Slobodan,
I opened the oxui.dll with dependancy walker, and checked if all files were
in my image and that was all OK.
It let filemon run on the xpe-machine while opening the property pages,
hoping that i could see if the machine
tried to open/read files that didn't exist. I paste here the filemon log
file...
the only thing that i can see (and don't understand) is on row 132: it tries
to open the file
oxui.dll.Manifest (and that doesnt exits) !?!? what i don't understand is
the meaning of "Manifest" at the end
of the filename.
On row 131 you can see that the file oxui.dll can be opened successfully...
Do you understand anything of all this???
filemon.log:
1 16:53:20 System:4 IRP_MJ_WRITE* C:\$LogFile SUCCESS Offset: 4468736
Length: 8192
2 16:53:20 System:4 IRP_MJ_WRITE* C:\$LogFile SUCCESS Offset: 8192 Length:
4096
3 16:53:20 System:4 IRP_MJ_WRITE* C:\$LogFile SUCCESS Offset: 4096 Length:
4096
4 16:53:20 System:4 IRP_MJ_WRITE* C:\$Directory SUCCESS Offset: 0 Length:
4096
5 16:53:21 System:4 IRP_MJ_WRITE* C:\$Directory SUCCESS Offset: 0 Length:
4096
6 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
7 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
8 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
9 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
10 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
11 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
12 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
13 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
14 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
15 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
16 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
17 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
18 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
19 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
20 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
21 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
22 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
23 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
24 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
25 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
26 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
27 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
28 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
29 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
30 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
31 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
32 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
33 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
34 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MmSys.Cpl
SUCCESS Attributes: A
35 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
36 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
37 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\MmSys.Cpl SUCCESS
Options: Open Access: All
38 16:53:21 mmc.exe:112 FASTIO_QUERY_BASIC_INFO
C:\WINDOWS\System32\MmSys.Cpl SUCCESS Attributes: A
39 16:53:21 mmc.exe:112 IRP_MJ_SET_INFORMATION
C:\WINDOWS\System32\MmSys.Cpl SUCCESS FileBasicInformation
40 16:53:21 mmc.exe:112 IRP_MJ_READ C:\WINDOWS\System32\MmSys.Cpl SUCCESS
Offset: 0 Length: 12
41 16:53:21 System:4 IRP_MJ_CLOSE C:\WINDOWS\system32\mmsys.cpl SUCCESS
42 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\MmSys.Cpl SUCCESS Length: 559616
43 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\MmSys.Cpl SUCCESS Length: 559616
44 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\MmSys.Cpl SUCCESS
45 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
46 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
47 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
48 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
49 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
50 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
51 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
52 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
53 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
54 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
55 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
56 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
57 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
58 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
59 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
60 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
61 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
62 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
63 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
64 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
65 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
66 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
67 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
68 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
69 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
70 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
71 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
72 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
73 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
74 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
75 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
76 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
77 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
78 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
79 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\SysSetup.Dll
SUCCESS Attributes: A
80 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
81 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
82 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\SysSetup.Dll
SUCCESS Options: Open Access: All
83 16:53:21 mmc.exe:112 FASTIO_QUERY_BASIC_INFO
C:\WINDOWS\System32\SysSetup.Dll SUCCESS Attributes: A
84 16:53:21 mmc.exe:112 IRP_MJ_SET_INFORMATION
C:\WINDOWS\System32\SysSetup.Dll SUCCESS FileBasicInformation
85 16:53:21 mmc.exe:112 IRP_MJ_READ C:\WINDOWS\System32\SysSetup.Dll
SUCCESS Offset: 0 Length: 12
86 16:53:21 System:4 IRP_MJ_CLOSE C:\WINDOWS\system32\syssetup.dll SUCCESS
87 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\SysSetup.Dll SUCCESS Length: 938496
88 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\SysSetup.Dll SUCCESS Length: 938496
89 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\SysSetup.Dll
SUCCESS
90 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
91 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
92 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
93 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
94 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
95 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
96 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
97 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
98 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
99 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
100 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
101 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
102 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
103 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
104 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
105 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
106 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
107 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
108 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
109 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
110 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
111 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
112 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
113 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
114 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
115 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
116 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
117 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
118 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\SETUPAPI.dll
SUCCESS Attributes: A
119 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
120 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
121 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\devmgr.dll
SUCCESS Attributes: A
122 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
123 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
124 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\devmgr.dll
SUCCESS Attributes: A
125 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
126 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
127 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\oxui.dll
SUCCESS Attributes: A
128 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
129 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
130 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\oxui.dll
SUCCESS Attributes: A
131 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
132 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN
C:\WINDOWS\System32\oxui.dll.Manifest FILE NOT FOUND Attributes: Error
133 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
134 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
135 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\oxui.dll
SUCCESS Attributes: A
136 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
137 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
138 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\oxui.dll SUCCESS
Options: Open Access: Execute
139 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\oxui.dll SUCCESS Length: 94208
140 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\oxui.dll SUCCESS
141 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\oxui.dll SUCCESS
142 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
143 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\oxui.dll
SUCCESS Attributes: A
144 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
145 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
146 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\oxui.dll SUCCESS
Options: Open Access: All
147 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\oxui.dll SUCCESS Length: 94208
148 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\oxui.dll SUCCESS
149 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\oxui.dll SUCCESS
150 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
151 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\oxui.dll SUCCESS
Options: Open Access: All
152 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\oxui.dll SUCCESS Length: 94208
153 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\oxui.dll SUCCESS
154 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\oxui.dll SUCCESS
155 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
156 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\oxui.dll
SUCCESS Attributes: A
157 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
158 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
159 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\oxui.dll SUCCESS
Options: Open Access: Execute
160 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\oxui.dll SUCCESS Length: 94208
161 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\oxui.dll SUCCESS
162 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\oxui.dll SUCCESS
163 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
164 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\oxui.dll
SUCCESS Attributes: A
165 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
166 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
167 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\oxui.dll SUCCESS
Options: Open Access: Execute
168 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\oxui.dll SUCCESS
169 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\oxui.dll SUCCESS
170 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
171 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
172 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\INF\ SUCCESS Options:
Open Directory Access: All
173 16:53:21 mmc.exe:112 IRP_MJ_DIRECTORY_CONTROL C:\WINDOWS\INF\ SUCCESS
FileBothDirectoryInformation: certclas.inf
174 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\INF\ SUCCESS
175 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\INF\ SUCCESS
176 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
177 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\Cabinet.dll
SUCCESS Attributes: A
178 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
179 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
180 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\system32\Cabinet.dll
SUCCESS Options: Open Access: Execute
181 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\Cabinet.dll SUCCESS Length: 59904
182 16:53:21 mmc.exe:112 IRP_MJ_READ* C:\WINDOWS\system32\Cabinet.dll
SUCCESS Offset: 0 Length: 4096
183 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\system32\Cabinet.dll
SUCCESS
184 16:53:21 mmc.exe:112 IRP_MJ_READ* C:\WINDOWS\system32\Cabinet.dll
SUCCESS Offset: 1024 Length: 32768
185 16:53:21 mmc.exe:112 IRP_MJ_READ* C:\WINDOWS\system32\Cabinet.dll
SUCCESS Offset: 33792 Length: 18944
186 16:53:21 mmc.exe:112 IRP_MJ_READ* C:\WINDOWS\system32\Cabinet.dll
SUCCESS Offset: 52736 Length: 5120
187 16:53:21 mmc.exe:112 IRP_MJ_READ* C:\WINDOWS\system32\Cabinet.dll
SUCCESS Offset: 57856 Length: 1024
188 16:53:21 mmc.exe:112 IRP_MJ_READ* C:\WINDOWS\system32\Cabinet.dll
SUCCESS Offset: 58880 Length: 1024
189 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
190 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\INF\certclas.PNF SUCCESS
Options: Open Access: All
191 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\INF\certclas.PNF SUCCESS Length: 7800
192 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\INF\certclas.PNF SUCCESS Length: 7800
193 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\INF\certclas.PNF SUCCESS
194 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\INF\certclas.PNF SUCCESS
195 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
196 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\INF\certclas.inf SUCCESS
Options: Open Access: All
197 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\INF\certclas.inf SUCCESS Length: 2186
198 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\INF\certclas.inf SUCCESS Length: 2186
199 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\INF\certclas.inf SUCCESS
200 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\INF\certclas.inf SUCCESS
201 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
202 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Attributes: A
203 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
204 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
205 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Attributes: A
206 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
207 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN
C:\WINDOWS\System32\MsPorts.Dll.Manifest FILE NOT FOUND Attributes: Error
208 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
209 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
210 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Attributes: A
211 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
212 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
213 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Options: Open Access: Execute
214 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\MsPorts.Dll SUCCESS Length: 41984
215 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
216 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
217 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
218 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Attributes: A
219 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
220 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
221 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Options: Open Access: All
222 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\MsPorts.Dll SUCCESS Length: 41984
223 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
224 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
225 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
226 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Options: Open Access: All
227 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\MsPorts.Dll SUCCESS Length: 41984
228 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
229 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
230 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
231 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Attributes: A
232 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
233 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
234 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Options: Open Access: Execute
235 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\System32\MsPorts.Dll SUCCESS Length: 41984
236 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
237 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
238 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
239 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Attributes: A
240 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
241 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
242 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS Options: Open Access: Execute
243 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
244 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\System32\MsPorts.Dll
SUCCESS
245 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
246 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
247 16:53:21 mmc.exe:112 IRP_MJ_CREATE
C:\WINDOWS\System32\MsPorts.Dll.2.Manifest FILE NOT FOUND Options: Open
Access: All
248 16:53:21 mmc.exe:112 IRP_MJ_CREATE
C:\WINDOWS\System32\MsPorts.Dll.2.Config FILE NOT FOUND Options: Open
Access: All
249 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
250 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_en-US_580a28ff\ FILE NOT FOUND Options: Open Directory
Access: All
251 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
252 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls\ PATH
NOT FOUND Options: Open Directory Access: All
253 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
254 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN C:\WINDOWS\System32\en-US FILE
NOT FOUND Attributes: Error
255 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
256 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN C:\WINDOWS\System32\en FILE NOT
FOUND Attributes: Error
257 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
258 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN C:\WINDOWS\System32\ SUCCESS
Attributes: D
259 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
260 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN C:\WINDOWS\System32\ SUCCESS
Attributes: D
261 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
262 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.0.0_en-US_f6b1e800.Manifest FILE NOT FOUND Attributes: Error
263 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
264 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls\6.0.0.0_en-US_6595
b64144ccf1df\Microsoft.Windows.Common-Controls.DLL PATH NOT FOUND
Attributes: Error
265 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
266 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_en_66c5eee6\ FILE NOT FOUND Options: Open Directory
Access: All
267 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
268 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls\ PATH
NOT FOUND Options: Open Directory Access: All
269 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
270 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.0.0_en_5cce9bd9.Manifest FILE NOT FOUND Attributes: Error
271 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
272 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls\6.0.0.0_en_6595b64
144ccf1df\Microsoft.Windows.Common-Controls.DLL PATH NOT FOUND Attributes:
Error
273 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
274 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\ SUCCESS Options: Open Directory Access: All
275 16:53:21 csrss.exe:604 IRP_MJ_DIRECTORY_CONTROL
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\ SUCCESS FileBothDirectoryInformation:
*.policy
276 16:53:21 csrss.exe:604 IRP_MJ_DIRECTORY_CONTROL
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\ NO MORE FILES FileBothDirectoryInformation
277 16:53:21 csrss.exe:604 IRP_MJ_CLEANUP
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\ SUCCESS
278 16:53:21 csrss.exe:604 IRP_MJ_CLOSE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\ SUCCESS
279 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
280 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy SUCCESS Options: Open
Sequential Access: All
281 16:53:21 csrss.exe:604 IRP_MJ_QUERY_VOLUME_INFORMATION
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy SUCCESS
FileFsVolumeInformation
282 16:53:21 csrss.exe:604 IRP_MJ_QUERY_INFORMATION
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy BUFFER OVERFLOW
FileAllInformation
283 16:53:21 csrss.exe:604 IRP_MJ_READ
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy SUCCESS Offset: 0 Length:
4095
284 16:53:21 csrss.exe:604 FASTIO_READ
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy END OF FILE Offset: 606
Length: 8178
285 16:53:21 csrss.exe:604 IRP_MJ_CLEANUP
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy SUCCESS
286 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
287 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls\ PATH
NOT FOUND Options: Open Directory Access: All
288 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
289 16:53:21 System:4 IRP_MJ_CLOSE
C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_
6595b64144ccf1df_x-ww_5ddad775\6.0.10.0.Policy SUCCESS
290 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS Attributes: A
291 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
292 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS Attributes: A
293 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
294 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.
mui_6595b64144ccf1df_en-US_186470ec\ FILE NOT FOUND Options: Open Directory
Access: All
295 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
296 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls.mui\
PATH NOT FOUND Options: Open Directory Access: All
297 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
298 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b6
4144ccf1df_6.0.10.0_en-US_e0908a4e.Manifest FILE NOT FOUND Attributes: Error
299 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
300 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls.mui\6.0.10.0_en-US
_6595b64144ccf1df\Microsoft.Windows.Common-Controls.mui.DLL PATH NOT FOUND
Attributes: Error
301 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
302 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.
mui_6595b64144ccf1df_en_272036d3\ FILE NOT FOUND Options: Open Directory
Access: All
303 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
304 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls.mui\
PATH NOT FOUND Options: Open Directory Access: All
305 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
306 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b6
4144ccf1df_6.0.10.0_en_46ad3e27.Manifest FILE NOT FOUND Attributes: Error
307 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
308 16:53:21 csrss.exe:604 FASTIO_QUERY_OPEN
C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls.mui\6.0.10.0_en_65
95b64144ccf1df\Microsoft.Windows.Common-Controls.mui.DLL PATH NOT FOUND
Attributes: Error
309 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
310 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS Options: Open Sequential
Access: All
311 16:53:21 csrss.exe:604 IRP_MJ_READ
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS Offset: 0 Length: 2
312 16:53:21 csrss.exe:604 IRP_MJ_CLEANUP
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS
313 16:53:21 csrss.exe:604 FSCTL_IS_VOLUME_MOUNTED C:\WINDOWS\system32
SUCCESS
314 16:53:21 csrss.exe:604 IRP_MJ_CREATE
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS Options: Open Sequential
Access: All
315 16:53:21 csrss.exe:604 IRP_MJ_QUERY_VOLUME_INFORMATION
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS FileFsVolumeInformation
316 16:53:21 csrss.exe:604 IRP_MJ_QUERY_INFORMATION
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest BUFFER OVERFLOW FileAllInformation
317 16:53:21 csrss.exe:604 IRP_MJ_READ
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS Offset: 0 Length: 4095
318 16:53:21 System:4 IRP_MJ_CLOSE
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS
319 16:53:21 csrss.exe:604 FASTIO_READ
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest END OF FILE Offset: 1807 Length: 8178
320 16:53:21 csrss.exe:604 IRP_MJ_CLEANUP
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS
321 16:53:21 csrss.exe:604 IRP_MJ_CLOSE
C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144
ccf1df_6.0.10.0_x-ww_f7fb5805.Manifest SUCCESS
322 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
323 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\rpcss.dll
SUCCESS Attributes: A
324 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
325 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
326 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\system32\rpcss.dll
SUCCESS Options: Open Access: Execute
327 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\rpcss.dll SUCCESS Length: 260608
328 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\system32\rpcss.dll
SUCCESS
329 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\system32\rpcss.dll SUCCESS
330 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
331 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\MSCTF.dll
SUCCESS Attributes: A
332 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
333 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
334 16:53:21 mmc.exe:112 FASTIO_QUERY_OPEN C:\WINDOWS\system32\rpcss.dll
SUCCESS Attributes: A
335 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
336 16:53:21 mmc.exe:112 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator SUCCESS
337 16:53:21 mmc.exe:112 IRP_MJ_CREATE C:\WINDOWS\system32\rpcss.dll
SUCCESS Options: Open Access: Execute
338 16:53:21 mmc.exe:112 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\rpcss.dll SUCCESS Length: 260608
339 16:53:21 mmc.exe:112 IRP_MJ_CLEANUP C:\WINDOWS\system32\rpcss.dll
SUCCESS
340 16:53:21 mmc.exe:112 IRP_MJ_CLOSE C:\WINDOWS\system32\rpcss.dll SUCCESS
341 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
342 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\ SUCCESS Options: Open
Directory Access: All
343 16:53:21 Filemon.exe:768 IRP_MJ_DIRECTORY_CONTROL C:\ SUCCESS
FileBothDirectoryInformation: WINDOWS
344 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\ SUCCESS
345 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\ SUCCESS
346 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
347 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\WINDOWS\ SUCCESS Options:
Open Directory Access: All
348 16:53:21 Filemon.exe:768 IRP_MJ_DIRECTORY_CONTROL C:\WINDOWS\ SUCCESS
FileBothDirectoryInformation: system32
349 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\WINDOWS\ SUCCESS
350 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\WINDOWS\ SUCCESS
351 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
352 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\WINDOWS\system32\ SUCCESS
Options: Open Directory Access: All
353 16:53:21 Filemon.exe:768 IRP_MJ_DIRECTORY_CONTROL C:\WINDOWS\system32\
SUCCESS FileBothDirectoryInformation: mmc.exe
354 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\WINDOWS\system32\ SUCCESS
355 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\WINDOWS\system32\ SUCCESS
356 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
357 16:53:21 Filemon.exe:768 FASTIO_QUERY_OPEN C:\WINDOWS\system32\mmc.exe
SUCCESS Attributes: A
358 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
359 16:53:21 Filemon.exe:768 FASTIO_QUERY_OPEN C:\WINDOWS\system32\mmc.exe
SUCCESS Attributes: A
360 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
361 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
362 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\WINDOWS\system32\mmc.exe
SUCCESS Options: Open Access: All
363 16:53:21 Filemon.exe:768 FASTIO_QUERY_BASIC_INFO
C:\WINDOWS\system32\mmc.exe SUCCESS Attributes: A
364 16:53:21 Filemon.exe:768 IRP_MJ_SET_INFORMATION
C:\WINDOWS\system32\mmc.exe SUCCESS FileBasicInformation
365 16:53:21 Filemon.exe:768 IRP_MJ_READ C:\WINDOWS\system32\mmc.exe
SUCCESS Offset: 0 Length: 12
366 16:53:21 System:4 IRP_MJ_CLOSE C:\WINDOWS\system32\mmc.exe SUCCESS
367 16:53:21 Filemon.exe:768 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\mmc.exe SUCCESS Length: 774144
368 16:53:21 Filemon.exe:768 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\mmc.exe SUCCESS Length: 774144
369 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\WINDOWS\system32\mmc.exe
SUCCESS
370 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
371 16:53:21 Filemon.exe:768 FASTIO_QUERY_OPEN C:\WINDOWS\system32\mmc.exe
SUCCESS Attributes: A
372 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
373 16:53:21 Filemon.exe:768 FASTIO_QUERY_OPEN C:\WINDOWS\system32\mmc.exe
SUCCESS Attributes: A
374 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
375 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
376 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\WINDOWS\system32\mmc.exe
SUCCESS Options: Open Access: All
377 16:53:21 Filemon.exe:768 FASTIO_QUERY_BASIC_INFO
C:\WINDOWS\system32\mmc.exe SUCCESS Attributes: A
378 16:53:21 Filemon.exe:768 IRP_MJ_SET_INFORMATION
C:\WINDOWS\system32\mmc.exe SUCCESS FileBasicInformation
379 16:53:21 Filemon.exe:768 IRP_MJ_READ C:\WINDOWS\system32\mmc.exe
SUCCESS Offset: 0 Length: 12
380 16:53:21 Filemon.exe:768 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\mmc.exe SUCCESS Length: 774144
381 16:53:21 Filemon.exe:768 FASTIO_QUERY_STANDARD_INFO
C:\WINDOWS\system32\mmc.exe SUCCESS Length: 774144
382 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\WINDOWS\system32\mmc.exe
SUCCESS
383 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\WINDOWS\system32\mmc.exe
SUCCESS
384 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
385 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\ SUCCESS Options: Open
Directory Access: All
386 16:53:21 Filemon.exe:768 IRP_MJ_DIRECTORY_CONTROL C:\ SUCCESS
FileBothDirectoryInformation: WINDOWS
387 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\ SUCCESS
388 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\ SUCCESS
389 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
390 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\WINDOWS\ SUCCESS Options:
Open Directory Access: All
391 16:53:21 Filemon.exe:768 IRP_MJ_DIRECTORY_CONTROL C:\WINDOWS\ SUCCESS
FileBothDirectoryInformation: system32
392 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\WINDOWS\ SUCCESS
393 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\WINDOWS\ SUCCESS
394 16:53:21 Filemon.exe:768 FSCTL_IS_VOLUME_MOUNTED C:\Documents and
Settings\Administrator\My Documents SUCCESS
395 16:53:21 Filemon.exe:768 IRP_MJ_CREATE C:\WINDOWS\system32\ SUCCESS
Options: Open Directory Access: All
396 16:53:21 Filemon.exe:768 IRP_MJ_DIRECTORY_CONTROL C:\WINDOWS\system32\
SUCCESS FileBothDirectoryInformation: mmc.exe
397 16:53:21 Filemon.exe:768 IRP_MJ_CLEANUP C:\WINDOWS\system32\ SUCCESS
398 16:53:21 Filemon.exe:768 IRP_MJ_CLOSE C:\WINDOWS\system32\ SUCCESS
Slobodan Brcin (eMVP) said:
None,
Yes it could be myriad of other components missing :-(
I have looked at oxui.dll and it has too many dynamic dependencies. (it
can't be determined for sure if they are needed or not :-( )
Some of them might be needed.
Only way for you is to use 'dependency walker" tool to list all required
dll files and them to find all components in TD and to add
them so that all these files are present in your final image. (Too much work)
Some alternative would be to use filemon to detect what files are tried to
be accessed when you try to look at the page from Device