Time of Day,“Process Name”,“PID”,“Operation”,“Path”,“Result”,“Detail”
19:08:21,7429918,“wermgr.exe”,“18324”,“RegOpenKey”,“HKLMSystemCurrentControlSetServicesWinSock2Parameters”,“ACCESS DENIED”,“Desired Access: All Access”
19:08:21,7642752,“wermgr.exe”,“18324”,“RegOpenKey”,“HKLMSystemCurrentControlSetServicesWinSock2Parameters”,“ACCESS DENIED”,“Desired Access: All Access”
19:08:22,2183243,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2185210,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2189649,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2191197,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2192253,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2193660,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2200763,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwarePoliciesMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2204347,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREPoliciesMicrosoftSystemCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2208025,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2210364,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2212164,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2213875,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesCA”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2223274,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2225310,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2229753,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2231177,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2233332,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2235727,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2243993,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwarePoliciesMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2246743,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREPoliciesMicrosoftSystemCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2251737,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2254051,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2255856,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2258541,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesDisallowed”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2276006,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2278824,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2280603,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2282177,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2298478,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesAuthRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2301172,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesAuthRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2324388,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwarePoliciesMicrosoftSystemCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2326642,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREPoliciesMicrosoftSystemCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2329888,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2332360,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2333514,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2335062,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2338107,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesSmartCardRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2340023,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesSmartCardRoot”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2351518,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2353750,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2357560,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2359044,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2360468,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2362067,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2366203,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwarePoliciesMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2368657,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREPoliciesMicrosoftSystemCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2371779,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2373229,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2374323,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2376308,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatesTrustedPeople”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2385532,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2387567,“wermgr.exe”,“18324”,“RegCreateKey”,“HKCUSoftwarePoliciesMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2391377,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2392831,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2393918,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2395372,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2400144,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwarePoliciesMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2403616,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREPoliciesMicrosoftSystemCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2408252,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2410501,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2412062,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSoftwareMicrosoftEnterpriseCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”
19:08:22,2414269,“wermgr.exe”,“18324”,“RegCreateKey”,“HKLMSOFTWAREMicrosoftEnterpriseCertificatestrust”,“ACCESS DENIED”,“Desired Access: Read/Write, Delete”