"Time of Day","Process Name","PID","Operation","Path","Result","Detail"
"10:47:52,9476725","setup.exe","2756","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS","Desired Access: Read"
"10:47:52,9477351","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses\#32770","SUCCESS","Type: REG_SZ, Length: 2, Data: "
"10:47:52,9477493","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS",""
"10:47:54,6620898","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}","SUCCESS","Desired Access: Read"
"10:47:54,6621474","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"10:47:54,6621614","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}","SUCCESS",""
"10:47:54,6625413","setup.exe","2756","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"10:47:54,6625656","setup.exe","2756","RegOpenKey","HKCU\Keyboard Layout\Toggle","SUCCESS","Desired Access: Read"
"10:47:54,6625846","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:47:54,6625930","setup.exe","2756","RegQueryValue","HKCU\Keyboard Layout\Toggle\Language Hotkey","SUCCESS","Type: REG_SZ, Length: 4, Data: 1"
"10:47:54,6626019","setup.exe","2756","RegQueryValue","HKCU\Keyboard Layout\Toggle\Layout Hotkey","SUCCESS","Type: REG_SZ, Length: 4, Data: 2"
"10:47:54,6626128","setup.exe","2756","RegCloseKey","HKCU\Keyboard Layout\Toggle","SUCCESS",""
"10:47:54,6628573","setup.exe","2756","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"10:47:54,6629084","setup.exe","2756","RegOpenKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS","Desired Access: Read"
"10:47:54,6629394","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:47:54,6629497","setup.exe","2756","RegEnumKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","NO MORE ENTRIES","Index: 0, Length: 288"
"10:47:54,6629587","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS",""
"10:48:01,1691780","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS","Desired Access: Query Value"
"10:48:01,1692428","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0"
"10:48:01,1692588","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer","SUCCESS",""
"10:48:14,8326679","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 2536, User Time: 0.0000000, Kernel Time: 0.0156250"
"10:48:32,4276869","setup.exe","2756","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS","Desired Access: Read"
"10:48:32,4277561","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses\#32770","SUCCESS","Type: REG_SZ, Length: 2, Data: "
"10:48:32,4277718","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS",""
"10:48:34,2982601","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}","SUCCESS","Desired Access: Read"
"10:48:34,2983316","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"10:48:34,2983456","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}","SUCCESS",""
"10:48:34,2986822","setup.exe","2756","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"10:48:34,2987247","setup.exe","2756","RegOpenKey","HKCU\Keyboard Layout\Toggle","SUCCESS","Desired Access: Read"
"10:48:34,2987448","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:34,2987546","setup.exe","2756","RegQueryValue","HKCU\Keyboard Layout\Toggle\Language Hotkey","SUCCESS","Type: REG_SZ, Length: 4, Data: 1"
"10:48:34,2987657","setup.exe","2756","RegQueryValue","HKCU\Keyboard Layout\Toggle\Layout Hotkey","SUCCESS","Type: REG_SZ, Length: 4, Data: 2"
"10:48:34,2987766","setup.exe","2756","RegCloseKey","HKCU\Keyboard Layout\Toggle","SUCCESS",""
"10:48:34,2990269","setup.exe","2756","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"10:48:34,2990767","setup.exe","2756","RegOpenKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS","Desired Access: Read"
"10:48:34,2990993","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:34,2991094","setup.exe","2756","RegEnumKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","NO MORE ENTRIES","Index: 0, Length: 288"
"10:48:34,2991191","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS",""
"10:48:36,6678207","setup.exe","2756","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS","Desired Access: Read"
"10:48:36,6678895","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses\#32770","SUCCESS","Type: REG_SZ, Length: 2, Data: "
"10:48:36,6679045","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS",""
"10:48:39,2478626","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 3016, User Time: 0.0312500, Kernel Time: 0.1406250"
"10:48:39,2512496","setup.exe","2756","Thread Create","","SUCCESS","Thread ID: 5956"
"10:48:40,5674725","setup.exe","2756","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS","Desired Access: Read"
"10:48:40,5675284","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses\Static","NAME NOT FOUND","Length: 144"
"10:48:40,5675404","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS",""
"10:48:41,6915363","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 1064, User Time: 0.0156250, Kernel Time: 0.0625000"
"10:48:42,3843132","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}","SUCCESS","Desired Access: Read"
"10:48:42,3843680","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"10:48:42,3843808","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}","SUCCESS",""
"10:48:42,3850750","setup.exe","2756","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"10:48:42,3851275","setup.exe","2756","RegOpenKey","HKCU\Keyboard Layout\Toggle","SUCCESS","Desired Access: Read"
"10:48:42,3851488","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:42,3851588","setup.exe","2756","RegQueryValue","HKCU\Keyboard Layout\Toggle\Language Hotkey","SUCCESS","Type: REG_SZ, Length: 4, Data: 1"
"10:48:42,3851692","setup.exe","2756","RegQueryValue","HKCU\Keyboard Layout\Toggle\Layout Hotkey","SUCCESS","Type: REG_SZ, Length: 4, Data: 2"
"10:48:42,3851829","setup.exe","2756","RegCloseKey","HKCU\Keyboard Layout\Toggle","SUCCESS",""
"10:48:42,3853318","setup.exe","2756","RegOpenKey","HKCU","SUCCESS","Desired Access: Read"
"10:48:42,3853753","setup.exe","2756","RegOpenKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS","Desired Access: Read"
"10:48:42,3853977","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:42,3854080","setup.exe","2756","RegEnumKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","NO MORE ENTRIES","Index: 0, Length: 288"
"10:48:42,3854172","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\CTF\DirectSwitchHotkeys","SUCCESS",""
"10:48:44,2997069","setup.exe","2756","RegOpenKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS","Desired Access: Read"
"10:48:44,2997737","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses\#32770","SUCCESS","Type: REG_SZ, Length: 2, Data: "
"10:48:44,2997885","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\CTF\KnownClasses","SUCCESS",""
"10:48:46,6464404","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","REPARSE","Desired Access: Read"
"10:48:46,6464719","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS","Desired Access: Read"
"10:48:46,6465152","setup.exe","2756","RegQueryValue","HKLM\System\CurrentControlSet\Control\Terminal Server\PerSessionTempDir","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0"
"10:48:46,6465284","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS",""
"10:48:46,6465365","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","REPARSE","Desired Access: Read"
"10:48:46,6465465","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS","Desired Access: Read"
"10:48:46,6465725","setup.exe","2756","RegQueryValue","HKLM\System\CurrentControlSet\Control\Terminal Server\FlatTempDir","NAME NOT FOUND","Length: 144"
"10:48:46,6465809","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS",""
"10:48:46,6473877","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Microsoft Integration","NAME NOT FOUND","Desired Access: Read/Write"
"10:48:46,6474198","setup.exe","2756","FileSystemControl","F:\VBExpress","SUCCESS","Control: FSCTL_IS_VOLUME_MOUNTED"
"10:48:46,6476662","setup.exe","2756","CreateFile","F:\Microsoft Visual Basic 2010 Express - ENU\DeleteTemp.exe","PATH NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"10:48:46,6477562","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","REPARSE","Desired Access: Read"
"10:48:46,6477701","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS","Desired Access: Read"
"10:48:46,6477911","setup.exe","2756","RegQueryValue","HKLM\System\CurrentControlSet\Control\Terminal Server\PerSessionTempDir","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0"
"10:48:46,6478000","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS",""
"10:48:46,6489334","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","REPARSE","Desired Access: Read"
"10:48:46,6489667","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS","Desired Access: Read"
"10:48:46,6490111","setup.exe","2756","RegQueryValue","HKLM\System\CurrentControlSet\Control\Terminal Server\PerSessionTempDir","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0"
"10:48:46,6490253","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Terminal Server","SUCCESS",""
"10:48:46,6496276","setup.exe","2756","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\System","SUCCESS","Desired Access: Query Value"
"10:48:46,6496654","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileBufferedSynchronousIo","NAME NOT FOUND","Length: 20"
"10:48:46,6496729","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS",""
"10:48:46,6501526","setup.exe","2756","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\System","SUCCESS","Desired Access: Query Value"
"10:48:46,6501741","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileChunkSize","NAME NOT FOUND","Length: 20"
"10:48:46,6501819","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileOverlappedCount","NAME NOT FOUND","Length: 20"
"10:48:46,6501889","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\System","SUCCESS",""
"10:48:46,7113433","setup.exe","2756","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Del51B0.tmp","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys"
"10:48:46,7122700","setup.exe","2756","Process Create","C:\Users\Tim\AppData\Local\Temp\Del51B0.tmp","SUCCESS","PID: 4620, Command line: ""C:\Users\Tim\AppData\Local\Temp\Del51B0.tmp"" 2756 ""C:\Users\Tim\AppData\Local\Temp\Ini51AF.tmp"""
"10:48:46,7123063","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls","REPARSE","Desired Access: Query Value"
"10:48:46,7123281","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls","NAME NOT FOUND","Desired Access: Query Value"
"10:48:46,7123515","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
"10:48:46,7123624","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
"10:48:46,7123781","setup.exe","2756","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value"
"10:48:46,7124161","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0"
"10:48:46,7124284","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 0"
"10:48:46,7124359","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS",""
"10:48:46,7124588","setup.exe","2756","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value"
"10:48:46,7124826","setup.exe","2756","RegQueryValue","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
"10:48:46,7125457","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\\GP","REPARSE","Desired Access: Read"
"10:48:46,7125580","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\Srp\\GP","SUCCESS","Desired Access: Read"
"10:48:46,7125817","setup.exe","2756","RegQueryValue","HKLM\System\CurrentControlSet\Control\Srp\Gp\RuleCount","NAME NOT FOUND","Length: 80"
"10:48:46,7125887","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Srp\Gp","SUCCESS",""
"10:48:46,7126200","setup.exe","2756","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Read"
"10:48:46,7126387","setup.exe","2756","RegQueryKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS","Query: Basic, Name: codeidentifiers"
"10:48:46,7126482","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS",""
"10:48:46,7126572","setup.exe","2756","RegOpenKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Read"
"10:48:46,7126728","setup.exe","2756","RegQueryKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Query: Basic, Name: CodeIdentifiers"
"10:48:46,7126801","setup.exe","2756","RegCloseKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS",""
"10:48:46,7141266","setup.exe","2756","RegOpenKey","HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS","Desired Access: Query Value"
"10:48:46,7141512","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\LogFileName","NAME NOT FOUND","Length: 536"
"10:48:46,7141599","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers","SUCCESS",""
"10:48:46,7141682","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","REPARSE","Desired Access: Query Value, Set Value"
"10:48:46,7141817","setup.exe","2756","RegOpenKey","HKLM\System\CurrentControlSet\Control\SafeBoot\Option","NAME NOT FOUND","Desired Access: Query Value, Set Value"
"10:48:46,7150334","setup.exe","2756","Load Image","C:\Users\Tim\AppData\Local\Temp\Del51B0.tmp","SUCCESS","Image Base: 0x9c0000, Image Size: 0x18000"
"10:48:46,7159900","setup.exe","2756","RegOpenKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS","Desired Access: Query Value"
"10:48:46,7160453","setup.exe","2756","RegQueryValue","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache","SUCCESS","Type: REG_SZ, Length: 140, Data: C:\Users\Tim\AppData\Local\Microsoft\Windows\Temporary Internet Files"
"10:48:46,7160690","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders","SUCCESS",""
"10:48:46,7160794","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read"
"10:48:46,7161101","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Users\Tim\AppData\Local\Temp\Del51B0.tmp","NAME NOT FOUND","Length: 1.024"
"10:48:46,7161534","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS",""
"10:48:46,7161677","setup.exe","2756","RegOpenKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS","Desired Access: Read"
"10:48:46,7162059","setup.exe","2756","RegQueryValue","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Users\Tim\AppData\Local\Temp\Del51B0.tmp","NAME NOT FOUND","Length: 1.024"
"10:48:46,7162210","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers","SUCCESS",""
"10:48:46,7162297","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Del51B0.tmp","NAME NOT FOUND","Desired Access: Read"
"10:48:46,7175243","setup.exe","2756","CreateFile","F:\VBExpress","SUCCESS","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
"10:48:46,7176276","setup.exe","2756","QueryDirectory","F:\VBExpress\*","SUCCESS","Filter: *, 1: ."
"10:48:46,7176536","setup.exe","2756","QueryDirectory","F:\VBExpress","SUCCESS","0: .., 1: BlockMSI_Text.htm, 2: BlockWIC_Text.htm, 3: CustomText.1033.dll, 4: DeleteTemp.exe, 5: ExpressRes.dll, 6: ExpressUI.dll, 7: HtmlLite.dll, 8: IA64block_text.htm, 9: Ixpvb.exe, 10: License.txt, 11: SITSetup.dll, 12: Silverlight_EULA.htm, 13: Silverlight_privacy.htm, 14: WindowsUpdate_Required_Text.htm, 15: autorun.exe, 16: autorun.inf, 17: baseline.dat, 18: deffactory.dat, 19: dlmgr.dll, 20: gencomp.dll, 21: locdata.ini, 22: logo.bmp, 23: pidgenx.dll, 24: pkconfig.xrm-ms, 25: readme.htm, 26: setup.exe, 27: setup.sdb, 28: setupres.dll, 29: sqmapi.dll, 30: vs70uimgr.dll, 31: vs_setup.MS_, 32: vs_setup.dll"
"10:48:46,7178073","setup.exe","2756","QueryDirectory","F:\VBExpress","SUCCESS","0: vs_setup.pdi, 1: vsbasereqs.dll, 2: vsscenario.dll, 3: wcu, 4: windowsSP_Requirements.htm"
"10:48:46,7178447","setup.exe","2756","QueryDirectory","F:\VBExpress","NO MORE FILES",""
"10:48:46,7178550","setup.exe","2756","CloseFile","F:\VBExpress","SUCCESS",""
"10:48:46,7217745","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS","Desired Access: Query Value, Enumerate Sub Keys"
"10:48:46,7218080","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisableLocalOverride","NAME NOT FOUND","Length: 1.024"
"10:48:46,7218178","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS","Desired Access: Read"
"10:48:46,7218432","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest","NAME NOT FOUND","Length: 20"
"10:48:46,7218513","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide","SUCCESS",""
"10:48:46,8458149","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 3176, User Time: 0.0000000, Kernel Time: 0.0000000"
"10:48:46,8458355","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 5160, User Time: 0.0000000, Kernel Time: 0.0000000"
"10:48:46,8458682","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 3756, User Time: 0.0000000, Kernel Time: 0.0000000"
"10:48:46,8458923","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 2604, User Time: 0.0000000, Kernel Time: 0.0000000"
"10:48:46,8459121","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 5956, User Time: 0.0000000, Kernel Time: 0.0000000"
"10:48:47,2690390","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag","SUCCESS",""
"10:48:47,2690586","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag","SUCCESS",""
"10:48:47,2690715","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag","SUCCESS",""
"10:48:47,2690916","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag","SUCCESS",""
"10:48:47,2691016","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag","SUCCESS",""
"10:48:47,2691120","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag","SUCCESS",""
"10:48:47,2691433","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer","SUCCESS",""
"10:48:47,2693318","setup.exe","2756","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS","Desired Access: Read"
"10:48:47,2693807","setup.exe","2756","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles","NAME NOT FOUND","Length: 20"
"10:48:47,2693902","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize","SUCCESS",""
"10:48:47,2695318","setup.exe","2756","Thread Exit","","SUCCESS","Thread ID: 2632, User Time: 0.5468750, Kernel Time: 1.8281250"
"10:48:47,2719646","setup.exe","2756","Process Exit","","SUCCESS","Exit Status: 0, User Time: 0.6093750 seconds, Kernel Time: 2.0625000 seconds, Private Bytes: 9.580.544, Peak Private Bytes: 15.970.304, Working Set: 20.090.880, Peak Working Set: 29.732.864"
"10:48:47,2719855","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Session Manager","SUCCESS",""
"10:48:47,2720422","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions","SUCCESS",""
"10:48:47,2720565","setup.exe","2756","RegCloseKey","HKLM","SUCCESS",""
"10:48:47,2721626","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder","SUCCESS",""
"10:48:47,2722828","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:47,2722925","setup.exe","2756","RegCloseKey","HKCR","SUCCESS",""
"10:48:47,2722998","setup.exe","2756","RegCloseKey","HKU","SUCCESS",""
"10:48:47,2723132","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Locale","SUCCESS",""
"10:48:47,2723208","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts","SUCCESS",""
"10:48:47,2723275","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\Language Groups","SUCCESS",""
"10:48:47,2724641","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\services\crypt32","SUCCESS",""
"10:48:47,2725015","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config","SUCCESS",""
"10:48:47,2725099","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\My","SUCCESS",""
"10:48:47,2725171","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\CA","SUCCESS",""
"10:48:47,2725244","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT","SUCCESS",""
"10:48:47,2725320","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\CA","SUCCESS",""
"10:48:47,2725395","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Disallowed","SUCCESS",""
"10:48:47,2725468","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA","SUCCESS",""
"10:48:47,2725532","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:47,2725593","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:47,2725660","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed","SUCCESS",""
"10:48:47,2725736","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed","SUCCESS",""
"10:48:47,2725817","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\Root","SUCCESS",""
"10:48:47,2725889","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot","SUCCESS",""
"10:48:47,2725965","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root","SUCCESS",""
"10:48:47,2726037","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS",""
"10:48:47,2726107","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\TrustedPeople","SUCCESS",""
"10:48:47,2726174","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot","SUCCESS",""
"10:48:47,2726239","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:47,2726306","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople","SUCCESS",""
"10:48:47,2726381","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople","SUCCESS",""
"10:48:47,2726451","setup.exe","2756","RegCloseKey","HKCU\Software\Microsoft\SystemCertificates\trust","SUCCESS",""
"10:48:47,2726515","setup.exe","2756","RegCloseKey","HKCU","SUCCESS",""
"10:48:47,2726582","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\SystemCertificates\trust","SUCCESS",""
"10:48:47,2726658","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust","SUCCESS",""
"10:48:47,2726968","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates","SUCCESS",""
"10:48:47,2727093","setup.exe","2756","RegCloseKey","HKCU\Software\Policies\Microsoft\SystemCertificates","SUCCESS",""
"10:48:47,2727716","setup.exe","2756","RegCloseKey","HKCU\Software\Classes","SUCCESS",""
"10:48:47,2727792","setup.exe","2756","RegCloseKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options","SUCCESS",""
"10:48:47,2727873","setup.exe","2756","RegCloseKey","HKLM\System\CurrentControlSet\Control\Nls\CustomLocale","SUCCESS",""
"10:48:47,2727940","setup.exe","2756","RegCloseKey","HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers","SUCCESS",""
"10:48:47,2728063","setup.exe","2756","CloseFile","F:\VBExpress","SUCCESS",""