mqdscli.dll, 318: mqgentr.dll, 319: mqise.dll, 320: mqlogmgr.dll, 321: mqoa.dll, 322: mqoa.tlb, 323: mqoa10.tlb, 324: mqoa20.tlb, 325: mqperf.dll, 326: mqperf.ini, 327: mqprfsym.h, 328: mqqm.dll, 329: mqrt.dll, 330: mqrtdep.dll, 331: mqsec.dll, 332: mqsnap.dll, 333: mqsvc.exe, 334: mqtgsvc.exe, 335: mqtrig.dll, 336: mqupgrd.dll, 337: mqutil.dll, 338: mrinfo.exe, 339: MRT.exe, 340: msaatext.dll, 341: msacm.dll, 342: msacm32.dll, 343: msacm32.drv, 344: msadds32.ax, 345: msadp32.acm, 346: msafd.dll, 347: msapsspc.dll, 348: msasn1.dll, 349: msaud32.acm, 350: msaudite.dll, 351: mscat32.dll, 352: mscdexnt.exe, 353: MSCMCFR.DLL, 354: mscms.dll, 355: Mscomct2.ocx, 356: MSCOMCTL.OCX, 357: msconf.dll, 358: mscoree.dll, 359: mscorier.dll, 360: mscories.dll, 361: mscpx32r.dll, 362: mscpxl32.dll, 363: msctf.dll, 364: msctfime.ime, 365: msctfp.dll, 366: msdadiag.dll, 367: msdart.dll, 368: msdatsrc.tlb, 369: msdbcrpt.kar.{fbdfea4c-c65a-477f-864c-f28667e6277a}, 370: msdelta.dll, 371: msdmo.dll, 372: msdrm.dll, 373: MsDtc, 374: msdtc.exe, 375: msdtclog.dll, 376: msdtcprf.h, 377: msdtcprf.ini, 378: msdtcprx.dll, 379: msdtctm.dll, 380: msdtcuiu.dll, 381: Msdvbnp.ax, 382: msdxm.ocx, 383: msdxmlc.dll, 384: msencode.dll, 385: msexch40.dll, 386: msexcl40.dll, 387: msfeeds.dll, 388: msfeedsbs.dll, 389: msfeedssync.exe, 390: msflxgrd.ocx, 391: msftedit.dll, 392: msg.exe, 393: msg711.acm, 394: msg723.acm, 395: msgina.dll, 396: msgsm32.acm, 397: msgsvc.dll, 398: msh261.drv, 399: msh263.drv, 400: mshta.exe, 401: mshtml.dll, 402: mshtml.tlb, 403: mshtmled.dll, 404: mshtmler.dll, 405: msi.dll, 406: msidcrl40.dll, 407: msident.dll, 408: msidle.dll, 409: msidntld.dll, 410: msieftp.dll, 411: msiexec.exe, 412: MsiExec.exe.log, 413: msihnd.dll, 414: msimg32.dll, 415: msimsg.dll, 416: msimtf.dll, 417: MSINET.OCX, 418: msisip.dll, 419: msjava.dll, 420: msjet40.dll, 421: msjetoledb40.dll, 422: msjint40.dll, 423: msjter40.dll, 424: msjtes40.dll, 425: mslbui.dll, 426: msls31.dll, 427: msltus40.dll, 428: msnetobj.dll, 429: msnp.ax, 430: msnsspc.dll, 431: msobjs.dll, 432: msoeacct0.dll, 433: msoert2000000000.dll, 434: msorc32r.dll, 435: msorcl32.dll, 436: mspatcha.dll, 437: mspbde40.dll, 438: mspmsnsv.dll, 439: mspmsp.dll, 440: msports.dll, 441: msprivs.dll
28114	2:50:03.4797237 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: msr2c.dll, 1: msr2cenu.dll, 2: msratelc.dll, 3: msrating.dll, 4: msrclr40.dll, 5: msrd2x40.dll, 6: msrd3x40.dll, 7: MSRDO20.DLL, 8: msrecr40.dll, 9: msrepl40.dll, 10: msrle32.dll, 11: mssap.dll, 12: msscds32.ax, 13: msscp.dll, 14: msscript.ocx, 15: mssha.dll, 16: msshavmsg.dll, 17: mssign32.dll, 18: mssip32.dll, 19: MSSTDFMT.DLL, 20: msstkprp.dll, 21: msswch.dll, 22: msswchx.exe, 23: mstask.dll, 24: mstext40.dll, 25: mstime.dll, 26: mstinit.exe, 27: mstlsapi.dll, 28: mstsc.exe, 29: mstscax.dll, 30: msutb.dll, 31: msv1_0.dll, 32: msvbvm50.dll, 33: msvbvm60.dll, 34: msvcirt.dll, 35: msvcp50.dll, 36: msvcp60.dll, 37: msvcp70.dll, 38: msvcp71.dll, 39: msvcp80.dll, 40: msvcr70.dll, 41: msvcr71.dll, 42: msvcr80.dll, 43: msvcrt.dll, 44: msvcrt20.dll, 45: msvcrt40.dll, 46: msvfw32.dll, 47: msvidc32.dll, 48: msvidctl.dll, 49: msvideo.dll, 50: msw3prt.dll, 51: mswdat10.dll, 52: mswebdvd.dll, 53: MSWINSCK.OCX, 54: mswmdm.dll, 55: mswsock.dll, 56: mswstr10.dll, 57: msxbde40.dll, 58: msxml.dll, 59: msxml2r.dll, 60: msx?azc ? 0: msr2c.dll, 1: msr2cenu.dll, 2: msratelc.dll, 3: msrating.dll, 4: msrclr40.dll, 5: msrd2x40.dll, 6: msrd3x40.dll, 7: MSRDO20.DLL, 8: msrecr40.dll, 9: msrepl40.dll, 10: msrle32.dll, 11: mssap.dll, 12: msscds32.ax, 13: msscp.dll, 14: msscript.ocx, 15: mssha.dll, 16: msshavmsg.dll, 17: mssign32.dll, 18: mssip32.dll, 19: MSSTDFMT.DLL, 20: msstkprp.dll, 21: msswch.dll, 22: msswchx.exe, 23: mstask.dll, 24: mstext40.dll, 25: mstime.dll, 26: mstinit.exe, 27: mstlsapi.dll, 28: mstsc.exe, 29: mstscax.dll, 30: msutb.dll, 31: msv1_0.dll, 32: msvbvm50.dll, 33: msvbvm60.dll, 34: msvcirt.dll, 35: msvcp50.dll, 36: msvcp60.dll, 37: msvcp70.dll, 38: msvcp71.dll, 39: msvcp80.dll, 40: msvcr70.dll, 41: msvcr71.dll, 42: msvcr80.dll, 43: msvcrt.dll, 44: msvcrt20.dll, 45: msvcrt40.dll, 46: msvfw32.dll, 47: msvidc32.dll, 48: msvidctl.dll, 49: msvideo.dll, 50: msw3prt.dll, 51: mswdat10.dll, 52: mswebdvd.dll, 53: MSWINSCK.OCX, 54: mswmdm.dll, 55: mswsock.dll, 56: mswstr10.dll, 57: msxbde40.dll, 58: msxml.dll, 59: msxml2r.dll, 60: msxml3.dll, 61: msxml3r.dll, 62: msxml4.dll, 63: msxml4r.dll, 64: msxml6.dll, 65: msxml6r.dll, 66: msxmlr.dll, 67: msyuv.dll, 68: mtxclu.dll, 69: mtxdm.dll, 70: mtxex.dll, 71: mtxlegih.dll, 72: mtxoci.dll, 73: mtxparhd.dll, 74: mucltui.dll, 75: mui, 76: muweb.dll, 77: mycomput.dll, 78: mydocs.dll, 79: napipsec.dll, 80: napmontr.dll, 81: napstat.exe, 82: narrator.exe, 83: narrhook.dll, 84: nbtstat.exe, 85: ncobjapi.dll, 86: ncpa.cpl, 87: ncpa.cpl.manifest, 88: ncxpnt.dll, 89: nddeapi.dll, 90: nddeapir.exe, 91: nddenb32.dll, 92: ndptsp.tsp, 93: net.exe, 94: net.hlp, 95: net1.exe, 96: netapi.dll, 97: netapi32.dll, 98: netcfgx.dll, 99: netdde.exe, 100: netevent.dll, 101: netfxperf.dll, 102: neth.dll, 103: netid.dll, 104: netlogon.dll, 105: netman.dll, 106: netmsg.dll, 107: netplwiz.dll, 108: netrap.dll, 109: netsetup.cpl, 110: netsetup.exe, 111: netsh.exe, 112: netshell.dll, 113: netstat.exe, 114: netui0.dll, 115: netui1.dll, 116: netui2.dll, 117: NETw3c32.dll, 118: NETw3r32.dll, 119: netware.drv, 120: newdev.dll, 121: nlhtml.dll, 122: nlsdl.dll, 123: nlsfunc.exe, 124: nmevtmsg.dll, 125: nmmkcert.dll, 126: noise.chs, 127: noise.cht, 128: noise.dat, 129: noise.deu, 130: noise.eng, 131: noise.enu, 132: noise.esn, 133: noise.fra, 134: noise.ita, 135: noise.nld, 136: noise.sve, 137: noise.tha, 138: normaliz.dll, 139: normidna.nls, 140: normnfc.nls, 141: normnfd.nls, 142: normnfkc.nls, 143: normnfkd.nls, 144: notepad.exe, 145: Npindeo.dll, 146: npp, 147: npptools.dll, 148: NPSWF32.dll, 149: NPSWF32_FlashUtil.exe, 150: npwmsdrm.dll, 151: NRad.dll, 152: nscompat.tlb, 153: nslookup.exe, 154: ntbackup.exe, 155: ntdll.dll, 156: ntdos.sys, 157: ntdos404.sys, 158: ntdos411.sys, 159: ntdos412.sys, 160: ntdos804.sys, 161: ntdsapi.dll, 162: ntdsbcli.dll, 163: ntimage.gif, 164: ntio.sys, 165: ntio404.sys, 166: ntio411.sys, 167: ntio412.sys, 168: ntio804.sys, 169: ntkrnlpa.exe, 170: ntlanman.dll, 171: ntlanui.dll, 172: ntlanui2.dll, 173: ntlsapi.dll, 174: ntmarta.dll, 175: ntmsapi.dll, 176: ntmsdba.dll, 177: ntmsevt.dll, 178: ntmsmgr.dll, 179: ntmsmgr.msc, 180: ntmsoprq.msc, 181: ntmssvc.dll, 182: ntoskrnl.exe, 183: ntprint.dll, 184: ntsd.exe, 185: ntsdexts.dll, 186: ntshrui.dll, 187: ntvdm.exe, 188: ntvdmd.dll, 189: nusrmgr.cpl, 190: nv4_disp.dll, 191: nw16.exe, 192: nwapi16.dll, 193: nwapi32.dll, 194: nwc.cpl, 195: nwc.cpl.manifest, 196: nwcfg.dll, 197: nwevent.dll, 198: nwprovau.dll, 199: nwscript.exe, 200: nwwks.dll, 201: oakley.dll, 202: objsel.dll, 203: occache.dll, 204: ocmanage.dll, 205: odbc16gt.dll, 206: odbc32.dll, 207: odbc32gt.dll, 208: odbcad32.exe, 209: odbcbcp.dll, 210: odbcconf.dll, 211: odbcconf.exe, 212: odbcconf.rsp, 213: odbccp32.cpl, 214: odbccp32.dll, 215: odbccr32.dll, 216: odbccu32.dll, 217: odbcint.dll, 218: odbcji32.dll, 219: odbcjt32.dll, 220: odbcp32r.dll, 221: odbctrac.dll, 222: oddbse32.dll, 223: odexl32.dll, 224: odfox32.dll, 225: odpdx32.dll, 226: odtext32.dll, 227: OEM.dll, 228: oembios.bin, 229: oembios.dat, 230: oembios.sig, 231: OEMBKGN1.BMP, 232: Oemdspif.dll, 233: OEMINFO.INI, 234: OEMINFO.PNF, 235: OEMLOGO.BMP, 236: offfilt.dll, 237: ole2.dll, 238: ole2disp.dll, 239: ole2nls.dll, 240: ole32.dll, 241: oleacc.dll, 242: oleaccrc.dll, 243: oleaut32.dll, 244: olecli.dll, 245: olecli32.dll, 246: olecnv32.dll, 247: oledlg.dll, 248: oleprn.dll, 249: olepro32.dll, 250: olesvr.dll, 251: olesvr32.dll, 252: olethk32.dll, 253: onex.dll, 254: oobe, 255: openfiles.exe, 256: opengl32.dll, 257: osk.exe, 258: osuninst.dll, 259: osuninst.exe, 260: p2p.dll, 261: p2pgasvc.dll, 262: p2pgraph.dll, 263: p2pnetsh.dll, 264: p2psvc.dll, 265: packager.exe, 266: pagefileconfig.vbs, 267: panmap.dll, 268: paqsp.dll, 269: pathping.exe, 270: pautoenr.dll, 271: PCCLPFR.DLL, 272: PCDLIB32.DLL, 273: pcl.sep, 274: pdf2html.dat, 275: pdh.dll, 276: pentnt.exe, 277: perfc009.dat, 278: perfci.h, 279: perfci.ini, 280: perfctrs.dll, 281: perfd009.dat, 282: perfdisk.dll, 283: perffilt.h, 284: perffilt.ini, 285: perfh009.dat, 286: perfi009.dat, 287: perfmon.exe, 288: perfmon.msc, 289: perfnet.dll, 290: perfnw.dll, 291: perfos.dll, 292: perfproc.dll, 293: PerfStringBackup.INI, 294: perfts.dll, 295: perfwci.h, 296: perfwci.ini, 297: photometadatahandler.dll, 298: photowiz.dll, 299: PICCLP32.OCX, 300: pid.dll, 301: pid.inf, 302: pidgen.dll, 303: pifmgr.dll, 304: ping.exe, 305: ping6.exe, 306: pintool.exe, 307: pjlmon.dll, 308: plustab.dll, 309: pmspl.dll, 310: pncrt.dll, 311: pndx5016.dll, 312: pndx5032.dll, 313: pngfilt.dll, 314: pnrpnsp.dll, 315: polstore.dll, 316: popup.ocx, 317: PortableDeviceApi.dll, 318: PortableDeviceClassExtension.dll, 319: PortableDeviceTypes.dll, 320: PortableDeviceWiaCompat.dll, 321: PortableDeviceWMDRM.dll, 322: powercfg.cpl, 323: powercfg.exe, 324: PowerToyReadme.htm, 325: powrprof.dll, 326: PreInstall, 327: PresentationCFFRasterizerNative_v0300.dll, 328: PresentationHost.exe, 329: PresentationHostProxy.dll, 330: PresentationNative_v0300.dll, 331: prflbmsg.dll, 332: Primomonnt.dll, 333: print.exe, 334: printui.dll, 335: prncnfg.vbs, 336: prndrvr.vbs, 337: prnjobs.vbs, 338: prnmngr.vbs, 339: prnport.vbs, 340: prnqctl.vbs, 341: prntvpt.dll, 342: Probe.inf, 343: proctexe.ocx, 344: prodspec.ini, 345: profmap.dll, 346: progman.exe, 347: PropertyGrid.ocx, 348: ProphetConnect4.ocx, 349: proquota.exe, 350: proxycfg.exe, 351: psapi.dll, 352: psbase.dll, 353: pschdcnt.h, 354: pschdprf.dll, 355: pschdprf.ini, 356: pscript.sep, 357: psisdecd.dll, 358: psisrndr.ax, 359: psnppagn.dll, 360: pstorec.dll, 361: pstorsvc.dll, 362: ptpusb.dll, 363: ptpusd.dll, 364: pubprn.vbs, 365: px.dll, 366: pxafs.dll, 367: pxcpya64.exe, 368: pxdrv.dll, 369: pxhpinst.exe, 370: pxinsa64.exe, 371: pxinsi64.exe, 372: pxmas.dll, 373: pxsfs.dll, 374: pxwave.dll, 375: qagent.dll, 376: qagentrt.dll, 377: qappsrv.exe, 378: qasf.dll, 379: qcap.dll, 380: qcliprov.dll, 381: qdiagd.ocx, 382: qdv.dll, 383: qdvd.dll, 384: qedit.dll, 385: qedwipes.dll, 386: qmgr.dll, 387: qmgrprxy.dll, 388: qosname.dll, 389: qprocess.exe, 390: qt-dx331.dll, 391: quartz.dll, 392: query.dll, 393: QuickTime.qts, 394: QuickTimeVR.qtx, 395: qutil.dll, 396: qwinsta.exe, 397: racpldlg.dll, 398: Rad.dll, 399: RadClkR.dll, 400: RadClock.exe, 401: RadEnu.dll, 402: RadEsp.dll, 403: RadExe.dll, 404: RadFra.dll, 405: RadHun.dll, 406: RadIta.dll, 407: RadNlb.dll, 408: RadPlk.dll, 409: RadProbe.sys, 410: RadType.dll, 411: ras, 412: rasadhlp.dll, 413: rasapi32.dll, 414: rasauto.dll, 415: rasautou.exe, 416: raschap.dll, 417: rasctrnm.h, 418: rasctrs.dll, 419: rasctrs.ini, 420: rasdial.exe, 421: rasdlg.dll, 422: rasman.dll, 423: rasmans.dll, 424: rasmontr.dll, 425: rasmxs.dll, 426: rasphone.exe, 427: rasppp.dll, 428: rasqec.dll, 429: rasrad.dll, 430
28117	2:50:03.4799941 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: rasser.dll, 1: rastapi.dll, 2: rastls.dll, 3: RBDELDRV.BAT, 4: rcbdyctl.dll, 5: rcimlby.exe, 6: rcp.exe, 7: rdchost.dll, 8: RDOCURS.DLL, 9: rdpcfgex.dll, 10: rdpclip.exe, 11: rdpdd.dll, 12: rdpsnd.dll, 13: rdpwsx.dll, 14: rdsaddin.exe, 15: rdshost.exe, 16: recover.exe, 17: redir.exe, 18: reg.exe, 19: regapi.dll, 20: regedt32.exe, 21: regini.exe, 22: regsvc.dll, 23: regsvr32.exe, 24: regwiz.exe, 25: regwizc.dll, 26: regxplor.dll, 27: ReinstallBackups, 28: relog.exe, 29: remotepg.dll, 30: remotesp.tsp, 31: rend.dll, 32: replace.exe, 33: reset.exe, 34: Restore, 35: results.txt, 36: resutils.dll, 37: rewire.dll, 38: REX Shared Library.dll, 39: rexec.exe, 40: ReyXpBasics.tlb, 41: rgb9rast_2.dll, 42: rhttpaa.dll, 43: riched20.dll, 44: riched32.dll, 45: richtx32.ocx, 46: rixdicon.dll, 47: RmActivate.exe, 48: RmActivate_isv.exe, 49: RmActivate_ssp.exe, 50: RmActivate_ssp_isv.exe, 51: rmc_fixasf.exe, 52: rmc_rtspdl.dll, 53: rmoc3260.dll, 54: RNBOSENT, 55: rnr20.dll, 56: RO5D3.tmp.LOG, 57: RO5D8.bac, 58: RO5D8.tmp.L?azd ? 0: rasser.dll, 1: rastapi.dll, 2: rastls.dll, 3: RBDELDRV.BAT, 4: rcbdyctl.dll, 5: rcimlby.exe, 6: rcp.exe, 7: rdchost.dll, 8: RDOCURS.DLL, 9: rdpcfgex.dll, 10: rdpclip.exe, 11: rdpdd.dll, 12: rdpsnd.dll, 13: rdpwsx.dll, 14: rdsaddin.exe, 15: rdshost.exe, 16: recover.exe, 17: redir.exe, 18: reg.exe, 19: regapi.dll, 20: regedt32.exe, 21: regini.exe, 22: regsvc.dll, 23: regsvr32.exe, 24: regwiz.exe, 25: regwizc.dll, 26: regxplor.dll, 27: ReinstallBackups, 28: relog.exe, 29: remotepg.dll, 30: remotesp.tsp, 31: rend.dll, 32: replace.exe, 33: reset.exe, 34: Restore, 35: results.txt, 36: resutils.dll, 37: rewire.dll, 38: REX Shared Library.dll, 39: rexec.exe, 40: ReyXpBasics.tlb, 41: rgb9rast_2.dll, 42: rhttpaa.dll, 43: riched20.dll, 44: riched32.dll, 45: richtx32.ocx, 46: rixdicon.dll, 47: RmActivate.exe, 48: RmActivate_isv.exe, 49: RmActivate_ssp.exe, 50: RmActivate_ssp_isv.exe, 51: rmc_fixasf.exe, 52: rmc_rtspdl.dll, 53: rmoc3260.dll, 54: RNBOSENT, 55: rnr20.dll, 56: RO5D3.tmp.LOG, 57: RO5D8.bac, 58: RO5D8.tmp.LOG, 59: RO5DB.bac, 60: RO5DB.tmp.LOG, 61: RO5E0.bac, 62: RO5E0.tmp.LOG, 63: RO5E3.bac, 64: RO5E3.tmp.LOG, 65: RO5E8.bac, 66: RO5E8.tmp.LOG, 67: RO5EB.bac, 68: RO5EB.tmp.LOG, 69: RO5F0.bac, 70: RO5F0.tmp.LOG, 71: RO5F3.bac, 72: RO5F3.tmp.LOG, 73: RO5F8.bac, 74: RO5F8.tmp.LOG, 75: RO5FB.bac, 76: RO5FB.tmp.LOG, 77: RO600.bac, 78: RO600.tmp.LOG, 79: RO6484.tmp.LOG, 80: RO6487.bac, 81: RO6487.tmp.LOG, 82: RO648C.bac, 83: RO648C.tmp.LOG, 84: RO648F.bac, 85: RO648F.tmp.LOG, 86: RO6494.bac, 87: RO6494.tmp.LOG, 88: RO6497.bac, 89: RO6497.tmp.LOG, 90: RO649C.bac, 91: RO649C.tmp.LOG, 92: RO649F.bac, 93: RO649F.tmp.LOG, 94: RO64A4.bac, 95: RO64A4.tmp.LOG, 96: RO64A7.bac, 97: RO64A7.tmp.LOG, 98: RO64AC.bac, 99: RO64AC.tmp.LOG, 100: RO64AF.bac, 101: RO64AF.tmp.LOG, 102: roboex32.dll, 103: ROC797.tmp, 104: ROC797.tmp.LOG, 105: ROC79C.bac, 106: ROC79C.tmp.LOG, 107: ROC79F.bac, 108: ROC79F.tmp.LOG, 109: ROC7A4.bac, 110: ROC7A4.tmp.LOG, 111: ROC7A7.bac, 112: ROC7A7.tmp.LOG, 113: ROC7AC.bac, 114: ROC7AC.tmp.LOG, 115: ROC7AF.bac, 116: ROC7AF.tmp.LOG, 117: ROC7B4.bac, 118: ROC7B4.tmp.LOG, 119: ROC7B7.bac, 120: ROC7B7.tmp.LOG, 121: ROC7BC.bac, 122: ROC7BC.tmp.LOG, 123: ROC7BF.bac, 124: ROC7BF.tmp.LOG, 125: ROC7C4.bac, 126: ROC7C4.tmp.LOG, 127: ROF353.tmp, 128: ROF353.tmp.LOG, 129: ROF358.bac, 130: ROF358.tmp.LOG, 131: ROF35B.bac, 132: ROF35B.tmp.LOG, 133: ROF360.bac, 134: ROF360.tmp.LOG, 135: ROF363.bac, 136: ROF363.tmp.LOG, 137: ROF368.bac, 138: ROF368.tmp.LOG, 139: ROF36B.bac, 140: ROF36B.tmp.LOG, 141: ROF370.bac, 142: ROF370.tmp.LOG, 143: ROF373.bac, 144: ROF373.tmp.LOG, 145: ROF378.bac, 146: ROF378.tmp.LOG, 147: ROF37B.bac, 148: ROF37B.tmp.LOG, 149: ROF380.bac, 150: ROF380.tmp.LOG, 151: RootkitReveal.txt, 152: route.exe, 153: routemon.exe, 154: routetab.dll, 155: rpcns4.dll, 156: rpcrt4.dll, 157: rpcss.dll, 158: rsaci.rat, 159: rsaenh.dll, 160: rsfsaps.dll, 161: rsh.exe, 162: rshx32.dll, 163: rsm.exe, 164: rsmps.dll, 165: rsmsink.exe, 166: rsmui.exe, 167: rsnotify.exe, 168: rsop.msc, 169: rsopprov.exe, 170: rspndr.exe, 171: rsvp.exe, 172: rsvp.ini, 173: rsvpcnts.h, 174: rsvpmsg.dll, 175: rsvpperf.dll, 176: rsvpsp.dll, 177: rtcshare.exe, 178: rtipxmib.dll, 179: rtm.dll, 180: rtutils.dll, 181: runas.exe, 182: rundll32.exe, 183: runonce.exe, 184: rwinsta.exe, 185: rwnh.dll, 186: s24NCfg.dll, 187: s3gnb.dll, 188: safrcdlg.dll, 189: safrdm.dll, 190: safrslv.dll, 191: samlib.dll, 192: samsrv.dll, 193: sapi.cpl.manifest, 194: savedump.exe, 195: sbe.dll, 196: sbeio.dll, 197: sc.exe, 198: scarddlg.dll, 199: scardssp.dll, 200: scardsvr.exe, 201: sccbase.dll, 202: sccsccp.dll, 203: scecli.dll, 204: scesrv.dll, 205: schannel.dll, 206: schedsvc.dll, 207: schtasks.exe, 208: sclgntfy.dll, 209: scredir.dll, 210: scripting, 211: scriptpw.dll, 212: scrobj.dll, 213: scrrun.dll, 214: sdbinst.exe, 215: sdelete.exe, 216: sdhcinst.dll, 217: sdpblb.dll, 218: secedit.exe, 219: seclogon.dll, 220: secpol.msc, 221: SecProc.dll, 222: SecProc_isv.dll, 223: SecProc_ssp.dll, 224: SecProc_ssp_isv.dll, 225: secupd.dat, 226: secupd.sig, 227: secur32.dll, 228: security.dll, 229: sendcmsg.dll, 230: sendmail.dll, 231: sens.dll, 232: sensapi.dll, 233: senscfg.dll, 234: serialui.dll, 235: servdeps.dll, 236: services.exe, 237: services.msc, 238: serwvdrv.dll, 239: sessmgr.exe, 240: SET8228.tmp, 241: SET8229.tmp, 242: SET822A.tmp, 243: SET822B.tmp, 244: SET8238.tmp, 245: SET8239.tmp, 246: SET823A.tmp, 247: SET823B.tmp, 248: SET823C.tmp, 249: SET823D.tmp, 250: SET827E.tmp, 251: SET828A.tmp, 252: sethc.exe, 253: setuid.dll, 254: Setup, 255: setup.bmp, 256: setup.exe, 257: setupapi.dll, 258: setupdll.dll, 259: setupn.exe, 260: setver.exe, 261: sfc.dll, 262: sfc.exe, 263: sfcfiles.dll, 264: sfc_os.dll, 265: sfman32.dll, 266: sfmapi.dll, 267: sfms32.dll, 268: shadow.exe, 269: share.exe, 270: shdoclc.dll, 271: shdocvw.bak, 272: shdocvw.dll, 273: shell.dll, 274: shell32.dll, 275: ShellExt, 276: shellstyle.dll, 277: shfolder.dll, 278: shgina.dll, 279: shiftjis.uce, 280: shimeng.dll, 281: shimgvw.dll, 282: shlwapi.dll, 283: shmedia.dll, 284: shmgrate.exe, 285: shrpubw.exe, 286: shscrap.dll, 287: shsvcs.dll, 288: shutdown.exe, 289: sigtab.dll, 290: sigverif.exe, 291: simpdata.tlb, 292: SimpleRegistry.dll, 293: SIntf16.dll, 294: SIntf32.dll, 295: SIntfNT.dll, 296: sisbkup.dll, 297: skdll.dll, 298: skeys.exe, 299: slayerxp.dll, 300: slbcsp.dll, 301: slbiop.dll, 302: slbrccsp.dll, 303: slcoinst.dll, 304: slextspk.dll, 305: slgen.dll, 306: slrundll.exe, 307: slserv.exe, 308: sl_anet.acm, 309: smbinst.exe, 310: smlogcfg.dll, 311: smlogsvc.exe, 312: smss.exe, 313: SMSUnins.dll, 314: smtpapi.dll, 315: sndrec32.exe, 316: sndvol32.exe, 317: snmpapi.dll, 318: snmpsnap.dll, 319: snymsico.dll, 320: softpub.dll, 321: SoftwareDistribution, 322: sol.exe, 323: sort.exe, 324: sortkey.nls, 325: sorttbls.nls, 326: sound.drv, 327: spdwnwxp.exe, 328: speedfan.sys, 329: spiisupd.exe, 330: spmsg.dll, 331: spmsg2.dll, 332: spnike.dll, 333: spnpinst.exe, 334: spool, 335: spoolss.dll, 336: spoolsv.exe, 337: SpoonUninstall.exe, 338: sprestrt.exe, 339: sprio600.dll, 340: sprio800.dll, 341: spupdsvc.exe, 342: spupdwxp.exe, 343: spupdwxp.log, 344: spxcoins.dll, 345: sqlsodbc.chm, 346: sqlsrv32.dll, 347: sqlsrv32.rll, 348: sqlunirl.dll, 349: sqlwid.dll, 350: sqlwoa.dll, 351: srclient.dll, 352: srrstr.dll, 353: srsvc.dll, 354: srvsvc.dll, 355: ssdpapi.dll, 356: ssdpsrv.dll, 357: ssubtmr6.dll, 358: st325602.dll, 359: stacapi.dll, 360: stacgui.cpl, 361: staco.dll, 362: Startup.cpl, 363: StartupCPL.exe, 364: stclient.dll, 365: stdole2.tlb, 366: stdole32.tlb, 367: sti.dll, 368: stimon.exe, 369: sti_ci.dll, 370: stlang.dll, 371: stobject.dll, 372: storage.dll, 373: storprop.dll, 374: streamci.dll, 375: strmdll.dll, 376: strmfilt.dll, 377: subrange.uce, 378: subst.exe, 379: svchost.exe, 380: svcpack.dll, 381: swprv.dll, 382: sxs.dll, 383: syncapp.exe, 384: synceng.dll, 385: SynCOM.dll, 386: SynCtrl.dll, 387: syncui.dll, 388: SynTPAPI.dll, 389: SynTPCo2.dll, 390: SynTPFcs.dll, 391: sysdm.cpl, 392: sysedit.exe, 393: sysinv.dll, 394: syskey.exe, 395: sysmon.ocx, 396: sysocmgr.exe, 397: sysprint.sep, 398: sysprtj.sep, 399: syssetup.dll, 400: system.drv, 401: systeminfo.exe, 402: systray.exe, 403: t2embed.dll, 404: tabctl32.ocx, 405: tapi.dll, 406: tapi3.dll, 407: tapi32.dll, 408: tapiperf.dll, 409: tapisrv.dll, 410: tapiui.dll, 411: taskkill.exe, 412: tasklist.exe, 413: taskman.exe, 414: taskmgr.exe, 415: TBTMon.dll, 416: tbtmon98Language.dll, 417: TBTMonUI.dll, 418: tcmsetup.exe, 419: tcpmib.dll, 420: tcpmon.dll, 421: tcpmon.ini, 422: tcpmonui.dll, 423: tcpsvcs.exe, 424: tdc.ocx, 425: telephon.cpl, 426: telnet.exe, 427: termcap, 428: termmgr.dll, 429: termsrv.dll, 430: tftp.exe, 431: themeui.dll, 432: ticrf.rat, 433: timedate.cpl, 434: timer.drv, 435: tlntadmn.exe, 436: tlntsess.exe, 437: tlntsvr.exe, 438: tlntsvrp.dll, 439: 
28132	2:50:03.4813418 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	0: tmp31.tmp, 1: tmpE0.tmp, 2: toolhelp.dll, 3: TosAcpiAPI.dll, 4: TosAvAPI.dll, 5: TosAvctAPI.dll, 6: TosAvdtAPI.dll, 7: TosBdAPI.dll, 8: TosBtAcc.dll, 9: TosBtAerialAPI.dll, 10: TosBtAPI.dll, 11: TosBtCapApi.dll, 12: TosBtECCAPI.dll, 13: TosBtExt.dll, 14: TosBtHcrpAPI.dll, 15: TosBtHSPAPI.dll, 16: TosBtSDDB.dll, 17: tosBtShell.dll, 18: TosCommAPI.dll, 19: TosGnsAPI.dll, 20: TosHidAPI.dll, 21: TosLaneAPI.dll, 22: TosSndAPI.dll, 23: TosSndPlug.dll, 24: tourstart.exe, 25: tracerpt.exe, 26: tracert.exe, 27: tracert6.exe, 28: traffic.dll, 29: tree.com, 30: trkwks.dll, 31: tsappcmp.dll, 32: tsbyuv.dll, 33: tscfgwmi.dll, 34: tscon.exe, 35: tscupgrd.exe, 36: tsd32.dll, 37: tsddd.dll, 38: tsdiscon.exe, 39: tsgqec.dll, 40: tskill.exe, 41: tslabels.h, 42: tslabels.ini, 43: tspkg.dll, 44: tsshutdn.exe, 45: tssoft32.acm, 46: tswpfwrp.exe, 47: TWAIN_32.DLL, 48: TweakUI.exe, 49: twext.dll, 50: TwnLib4.dll, 51: TWUNK_16.EXE, 52: TWUNK_32.EXE, 53: txflog.dll, 54: typelib.dll, 55: typeperf.exe, 56: tzchange.exe, 57: TZLog.lo?azc ? 0: tmp31.tmp, 1: tmpE0.tmp, 2: toolhelp.dll, 3: TosAcpiAPI.dll, 4: TosAvAPI.dll, 5: TosAvctAPI.dll, 6: TosAvdtAPI.dll, 7: TosBdAPI.dll, 8: TosBtAcc.dll, 9: TosBtAerialAPI.dll, 10: TosBtAPI.dll, 11: TosBtCapApi.dll, 12: TosBtECCAPI.dll, 13: TosBtExt.dll, 14: TosBtHcrpAPI.dll, 15: TosBtHSPAPI.dll, 16: TosBtSDDB.dll, 17: tosBtShell.dll, 18: TosCommAPI.dll, 19: TosGnsAPI.dll, 20: TosHidAPI.dll, 21: TosLaneAPI.dll, 22: TosSndAPI.dll, 23: TosSndPlug.dll, 24: tourstart.exe, 25: tracerpt.exe, 26: tracert.exe, 27: tracert6.exe, 28: traffic.dll, 29: tree.com, 30: trkwks.dll, 31: tsappcmp.dll, 32: tsbyuv.dll, 33: tscfgwmi.dll, 34: tscon.exe, 35: tscupgrd.exe, 36: tsd32.dll, 37: tsddd.dll, 38: tsdiscon.exe, 39: tsgqec.dll, 40: tskill.exe, 41: tslabels.h, 42: tslabels.ini, 43: tspkg.dll, 44: tsshutdn.exe, 45: tssoft32.acm, 46: tswpfwrp.exe, 47: TWAIN_32.DLL, 48: TweakUI.exe, 49: twext.dll, 50: TwnLib4.dll, 51: TWUNK_16.EXE, 52: TWUNK_32.EXE, 53: txflog.dll, 54: typelib.dll, 55: typeperf.exe, 56: tzchange.exe, 57: TZLog.log, 58: uci100.dll, 59: udhisapi.dll, 60: ufat.dll, 61: UIAutomationCore.dll, 62: ulib.dll, 63: umandlg.dll, 64: umdmxfrm.dll, 65: umpnpmgr.dll, 66: unicode.nls, 67: unimdm.tsp, 68: unimdmat.dll, 69: uniplat.dll, 70: unlodctr.exe, 71: unrar.dll, 72: untfs.dll, 73: upnp.dll, 74: upnpcont.exe, 75: upnphost.dll, 76: upnpui.dll, 77: ups.exe, 78: ureg.dll, 79: url.dll, 80: urlmon.dll, 81: URTTemp, 82: usbmon.dll, 83: usbui.dll, 84: user.exe, 85: user32.dll, 86: userenv.dll, 87: userinit.exe, 88: usmt, 89: usp10.dll, 90: usrcntra.dll, 91: usrcoina.dll, 92: usrdpa.dll, 93: usrdtea.dll, 94: usrfaxa.dll, 95: usrlbva.dll, 96: usrlogon.cmd, 97: usrmlnka.exe, 98: usrprbda.exe, 99: usrrtosa.dll, 100: usrsdpia.dll, 101: usrshuta.exe, 102: usrsvpia.dll, 103: usrv42a.dll, 104: usrv80a.dll, 105: usrvoica.dll, 106: usrvpa.dll, 107: utildll.dll, 108: utilman.exe, 109: uwdf.exe, 110: uxtheme.dll, 111: v7vga.rom, 112: VB6FR.DLL, 113: VB6STKIT.DLL, 114: VBAEN32.OLB, 115: VBAEND32.OLB, 116: vbajet32.dll, 117: vbalProgBar6.ocx, 118: VBICodec.ax, 119: vbisurf.ax, 120: vbscript.dll, 121: vcdex.dll, 122: vdmdbg.dll, 123: vdmredir.dll, 124: VEN2232.OLB, 125: ver.dll, 126: verclsid.exe, 127: verifier.dll, 128: verifier.exe, 129: version.dll, 130: vfpodbc.dll, 131: vfwwdm32.dll, 132: vga.dll, 133: vga.drv, 134: vga256.dll, 135: vga64k.dll, 136: vidcap.ax, 137: View Channels.scf, 138: vjoy.dll, 139: VSFLEX3.OCX, 140: vssadmin.exe, 141: vssapi.dll, 142: vssvc.exe, 143: vss_ps.dll, 144: vwipxspx.dll, 145: vwipxspx.exe, 146: vxblock.dll, 147: w32time.dll, 148: w32tm.exe, 149: w32topl.dll, 150: w39MLRes.dll, 151: w39NCPA.dll, 152: w3ssl.dll, 153: watchdog.sys, 154: wavemsp.dll, 155: wbcache.deu, 156: wbcache.enu, 157: wbcache.esn, 158: wbcache.fra, 159: wbcache.ita, 160: wbcache.nld, 161: wbcache.sve, 162: wbdbase.deu, 163: wbdbase.enu, 164: wbdbase.esn, 165: wbdbase.fra, 166: wbdbase.ita, 167: wbdbase.nld, 168: wbdbase.sve, 169: wbem, 170: wdfapi.dll, 171: WdfCoInstaller01005.dll, 172: wdfmgr.exe, 173: wdigest.dll, 174: wdl.trm, 175: wdmaud.drv, 176: webcheck.dll, 177: webclnt.dll, 178: webfldrs.msi, 179: webhits.dll, 180: webvw.dll, 181: wextract.exe, 182: wfwnet.drv, 183: WgaLogon.dll, 184: WgaTray.exe, 185: wiaacmgr.exe, 186: wiadefui.dll, 187: wiadss.dll, 188: wiascr.dll, 189: wiaservc.dll, 190: wiasf.ax, 191: wiashext.dll, 192: wiavideo.dll, 193: wiavusd.dll, 194: wifeman.dll, 195: win.com, 196: win32k.sys, 197: win32spl.dll, 198: win87em.dll, 199: winbrand.dll, 200: winchat.exe, 201: windowscodecs.dll, 202: windowscodecsext.dll, 203: WindowsLogon.manifest, 204: WindowsUptime.exe, 205: winfax.dll, 206: WinFXDocObj.exe, 207: winhelp.hlp, 208: winhlp32.exe, 209: winhttp.dll, 210: wininet.dll, 211: winipsec.dll, 212: winlogon.exe, 213: winmine.exe, 214: winmm.dll, 215: winmsd.exe, 216: winnls.dll, 217: winntbbu.dll, 218: winoldap.mod, 219: winrnr.dll, 220: wins, 221: winscard.dll, 222: winshfhc.dll, 223: winsock.dll, 224: winspool.drv, 225: winspool.exe, 226: winsrv.dll, 227: winsta.dll, 228: winstrm.dll, 229: wintrust.dll, 230: winver.exe, 231: wkssvc.dll, 232: wlanapi.dll, 233: wldap32.dll, 234: wlnotify.dll, 235: WMADMOD.dll, 236: WMADMOE.dll, 237: wmasf.dll, 238: wmdmlog.dll, 239: wmdmps.dll, 240: wmdrmdev.dll, 241: wmdrmnet.dll, 242: wmdrmsdk.dll, 243: wmerrenu.dll, 244: wmerror.dll, 245: wmi.dll, 246: wmidx.dll, 247: wmidx.ocx, 248: wmimgmt.msc, 249: wmiprop.dll, 250: wmiscmgr.dll, 251: WMNetMgr.dll, 252: wmp.dll, 253: wmp.ocx, 254: wmpasf.dll, 255: wmpcd.dll, 256: wmpcore.dll, 257: wmpdxm.dll, 258: wmpeffects.dll, 259: wmpencen.dll, 260: wmphoto.dll, 261: wmploc.dll, 262: wmpmde.dll, 263: wmpps.dll, 264: wmpshell.dll, 265: wmpsrcwp.dll, 266: wmpui.dll, 267: wmsdmod.dll, 268: wmsdmoe.dll, 269: wmsdmoe2.dll, 270: WMSPDMOD.dll, 271: WMSPDMOE.dll, 272: wmstream.dll, 273: wmv8dmod.dll, 274: wmv8dmoe.dll, 275: wmv8ds32.ax, 276: WMVADVD.dll, 277: WMVADVE.DLL, 278: wmvcore.dll, 279: WMVDECOD.dll, 280: wmvdmod.dll, 281: wmvdmoe.dll, 282: wmvdmoe2.dll, 283: wmvds32.ax, 284: WMVENCOD.dll, 285: WMVSDECD.dll, 286: WMVSENCD.dll, 287: WMVXENCD.dll, 288: WNASPI32.DLL, 289: wow32.dll, 290: wowdeb.exe, 291: wowexec.exe, 292: wowfax.dll, 293: wowfaxui.dll, 294: wpa.dbl, 295: wpabaln.exe, 296: wpdconns.dll, 297: wpdmtp.dll, 298: wpdmtpdr.dll, 299: wpdmtpus.dll, 300: WpdShext.dll, 301: wpdshextautoplay.exe, 302: wpdshextres.dll, 303: WPDShServiceObj.dll, 304: wpdsp.dll, 305: wpdtrace.dll, 306: wpd_ci.dll, 307: wpnpinst.exe, 308: write.exe, 309: ws2help.dll, 310: ws2_32.dll, 311: wscntfy.exe, 312: wscript.exe, 313: wscsvc.dll, 314: wscui.cpl, 315: wsecedit.dll, 316: wshatm.dll, 317: wshbth.dll, 318: wshcon.dll, 319: wshext.dll, 320: wship6.dll, 321: wshisn.dll, 322: wshnetbs.dll, 323: wshom.ocx, 324: wshrm.dll, 325: wshtcpip.dll, 326: wsnmp32.dll, 327: wsock32.dll, 328: wstdecod.dll, 329: wstpager.ax, 330: wstrenderer.ax, 331: wtsapi32.dll, 332: wuapi.dll, 333: wuapi.dll.mui, 334: wuauclt.exe, 335: wuauclt1.exe, 336: wuaucpl.cpl, 337: wuaucpl.cpl.manifest, 338: wuaucpl.cpl.mui, 339: wuaueng.dll, 340: wuaueng.dll.mui, 341: wuaueng1.dll, 342: wuauserv.dll, 343: wucltui.dll, 344: wucltui.dll.mui, 345: WUDFCoinstaller.dll, 346: WudfHost.exe, 347: WudfPlatform.dll, 348: WudfSvc.dll, 349: WUDFx.dll, 350: wupdmgr.exe, 351: wups.dll, 352: wups2.dll, 353: wuweb.dll, 354: wzcdlg.dll, 355: wzcsapi.dll, 356: wzcsvc.dll, 357: x3daudio1_0.dll, 358: x3daudio1_1.dll, 359: X3DAudio1_2.dll, 360: X3DAudio1_3.dll, 361: X3DAudio1_4.dll, 362: xactengine2_0.dll, 363: xactengine2_1.dll, 364: xactengine2_10.dll, 365: xactengine2_2.dll, 366: xactengine2_3.dll, 367: xactengine2_4.dll, 368: xactengine2_5.dll, 369: xactengine2_6.dll, 370: xactengine2_7.dll, 371: xactengine2_8.dll, 372: xactengine2_9.dll, 373: xactengine3_0.dll, 374: xactengine3_1.dll, 375: xactengine3_2.dll, 376: xactsrv.dll, 377: XAPOFX1_0.dll, 378: XAPOFX1_1.dll, 379: XAudio2_0.dll, 380: XAudio2_1.dll, 381: XAudio2_2.dll, 382: xcopy.exe, 383: xenroll.dll, 384: xinput1_1.dll, 385: xinput1_2.dll, 386: xinput1_3.dll, 387: xinput9_1_0.dll, 388: xircom, 389: xlive.dll, 390: xlive.dll.cat, 391: xlivefnt.dll, 392: xmllite.dll, 393: xmlprov.dll, 394: xmlprovi.dll, 395: xolehlp.dll, 396: XPbuttons.ocx, 397: xpob2res.dll, 398: xpsp1res.dll, 399: xpsp2res.dll, 400: xpsp3res.dll, 401: XPSSHHDR.dll, 402: XpsSvcs.dll, 403: XPSViewer, 404: xvidcore.dll, 405: xvidvfw.dll, 406: yv12vfw.dll, 407: zipfldr.dll, 408
28133	2:50:03.4816399 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	NO MORE FILES	
28134	2:50:03.4817265 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32	SUCCESS	
28136	2:50:03.4818687 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28137	2:50:03.4819545 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS	SUCCESS	0: ., 1: .., 2: InstallTemp, 3: Manifests, 4: MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e, 5: Policies, 6: x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a, 7: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d, 8: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213, 9: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a, 10: x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7, 11: x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a, 12: x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841, 13: x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474, 14: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2, 15: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd, 16: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700, 17: x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0, ?azc ? 0: ., 1: .., 2: InstallTemp, 3: Manifests, 4: MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e, 5: Policies, 6: x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a, 7: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d, 8: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213, 9: x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a, 10: x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7, 11: x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a, 12: x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841, 13: x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474, 14: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2, 15: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd, 16: x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700, 17: x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0, 18: x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303, 19: x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2, 20: x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05, 21: x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867, 22: x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a, 23: x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9, 24: x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375, 25: x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a, 26: x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a, 27: x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1, 28: x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a, 29: x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9, 30: x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b, 31: x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03, 32: x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83, 33: x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a, 34: x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9, 35: x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.3085_x-ww_e059201c, 36: x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63, 37: x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13, 38: x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82, 39: x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c, 40: x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7, 41: x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95, 42: x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0, 43
28138	2:50:03.4821159 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS	NO MORE FILES	
28139	2:50:03.4821922 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS	SUCCESS	
28141	2:50:03.4823098 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\X86_MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_8.0.50727.1433_X-WW_5CF844D2	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28142	2:50:03.4823992 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	0: ., 1: .., 2: msvcm80.dll, 3: msvcp80.dll, 4: msvcr80.dll
28144	2:50:03.4826241 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	NO MORE FILES	
28145	2:50:03.4827045 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
28150	2:50:03.4829068 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.5512_X-WW_35D4CE83	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28153	2:50:03.4830152 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	0: ., 1: .., 2: comctl32.dll
28154	2:50:03.4831323 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	NO MORE FILES	
28155	2:50:03.4832116 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
28157	2:50:03.4833965 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28159	2:50:03.4835211 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	AllocationSize: 708,608, EndOfFile: 706,048, NumberOfLinks: 1, DeletePending: False, Directory: False
28163	2:50:03.4836888 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28165	2:50:03.4838192 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	AllocationSize: 991,232, EndOfFile: 989,696, NumberOfLinks: 1, DeletePending: False, Directory: False
28169	2:50:03.4839840 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\unicode.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28171	2:50:03.4841056 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\unicode.nls	SUCCESS	AllocationSize: 90,112, EndOfFile: 89,588, NumberOfLinks: 1, DeletePending: False, Directory: False
28175	2:50:03.4842676 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\locale.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28177	2:50:03.4843874 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\locale.nls	SUCCESS	AllocationSize: 266,240, EndOfFile: 265,948, NumberOfLinks: 1, DeletePending: False, Directory: False
28184	2:50:03.4845632 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\sorttbls.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28186	2:50:03.4846841 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\sorttbls.nls	SUCCESS	AllocationSize: 24,576, EndOfFile: 23,044, NumberOfLinks: 1, DeletePending: False, Directory: False
28190	2:50:03.4849397 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28193	2:50:03.4850459 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	AllocationSize: 15,884,288, EndOfFile: 15,881,488, NumberOfLinks: 1, DeletePending: False, Directory: False
28205	2:50:03.4852549 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28208	2:50:03.4853996 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	AllocationSize: 638,976, EndOfFile: 635,904, NumberOfLinks: 1, DeletePending: False, Directory: False
28218	2:50:03.4855862 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28222	2:50:03.4857167 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	AllocationSize: 344,064, EndOfFile: 343,040, NumberOfLinks: 1, DeletePending: False, Directory: False
28227	2:50:03.4858941 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28235	2:50:03.4860337 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	AllocationSize: 8,462,336, EndOfFile: 8,461,312, NumberOfLinks: 1, DeletePending: False, Directory: False
28239	2:50:03.4861955 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28243	2:50:03.4863162 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	AllocationSize: 618,496, EndOfFile: 617,472, NumberOfLinks: 1, DeletePending: False, Directory: False
28249	2:50:03.4865184 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28251	2:50:03.4866380 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	AllocationSize: 585,728, EndOfFile: 584,704, NumberOfLinks: 1, DeletePending: False, Directory: False
28260	2:50:03.4868520 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28263	2:50:03.4869881 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	AllocationSize: 57,344, EndOfFile: 56,320, NumberOfLinks: 1, DeletePending: False, Directory: False
28269	2:50:03.4871766 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28277	2:50:03.4874116 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	AllocationSize: 286,720, EndOfFile: 285,184, NumberOfLinks: 1, DeletePending: False, Directory: False
28281	2:50:03.4875716 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\user32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28283	2:50:03.4876895 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\user32.dll	SUCCESS	AllocationSize: 581,632, EndOfFile: 578,560, NumberOfLinks: 1, DeletePending: False, Directory: False
28287	2:50:03.4878535 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28289	2:50:03.4879714 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	AllocationSize: 475,136, EndOfFile: 474,112, NumberOfLinks: 1, DeletePending: False, Directory: False
28295	2:50:03.4881572 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28298	2:50:03.4882958 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	AllocationSize: 1,691,648, EndOfFile: 1,689,088, NumberOfLinks: 1, DeletePending: False, Directory: False
28309	2:50:03.4885410 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28311	2:50:03.4886634 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	AllocationSize: 8,192, EndOfFile: 8,192, NumberOfLinks: 1, DeletePending: False, Directory: False
28315	2:50:03.4889347 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\version.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28319	2:50:03.4890811 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\version.dll	SUCCESS	AllocationSize: 20,480, EndOfFile: 18,944, NumberOfLinks: 1, DeletePending: False, Directory: False
28330	2:50:03.4892573 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28333	2:50:03.4893917 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	AllocationSize: 176,128, EndOfFile: 176,128, NumberOfLinks: 1, DeletePending: False, Directory: False
28343	2:50:03.4895822 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28347	2:50:03.4897233 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	AllocationSize: 3,731,456, EndOfFile: 3,727,720, NumberOfLinks: 1, DeletePending: False, Directory: False
28353	2:50:03.4898845 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28361	2:50:03.4900158 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	AllocationSize: 184,320, EndOfFile: 181,760, NumberOfLinks: 1, DeletePending: False, Directory: False
28367	2:50:03.4901773 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28369	2:50:03.4903103 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	AllocationSize: 368,640, EndOfFile: 367,616, NumberOfLinks: 1, DeletePending: False, Directory: False
28373	2:50:03.4904846 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28375	2:50:03.4906299 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	AllocationSize: 1,290,240, EndOfFile: 1,287,168, NumberOfLinks: 1, DeletePending: False, Directory: False
28379	2:50:03.4907405 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\XINPUT1_3.DLL	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28381	2:50:03.4908075 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\xinput1_3.dll	SUCCESS	AllocationSize: 81,920, EndOfFile: 81,768, NumberOfLinks: 1, DeletePending: False, Directory: False
28385	2:50:03.4909682 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28387	2:50:03.4911067 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	AllocationSize: 987,136, EndOfFile: 985,088, NumberOfLinks: 1, DeletePending: False, Directory: False
28391	2:50:03.4912718 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28393	2:50:03.4913934 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	AllocationSize: 561,152, EndOfFile: 558,080, NumberOfLinks: 1, DeletePending: False, Directory: False
28397	2:50:03.4915652 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28399	2:50:03.4916926 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 110,080, NumberOfLinks: 1, DeletePending: False, Directory: False
28403	2:50:03.4918512 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28405	2:50:03.4919677 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	AllocationSize: 831,488, EndOfFile: 830,464, NumberOfLinks: 1, DeletePending: False, Directory: False
28409	2:50:03.4921231 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28411	2:50:03.4922410 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	AllocationSize: 24,576, EndOfFile: 23,552, NumberOfLinks: 1, DeletePending: False, Directory: False
28415	2:50:03.4923957 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28417	2:50:03.4925122 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	AllocationSize: 1,191,936, EndOfFile: 1,188,352, NumberOfLinks: 1, DeletePending: False, Directory: False
28421	2:50:03.4926670 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28423	2:50:03.4927846 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	AllocationSize: 552,960, EndOfFile: 551,936, NumberOfLinks: 1, DeletePending: False, Directory: False
28427	2:50:03.4929385 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28429	2:50:03.4930550 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	AllocationSize: 270,336, EndOfFile: 268,800, NumberOfLinks: 1, DeletePending: False, Directory: False
28433	2:50:03.4931805 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\IESETTING.DLL	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28435	2:50:03.4932685 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\IESetting.dll	SUCCESS	AllocationSize: 143,360, EndOfFile: 142,848, NumberOfLinks: 1, DeletePending: False, Directory: False
28439	2:50:03.4934232 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28441	2:50:03.4935392 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	AllocationSize: 86,016, EndOfFile: 82,432, NumberOfLinks: 1, DeletePending: False, Directory: False
28445	2:50:03.4936984 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28447	2:50:03.4938143 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	AllocationSize: 20,480, EndOfFile: 19,968, NumberOfLinks: 1, DeletePending: False, Directory: False
28451	2:50:03.4939702 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\netapi32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28453	2:50:03.4940870 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\netapi32.dll	SUCCESS	AllocationSize: 339,968, EndOfFile: 337,408, NumberOfLinks: 1, DeletePending: False, Directory: False
28457	2:50:03.4942412 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28459	2:50:03.4943580 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	AllocationSize: 409,600, EndOfFile: 406,016, NumberOfLinks: 1, DeletePending: False, Directory: False
28463	2:50:03.4945267 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28465	2:50:03.4946591 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	AllocationSize: 24,576, EndOfFile: 22,528, NumberOfLinks: 1, DeletePending: False, Directory: False
28469	2:50:03.4948147 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28471	2:50:03.4949343 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	AllocationSize: 65,536, EndOfFile: 65,024, NumberOfLinks: 1, DeletePending: False, Directory: False
28475	2:50:03.4950905 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28477	2:50:03.4952106 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
28481	2:50:03.4953651 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ctype.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28483	2:50:03.4954816 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\ctype.nls	SUCCESS	AllocationSize: 12,288, EndOfFile: 8,386, NumberOfLinks: 1, DeletePending: False, Directory: False
28487	2:50:03.4956428 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28489	2:50:03.4957635 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	AllocationSize: 1,056,768, EndOfFile: 1,054,208, NumberOfLinks: 1, DeletePending: False, Directory: False
28493	2:50:03.4958632 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WINDOWSSHELL.MANIFEST	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28495	2:50:03.4959258 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
28499	2:50:03.4960808 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28501	2:50:03.4961979 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	AllocationSize: 618,496, EndOfFile: 617,472, NumberOfLinks: 1, DeletePending: False, Directory: False
28505	2:50:03.4963513 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\sortkey.nls	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28507	2:50:03.4964678 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\sortkey.nls	SUCCESS	AllocationSize: 266,240, EndOfFile: 262,148, NumberOfLinks: 1, DeletePending: False, Directory: False
28511	2:50:03.4966259 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28513	2:50:03.4967426 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	AllocationSize: 98,304, EndOfFile: 94,720, NumberOfLinks: 1, DeletePending: False, Directory: False
28517	2:50:03.4968977 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28519	2:50:03.4970139 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	AllocationSize: 24,576, EndOfFile: 23,040, NumberOfLinks: 1, DeletePending: False, Directory: False
28523	2:50:03.4971190 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28525	2:50:03.4971829 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	AllocationSize: 3,489,792, EndOfFile: 3,486,992, NumberOfLinks: 1, DeletePending: False, Directory: False
28529	2:50:03.4973802 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\CMDLINEEXT.DLL	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28531	2:50:03.4975274 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 107,888, NumberOfLinks: 1, DeletePending: False, Directory: False
28535	2:50:03.4976847 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28537	2:50:03.4978093 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	AllocationSize: 434,176, EndOfFile: 433,664, NumberOfLinks: 1, DeletePending: False, Directory: False
28541	2:50:03.4979635 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28543	2:50:03.4980797 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	AllocationSize: 221,184, EndOfFile: 218,624, NumberOfLinks: 1, DeletePending: False, Directory: False
28547	2:50:03.4982423 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28549	2:50:03.4983585 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	AllocationSize: 49,152, EndOfFile: 45,584, NumberOfLinks: 1, DeletePending: False, Directory: False
28553	2:50:03.4985135 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28555	2:50:03.4986309 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	AllocationSize: 118,784, EndOfFile: 118,784, NumberOfLinks: 1, DeletePending: False, Directory: False
28559	2:50:03.4987856 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28561	2:50:03.4989021 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	AllocationSize: 65,536, EndOfFile: 64,000, NumberOfLinks: 1, DeletePending: False, Directory: False
28565	2:50:03.4990558 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28567	2:50:03.4991720 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	AllocationSize: 172,032, EndOfFile: 172,032, NumberOfLinks: 1, DeletePending: False, Directory: False
28571	2:50:03.4993265 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28573	2:50:03.4994447 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
28577	2:50:03.4995980 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28579	2:50:03.4997143 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	AllocationSize: 126,976, EndOfFile: 125,952, NumberOfLinks: 1, DeletePending: False, Directory: False
28583	2:50:03.4998394 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\win.ini	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28585	2:50:03.4999271 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\win.ini	SUCCESS	AllocationSize: 4,096, EndOfFile: 1,220, NumberOfLinks: 1, DeletePending: False, Directory: False
28589	2:50:03.5000520 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\CMDLINEEXT.DLL	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28591	2:50:03.5001411 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\CmdLineExt.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 107,888, NumberOfLinks: 1, DeletePending: False, Directory: False
28595	2:50:03.5002948 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\rpcss.dll	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28597	2:50:03.5004129 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\rpcss.dll	SUCCESS	AllocationSize: 401,408, EndOfFile: 399,360, NumberOfLinks: 1, DeletePending: False, Directory: False
28601	2:50:03.5005473 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\My Documents\desktop.ini	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28603	2:50:03.5006401 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Documents and Settings\Owner\My Documents\desktop.ini	SUCCESS	AllocationSize: 4,096, EndOfFile: 80, NumberOfLinks: 1, DeletePending: False, Directory: False
28607	2:50:03.5007448 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\All Users\Documents\desktop.ini	SUCCESS	Desired Access: Read Data/List Directory, Read Attributes, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28609	2:50:03.5008113 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Documents and Settings\All Users\Documents\desktop.ini	SUCCESS	AllocationSize: 4,096, EndOfFile: 62, NumberOfLinks: 1, DeletePending: False, Directory: False
28613	2:50:03.5010287 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	
28615	2:50:03.5011547 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	
28617	2:50:03.5012695 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\unicode.nls	SUCCESS	
28619	2:50:03.5013821 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\locale.nls	SUCCESS	
28621	2:50:03.5014935 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\sorttbls.nls	SUCCESS	
28623	2:50:03.5015854 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	
28625	2:50:03.5016994 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	
28627	2:50:03.5018131 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	
28629	2:50:03.5019251 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	
28631	2:50:03.5020380 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	
28633	2:50:03.5021495 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	
28635	2:50:03.5022623 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	
28637	2:50:03.5023758 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	
28639	2:50:03.5024870 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\user32.dll	SUCCESS	
28641	2:50:03.5025993 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	
28643	2:50:03.5027118 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	
28645	2:50:03.5028244 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	
28647	2:50:03.5029373 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\version.dll	SUCCESS	
28649	2:50:03.5030488 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	
28651	2:50:03.5031627 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	
28653	2:50:03.5032756 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	
28655	2:50:03.5033887 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	
28657	2:50:03.5045649 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	
28659	2:50:03.5046272 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\xinput1_3.dll	SUCCESS	
28661	2:50:03.5047786 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	
28663	2:50:03.5049051 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	
28665	2:50:03.5050208 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
28667	2:50:03.5051339 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	
28669	2:50:03.5052471 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	
28671	2:50:03.5053661 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	
28673	2:50:03.5054801 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	
28675	2:50:03.5056022 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	
28677	2:50:03.5056865 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\IESetting.dll	SUCCESS	
28679	2:50:03.5057991 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	
28681	2:50:03.5059109 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	
28683	2:50:03.5060243 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\netapi32.dll	SUCCESS	
28685	2:50:03.5061360 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	
28687	2:50:03.5062478 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	
28689	2:50:03.5063729 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	
28691	2:50:03.5064838 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
28693	2:50:03.5065964 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ctype.nls	SUCCESS	
28695	2:50:03.5067104 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
28697	2:50:03.5067713 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
28699	2:50:03.5068844 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	
28701	2:50:03.5069956 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\sortkey.nls	SUCCESS	
28703	2:50:03.5071079 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	
28705	2:50:03.5072194 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	
28707	2:50:03.5072884 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
28709	2:50:03.5074312 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	
28711	2:50:03.5075460 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	
28713	2:50:03.5076591 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
28715	2:50:03.5077734 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
28717	2:50:03.5078862 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	
28719	2:50:03.5079983 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	
28721	2:50:03.5081103 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	
28723	2:50:03.5083190 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
28725	2:50:03.5084327 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	
28727	2:50:03.5085179 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\win.ini	SUCCESS	
28729	2:50:03.5086037 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\CmdLineExt.dll	SUCCESS	
28731	2:50:03.5087154 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\rpcss.dll	SUCCESS	
28733	2:50:03.5088054 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\My Documents\desktop.ini	SUCCESS	
28735	2:50:03.5088693 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\All Users\Documents\desktop.ini	SUCCESS	
28737	2:50:03.5090261 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28744	2:50:03.5093275 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28751	2:50:03.5096043 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28777	2:50:03.5103947 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28784	2:50:03.5106858 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28791	2:50:03.5109704 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28798	2:50:03.5112836 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28805	2:50:03.5115672 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28812	2:50:03.5118608 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28819	2:50:03.5122396 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28826	2:50:03.5125217 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\user32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28833	2:50:03.5128031 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28840	2:50:03.5130844 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28847	2:50:03.5133752 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28854	2:50:03.5136540 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\version.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28861	2:50:03.5139750 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28868	2:50:03.5142756 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28875	2:50:03.5145664 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28882	2:50:03.5148547 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28889	2:50:03.5151377 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28896	2:50:03.5153816 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\XINPUT1_3.DLL	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28903	2:50:03.5156140 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28910	2:50:03.5159004 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28917	2:50:03.5161848 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28924	2:50:03.5164644 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28931	2:50:03.5167460 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28938	2:50:03.5170254 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28945	2:50:03.5173073 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28952	2:50:03.5175875 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28959	2:50:03.5178392 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\IESETTING.DLL	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28966	2:50:03.5180906 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28973	2:50:03.5183756 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28980	2:50:03.5186546 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\netapi32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28987	2:50:03.5189346 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
28994	2:50:03.5192184 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29001	2:50:03.5194964 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29008	2:50:03.5197813 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29015	2:50:03.5200721 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29022	2:50:03.5203563 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29029	2:50:03.5206367 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29036	2:50:03.5209192 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29043	2:50:03.5212016 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29050	2:50:03.5214952 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29057	2:50:03.5218101 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29064	2:50:03.5221163 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29071	2:50:03.5223984 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29078	2:50:03.5226828 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29085	2:50:03.5229736 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	Desired Access: Execute/Traverse, Disposition: Open, Options: Non-Directory File, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
29092	2:50:03.5240436 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ntdll.dll	SUCCESS	
29094	2:50:03.5241632 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\kernel32.dll	SUCCESS	
29096	2:50:03.5242556 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	
29098	2:50:03.5243713 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	
29100	2:50:03.5244850 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	
29102	2:50:03.5245984 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	
29104	2:50:03.5247110 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\advapi32.dll	SUCCESS	
29106	2:50:03.5248328 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	
29108	2:50:03.5249462 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\secur32.dll	SUCCESS	
29110	2:50:03.5250594 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\gdi32.dll	SUCCESS	
29112	2:50:03.5251720 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\user32.dll	SUCCESS	
29114	2:50:03.5252848 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	
29116	2:50:03.5253977 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	
29118	2:50:03.5255203 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	
29120	2:50:03.5256326 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\version.dll	SUCCESS	
29122	2:50:03.5257449 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	
29124	2:50:03.5258718 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	
29126	2:50:03.5259835 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	
29128	2:50:03.5260953 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	
29130	2:50:03.5262076 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ole32.dll	SUCCESS	
29132	2:50:03.5262685 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\xinput1_3.dll	SUCCESS	
29134	2:50:03.5263813 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	
29136	2:50:03.5264931 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	
29138	2:50:03.5266051 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
29140	2:50:03.5267171 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wininet.dll	SUCCESS	
29142	2:50:03.5268599 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\normaliz.dll	SUCCESS	
29144	2:50:03.5269764 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\urlmon.dll	SUCCESS	
29146	2:50:03.5270901 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	
29148	2:50:03.5272029 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\iertutil.dll	SUCCESS	
29150	2:50:03.5272879 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\IESetting.dll	SUCCESS	
29152	2:50:03.5273999 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	
29154	2:50:03.5275102 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	
29156	2:50:03.5276231 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\netapi32.dll	SUCCESS	
29158	2:50:03.5277343 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	
29160	2:50:03.5278483 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	
29162	2:50:03.5279600 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	
29164	2:50:03.5281050 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
29166	2:50:03.5282198 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	
29168	2:50:03.5283335 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	
29170	2:50:03.5284453 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	
29172	2:50:03.5285590 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	
29174	2:50:03.5286704 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
29176	2:50:03.5287861 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
29178	2:50:03.5288990 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	
29180	2:50:03.5290177 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	
29182	2:50:03.5291294 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wldap32.dll	SUCCESS	
29184	2:50:03.5292409 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
29186	2:50:03.5293518 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\apphelp.dll	SUCCESS	
29188	2:50:03.5293831 PM	ra3game.dat	3416	CloseFile	C:	SUCCESS	
29191	2:50:03.5294854 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ra3game.dat	NAME NOT FOUND	Desired Access: Read
29196	2:50:03.5296217 PM	ra3game.dat	3416	FileSystemControl	C:\Program Files\Red Alert 3 Beta	SUCCESS	Control: FSCTL_IS_VOLUME_MOUNTED
29197	2:50:03.5296418 PM	ra3game.dat	3416	FileSystemControl	C:\Program Files\Red Alert 3 Beta	SUCCESS	Control: FSCTL_IS_VOLUME_MOUNTED
29200	2:50:03.5298784 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\kernel32.dll	SUCCESS	Image Base: 0x7c800000, Image Size: 0xf6000
29201	2:50:03.5300871 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	Desired Access: Read
29202	2:50:03.5301276 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29203	2:50:03.5301502 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	
29208	2:50:03.5304196 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
29209	2:50:03.5305302 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Local	NAME NOT FOUND	
29210	2:50:03.5306595 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	CreationTime: 3/4/2008 4:56:27 AM, LastAccessTime: 3/4/2008 4:56:27 AM, LastWriteTime: 3/4/2008 4:56:27 AM, ChangeTime: 3/4/2008 4:56:27 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
29211	2:50:03.5307878 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
29212	2:50:03.5309381 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29219	2:50:03.5311171 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\SafeBoot\Option	NAME NOT FOUND	Desired Access: Query Value, Set Value
29220	2:50:03.5311370 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	Desired Access: Query Value
29221	2:50:03.5311973 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
29222	2:50:03.5312157 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers	SUCCESS	
29223	2:50:03.5312367 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers	NAME NOT FOUND	Desired Access: Query Value
29224	2:50:03.5313501 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	
29228	2:50:03.5315429 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	Image Base: 0x78130000, Image Size: 0x9b000
29231	2:50:03.5318234 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\msvcrt.dll	SUCCESS	Image Base: 0x77c10000, Image Size: 0x58000
29236	2:50:03.5322980 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\shell32.dll	SUCCESS	Image Base: 0x7c9c0000, Image Size: 0x817000
29244	2:50:03.5324969 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\advapi32.dll	SUCCESS	Image Base: 0x77dd0000, Image Size: 0x9b000
29249	2:50:03.5327014 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\rpcrt4.dll	SUCCESS	Image Base: 0x77e70000, Image Size: 0x92000
29252	2:50:03.5328866 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\secur32.dll	SUCCESS	Image Base: 0x77fe0000, Image Size: 0x11000
29255	2:50:03.5330487 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\gdi32.dll	SUCCESS	Image Base: 0x77f10000, Image Size: 0x49000
29258	2:50:03.5332277 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\user32.dll	SUCCESS	Image Base: 0x7e410000, Image Size: 0x91000
29263	2:50:03.5334518 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\shlwapi.dll	SUCCESS	Image Base: 0x77f60000, Image Size: 0x76000
29269	2:50:03.5337756 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\d3d9.dll	NAME NOT FOUND	
29272	2:50:03.5339354 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\d3d9.dll	SUCCESS	CreationTime: 8/16/2005 5:18:07 AM, LastAccessTime: 6/5/2008 7:56:16 AM, LastWriteTime: 4/14/2008 5:41:52 AM, ChangeTime: 6/5/2008 7:56:16 AM, AllocationSize: 1,691,648, EndOfFile: 1,689,088, FileAttributes: A
29275	2:50:03.5343857 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29289	2:50:03.5346944 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3d9.dll	SUCCESS	
29293	2:50:03.5348824 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\d3d9.dll	SUCCESS	Image Base: 0x4fdd0000, Image Size: 0x1a6000
29296	2:50:03.5350539 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\d3d8thk.dll	NAME NOT FOUND	
29302	2:50:03.5352230 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	CreationTime: 8/16/2005 5:18:07 AM, LastAccessTime: 6/5/2008 7:53:13 AM, LastWriteTime: 4/14/2008 5:41:52 AM, ChangeTime: 6/5/2008 7:53:13 AM, AllocationSize: 8,192, EndOfFile: 8,192, FileAttributes: A
29303	2:50:03.5353640 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29312	2:50:03.5357551 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	
29316	2:50:03.5360169 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\d3d8thk.dll	SUCCESS	Image Base: 0x6d990000, Image Size: 0x6000
29321	2:50:03.5362608 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\version.dll	SUCCESS	Image Base: 0x77c00000, Image Size: 0x8000
29327	2:50:03.5364128 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\WINMM.dll	NAME NOT FOUND	
29328	2:50:03.5365955 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\winmm.dll	SUCCESS	CreationTime: 8/16/2005 5:18:45 AM, LastAccessTime: 6/5/2008 7:52:15 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 176,128, EndOfFile: 176,128, FileAttributes: A
29331	2:50:03.5367424 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29340	2:50:03.5370838 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\winmm.dll	SUCCESS	
29349	2:50:03.5372852 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\winmm.dll	SUCCESS	Image Base: 0x76b40000, Image Size: 0x2d000
29352	2:50:03.5374671 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\d3dx9_35.dll	NAME NOT FOUND	
29354	2:50:03.5377953 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	CreationTime: 11/20/2007 4:24:51 PM, LastAccessTime: 11/20/2007 4:24:51 PM, LastWriteTime: 7/19/2007 7:14:42 PM, ChangeTime: 8/4/2008 7:37:39 PM, AllocationSize: 3,731,456, EndOfFile: 3,727,720, FileAttributes: A
29356	2:50:03.5379655 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29370	2:50:03.5382543 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	
29374	2:50:03.5384256 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\d3dx9_35.dll	SUCCESS	Image Base: 0x1dc0000, Image Size: 0x3a8000
29410	2:50:03.5451337 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\DINPUT8.dll	NAME NOT FOUND	
29411	2:50:03.5452980 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\dinput8.dll	SUCCESS	CreationTime: 8/16/2005 5:18:08 AM, LastAccessTime: 6/5/2008 7:53:11 AM, LastWriteTime: 4/14/2008 5:41:54 AM, ChangeTime: 6/5/2008 7:53:11 AM, AllocationSize: 184,320, EndOfFile: 181,760, FileAttributes: A
29412	2:50:03.5455477 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29419	2:50:03.5458226 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\dinput8.dll	SUCCESS	
29422	2:50:03.5461081 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\dinput8.dll	SUCCESS	Image Base: 0x6ce10000, Image Size: 0x38000
29424	2:50:03.5463143 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\DSOUND.dll	NAME NOT FOUND	
29425	2:50:03.5464604 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\dsound.dll	SUCCESS	CreationTime: 8/16/2005 5:18:15 AM, LastAccessTime: 6/5/2008 7:53:09 AM, LastWriteTime: 4/14/2008 5:41:54 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 368,640, EndOfFile: 367,616, FileAttributes: A
29426	2:50:03.5465970 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29433	2:50:03.5468582 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\dsound.dll	SUCCESS	
29436	2:50:03.5470479 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\dsound.dll	SUCCESS	Image Base: 0x73f10000, Image Size: 0x5c000
29440	2:50:03.5472547 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\ole32.dll	SUCCESS	Image Base: 0x774e0000, Image Size: 0x13d000
29441	2:50:03.5474343 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\XINPUT1_3.dll	SUCCESS	CreationTime: 7/2/2008 12:49:54 PM, LastAccessTime: 8/22/2008 2:42:16 PM, LastWriteTime: 7/2/2008 12:49:54 PM, ChangeTime: 8/22/2008 2:42:16 PM, AllocationSize: 81,920, EndOfFile: 81,768, FileAttributes: A
29442	2:50:03.5475209 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\XINPUT1_3.dll	SUCCESS	CreationTime: 7/2/2008 12:49:54 PM, LastAccessTime: 8/22/2008 2:42:16 PM, LastWriteTime: 7/2/2008 12:49:54 PM, ChangeTime: 8/22/2008 2:42:16 PM, AllocationSize: 81,920, EndOfFile: 81,768, FileAttributes: A
29443	2:50:03.5476237 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\XINPUT1_3.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29450	2:50:03.5478176 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\xinput1_3.dll	SUCCESS	
29453	2:50:03.5479880 PM	ra3game.dat	3416	Load Image	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\xinput1_3.dll	SUCCESS	Image Base: 0x350000, Image Size: 0x16000
29455	2:50:03.5483461 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\SETUPAPI.dll	NAME NOT FOUND	
29456	2:50:03.5484953 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\setupapi.dll	SUCCESS	CreationTime: 8/16/2005 5:18:36 AM, LastAccessTime: 6/5/2008 7:52:01 AM, LastWriteTime: 4/14/2008 5:42:06 AM, ChangeTime: 6/5/2008 7:52:01 AM, AllocationSize: 987,136, EndOfFile: 985,088, FileAttributes: A
29457	2:50:03.5486305 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29464	2:50:03.5488931 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\setupapi.dll	SUCCESS	
29468	2:50:03.5490730 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\setupapi.dll	SUCCESS	Image Base: 0x77920000, Image Size: 0xf3000
29469	2:50:03.5493222 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29476	2:50:03.5495879 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	
29480	2:50:03.5497466 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll	SUCCESS	Image Base: 0x7c420000, Image Size: 0x87000
29481	2:50:03.5499514 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\IMM32.dll	NAME NOT FOUND	
29482	2:50:03.5500944 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
29483	2:50:03.5502304 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29490	2:50:03.5504863 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\imm32.dll	SUCCESS	
29494	2:50:03.5506534 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\imm32.dll	SUCCESS	Image Base: 0x76390000, Image Size: 0x1d000
29497	2:50:03.5508635 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\wininet.dll	SUCCESS	Image Base: 0x78050000, Image Size: 0xd0000
29500	2:50:03.5512336 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\normaliz.dll	SUCCESS	Image Base: 0x370000, Image Size: 0x9000
29503	2:50:03.5514817 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\urlmon.dll	SUCCESS	Image Base: 0x7f560000, Image Size: 0x12e000
29506	2:50:03.5517142 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\oleaut32.dll	SUCCESS	Image Base: 0x77120000, Image Size: 0x8b000
29509	2:50:03.5521282 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\iertutil.dll	SUCCESS	Image Base: 0x5dca0000, Image Size: 0x45000
29512	2:50:03.5523690 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\IESetting.dll	SUCCESS	Image Base: 0x77270000, Image Size: 0x26000
29513	2:50:03.5526637 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\WS2_32.dll	NAME NOT FOUND	
29514	2:50:03.5528163 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:46 AM, LastAccessTime: 6/5/2008 7:52:13 AM, LastWriteTime: 4/14/2008 5:42:12 AM, ChangeTime: 6/5/2008 8:00:05 AM, AllocationSize: 86,016, EndOfFile: 82,432, FileAttributes: A
29515	2:50:03.5529531 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29522	2:50:03.5532174 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	
29526	2:50:03.5533817 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\ws2_32.dll	SUCCESS	Image Base: 0x71ab0000, Image Size: 0x17000
29527	2:50:03.5535300 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\WS2HELP.dll	NAME NOT FOUND	
29528	2:50:03.5536666 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\ws2help.dll	SUCCESS	CreationTime: 8/16/2005 5:18:46 AM, LastAccessTime: 6/5/2008 7:52:13 AM, LastWriteTime: 4/14/2008 5:42:12 AM, ChangeTime: 6/5/2008 8:00:05 AM, AllocationSize: 20,480, EndOfFile: 19,968, FileAttributes: A
29529	2:50:03.5538002 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29536	2:50:03.5540572 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ws2help.dll	SUCCESS	
29540	2:50:03.5542279 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\ws2help.dll	SUCCESS	Image Base: 0x71aa0000, Image Size: 0x8000
29543	2:50:03.5544352 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\netapi32.dll	SUCCESS	Image Base: 0x5b860000, Image Size: 0x55000
29544	2:50:03.5546145 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\USP10.dll	NAME NOT FOUND	
29545	2:50:03.5547573 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\usp10.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 7:52:18 AM, AllocationSize: 409,600, EndOfFile: 406,016, FileAttributes: A
29546	2:50:03.5548914 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29553	2:50:03.5551503 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\usp10.dll	SUCCESS	
29557	2:50:03.5553121 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\usp10.dll	SUCCESS	Image Base: 0x74d90000, Image Size: 0x6b000
29558	2:50:03.5555208 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\WSOCK32.dll	NAME NOT FOUND	
29559	2:50:03.5556591 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\wsock32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:46 AM, LastAccessTime: 6/5/2008 7:52:12 AM, LastWriteTime: 4/14/2008 5:42:12 AM, ChangeTime: 6/5/2008 8:00:05 AM, AllocationSize: 24,576, EndOfFile: 22,528, FileAttributes: A
29560	2:50:03.5558080 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29567	2:50:03.5560647 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\wsock32.dll	SUCCESS	
29570	2:50:03.5562220 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\wsock32.dll	SUCCESS	Image Base: 0x71ad0000, Image Size: 0x9000
29572	2:50:03.5567385 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ShimEng.dll	NAME NOT FOUND	
29573	2:50:03.5568785 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\shimeng.dll	SUCCESS	CreationTime: 8/16/2005 5:18:36 AM, LastAccessTime: 6/5/2008 7:52:26 AM, LastWriteTime: 4/14/2008 5:42:06 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 65,536, EndOfFile: 65,024, FileAttributes: A
29574	2:50:03.5570123 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29581	2:50:03.5572718 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shimeng.dll	SUCCESS	
29585	2:50:03.5574316 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\shimeng.dll	SUCCESS	Image Base: 0x5cb70000, Image Size: 0x26000
29586	2:50:03.5576560 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
29587	2:50:03.5577627 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
29589	2:50:03.5578691 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
29593	2:50:03.5579968 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
29595	2:50:03.5581326 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
29596	2:50:03.5581661 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
29597	2:50:03.5581834 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
29598	2:50:03.5582105 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
29599	2:50:03.5582315 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
29600	2:50:03.5584471 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
29602	2:50:03.5585008 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	Desired Access: Read
29603	2:50:03.5585312 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29604	2:50:03.5585497 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	
29605	2:50:03.5587785 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvcrt.dll	NAME NOT FOUND	Desired Access: Read
29607	2:50:03.5589802 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSVCR80.dll	NAME NOT FOUND	Desired Access: Read
29608	2:50:03.5592257 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	Desired Access: Query Value
29609	2:50:03.5592562 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\SafeDllSearchMode	NAME NOT FOUND	Length: 16
29610	2:50:03.5592752 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	
29611	2:50:03.5594615 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll	SUCCESS	CreationTime: 10/24/2007 2:47:56 AM, LastAccessTime: 3/4/2008 4:56:27 AM, LastWriteTime: 10/24/2007 2:47:56 AM, ChangeTime: 3/4/2008 4:56:27 AM, AllocationSize: 638,976, EndOfFile: 635,904, FileAttributes: A
29612	2:50:03.5594931 PM	ra3game.dat	3416	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
29613	2:50:03.5595165 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS	SUCCESS	Filter: WINDOWS, 1: WINDOWS
29614	2:50:03.5595428 PM	ra3game.dat	3416	CloseFile	C:\	SUCCESS	
29616	2:50:03.5596342 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
29617	2:50:03.5596858 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS	SUCCESS	Filter: WinSxS, 1: WinSxS
29618	2:50:03.5597406 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS	SUCCESS	
29620	2:50:03.5598649 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
29621	2:50:03.5599457 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll	SUCCESS	Filter: MSVCR80.dll, 1: msvcr80.dll
29622	2:50:03.5600272 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
29624	2:50:03.5600689 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secur32.dll	NAME NOT FOUND	Desired Access: Read
29625	2:50:03.5600954 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll	NAME NOT FOUND	Desired Access: Read
29626	2:50:03.5601149 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll	NAME NOT FOUND	Desired Access: Read
29627	2:50:03.5601362 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	Desired Access: Read
29628	2:50:03.5601610 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSAppCompat	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29629	2:50:03.5601745 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Terminal Server\TSUserEnabled	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29630	2:50:03.5601895 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\Terminal Server	SUCCESS	
29631	2:50:03.5602049 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon	SUCCESS	Desired Access: Read
29632	2:50:03.5602306 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LeakTrack	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29633	2:50:03.5602538 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon	SUCCESS	
29634	2:50:03.5602672 PM	ra3game.dat	3416	RegOpenKey	HKLM	SUCCESS	Desired Access: Maximum Allowed
29635	2:50:03.5602856 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics	NAME NOT FOUND	Desired Access: Read
29636	2:50:03.5603088 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USER32.dll	NAME NOT FOUND	Desired Access: Read
29637	2:50:03.5605290 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
29638	2:50:03.5607022 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\imm32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:19 AM, LastAccessTime: 6/5/2008 7:53:01 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 110,592, EndOfFile: 110,080, FileAttributes: A
29639	2:50:03.5607198 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\Error Message Instrument	NAME NOT FOUND	Desired Access: Read
29640	2:50:03.5607438 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	Desired Access: Read
29641	2:50:03.5607673 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles	NAME NOT FOUND	Length: 20
29642	2:50:03.5607829 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	
29643	2:50:03.5609083 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32	SUCCESS	Desired Access: Read
29644	2:50:03.5609315 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\ra3game	NAME NOT FOUND	Length: 172
29645	2:50:03.5609475 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32	SUCCESS	
29646	2:50:03.5609578 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility	SUCCESS	Desired Access: Read
29647	2:50:03.5609793 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IME Compatibility\ra3game	NAME NOT FOUND	Length: 172
29648	2:50:03.5609924 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IME Compatibility	SUCCESS	
29649	2:50:03.5610718 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	Desired Access: Read
29650	2:50:03.5610930 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs	SUCCESS	Type: REG_SZ, Length: 2, Data: 
29651	2:50:03.5611086 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
29652	2:50:03.5611830 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll	NAME NOT FOUND	Desired Access: Read
29653	2:50:03.5611980 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHLWAPI.dll	NAME NOT FOUND	Desired Access: Read
29654	2:50:03.5612226 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Performance	NAME NOT FOUND	Desired Access: Maximum Allowed
29655	2:50:03.5612704 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHELL32.dll	NAME NOT FOUND	Desired Access: Read
29656	2:50:03.5613573 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\Setup	SUCCESS	Desired Access: Query Value
29657	2:50:03.5613830 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\Setup\SystemSetupInProgress	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29658	2:50:03.5613975 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\Setup	SUCCESS	
29659	2:50:03.5614268 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
29660	2:50:03.5614498 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
29661	2:50:03.5614632 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
29662	2:50:03.5614841 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
29663	2:50:03.5615037 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
29664	2:50:03.5615165 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
29665	2:50:03.5616914 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
29667	2:50:03.5618157 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	AllocationSize: 8,462,336, EndOfFile: 8,461,312, NumberOfLinks: 1, DeletePending: False, Directory: False
29671	2:50:03.5619576 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\SHELL32.dll.124.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
29672	2:50:03.5620076 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
29673	2:50:03.5620275 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
29674	2:50:03.5620389 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
29675	2:50:03.5620579 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
29676	2:50:03.5620708 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
29677	2:50:03.5620828 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
29678	2:50:03.5621962 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\SHELL32.dll.124.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
29761	2:50:03.5725503 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\shell32.dll	SUCCESS	
29763	2:50:03.5726213 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
29764	2:50:03.5728149 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Local	NAME NOT FOUND	
29765	2:50:03.5729347 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	CreationTime: 6/5/2008 7:56:33 AM, LastAccessTime: 6/5/2008 7:56:33 AM, LastWriteTime: 6/5/2008 7:56:33 AM, ChangeTime: 6/5/2008 7:56:33 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
29766	2:50:03.5730392 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
29767	2:50:03.5731864 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29769	2:50:03.5733102 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	AllocationSize: 1,056,768, EndOfFile: 1,054,208, NumberOfLinks: 1, DeletePending: False, Directory: False
29773	2:50:03.5734415 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
29776	2:50:03.5736189 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29786	2:50:03.5739505 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	
29793	2:50:03.5741790 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll	SUCCESS	Image Base: 0x773d0000, Image Size: 0x103000
29803	2:50:03.5743975 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll	NAME NOT FOUND	Desired Access: Read
29804	2:50:03.5744489 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
29807	2:50:03.5744835 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
29808	2:50:03.5745006 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
29810	2:50:03.5745414 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
29811	2:50:03.5745632 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
29812	2:50:03.5745766 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
29815	2:50:03.5747118 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	CreationTime: 8/16/2005 5:40:51 AM, LastAccessTime: 4/9/2006 1:04:37 AM, LastWriteTime: 8/16/2005 5:40:52 AM, ChangeTime: 8/4/2008 7:40:37 PM, AllocationSize: 4,096, EndOfFile: 749, FileAttributes: RHA
29818	2:50:03.5747989 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29825	2:50:03.5748878 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
29830	2:50:03.5749685 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
29835	2:50:03.5751364 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	CreationTime: 8/16/2005 5:40:51 AM, LastAccessTime: 4/9/2006 1:04:37 AM, LastWriteTime: 8/16/2005 5:40:52 AM, ChangeTime: 8/4/2008 7:40:37 PM, AllocationSize: 4,096, EndOfFile: 749, FileAttributes: RHA
29836	2:50:03.5752216 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
29838	2:50:03.5752861 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
29842	2:50:03.5753610 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
29844	2:50:03.5754708 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
29846	2:50:03.5755359 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
29850	2:50:03.5756169 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	AllocationSize: 4,096, EndOfFile: 749, NumberOfLinks: 1, DeletePending: False, Directory: False
29851	2:50:03.5756882 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WindowsShell.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
29908	2:50:03.5842378 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WindowsShell.Manifest	SUCCESS	
29910	2:50:03.5843225 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
29911	2:50:03.5843616 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
29912	2:50:03.5843851 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\SmoothScroll	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29913	2:50:03.5844116 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
29914	2:50:03.5844457 PM	ra3game.dat	3416	RegOpenKey	HKCU\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced	SUCCESS	Desired Access: Read
29915	2:50:03.5844731 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29916	2:50:03.5845013 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced	SUCCESS	
29917	2:50:03.5845189 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
29918	2:50:03.5845384 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\LanguagePack	SUCCESS	Desired Access: Query Value
29919	2:50:03.5845711 PM	ra3game.dat	3416	RegEnumValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack	NO MORE ENTRIES	Index: 0, Length: 220
29920	2:50:03.5845854 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack	SUCCESS	
29921	2:50:03.5848636 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll	NAME NOT FOUND	Desired Access: Read
29922	2:50:03.5848795 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernel32.dll	NAME NOT FOUND	Desired Access: Read
29923	2:50:03.5848938 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\d3d8thk.dll	NAME NOT FOUND	Desired Access: Read
29924	2:50:03.5849064 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VERSION.dll	NAME NOT FOUND	Desired Access: Read
29925	2:50:03.5849192 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINMM.dll	NAME NOT FOUND	Desired Access: Read
29926	2:50:03.5849321 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\d3d9.dll	NAME NOT FOUND	Desired Access: Read
29927	2:50:03.5849449 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\d3dx9_35.dll	NAME NOT FOUND	Desired Access: Read
29928	2:50:03.5849575 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DINPUT8.dll	NAME NOT FOUND	Desired Access: Read
29929	2:50:03.5849703 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll	NAME NOT FOUND	Desired Access: Read
29930	2:50:03.5849835 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DSOUND.dll	NAME NOT FOUND	Desired Access: Read
29931	2:50:03.5849966 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPAPI.dll	NAME NOT FOUND	Desired Access: Read
29932	2:50:03.5850095 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XINPUT1_3.dll	NAME NOT FOUND	Desired Access: Read
29933	2:50:03.5850217 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSVCP80.dll	NAME NOT FOUND	Desired Access: Read
29934	2:50:03.5850343 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.dll	NAME NOT FOUND	Desired Access: Read
29935	2:50:03.5850472 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Normaliz.dll	NAME NOT FOUND	Desired Access: Read
29936	2:50:03.5850639 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLEAUT32.dll	NAME NOT FOUND	Desired Access: Read
29937	2:50:03.5850776 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IESetting.dll	NAME NOT FOUND	Desired Access: Read
29938	2:50:03.5850902 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iertutil.dll	NAME NOT FOUND	Desired Access: Read
29939	2:50:03.5851028 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\urlmon.dll	NAME NOT FOUND	Desired Access: Read
29940	2:50:03.5851156 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WININET.dll	NAME NOT FOUND	Desired Access: Read
29941	2:50:03.5851315 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2HELP.dll	NAME NOT FOUND	Desired Access: Read
29942	2:50:03.5851444 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2_32.dll	NAME NOT FOUND	Desired Access: Read
29943	2:50:03.5851572 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NETAPI32.dll	NAME NOT FOUND	Desired Access: Read
29944	2:50:03.5851701 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USP10.dll	NAME NOT FOUND	Desired Access: Read
29945	2:50:03.5851829 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSOCK32.dll	NAME NOT FOUND	Desired Access: Read
29946	2:50:03.5851955 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ShimEng.dll	NAME NOT FOUND	Desired Access: Read
29949	2:50:03.5854682 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Image Base: 0x5d090000, Image Size: 0x9a000
29950	2:50:03.5855416 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll	NAME NOT FOUND	Desired Access: Read
29951	2:50:03.5856788 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
29952	2:50:03.5857037 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
29953	2:50:03.5857171 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
29954	2:50:03.5857378 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
29955	2:50:03.5857542 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
29956	2:50:03.5857704 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
29957	2:50:03.5859473 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
29959	2:50:03.5860724 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	AllocationSize: 618,496, EndOfFile: 617,472, NumberOfLinks: 1, DeletePending: False, Directory: False
29963	2:50:03.5862149 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\comctl32.dll.124.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
29964	2:50:03.5863543 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\comctl32.dll.124.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
29965	2:50:03.5873620 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\comctl32.dll	SUCCESS	
29967	2:50:03.5874575 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
29968	2:50:03.5874852 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
29969	2:50:03.5875050 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\SmoothScroll	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
29970	2:50:03.5875254 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
29971	2:50:03.5875478 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
29972	2:50:03.5877802 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32	SUCCESS	Desired Access: Read
29973	2:50:03.5878062 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29974	2:50:03.5878464 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29975	2:50:03.5878685 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29977	2:50:03.5878866 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29978	2:50:03.5879084 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29979	2:50:03.5879224 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29980	2:50:03.5879361 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29981	2:50:03.5879498 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29982	2:50:03.5879635 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29983	2:50:03.5879774 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29984	2:50:03.5879914 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29985	2:50:03.5880056 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29986	2:50:03.5880199 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29987	2:50:03.5880341 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29988	2:50:03.5880487 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29989	2:50:03.5880635 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29990	2:50:03.5880783 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29991	2:50:03.5880936 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29992	2:50:03.5881084 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29993	2:50:03.5881244 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\wave9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29994	2:50:03.5881400 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29995	2:50:03.5881568 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29996	2:50:03.5881735 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29997	2:50:03.5881872 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29998	2:50:03.5882006 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
29999	2:50:03.5882143 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30000	2:50:03.5882283 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30001	2:50:03.5882423 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30002	2:50:03.5882565 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30003	2:50:03.5882708 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30004	2:50:03.5882853 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30005	2:50:03.5884009 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30006	2:50:03.5884163 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30007	2:50:03.5884317 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30008	2:50:03.5884468 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30009	2:50:03.5884627 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30010	2:50:03.5884780 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30011	2:50:03.5884940 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30012	2:50:03.5885099 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30013	2:50:03.5885264 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\midi9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30014	2:50:03.5885437 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30015	2:50:03.5885579 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30016	2:50:03.5885716 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30017	2:50:03.5885862 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30018	2:50:03.5886004 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30019	2:50:03.5886149 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30020	2:50:03.5886295 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30021	2:50:03.5886445 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30022	2:50:03.5886596 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30023	2:50:03.5886747 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30024	2:50:03.5886898 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30025	2:50:03.5887052 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30026	2:50:03.5887208 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30027	2:50:03.5887365 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30028	2:50:03.5887518 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux7	NAME NOT FOUND	Length: 536
30029	2:50:03.5887694 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux8	NAME NOT FOUND	Length: 536
30030	2:50:03.5887881 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\aux9	NAME NOT FOUND	Length: 536
30031	2:50:03.5888043 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm	SUCCESS	Desired Access: All Access
30032	2:50:03.5888661 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm\wheel	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
30033	2:50:03.5888842 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm	SUCCESS	
30034	2:50:03.5889102 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30035	2:50:03.5889298 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30036	2:50:03.5889474 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30037	2:50:03.5889613 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer1	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30038	2:50:03.5889748 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30039	2:50:03.5889887 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer2	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30040	2:50:03.5890024 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30041	2:50:03.5890169 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer3	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30042	2:50:03.5890312 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30043	2:50:03.5890457 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer4	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30044	2:50:03.5890602 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30045	2:50:03.5890751 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer5	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30046	2:50:03.5890899 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30047	2:50:03.5891049 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer6	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30048	2:50:03.5891200 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30049	2:50:03.5891357 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer7	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30050	2:50:03.5891513 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30051	2:50:03.5891672 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer8	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30052	2:50:03.5891837 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30053	2:50:03.5892005 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\mixer9	SUCCESS	Type: REG_SZ, Length: 22, Data: wdmaud.drv
30054	2:50:03.5893516 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Direct3D	SUCCESS	Desired Access: Query Value
30055	2:50:03.5893779 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Direct3D\GeometryDriver	NAME NOT FOUND	Length: 144
30056	2:50:03.5893930 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Direct3D	SUCCESS	
30057	2:50:03.5894178 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
30058	2:50:03.5894502 PM	ra3game.dat	3416	RegCreateKey	HKCU\Software\Microsoft\Direct3D\MostRecentApplication	SUCCESS	Desired Access: Set Value
30059	2:50:03.5894779 PM	ra3game.dat	3416	RegSetValue	HKCU\Software\Microsoft\Direct3D\MostRecentApplication\Name	SUCCESS	Type: REG_SZ, Length: 24, Data: ra3game.dat
30060	2:50:03.5894916 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Direct3D\MostRecentApplication	SUCCESS	
30061	2:50:03.5897444 PM	ra3game.dat	3416	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	BUFFER OVERFLOW	Name: \P
30062	2:50:03.5897634 PM	ra3game.dat	3416	QueryNameInformationFile	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat	SUCCESS	Name: \Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat
30063	2:50:03.5898383 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: 4A 2F EB C8 79 AE 0F F3 C7 5E 7B 3A C4 C7 24 05
30064	2:50:03.5899246 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Control\Session Manager	SUCCESS	Desired Access: Read
30065	2:50:03.5899598 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\CriticalSectionTimeout	SUCCESS	Type: REG_DWORD, Length: 4, Data: 2592000
30066	2:50:03.5899757 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager	SUCCESS	
30067	2:50:03.5899883 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Ole	SUCCESS	Desired Access: Read
30068	2:50:03.5900101 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Ole\RWLockResourceTimeOut	NAME NOT FOUND	Length: 144
30069	2:50:03.5900235 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Ole	SUCCESS	
30070	2:50:03.5900428 PM	ra3game.dat	3416	RegOpenKey	HKCR\Interface	SUCCESS	Desired Access: Read
30071	2:50:03.5900721 PM	ra3game.dat	3416	RegCloseKey	HKCR\Interface	SUCCESS	
30072	2:50:03.5900824 PM	ra3game.dat	3416	RegOpenKey	HKCR\Interface\{00020400-0000-0000-C000-000000000046}	SUCCESS	Desired Access: Read
30073	2:50:03.5901104 PM	ra3game.dat	3416	RegCloseKey	HKCR\Interface\{00020400-0000-0000-C000-000000000046}	SUCCESS	
30074	2:50:03.5903459 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\dsound.dll	SUCCESS	CreationTime: 8/16/2005 5:18:15 AM, LastAccessTime: 6/5/2008 7:53:09 AM, LastWriteTime: 4/14/2008 5:41:54 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 368,640, EndOfFile: 367,616, FileAttributes: A
30075	2:50:03.5903727 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\DirectX	SUCCESS	Desired Access: Maximum Allowed
30076	2:50:03.5903967 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\DirectX\GlitchInstrumentation	NAME NOT FOUND	Length: 144
30077	2:50:03.5904110 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\DirectX	SUCCESS	
30078	2:50:03.5904518 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\Setup	SUCCESS	Desired Access: Read
30079	2:50:03.5904733 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\Setup\SystemSetupInProgress	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
30080	2:50:03.5904872 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\Setup	SUCCESS	
30081	2:50:03.5905037 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Control\MiniNT	NAME NOT FOUND	Desired Access: All Access
30082	2:50:03.5905216 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\WPA\PnP	SUCCESS	Desired Access: Read
30083	2:50:03.5905420 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\WPA\PnP\seed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 35051770
30084	2:50:03.5905551 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\WPA\PnP	SUCCESS	
30085	2:50:03.5905666 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\Setup	SUCCESS	Desired Access: Read
30086	2:50:03.5905847 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\Setup\OsLoaderPath	SUCCESS	Type: REG_SZ, Length: 4, Data: \
30087	2:50:03.5905956 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\Setup\OsLoaderPath	SUCCESS	Type: REG_SZ, Length: 4, Data: \
30088	2:50:03.5906079 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\Setup	SUCCESS	
30089	2:50:03.5906194 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\Setup	SUCCESS	Desired Access: Read
30090	2:50:03.5906375 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\Setup\SystemPartition	SUCCESS	Type: REG_SZ, Length: 48, Data: \Device\HarddiskVolume2
30091	2:50:03.5906479 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\Setup\SystemPartition	SUCCESS	Type: REG_SZ, Length: 48, Data: \Device\HarddiskVolume2
30092	2:50:03.5906604 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\Setup	SUCCESS	
30093	2:50:03.5906853 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	Desired Access: Read
30094	2:50:03.5907093 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath	SUCCESS	Type: REG_SZ, Length: 8, Data: C:\
30095	2:50:03.5907216 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath	SUCCESS	Type: REG_SZ, Length: 8, Data: C:\
30096	2:50:03.5907353 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	
30097	2:50:03.5907471 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	Desired Access: Read
30098	2:50:03.5907680 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ServicePackSourcePath	SUCCESS	Type: REG_SZ, Length: 56, Data: c:\windows\ServicePackFiles
30099	2:50:03.5907797 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ServicePackSourcePath	SUCCESS	Type: REG_SZ, Length: 56, Data: c:\windows\ServicePackFiles
30100	2:50:03.5907934 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	
30101	2:50:03.5908049 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	Desired Access: Read
30102	2:50:03.5908250 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ServicePackCachePath	SUCCESS	Type: REG_SZ, Length: 90, Data: c:\windows\ServicePackFiles\ServicePackCache
30103	2:50:03.5908378 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ServicePackCachePath	SUCCESS	Type: REG_SZ, Length: 90, Data: c:\windows\ServicePackFiles\ServicePackCache
30104	2:50:03.5908518 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	
30105	2:50:03.5908663 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	Desired Access: Read
30106	2:50:03.5908870 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\DriverCachePath	SUCCESS	Type: REG_EXPAND_SZ, Length: 52, Data: %SystemRoot%\Driver Cache
30107	2:50:03.5908982 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\DriverCachePath	SUCCESS	Type: REG_EXPAND_SZ, Length: 52, Data: %SystemRoot%\Driver Cache
30108	2:50:03.5909116 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	
30109	2:50:03.5909281 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion	SUCCESS	Desired Access: Read
30110	2:50:03.5909485 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath	NAME NOT FOUND	Length: 144
30111	2:50:03.5909641 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion	SUCCESS	
30112	2:50:03.5909915 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	Desired Access: Query Value
30113	2:50:03.5910130 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
30114	2:50:03.5910245 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel	SUCCESS	Type: REG_DWORD, Length: 4, Data: 0
30115	2:50:03.5910382 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogPath	NAME NOT FOUND	Length: 144
30116	2:50:03.5910490 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\AppLogLevels	NAME NOT FOUND	Desired Access: Query Value
30117	2:50:03.5910650 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup	SUCCESS	
30118	2:50:03.5911485 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS	SUCCESS	CreationTime: 4/3/2006 7:03:12 PM, LastAccessTime: 8/22/2008 2:42:23 PM, LastWriteTime: 8/22/2008 2:42:23 PM, ChangeTime: 8/22/2008 2:42:23 PM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
30119	2:50:03.5911714 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName	SUCCESS	Desired Access: Read
30120	2:50:03.5912007 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName	SUCCESS	Type: REG_SZ, Length: 26, Data: MIKE047342KA
30121	2:50:03.5912161 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName	SUCCESS	
30122	2:50:03.5912348 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters	SUCCESS	Desired Access: Read
30123	2:50:03.5912616 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Hostname	SUCCESS	Type: REG_SZ, Length: 26, Data: MIKE047342KA
30124	2:50:03.5912773 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters	SUCCESS	
30125	2:50:03.5912907 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\System\DNSclient	NAME NOT FOUND	Desired Access: Read
30126	2:50:03.5913030 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters	SUCCESS	Desired Access: Read
30127	2:50:03.5913253 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Domain	SUCCESS	Type: REG_SZ, Length: 2, Data: 
30128	2:50:03.5913396 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters	SUCCESS	
30129	2:50:03.5917290 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\OLEAUT	NAME NOT FOUND	Desired Access: Query Value
30130	2:50:03.5917570 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\OLEAUT\UserEra	NAME NOT FOUND	Desired Access: Query Value, Enumerate Sub Keys
30131	2:50:03.5917701 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\OLEAUT	NAME NOT FOUND	Desired Access: Query Value
30132	2:50:03.5920059 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
30133	2:50:03.5920274 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
30134	2:50:03.5920400 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
30135	2:50:03.5920598 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
30136	2:50:03.5920777 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
30137	2:50:03.5920908 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
30138	2:50:03.5922168 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\urlmon.dll.123.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
30139	2:50:03.5923467 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\urlmon.dll.123.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
30232	2:50:03.6029883 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
30233	2:50:03.6030902 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Local	NAME NOT FOUND	
30234	2:50:03.6032118 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	CreationTime: 6/5/2008 7:56:33 AM, LastAccessTime: 6/5/2008 7:56:33 AM, LastWriteTime: 6/5/2008 7:56:33 AM, ChangeTime: 6/5/2008 7:56:33 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
30235	2:50:03.6033168 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
30236	2:50:03.6034193 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes	SUCCESS	Desired Access: Maximum Allowed
30237	2:50:03.6034484 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Classes	SUCCESS	Query: Name
30238	2:50:03.6034643 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes\PROTOCOLS\Name-Space Handler	NAME NOT FOUND	Desired Access: Maximum Allowed
30239	2:50:03.6034746 PM	ra3game.dat	3416	RegOpenKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	Desired Access: Maximum Allowed
30240	2:50:03.6035029 PM	ra3game.dat	3416	RegQueryKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	Query: Name
30241	2:50:03.6035213 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes\PROTOCOLS\Name-Space Handler	NAME NOT FOUND	Desired Access: Maximum Allowed
30242	2:50:03.6035367 PM	ra3game.dat	3416	RegEnumKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	Index: 0, Name: mk
30243	2:50:03.6035599 PM	ra3game.dat	3416	RegEnumKey	HKCR\PROTOCOLS\Name-Space Handler	NO MORE ENTRIES	Index: 1, Length: 288
30244	2:50:03.6035789 PM	ra3game.dat	3416	RegCloseKey	HKCR\PROTOCOLS\Name-Space Handler	SUCCESS	
30245	2:50:03.6035976 PM	ra3game.dat	3416	RegOpenKey	HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
30246	2:50:03.6036127 PM	ra3game.dat	3416	RegOpenKey	HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
30247	2:50:03.6036249 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings	SUCCESS	Desired Access: Query Value
30248	2:50:03.6036881 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck	NAME NOT FOUND	Length: 144
30249	2:50:03.6037046 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings	SUCCESS	
30250	2:50:03.6037213 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
30251	2:50:03.6037532 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
30252	2:50:03.6037652 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
30253	2:50:03.6037786 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
30254	2:50:03.6037903 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
30255	2:50:03.6038104 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
30256	2:50:03.6038356 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915	NAME NOT FOUND	Desired Access: Query Value
30257	2:50:03.6038512 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915	NAME NOT FOUND	Desired Access: Query Value
30258	2:50:03.6038683 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
30259	2:50:03.6038845 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
30260	2:50:03.6038979 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains	NAME NOT FOUND	Desired Access: Read
30261	2:50:03.6039124 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains	NAME NOT FOUND	Desired Access: Read
30262	2:50:03.6040211 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains	NAME NOT FOUND	Desired Access: Read
30263	2:50:03.6040337 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges	NAME NOT FOUND	Desired Access: Read
30264	2:50:03.6040465 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges	NAME NOT FOUND	Desired Access: Read
30265	2:50:03.6040577 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges	NAME NOT FOUND	Desired Access: Read
30266	2:50:03.6040705 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings	NAME NOT FOUND	Desired Access: Query Value
30267	2:50:03.6040814 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
30268	2:50:03.6040929 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl	NAME NOT FOUND	Desired Access: Query Value
30269	2:50:03.6041035 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
30270	2:50:03.6041225 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	Desired Access: Query Value
30271	2:50:03.6041451 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING	NAME NOT FOUND	Desired Access: Query Value
30272	2:50:03.6041613 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING	SUCCESS	Desired Access: Query Value
30273	2:50:03.6041823 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\ra3game.dat	NAME NOT FOUND	Length: 144
30274	2:50:03.6041949 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING\*	NAME NOT FOUND	Length: 144
30275	2:50:03.6042091 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING	SUCCESS	
30276	2:50:03.6042242 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION	NAME NOT FOUND	Desired Access: Query Value
30277	2:50:03.6042368 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION	SUCCESS	Desired Access: Query Value
30278	2:50:03.6042558 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\ra3game.dat	NAME NOT FOUND	Length: 144
30279	2:50:03.6042683 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\*	NAME NOT FOUND	Length: 144
30280	2:50:03.6042823 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION	SUCCESS	
30281	2:50:03.6042971 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING	NAME NOT FOUND	Desired Access: Query Value
30282	2:50:03.6043102 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING	SUCCESS	Desired Access: Query Value
30283	2:50:03.6043287 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\ra3game.dat	NAME NOT FOUND	Length: 144
30284	2:50:03.6043426 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\*	NAME NOT FOUND	Length: 144
30285	2:50:03.6043563 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING	SUCCESS	
30286	2:50:03.6043711 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING	NAME NOT FOUND	Desired Access: Query Value
30287	2:50:03.6043840 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING	SUCCESS	Desired Access: Query Value
30288	2:50:03.6044024 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\ra3game.dat	NAME NOT FOUND	Length: 144
30289	2:50:03.6044147 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\*	NAME NOT FOUND	Length: 144
30290	2:50:03.6044287 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING	SUCCESS	
30291	2:50:03.6044435 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS	NAME NOT FOUND	Desired Access: Query Value
30292	2:50:03.6044563 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS	SUCCESS	Desired Access: Query Value
30293	2:50:03.6044759 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\ra3game.dat	NAME NOT FOUND	Length: 144
30294	2:50:03.6044882 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\*	NAME NOT FOUND	Length: 144
30295	2:50:03.6045019 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS	SUCCESS	
30296	2:50:03.6045167 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT	NAME NOT FOUND	Desired Access: Query Value
30297	2:50:03.6045298 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT	SUCCESS	Desired Access: Query Value
30298	2:50:03.6045488 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT\ra3game.dat	NAME NOT FOUND	Length: 144
30299	2:50:03.6045611 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT\*	NAME NOT FOUND	Length: 144
30300	2:50:03.6045751 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT	SUCCESS	
30301	2:50:03.6045899 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS	NAME NOT FOUND	Desired Access: Query Value
30302	2:50:03.6046030 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS	SUCCESS	Desired Access: Query Value
30303	2:50:03.6046212 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\ra3game.dat	NAME NOT FOUND	Length: 144
30304	2:50:03.6046340 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS\*	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
30305	2:50:03.6046491 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS	SUCCESS	
30306	2:50:03.6046639 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL	NAME NOT FOUND	Desired Access: Query Value
30307	2:50:03.6046768 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL	SUCCESS	Desired Access: Query Value
30308	2:50:03.6046952 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\ra3game.dat	NAME NOT FOUND	Length: 144
30309	2:50:03.6047092 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\*	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
30310	2:50:03.6047234 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL	SUCCESS	
30311	2:50:03.6047382 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	Desired Access: Query Value
30312	2:50:03.6047606 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\ra3game.dat	NAME NOT FOUND	Length: 144
30313	2:50:03.6047734 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*	NAME NOT FOUND	Length: 144
30314	2:50:03.6047882 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	
30315	2:50:03.6048025 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	Desired Access: Query Value
30316	2:50:03.6048215 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\ra3game.dat	NAME NOT FOUND	Length: 144
30317	2:50:03.6048338 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*	NAME NOT FOUND	Length: 144
30318	2:50:03.6048474 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN	SUCCESS	
30319	2:50:03.6048623 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND	NAME NOT FOUND	Desired Access: Query Value
30320	2:50:03.6048751 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND	SUCCESS	Desired Access: Query Value
30321	2:50:03.6049022 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND\ra3game.dat	NAME NOT FOUND	Length: 144
30322	2:50:03.6049139 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND\*	NAME NOT FOUND	Length: 144
30323	2:50:03.6049276 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND	SUCCESS	
30324	2:50:03.6049427 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL	NAME NOT FOUND	Desired Access: Query Value
30325	2:50:03.6049558 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL	SUCCESS	Desired Access: Query Value
30326	2:50:03.6049748 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\ra3game.dat	NAME NOT FOUND	Length: 144
30327	2:50:03.6049860 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\*	NAME NOT FOUND	Length: 144
30328	2:50:03.6049997 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL	SUCCESS	
30329	2:50:03.6050145 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL	NAME NOT FOUND	Desired Access: Query Value
30330	2:50:03.6050274 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL	SUCCESS	Desired Access: Query Value
30331	2:50:03.6050464 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL\ra3game.dat	NAME NOT FOUND	Length: 144
30332	2:50:03.6050581 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL\*	NAME NOT FOUND	Length: 144
30333	2:50:03.6050721 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL	SUCCESS	
30334	2:50:03.6050869 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD	NAME NOT FOUND	Desired Access: Query Value
30335	2:50:03.6050997 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD	SUCCESS	Desired Access: Query Value
30336	2:50:03.6051182 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\ra3game.dat	NAME NOT FOUND	Length: 144
30337	2:50:03.6051299 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\*	NAME NOT FOUND	Length: 144
30338	2:50:03.6051436 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD	SUCCESS	
30339	2:50:03.6051584 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT	NAME NOT FOUND	Desired Access: Query Value
30340	2:50:03.6051710 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT	SUCCESS	Desired Access: Query Value
30341	2:50:03.6051899 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT\ra3game.dat	NAME NOT FOUND	Length: 144
30342	2:50:03.6052011 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT\*	NAME NOT FOUND	Length: 144
30343	2:50:03.6052148 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT	SUCCESS	
30344	2:50:03.6052293 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN	NAME NOT FOUND	Desired Access: Query Value
30345	2:50:03.6052422 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN	SUCCESS	Desired Access: Query Value
30346	2:50:03.6052609 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\ra3game.dat	NAME NOT FOUND	Length: 144
30347	2:50:03.6052729 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*	NAME NOT FOUND	Length: 144
30348	2:50:03.6052866 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN	SUCCESS	
30349	2:50:03.6053014 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE	NAME NOT FOUND	Desired Access: Query Value
30350	2:50:03.6053145 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE	SUCCESS	Desired Access: Query Value
30351	2:50:03.6053344 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\ra3game.dat	NAME NOT FOUND	Length: 144
30352	2:50:03.6053461 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*	NAME NOT FOUND	Length: 144
30353	2:50:03.6053598 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE	SUCCESS	
30354	2:50:03.6053746 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT	NAME NOT FOUND	Desired Access: Query Value
30355	2:50:03.6053877 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT	SUCCESS	Desired Access: Query Value
30356	2:50:03.6054065 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\ra3game.dat	NAME NOT FOUND	Length: 144
30357	2:50:03.6054187 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\*	NAME NOT FOUND	Length: 144
30358	2:50:03.6054324 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT	SUCCESS	
30359	2:50:03.6054472 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK	NAME NOT FOUND	Desired Access: Query Value
30360	2:50:03.6054601 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK	SUCCESS	Desired Access: Query Value
30361	2:50:03.6054788 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\ra3game.dat	NAME NOT FOUND	Length: 144
30362	2:50:03.6054905 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\*	NAME NOT FOUND	Length: 144
30363	2:50:03.6055073 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK	SUCCESS	
30364	2:50:03.6055257 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GET_URL_DOM_FILEPATH_UNENCODED	NAME NOT FOUND	Desired Access: Query Value
30365	2:50:03.6055394 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_GET_URL_DOM_FILEPATH_UNENCODED	NAME NOT FOUND	Desired Access: Query Value
30366	2:50:03.6055654 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING	NAME NOT FOUND	Desired Access: Query Value
30367	2:50:03.6055811 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_TABBED_BROWSING	NAME NOT FOUND	Desired Access: Query Value
30368	2:50:03.6055950 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX	NAME NOT FOUND	Desired Access: Query Value
30369	2:50:03.6056087 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX	NAME NOT FOUND	Desired Access: Query Value
30370	2:50:03.6056221 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS	NAME NOT FOUND	Desired Access: Query Value
30371	2:50:03.6056353 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NAVIGATION_SOUNDS	NAME NOT FOUND	Desired Access: Query Value
30372	2:50:03.6056484 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION	NAME NOT FOUND	Desired Access: Query Value
30373	2:50:03.6056604 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION	NAME NOT FOUND	Desired Access: Query Value
30374	2:50:03.6056738 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS	NAME NOT FOUND	Desired Access: Query Value
30375	2:50:03.6056864 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS	NAME NOT FOUND	Desired Access: Query Value
30376	2:50:03.6056995 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP	NAME NOT FOUND	Desired Access: Query Value
30377	2:50:03.6057118 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XMLHTTP	NAME NOT FOUND	Desired Access: Query Value
30378	2:50:03.6057244 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL	NAME NOT FOUND	Desired Access: Query Value
30379	2:50:03.6057364 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL	NAME NOT FOUND	Desired Access: Query Value
30380	2:50:03.6057495 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS	NAME NOT FOUND	Desired Access: Query Value
30381	2:50:03.6057610 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS	NAME NOT FOUND	Desired Access: Query Value
30382	2:50:03.6057735 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS	NAME NOT FOUND	Desired Access: Query Value
30383	2:50:03.6058001 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS	NAME NOT FOUND	Desired Access: Query Value
30384	2:50:03.6058132 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOMSTORAGE	NAME NOT FOUND	Desired Access: Query Value
30385	2:50:03.6058255 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOMSTORAGE	NAME NOT FOUND	Desired Access: Query Value
30386	2:50:03.6058381 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST	NAME NOT FOUND	Desired Access: Query Value
30387	2:50:03.6058501 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST	NAME NOT FOUND	Desired Access: Query Value
30388	2:50:03.6058629 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DATAURI	NAME NOT FOUND	Desired Access: Query Value
30389	2:50:03.6058755 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DATAURI	NAME NOT FOUND	Desired Access: Query Value
30390	2:50:03.6058886 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONSERVICES	NAME NOT FOUND	Desired Access: Query Value
30391	2:50:03.6059007 PM	ra3game.dat	3416	RegOpenKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_AJAX_CONNECTIONSERVICES	NAME NOT FOUND	Desired Access: Query Value
30392	2:50:03.6059180 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
30393	2:50:03.6059353 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl	SUCCESS	
30394	2:50:03.6060630 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	Desired Access: Read, Maximum Allowed
30395	2:50:03.6060979 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\DF8480A1-7492-4F45-AB78-1084642581FB	NAME NOT FOUND	Length: 130
30396	2:50:03.6061124 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\00000000-0000-0000-0000-000000000000	NAME NOT FOUND	Length: 130
30397	2:50:03.6061241 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	
30398	2:50:03.6062387 PM	ra3game.dat	3416	Thread Create		SUCCESS	Thread ID: 1960
30399	2:50:03.6063007 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	Desired Access: Read, Maximum Allowed
30400	2:50:03.6063275 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\DF8480A1-7492-4F45-AB78-1084642581FB	NAME NOT FOUND	Length: 130
30401	2:50:03.6063390 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\WMI\Security\00000000-0000-0000-0000-000000000000	NAME NOT FOUND	Length: 130
30402	2:50:03.6063507 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\WMI\Security	SUCCESS	
30405	2:50:03.6064622 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
30406	2:50:03.6064848 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
30407	2:50:03.6064982 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
30408	2:50:03.6065194 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
30409	2:50:03.6065401 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
30410	2:50:03.6065549 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
30411	2:50:03.6066968 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\WININET.dll.123.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
30413	2:50:03.6068664 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\WININET.dll.123.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
30521	2:50:03.6173164 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
30522	2:50:03.6174144 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Local	NAME NOT FOUND	
30523	2:50:03.6175457 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	CreationTime: 6/5/2008 7:56:33 AM, LastAccessTime: 6/5/2008 7:56:33 AM, LastWriteTime: 6/5/2008 7:56:33 AM, ChangeTime: 6/5/2008 7:56:33 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
30524	2:50:03.6176636 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
30525	2:50:03.6177625 PM	ra3game.dat	3416	RegCreateKey	HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings	SUCCESS	Desired Access: Read/Write
30855	2:50:04.9202308 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\IPHLPAPI.dll	NAME NOT FOUND	
30856	2:50:04.9204859 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	CreationTime: 8/16/2005 5:18:20 AM, LastAccessTime: 6/5/2008 7:53:00 AM, LastWriteTime: 4/14/2008 5:41:56 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 98,304, EndOfFile: 94,720, FileAttributes: A
30857	2:50:04.9206247 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
30864	2:50:04.9209024 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	
30868	2:50:04.9211388 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\iphlpapi.dll	SUCCESS	Image Base: 0x76d60000, Image Size: 0x19000
30869	2:50:04.9212511 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IPHLPAPI.dll	NAME NOT FOUND	Desired Access: Read
30874	2:50:04.9216743 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage	SUCCESS	Desired Access: Read
30875	2:50:04.9217226 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters	SUCCESS	Desired Access: Read
30876	2:50:04.9217545 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces	SUCCESS	Desired Access: Read
30877	2:50:04.9217869 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters	SUCCESS	Desired Access: Read
30878	2:50:04.9423096 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30879	2:50:04.9423518 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30880	2:50:04.9423691 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30881	2:50:04.9423817 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30882	2:50:04.9423931 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30883	2:50:04.9424183 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30884	2:50:04.9424465 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30885	2:50:04.9424694 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30886	2:50:04.9424809 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30887	2:50:04.9424923 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30888	2:50:04.9425032 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30889	2:50:04.9425175 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30890	2:50:04.9425412 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30891	2:50:04.9425633 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30892	2:50:04.9425747 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30893	2:50:04.9425862 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30894	2:50:04.9425971 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30895	2:50:04.9426116 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30896	2:50:04.9426496 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30897	2:50:04.9426722 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30898	2:50:04.9426834 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30899	2:50:04.9426951 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30900	2:50:04.9427060 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30901	2:50:04.9427203 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30902	2:50:04.9428114 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30903	2:50:04.9428351 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30904	2:50:04.9428493 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30905	2:50:04.9428616 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30906	2:50:04.9428728 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30907	2:50:04.9428871 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30933	2:50:05.1855282 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30934	2:50:05.1855947 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30935	2:50:05.1856132 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30936	2:50:05.1856263 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30937	2:50:05.1856377 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30938	2:50:05.1856593 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30939	2:50:05.1857224 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30940	2:50:05.1857464 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30941	2:50:05.1857579 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30942	2:50:05.1857696 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30943	2:50:05.1857805 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30944	2:50:05.1857947 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30945	2:50:05.1858224 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30946	2:50:05.1858456 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30947	2:50:05.1858568 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30948	2:50:05.1858688 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30949	2:50:05.1858797 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30950	2:50:05.1858939 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30951	2:50:05.1859291 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	Desired Access: Read
30952	2:50:05.1859646 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs	SUCCESS	Type: REG_SZ, Length: 2, Data: 
30953	2:50:05.1859766 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs	SUCCESS	Type: REG_SZ, Length: 2, Data: 
30954	2:50:05.1859889 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs	SUCCESS	Type: REG_SZ, Length: 2, Data: 
30955	2:50:05.1859992 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs	SUCCESS	Type: REG_SZ, Length: 2, Data: 
30956	2:50:05.1860168 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
30957	2:50:05.1860411 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
30958	2:50:05.1860646 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30959	2:50:05.1860761 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
30960	2:50:05.1860881 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30961	2:50:05.1860990 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
30962	2:50:05.1861132 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
30963	2:50:05.1861537 PM	ra3game.dat	3416	RegOpenKey	HKLM\system\currentcontrolset\control	SUCCESS	Desired Access: Read
30964	2:50:05.1861917 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\SystemStartOptions	SUCCESS	Type: REG_SZ, Length: 82, Data: FASTDETECT  NOEXECUTE=OPTOUT  USEPMTIMER
30965	2:50:05.1862035 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\SystemStartOptions	SUCCESS	Type: REG_SZ, Length: 82, Data: FASTDETECT  NOEXECUTE=OPTOUT  USEPMTIMER
30966	2:50:05.1862188 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control	SUCCESS	
30967	2:50:05.1863188 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Rpc\PagedBuffers	NAME NOT FOUND	Desired Access: Read
30968	2:50:05.1863334 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Rpc	SUCCESS	Desired Access: Read
30969	2:50:05.1863549 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize	NAME NOT FOUND	Length: 144
30970	2:50:05.1863686 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Rpc	SUCCESS	
30971	2:50:05.1863814 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ra3game.dat\RpcThreadPoolThrottle	NAME NOT FOUND	Desired Access: Read
30972	2:50:05.1864244 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Policies\Microsoft\Windows NT\Rpc	NAME NOT FOUND	Desired Access: Read
30973	2:50:05.1864842 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\ComputerName	SUCCESS	Desired Access: Read
30974	2:50:05.1865127 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName	SUCCESS	Desired Access: Read
30975	2:50:05.1865359 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName	SUCCESS	Type: REG_SZ, Length: 26, Data: MIKE047342KA
30976	2:50:05.1865513 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName	SUCCESS	
30977	2:50:05.1865669 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\ComputerName	SUCCESS	
31138	2:50:05.1974904 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\psapi.dll	NAME NOT FOUND	
31139	2:50:05.1976493 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\psapi.dll	SUCCESS	CreationTime: 8/16/2005 5:18:33 AM, LastAccessTime: 6/5/2008 7:52:35 AM, LastWriteTime: 4/14/2008 5:42:04 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 24,576, EndOfFile: 23,040, FileAttributes: A
31140	2:50:05.1977882 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31147	2:50:05.1980631 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\psapi.dll	SUCCESS	
31151	2:50:05.1982871 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\psapi.dll	SUCCESS	Image Base: 0x76bf0000, Image Size: 0xb000
31152	2:50:05.1983340 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psapi.dll	NAME NOT FOUND	Desired Access: Read
31153	2:50:05.1985642 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	CreationTime: 7/25/2008 3:37:28 PM, LastAccessTime: 8/22/2008 2:42:14 PM, LastWriteTime: 7/25/2008 3:37:28 PM, ChangeTime: 8/22/2008 2:50:03 PM, AllocationSize: 3,489,792, EndOfFile: 3,486,992, FileAttributes: A
31154	2:50:05.1986768 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	CreationTime: 7/25/2008 3:37:28 PM, LastAccessTime: 8/22/2008 2:42:14 PM, LastWriteTime: 7/25/2008 3:37:28 PM, ChangeTime: 8/22/2008 2:50:03 PM, AllocationSize: 3,489,792, EndOfFile: 3,486,992, FileAttributes: A
31155	2:50:05.1987578 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31157	2:50:05.1988229 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	AllocationSize: 3,489,792, EndOfFile: 3,486,992, NumberOfLinks: 1, DeletePending: False, Directory: False
31161	2:50:05.1988978 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
31164	2:50:05.1990185 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	CreationTime: 7/25/2008 3:37:28 PM, LastAccessTime: 8/22/2008 2:42:14 PM, LastWriteTime: 7/25/2008 3:37:28 PM, ChangeTime: 8/22/2008 2:50:03 PM, AllocationSize: 3,489,792, EndOfFile: 3,486,992, FileAttributes: A
31165	2:50:05.1990990 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31167	2:50:05.1991635 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	AllocationSize: 3,489,792, EndOfFile: 3,486,992, NumberOfLinks: 1, DeletePending: False, Directory: False
31171	2:50:05.1992367 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
31173	2:50:05.1996669 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	CreationTime: 7/25/2008 3:37:28 PM, LastAccessTime: 8/22/2008 2:42:14 PM, LastWriteTime: 7/25/2008 3:37:28 PM, ChangeTime: 8/22/2008 2:50:03 PM, AllocationSize: 3,489,792, EndOfFile: 3,486,992, FileAttributes: A
31174	2:50:05.1997664 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31176	2:50:05.1998298 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	AllocationSize: 3,489,792, EndOfFile: 3,486,992, NumberOfLinks: 1, DeletePending: False, Directory: False
31180	2:50:05.1999024 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
31182	2:50:05.2000111 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	CreationTime: 7/25/2008 3:37:28 PM, LastAccessTime: 8/22/2008 2:42:14 PM, LastWriteTime: 7/25/2008 3:37:28 PM, ChangeTime: 8/22/2008 2:50:03 PM, AllocationSize: 3,489,792, EndOfFile: 3,486,992, FileAttributes: A
31183	2:50:05.2000901 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31185	2:50:05.2001538 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	AllocationSize: 3,489,792, EndOfFile: 3,486,992, NumberOfLinks: 1, DeletePending: False, Directory: False
31189	2:50:05.2002265 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
31191	2:50:05.2011450 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
31192	2:50:05.2012009 PM	ra3game.dat	3416	ReadFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Offset: 0, Length: 8,192
31194	2:50:05.2012730 PM	ra3game.dat	3416	ReadFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Offset: 264, Length: 8,192
31196	2:50:05.2013381 PM	ra3game.dat	3416	ReadFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	Offset: 0, Length: 816
31198	2:50:05.2014526 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Red Alert 3 Beta\RA3Beta.exe	SUCCESS	
31199	2:50:05.2014803 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Classes	SUCCESS	Query: Name
31200	2:50:05.2014970 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes\CureROM.Profile\Shell\Open\Command	NAME NOT FOUND	Desired Access: Maximum Allowed
31201	2:50:05.2015096 PM	ra3game.dat	3416	RegOpenKey	HKCR\CureROM.Profile\Shell\Open\Command	NAME NOT FOUND	Desired Access: Maximum Allowed
31202	2:50:05.2016403 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31203	2:50:05.2016775 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31204	2:50:05.2016934 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31205	2:50:05.2017063 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31206	2:50:05.2017180 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31207	2:50:05.2017362 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31208	2:50:05.2017655 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31209	2:50:05.2017887 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31210	2:50:05.2018001 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31211	2:50:05.2018121 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31212	2:50:05.2018230 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31213	2:50:05.2018373 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31214	2:50:05.2018624 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31215	2:50:05.2018912 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31216	2:50:05.2019032 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31217	2:50:05.2019158 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31218	2:50:05.2019270 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31219	2:50:05.2019420 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31229	2:50:05.2032939 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31230	2:50:05.2033216 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31231	2:50:05.2033350 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31232	2:50:05.2033475 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31233	2:50:05.2033587 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31234	2:50:05.2033738 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31235	2:50:05.2034012 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31236	2:50:05.2034246 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31237	2:50:05.2034361 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31238	2:50:05.2034481 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31239	2:50:05.2034590 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31240	2:50:05.2034733 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31241	2:50:05.2035735 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Classes	SUCCESS	Query: Name
31242	2:50:05.2035886 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	NAME NOT FOUND	Desired Access: Read
31243	2:50:05.2036018 PM	ra3game.dat	3416	RegOpenKey	HKCR\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	SUCCESS	Desired Access: Read
31244	2:50:05.2036275 PM	ra3game.dat	3416	RegQueryKey	HKCR\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	SUCCESS	Query: Name
31245	2:50:05.2036481 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	NAME NOT FOUND	Desired Access: Maximum Allowed
31246	2:50:05.2036649 PM	ra3game.dat	3416	RegQueryValue	HKCR\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32\(Default)	SUCCESS	Type: REG_SZ, Length: 94, Data: C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll
31247	2:50:05.2036766 PM	ra3game.dat	3416	RegQueryKey	HKCR\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	SUCCESS	Query: Name
31248	2:50:05.2036937 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Classes\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	NAME NOT FOUND	Desired Access: Maximum Allowed
31249	2:50:05.2037096 PM	ra3game.dat	3416	RegQueryValue	HKCR\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32\(Default)	SUCCESS	Type: REG_SZ, Length: 94, Data: C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll
31250	2:50:05.2039065 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:42:56 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 110,592, EndOfFile: 107,888, FileAttributes: A
31251	2:50:05.2040764 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31253	2:50:05.2042225 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 107,888, NumberOfLinks: 1, DeletePending: False, Directory: False
31257	2:50:05.2043759 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	
31260	2:50:05.2045773 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:42:56 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 110,592, EndOfFile: 107,888, FileAttributes: A
31261	2:50:05.2047410 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31263	2:50:05.2048860 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 107,888, NumberOfLinks: 1, DeletePending: False, Directory: False
31267	2:50:05.2050366 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	
31269	2:50:05.2052525 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:42:56 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 110,592, EndOfFile: 107,888, FileAttributes: A
31270	2:50:05.2054154 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31272	2:50:05.2055615 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 107,888, NumberOfLinks: 1, DeletePending: False, Directory: False
31276	2:50:05.2057126 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	
31278	2:50:05.2059149 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:42:56 PM, ChangeTime: 8/22/2008 2:42:56 PM, AllocationSize: 110,592, EndOfFile: 107,888, FileAttributes: A
31279	2:50:05.2060775 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31281	2:50:05.2062216 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\CmdLineExt.dll	SUCCESS	AllocationSize: 110,592, EndOfFile: 107,888, NumberOfLinks: 1, DeletePending: False, Directory: False
31285	2:50:05.2063717 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\CmdLineExt.dll	SUCCESS	
31287	2:50:05.2064753 PM	ra3game.dat	3416	RegCloseKey	HKCR\CLSID\{F0407C3D-349C-42b9-B83E-821E31623DF9}\InprocServer32	SUCCESS	
31288	2:50:05.2065111 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31289	2:50:05.2065379 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31290	2:50:05.2065510 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31291	2:50:05.2065630 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31292	2:50:05.2065742 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31293	2:50:05.2065887 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31294	2:50:05.2066879 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31295	2:50:05.2067122 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31296	2:50:05.2067239 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31297	2:50:05.2067360 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31298	2:50:05.2067471 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31299	2:50:05.2067614 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31300	2:50:05.2069829 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31301	2:50:05.2070067 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31302	2:50:05.2070184 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31303	2:50:05.2070304 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31304	2:50:05.2070413 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31305	2:50:05.2070558 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31306	2:50:05.2070810 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31307	2:50:05.2071042 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31308	2:50:05.2071153 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31309	2:50:05.2071273 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31310	2:50:05.2071385 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31311	2:50:05.2071528 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31312	2:50:05.2071771 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31313	2:50:05.2071997 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31314	2:50:05.2072109 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31315	2:50:05.2072232 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31316	2:50:05.2072341 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31317	2:50:05.2072483 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31318	2:50:05.2072860 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31319	2:50:05.2073084 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31320	2:50:05.2073195 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31321	2:50:05.2073307 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31322	2:50:05.2073416 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31323	2:50:05.2073559 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31324	2:50:05.2081479 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31325	2:50:05.2081711 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31326	2:50:05.2081825 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31327	2:50:05.2081945 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31328	2:50:05.2082057 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31329	2:50:05.2082197 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31330	2:50:05.2084901 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: BA CB 4B 7E ED 29 7C C7 B5 F4 E0 1F 39 7E 64 76
31331	2:50:05.2086477 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: FE 6E 04 8A 24 C7 15 66 3D 2A 51 66 5D CC 8A 3E
31332	2:50:05.2087530 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: 4A 05 EF CB C7 D9 4A E7 C0 E2 1B D9 E4 9C 08 2B
31333	2:50:05.2088577 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: D8 F5 87 DB 99 F5 08 C4 F5 90 EC AF 3B CF CD 4E
31334	2:50:05.2089678 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: 42 03 9A 8E C1 15 76 E4 DE 0F 11 E7 40 AE F1 D8
31335	2:50:05.2090726 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: CF 64 F8 0F 94 45 02 D5 AC 7E 77 9F 9F 80 FA 20
31336	2:50:05.2091768 PM	ra3game.dat	3416	RegSetValue	HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed	SUCCESS	Type: REG_BINARY, Length: 80, Data: E8 6E B0 6D D4 2C 9F 47 94 D0 01 C6 5E 15 6D C9
31345	2:50:05.2175323 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion	SUCCESS	Desired Access: Query Value
31346	2:50:05.2175630 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner	NAME NOT FOUND	Length: 144
31347	2:50:05.2175812 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion	SUCCESS	
31348	2:50:05.2175940 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Query Value
31349	2:50:05.2176175 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner	SUCCESS	Type: REG_SZ, Length: 12, Data: Owner
31350	2:50:05.2176304 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner	SUCCESS	Type: REG_SZ, Length: 12, Data: Owner
31351	2:50:05.2176482 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization	SUCCESS	Type: REG_SZ, Length: 2, Data: 
31352	2:50:05.2176589 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization	SUCCESS	Type: REG_SZ, Length: 2, Data: 
31353	2:50:05.2176745 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31354	2:50:05.2212501 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\ComputerName	SUCCESS	Desired Access: Read
31355	2:50:05.2212817 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName	SUCCESS	Desired Access: Read
31356	2:50:05.2213051 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName	SUCCESS	Type: REG_SZ, Length: 26, Data: MIKE047342KA
31357	2:50:05.2213213 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName	SUCCESS	
31358	2:50:05.2213370 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\ComputerName	SUCCESS	
31367	2:50:05.2300618 PM	ra3game.dat	3416	Thread Create		SUCCESS	Thread ID: 3264
31391	2:50:05.2307762 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31394	2:50:05.2308326 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31395	2:50:05.2308466 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31397	2:50:05.2308795 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31399	2:50:05.2308977 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31402	2:50:05.2309443 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31404	2:50:05.2309902 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31406	2:50:05.2310220 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31408	2:50:05.2310555 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31410	2:50:05.2310706 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31411	2:50:05.2310835 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31414	2:50:05.2311050 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
31430	2:50:05.2313846 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\Riched20.dll	NAME NOT FOUND	
31431	2:50:05.2315455 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\riched20.dll	SUCCESS	CreationTime: 8/16/2005 5:18:34 AM, LastAccessTime: 6/5/2008 7:52:31 AM, LastWriteTime: 4/14/2008 5:42:06 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 434,176, EndOfFile: 433,664, FileAttributes: A
31432	2:50:05.2316833 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31439	2:50:05.2320554 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\riched20.dll	SUCCESS	
31442	2:50:05.2322819 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\riched20.dll	SUCCESS	Image Base: 0x74e30000, Image Size: 0x6d000
31444	2:50:05.2325004 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Riched20.dll	NAME NOT FOUND	Desired Access: Read
31445	2:50:05.2340710 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: None, AllocationSize: 0, OpenResult: Overwritten
31446	2:50:05.2342255 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	Desired Access: Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31447	2:50:05.2343601 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp	SUCCESS	
31451	2:50:05.2348448 PM	ra3game.dat	3416	WriteFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	Offset: 0, Length: 65,536
31454	2:50:05.2351345 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	
31456	2:50:05.2353918 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:50:05 PM, ChangeTime: 8/22/2008 2:50:05 PM, AllocationSize: 65,536, EndOfFile: 65,536, FileAttributes: A
31457	2:50:05.2355592 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31459	2:50:05.2357072 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	AllocationSize: 65,536, EndOfFile: 65,536, NumberOfLinks: 1, DeletePending: False, Directory: False
31463	2:50:05.2360246 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	
31465	2:50:05.2362190 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:50:05 PM, ChangeTime: 8/22/2008 2:50:05 PM, AllocationSize: 65,536, EndOfFile: 65,536, FileAttributes: A
31466	2:50:05.2363836 PM	ra3game.dat	3416	QueryOpen	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	CreationTime: 8/22/2008 2:42:56 PM, LastAccessTime: 8/22/2008 2:42:56 PM, LastWriteTime: 8/22/2008 2:50:05 PM, ChangeTime: 8/22/2008 2:50:05 PM, AllocationSize: 65,536, EndOfFile: 65,536, FileAttributes: A
31467	2:50:05.2365462 PM	ra3game.dat	3416	CreateFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31509	2:50:05.2548918 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	AllocationSize: 65,536, EndOfFile: 65,536, NumberOfLinks: 1, DeletePending: False, Directory: False
31517	2:50:05.2552131 PM	ra3game.dat	3416	CloseFile	C:\Documents and Settings\Owner\Local Settings\Temp\drm_dialogs.dll	SUCCESS	
31519	2:50:05.2554022 PM	ra3game.dat	3416	Load Image	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	Image Base: 0x10000000, Image Size: 0x11000
31520	2:50:05.2554176 PM	ra3game.dat	3416	ReadFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	Offset: 24,576, Length: 8,192, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
31521	2:50:05.2556154 PM	ra3game.dat	3416	ReadFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	Offset: 36,864, Length: 16,384, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
31522	2:50:05.2559704 PM	ra3game.dat	3416	ReadFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	Offset: 32,768, Length: 4,096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
31523	2:50:05.2562087 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drm_dialogs.dll	NAME NOT FOUND	Desired Access: Read
31524	2:50:05.2562381 PM	ra3game.dat	3416	ReadFile	C:\DOCUME~1\Owner\LOCALS~1\Temp\drm_dialogs.dll	SUCCESS	Offset: 4,096, Length: 20,480, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O
31525	2:50:05.2568161 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
31526	2:50:05.2569546 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31528	2:50:05.2570728 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	AllocationSize: 221,184, EndOfFile: 218,624, NumberOfLinks: 1, DeletePending: False, Directory: False
31532	2:50:05.2572002 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
31535	2:50:05.2574661 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
31536	2:50:05.2576148 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31543	2:50:05.2578701 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	
31546	2:50:05.2580520 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	Image Base: 0x5ad70000, Image Size: 0x38000
31547	2:50:05.2581651 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uxtheme.dll	NAME NOT FOUND	Desired Access: Read
31548	2:50:05.2582322 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Read/Write
31549	2:50:05.2582615 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager	SUCCESS	Desired Access: Query Value
31550	2:50:05.2583028 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager\Compositing	NAME NOT FOUND	Length: 144
31551	2:50:05.2583291 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows\CurrentVersion\ThemeManager	SUCCESS	
31552	2:50:05.2583464 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
31553	2:50:05.2583721 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
31554	2:50:05.2583911 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Query Value
31555	2:50:05.2584118 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\LameButtonText	NAME NOT FOUND	Length: 144
31556	2:50:05.2584353 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
31557	2:50:05.2584501 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
31563	2:50:05.2588420 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
31568	2:50:05.2593563 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
31569	2:50:05.2595678 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\uxtheme.dll	SUCCESS	CreationTime: 8/16/2005 5:18:42 AM, LastAccessTime: 6/5/2008 7:52:18 AM, LastWriteTime: 4/14/2008 5:42:10 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 221,184, EndOfFile: 218,624, FileAttributes: A
31570	2:50:05.2599924 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	CreationTime: 8/13/2008 10:34:00 AM, LastAccessTime: 8/13/2008 10:34:00 AM, LastWriteTime: 5/2/2008 2:42:50 AM, ChangeTime: 8/13/2008 10:34:01 AM, AllocationSize: 49,152, EndOfFile: 45,584, FileAttributes: A
31571	2:50:05.2601282 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31573	2:50:05.2602576 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	AllocationSize: 49,152, EndOfFile: 45,584, NumberOfLinks: 1, DeletePending: False, Directory: False
31577	2:50:05.2603852 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
31580	2:50:05.2605568 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	CreationTime: 8/13/2008 10:34:00 AM, LastAccessTime: 8/13/2008 10:34:00 AM, LastWriteTime: 5/2/2008 2:42:50 AM, ChangeTime: 8/13/2008 10:34:01 AM, AllocationSize: 49,152, EndOfFile: 45,584, FileAttributes: A
31581	2:50:05.2606889 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	CreationTime: 8/13/2008 10:34:00 AM, LastAccessTime: 8/13/2008 10:34:00 AM, LastWriteTime: 5/2/2008 2:42:50 AM, ChangeTime: 8/13/2008 10:34:01 AM, AllocationSize: 49,152, EndOfFile: 45,584, FileAttributes: A
31582	2:50:05.2608202 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31589	2:50:05.2610761 PM	ra3game.dat	3416	CloseFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	
31592	2:50:05.2612686 PM	ra3game.dat	3416	Load Image	C:\Program Files\Logitech\SetPoint\lgscroll.dll	SUCCESS	Image Base: 0x10100000, Image Size: 0xe000
31593	2:50:05.2612990 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Maximum Allowed
31594	2:50:05.2613460 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Policies\Microsoft\Control Panel\Desktop	NAME NOT FOUND	Desired Access: Read
31595	2:50:05.2613664 PM	ra3game.dat	3416	RegOpenKey	HKCU\Control Panel\Desktop	SUCCESS	Desired Access: Read
31596	2:50:05.2613949 PM	ra3game.dat	3416	RegQueryValue	HKCU\Control Panel\Desktop\MultiUILanguageId	NAME NOT FOUND	Length: 256
31597	2:50:05.2614136 PM	ra3game.dat	3416	RegCloseKey	HKCU\Control Panel\Desktop	SUCCESS	
31598	2:50:05.2614270 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
31599	2:50:05.2615468 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll.2.Manifest	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
31600	2:50:05.2616630 PM	ra3game.dat	3416	CreateFile	C:\Program Files\Logitech\SetPoint\lgscroll.dll.2.Config	NAME NOT FOUND	Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: n/a
31663	2:50:05.2682630 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots	NAME NOT FOUND	Desired Access: Enumerate Sub Keys
31664	2:50:05.2683628 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\ra3game.dat.Local	NAME NOT FOUND	
31665	2:50:05.2684835 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	CreationTime: 3/4/2008 4:56:27 AM, LastAccessTime: 3/4/2008 4:56:27 AM, LastWriteTime: 3/4/2008 4:56:27 AM, ChangeTime: 3/4/2008 4:56:27 AM, AllocationSize: 0, EndOfFile: 0, FileAttributes: D
31666	2:50:05.2685874 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31667	2:50:05.2686824 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lgscroll.dll	NAME NOT FOUND	Desired Access: Read
31668	2:50:05.2688640 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\NTMARTA.DLL	NAME NOT FOUND	
31669	2:50:05.2690062 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	CreationTime: 8/16/2005 5:18:30 AM, LastAccessTime: 6/5/2008 7:52:40 AM, LastWriteTime: 4/14/2008 5:42:04 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 118,784, EndOfFile: 118,784, FileAttributes: A
31670	2:50:05.2691506 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31677	2:50:05.2694098 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	
31681	2:50:05.2696071 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\ntmarta.dll	SUCCESS	Image Base: 0x77690000, Image Size: 0x21000
31682	2:50:05.2697646 PM	ra3game.dat	3416	QueryOpen	C:\Program Files\Red Alert 3 Beta\RetailExe\1.0\SAMLIB.dll	NAME NOT FOUND	
31683	2:50:05.2699043 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\samlib.dll	SUCCESS	CreationTime: 8/16/2005 5:18:35 AM, LastAccessTime: 6/5/2008 7:52:01 AM, LastWriteTime: 4/14/2008 5:42:06 AM, ChangeTime: 6/5/2008 7:52:01 AM, AllocationSize: 65,536, EndOfFile: 64,000, FileAttributes: A
31684	2:50:05.2700373 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31691	2:50:05.2702910 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\samlib.dll	SUCCESS	
31695	2:50:05.2704871 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\samlib.dll	SUCCESS	Image Base: 0x71bf0000, Image Size: 0x13000
31698	2:50:05.2706634 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\wldap32.dll	SUCCESS	Image Base: 0x76f60000, Image Size: 0x2c000
31699	2:50:05.2707866 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAMLIB.dll	NAME NOT FOUND	Desired Access: Read
31700	2:50:05.2708162 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WLDAP32.dll	NAME NOT FOUND	Desired Access: Read
31701	2:50:05.2708494 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Services\LDAP	SUCCESS	Desired Access: Read
31702	2:50:05.2708994 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Services\ldap\LdapClientIntegrity	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
31703	2:50:05.2709229 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\ldap	SUCCESS	
31704	2:50:05.2709357 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NTMARTA.DLL	NAME NOT FOUND	Desired Access: Read
31706	2:50:05.2711034 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\IMM	SUCCESS	Desired Access: Maximum Allowed
31708	2:50:05.2711377 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM\Ime File	SUCCESS	Type: REG_SZ, Length: 26, Data: msctfime.ime
31709	2:50:05.2711676 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM	SUCCESS	
31715	2:50:05.2714623 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31718	2:50:05.2716090 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31720	2:50:05.2717389 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
31725	2:50:05.2718870 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
31731	2:50:05.2721261 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31735	2:50:05.2722809 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31739	2:50:05.2724111 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
31743	2:50:05.2725407 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
31745	2:50:05.2727469 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31746	2:50:05.2728810 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31748	2:50:05.2731047 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
31752	2:50:05.2732324 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
31754	2:50:05.2733958 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31755	2:50:05.2735282 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31757	2:50:05.2736459 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
31761	2:50:05.2737732 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
31765	2:50:05.2740356 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\apphelp.dll	SUCCESS	Image Base: 0x77b40000, Image Size: 0x22000
31766	2:50:05.2740783 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apphelp.dll	NAME NOT FOUND	Desired Access: Read
31767	2:50:05.2741037 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility	SUCCESS	Desired Access: Query Value
31768	2:50:05.2741387 PM	ra3game.dat	3416	RegQueryValue	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility\DisableAppCompat	NAME NOT FOUND	Length: 20
31769	2:50:05.2741568 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility	SUCCESS	
31770	2:50:05.2743099 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
31771	2:50:05.2744161 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
31773	2:50:05.2745205 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
31777	2:50:05.2746468 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
31778	2:50:05.2747759 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
31779	2:50:05.2748094 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
31780	2:50:05.2748223 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
31781	2:50:05.2748435 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
31782	2:50:05.2748670 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
31784	2:50:05.2750541 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31785	2:50:05.2751659 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
31787	2:50:05.2752835 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32	SUCCESS	
31794	2:50:05.2754503 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31795	2:50:05.2754807 PM	ra3game.dat	3416	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31796	2:50:05.2755059 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS	SUCCESS	Filter: WINDOWS, 1: WINDOWS
31798	2:50:05.2755542 PM	ra3game.dat	3416	CloseFile	C:\	SUCCESS	
31801	2:50:05.2756889 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31802	2:50:05.2757405 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	Filter: system32, 1: system32
31803	2:50:05.2757945 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS	SUCCESS	
31805	2:50:05.2759188 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31806	2:50:05.2759962 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
31807	2:50:05.2760828 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32	SUCCESS	
31809	2:50:05.2761185 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
31810	2:50:05.2761481 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
31811	2:50:05.2761671 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
31812	2:50:05.2761906 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
31814	2:50:05.2762224 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
31815	2:50:05.2762389 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
31816	2:50:05.2762504 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\msctfime.ime	NAME NOT FOUND	Desired Access: Read, WOW64_64Key
31823	2:50:05.2765133 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
31827	2:50:05.2767281 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31828	2:50:05.2769832 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31830	2:50:05.2771036 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	AllocationSize: 180,224, EndOfFile: 177,152, NumberOfLinks: 1, DeletePending: False, Directory: False
31834	2:50:05.2772315 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
31836	2:50:05.2773935 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31837	2:50:05.2775268 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
31844	2:50:05.2777833 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctfime.ime	SUCCESS	
31847	2:50:05.2779752 PM	ra3game.dat	3416	Load Image	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Image Base: 0x755c0000, Image Size: 0x2e000
31848	2:50:05.2781515 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msctfime.ime	NAME NOT FOUND	Desired Access: Read
31849	2:50:05.2783917 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\ole32.dll	SUCCESS	CreationTime: 8/16/2005 5:18:32 AM, LastAccessTime: 6/5/2008 7:52:37 AM, LastWriteTime: 4/14/2008 5:42:04 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 1,290,240, EndOfFile: 1,287,168, FileAttributes: A
31850	2:50:05.2786141 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\ntdll.dll	SUCCESS	CreationTime: 8/16/2005 5:18:29 AM, LastAccessTime: 4/14/2008 5:41:26 AM, LastWriteTime: 4/14/2008 5:41:26 AM, ChangeTime: 6/5/2008 7:52:03 AM, AllocationSize: 708,608, EndOfFile: 706,048, FileAttributes: A
31851	2:50:05.2786901 PM	ra3game.dat	3416	RegOpenKey	HKCU\SOFTWARE\Microsoft\CTF	SUCCESS	Desired Access: Maximum Allowed
31852	2:50:05.2787205 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\CTF\Disable Thread Input Manager	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
31853	2:50:05.2787406 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\CTF	SUCCESS	
31854	2:50:05.2789077 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened
31855	2:50:05.2790130 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
31857	2:50:05.2791195 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
31861	2:50:05.2792468 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	AllocationSize: 1,204,224, EndOfFile: 1,202,774, NumberOfLinks: 1, DeletePending: False, Directory: False
31862	2:50:05.2794080 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\AppPatch\systest.sdb	NAME NOT FOUND	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a
31863	2:50:05.2794318 PM	ra3game.dat	3416	RegOpenKey	HKLM\System\WPA\TabletPC	NAME NOT FOUND	Desired Access: Query Value, WOW64_64Key
31864	2:50:05.2794441 PM	ra3game.dat	3416	RegOpenKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	Desired Access: Query Value, WOW64_64Key
31865	2:50:05.2794648 PM	ra3game.dat	3416	RegQueryValue	HKLM\SYSTEM\WPA\MediaCenter\Installed	SUCCESS	Type: REG_DWORD, Length: 4, Data: 1
31866	2:50:05.2794801 PM	ra3game.dat	3416	RegCloseKey	HKLM\SYSTEM\WPA\MediaCenter	SUCCESS	
31867	2:50:05.2796002 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31868	2:50:05.2796793 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
31869	2:50:05.2797707 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32	SUCCESS	
31871	2:50:05.2799788 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31872	2:50:05.2800092 PM	ra3game.dat	3416	CreateFile	C:\	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31874	2:50:05.2800361 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS	SUCCESS	Filter: WINDOWS, 1: WINDOWS
31875	2:50:05.2800662 PM	ra3game.dat	3416	CloseFile	C:\	SUCCESS	
31878	2:50:05.2801769 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31879	2:50:05.2802576 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32	SUCCESS	Filter: system32, 1: system32
31885	2:50:05.2803330 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS	SUCCESS	
31887	2:50:05.2804948 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32	SUCCESS	Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
31890	2:50:05.2805844 PM	ra3game.dat	3416	QueryDirectory	C:\WINDOWS\system32\msctfime.ime	SUCCESS	Filter: msctfime.ime, 1: msctfime.ime
31891	2:50:05.2806685 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32	SUCCESS	
31893	2:50:05.2806995 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
31894	2:50:05.2807266 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
31895	2:50:05.2808431 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
31896	2:50:05.2808694 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	Desired Access: Read, WOW64_64Key
31897	2:50:05.2809362 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\WINDOWS\system32\msctfime.ime	NAME NOT FOUND	Length: 1,024
31898	2:50:05.2809521 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers	SUCCESS	
31899	2:50:05.2809635 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\msctfime.ime	NAME NOT FOUND	Desired Access: Read, WOW64_64Key
31900	2:50:05.2812144 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\AppPatch\sysmain.sdb	SUCCESS	
31902	2:50:05.2813879 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctfime.ime	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:56:13 AM, LastWriteTime: 4/14/2008 5:40:08 AM, ChangeTime: 6/5/2008 8:00:07 AM, AllocationSize: 180,224, EndOfFile: 177,152, FileAttributes: A
31903	2:50:05.2818391 PM	ra3game.dat	3416	RegOpenKey	HKCU	SUCCESS	Desired Access: Read
31904	2:50:05.2818642 PM	ra3game.dat	3416	RegCloseKey	HKCU	SUCCESS	
31905	2:50:05.2818771 PM	ra3game.dat	3416	RegOpenKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	Desired Access: Read
31906	2:50:05.2819028 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset	NAME NOT FOUND	Length: 16
31907	2:50:05.2819187 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
31908	2:50:05.2819355 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	BUFFER OVERFLOW	Query: Basic, Length: 24
31909	2:50:05.2819486 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay	NAME NOT FOUND	Length: 16
31910	2:50:05.2819628 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
31911	2:50:05.2819782 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	BUFFER OVERFLOW	Query: Basic, Length: 24
31912	2:50:05.2819905 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist	NAME NOT FOUND	Length: 16
31913	2:50:05.2820045 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
31914	2:50:05.2820198 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	BUFFER OVERFLOW	Query: Basic, Length: 24
31915	2:50:05.2820321 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay	NAME NOT FOUND	Length: 16
31916	2:50:05.2820458 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
31917	2:50:05.2820609 PM	ra3game.dat	3416	RegQueryKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	BUFFER OVERFLOW	Query: Basic, Length: 24
31918	2:50:05.2820732 PM	ra3game.dat	3416	RegQueryValue	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval	NAME NOT FOUND	Length: 16
31919	2:50:05.2820869 PM	ra3game.dat	3416	RegCloseKey	HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows	SUCCESS	
31920	2:50:05.2822070 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\win.ini	SUCCESS	Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
31921	2:50:05.2822889 PM	ra3game.dat	3416	LockFile	C:\WINDOWS\win.ini	SUCCESS	Exclusive: False, Offset: 0, Length: 4,294,967,295, Fail Immediately: False
31922	2:50:05.2823595 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\win.ini	SUCCESS	AllocationSize: 4,096, EndOfFile: 1,220, NumberOfLinks: 1, DeletePending: False, Directory: False
31923	2:50:05.2824394 PM	ra3game.dat	3416	ReadFile	C:\WINDOWS\win.ini	SUCCESS	Offset: 0, Length: 1,220
31926	2:50:05.2825844 PM	ra3game.dat	3416	UnlockFileSingle	C:\WINDOWS\win.ini	RANGE NOT LOCKED	Offset: 0, Length: 4,294,967,295
31927	2:50:05.2826579 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\win.ini	SUCCESS	
31928	2:50:05.2840039 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
31929	2:50:05.2840433 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31930	2:50:05.2840586 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
31931	2:50:05.2840715 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31932	2:50:05.2840829 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
31933	2:50:05.2841003 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
34671	2:50:13.6406235 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msimtf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:48 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 159,744, EndOfFile: 159,232, FileAttributes: A
34672	2:50:13.6409001 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
34674	2:50:13.6411378 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	AllocationSize: 159,744, EndOfFile: 159,232, NumberOfLinks: 1, DeletePending: False, Directory: False
34676	2:50:13.6413644 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	
34681	2:50:13.6508865 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msimtf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:48 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 159,744, EndOfFile: 159,232, FileAttributes: A
34682	2:50:13.6511871 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
34684	2:50:13.6514724 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	AllocationSize: 159,744, EndOfFile: 159,232, NumberOfLinks: 1, DeletePending: False, Directory: False
34686	2:50:13.6517073 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msimtf.dll	SUCCESS	
34688	2:50:13.6583766 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:51 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 299,008, EndOfFile: 297,984, FileAttributes: A
34689	2:50:13.6586568 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
34691	2:50:13.6588943 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	AllocationSize: 299,008, EndOfFile: 297,984, NumberOfLinks: 1, DeletePending: False, Directory: False
34693	2:50:13.6605674 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	
34695	2:50:13.6607872 PM	ra3game.dat	3416	Thread Exit		SUCCESS	User Time: 0.0000000, Kernel Time: 0.0625000
34703	2:50:13.6701778 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion	SUCCESS	Desired Access: Read
34704	2:50:13.6702530 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
34705	2:50:13.6702798 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentVersion	SUCCESS	Type: REG_SZ, Length: 8, Data: 5.1
34706	2:50:13.6703030 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
34707	2:50:13.6703231 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber	SUCCESS	Type: REG_SZ, Length: 10, Data: 2600
34708	2:50:13.6703561 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion	SUCCESS	
34714	2:50:13.6712039 PM	ra3game.dat	3416	QueryOpen	C:\WINDOWS\system32\msctf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:51 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 299,008, EndOfFile: 297,984, FileAttributes: A
34715	2:50:13.6713310 PM	ra3game.dat	3416	Thread Exit		SUCCESS	User Time: 0.0000000, Kernel Time: 0.0000000
34718	2:50:13.6717763 PM	ra3game.dat	3416	CreateFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
34720	2:50:13.6720244 PM	ra3game.dat	3416	QueryStandardInformationFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	AllocationSize: 299,008, EndOfFile: 297,984, NumberOfLinks: 1, DeletePending: False, Directory: False
34722	2:50:13.6722454 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	
34724	2:50:13.6734450 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\NetBT\Parameters	SUCCESS	
34725	2:50:13.6734782 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\NetBT\Parameters\Interfaces	SUCCESS	
34726	2:50:13.6735076 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\Tcpip\Parameters	SUCCESS	
34727	2:50:13.6735358 PM	ra3game.dat	3416	RegCloseKey	HKLM\System\CurrentControlSet\Services\Tcpip\Linkage	SUCCESS	
34728	2:50:13.6741920 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
34730	2:50:13.6744823 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
34732	2:50:13.6749860 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32	SUCCESS	
34733	2:50:13.6751081 PM	ra3game.dat	3416	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	Desired Access: Read
34734	2:50:13.6751575 PM	ra3game.dat	3416	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles	NAME NOT FOUND	Length: 20
34735	2:50:13.6751852 PM	ra3game.dat	3416	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	
34736	2:50:13.6755508 PM	ra3game.dat	3416	Thread Exit		SUCCESS	User Time: 1.5781250, Kernel Time: 0.1718750
34750	2:50:13.7727640 PM	ra3game.dat	3416	Process Exit		SUCCESS	Exit Status: 1, User Time: 1.5937500, Kernel Time: 0.1875000, Private Bytes: 24,494,080, Peak Private Bytes: 25,874,432, Working Set: 19,275,776, Peak Working Set: 20,230,144
34751	2:50:13.7729752 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
34753	2:50:13.7732901 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
34755	2:50:13.7735245 PM	ra3game.dat	3416	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
38334	2:50:23.5439168 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:51 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 299,008, EndOfFile: 297,984, FileAttributes: A
38341	2:50:23.5442780 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
38350	2:50:23.5446345 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	AllocationSize: 299,008, EndOfFile: 297,984, NumberOfLinks: 1, DeletePending: False, Directory: False
38360	2:50:23.5449460 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	
38376	2:50:23.5454349 PM	RA3Beta.exe	388	Thread Exit		SUCCESS	User Time: 0.0000000, Kernel Time: 0.0000000
38440	2:50:23.5497005 PM	RA3Beta.exe	388	QueryOpen	C:\WINDOWS\system32\msctf.dll	SUCCESS	CreationTime: 8/16/2005 5:18:49 AM, LastAccessTime: 6/5/2008 7:52:51 AM, LastWriteTime: 4/14/2008 5:42:00 AM, ChangeTime: 6/5/2008 8:00:06 AM, AllocationSize: 299,008, EndOfFile: 297,984, FileAttributes: A
38443	2:50:23.5499785 PM	RA3Beta.exe	388	CreateFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
38444	2:50:23.5500687 PM	RA3Beta.exe	388	Thread Exit		SUCCESS	User Time: 0.0000000, Kernel Time: 0.0000000
38446	2:50:23.5503347 PM	RA3Beta.exe	388	QueryStandardInformationFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	AllocationSize: 299,008, EndOfFile: 297,984, NumberOfLinks: 1, DeletePending: False, Directory: False
38456	2:50:23.5505760 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\system32\msctf.dll	SUCCESS	
38544	2:50:23.5550570 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
38556	2:50:23.5555026 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
38558	2:50:23.5559859 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32	SUCCESS	
38560	2:50:23.5563519 PM	RA3Beta.exe	388	RegOpenKey	HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	Desired Access: Read
38561	2:50:23.5564019 PM	RA3Beta.exe	388	RegQueryValue	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles	NAME NOT FOUND	Length: 20
38562	2:50:23.5564307 PM	RA3Beta.exe	388	RegCloseKey	HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize	SUCCESS	
38564	2:50:23.5567687 PM	RA3Beta.exe	388	Thread Exit		SUCCESS	User Time: 0.0468750, Kernel Time: 0.1875000
38609	2:50:23.6525298 PM	RA3Beta.exe	388	Process Exit		SUCCESS	Exit Status: 0, User Time: 0.0625000, Kernel Time: 0.1250000, Private Bytes: 2,387,968, Peak Private Bytes: 7,147,520, Working Set: 5,177,344, Peak Working Set: 9,887,744
38610	2:50:23.6525909 PM	RA3Beta.exe	388	CloseFile	C:\Program Files\Red Alert 3 Beta	SUCCESS	
38612	2:50:23.6528980 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c	SUCCESS	
38614	2:50:23.6531072 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83	SUCCESS	
38616	2:50:23.6533930 PM	RA3Beta.exe	388	CloseFile	C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2	SUCCESS	
