14:00:27,3756175 tlou-i.exe 9452 RegOpenKey HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management REPARSE Desired Access: Query Value
14:00:27,3756345 tlou-i.exe 9452 RegOpenKey HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management SUCCESS Desired Access: Query Value
14:00:27,3756502 tlou-i.exe 9452 RegQueryValue HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management\HotPatchRestrictions NAME NOT FOUND Length: 20
14:00:27,3756622 tlou-i.exe 9452 RegCloseKey HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management SUCCESS
14:00:27,3756742 tlou-i.exe 9452 RegOpenKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe NAME NOT FOUND Desired Access: Query Value, Enumerate Sub Keys
14:00:27,3756881 tlou-i.exe 9452 RegOpenKey HKLM\Software\Microsoft\Wow64\x86\xtajit NAME NOT FOUND Desired Access: Query Value
14:00:27,3758890 tlou-i.exe 9452 CreateFile C:\Windows\System32\WerFault.exe SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
14:00:27,3759971 tlou-i.exe 9452 CreateFileMapping C:\Windows\System32\WerFault.exe FILE LOCKED WITH ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE_READWRITE