Ups, nothing like process monitor ... had a filter there excluding explorer (the windows shell)

)
So ... the behaviour is variable ... for now never mind the similar behaviour for startmenuposition.dll used by objectdock.exe process ... look at explorer.exe process:
1st) Quit/Restart ObjectDock and click startmenu icon
In the dump: StartMenuPosition.dll uses Explorer to load DockShellHook (ok start menu appears)
2nd) click startmenu icon a 2nd time
No Explorer with DockShellHook there in the dump? + the "inject" error prompts user
3rd) click startmenu icon a 3rd time
No Explorer with DockShellHook there in the dump? + the "cannot find startmenu" error prompts user
This time an entry where Explorer quires OjectDock.exe (just to state behaviour is different)
So something wrong with startmenuposition.dll or is it DockShellHook? This approach for collaborating with Windows Vista is may be a "hack" by design and will not work I guess since like virus-behaviour or spyware. Guess some security feature is preventing this approach from working. I will stop using the startmehu feature in ObjectDock until changed.
4th) A 4th click does the same as the 3rd ... and keeps it like that from there ... no standard behaviour ... does not work and cannot find startmenu
94 01:19:11,5849152 Explorer.EXE 35152 QueryOpen C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe FAST IO DISALLOWED
95 01:19:11,5851818 Explorer.EXE 35152 CreateFile C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
96 01:19:11,5852527 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe SUCCESS CreationTime: 05-11-2007 07:54:24, LastAccessTime: 12-01-2008 06:31:02, LastWriteTime: 05-11-2007 07:54:24, ChangeTime: 18-02-2008 00:04:28, FileAttributes: A
97 01:19:11,5852723 Explorer.EXE 35152 CloseFile C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe SUCCESS
99 01:19:11,5863232 Explorer.EXE 35152 CreateFile C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
107 01:19:11,5872222 Explorer.EXE 35152 Load Image C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe SUCCESS Image Base: 0xdc70000, Image Size: 0x264000
108 01:19:11,5873340 Explorer.EXE 35152 CloseFile C:\Program Files\Microsoft\Windows Sysinternals Suite\Procmon.exe SUCCESS
3285 01:19:12,1170812 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
3286 01:19:12,1171100 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\{B3AFAE44-F603-4456-808F-C9F8F0C76082} NAME NOT FOUND Desired Access: Maximum Allowed
3287 01:19:12,1171318 Explorer.EXE 35152 RegOpenKey HKCR\{B3AFAE44-F603-4456-808F-C9F8F0C76082} NAME NOT FOUND Desired Access: Maximum Allowed
3288 01:19:12,1172578 Explorer.EXE 35152 Thread Exit SUCCESS User Time: 0.0000000, Kernel Time: 0.0000000
4456 01:19:12,8903800 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
5002 01:19:13,0185282 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
5005 01:19:13,0186807 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
5006 01:19:13,0188014 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
5007 01:19:13,0188210 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
5011 01:19:13,0191394 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
5017 01:19:13,0192903 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
5020 01:19:13,0193791 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
5021 01:19:13,0193962 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
5023 01:19:13,0196428 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
5040 01:19:13,0202371 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x3190000, Image Size: 0x10000
5041 01:19:13,0202938 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
5044 01:19:13,0206086 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
5060 01:19:13,0212978 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
5063 01:19:13,0214048 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
5064 01:19:13,0214255 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
5067 01:19:13,0216727 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
5080 01:19:13,0219845 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
5092 01:19:13,0227458 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x3190000, Image Size: 0x10000
5096 01:19:13,0230874 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Policies\Microsoft\MUI\Settings NAME NOT FOUND Desired Access: Read
5097 01:19:13,0232319 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152 SUCCESS Desired Access: Maximum Allowed, Granted Access: All Access
5099 01:19:13,0232788 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Policies\Microsoft\Control Panel\Desktop NAME NOT FOUND Desired Access: Read
5102 01:19:13,0233137 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Control Panel\Desktop SUCCESS Desired Access: Read
5106 01:19:13,0233481 ObjectDock.exe 5220 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152 SUCCESS
5107 01:19:13,0233791 ObjectDock.exe 5220 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Control Panel\Desktop\PreferredUILanguages NAME NOT FOUND Length: 12
5108 01:19:13,0234199 ObjectDock.exe 5220 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Control Panel\Desktop SUCCESS
5111 01:19:13,0236012 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide SUCCESS Desired Access: Read
5112 01:19:13,0236774 ObjectDock.exe 5220 RegQueryValue HKLM\COMPONENTS\PreferExternalManifest NAME NOT FOUND Length: 20
5113 01:19:13,0237043 ObjectDock.exe 5220 RegCloseKey HKLM\COMPONENTS SUCCESS
5121 01:19:13,0240479 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
5124 01:19:13,0241733 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
5126 01:19:13,0244842 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
5129 01:19:13,0247767 ObjectDock.exe 5220 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\StartMenuPosition.dll NAME NOT FOUND Length: 1.024
5138 01:19:13,0252841 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Name: \Program Files\Stardock\ObjectDock\StartMenuPosition.dll
5139 01:19:13,0253888 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\CrashRpt.dll SUCCESS Name: \PROGRA~1\Stardock\OBJECT~1\CrashRpt.dll
5144 01:19:13,0258397 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
5148 01:19:13,0259842 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
5151 01:19:13,0260842 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
5152 01:19:13,0261018 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
8776 01:19:13,2804676 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\DockShellHook.dll FAST IO DISALLOWED
8777 01:19:13,2805400 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
8778 01:19:13,2805805 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:18:50, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
8779 01:19:13,2805925 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS
8781 01:19:13,2807132 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
8791 01:19:13,2810814 Explorer.EXE 35152 Load Image C:\PROGRA~1\Stardock\OBJECT~1\DOCKSH~1.DLL SUCCESS Image Base: 0x23e0000, Image Size: 0x1b000
8795 01:19:13,2811230 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS
8801 01:19:13,2812937 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\DockShellHook.dll FAST IO DISALLOWED
8802 01:19:13,2813823 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
8804 01:19:13,2814194 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:18:50, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
8805 01:19:13,2814412 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS
8811 01:19:13,2815546 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
8822 01:19:13,2816535 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS
8826 01:19:13,2818924 Explorer.EXE 35152 Load Image C:\PROGRA~1\Stardock\OBJECT~1\DOCKSH~1.DLL SUCCESS Image Base: 0x23e0000, Image Size: 0x1b000
8835 01:19:13,2821807 Explorer.EXE 35152 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide SUCCESS Desired Access: Read
8837 01:19:13,2822271 Explorer.EXE 35152 RegQueryValue HKLM\COMPONENTS\PreferExternalManifest NAME NOT FOUND Length: 20
8838 01:19:13,2822444 Explorer.EXE 35152 RegCloseKey HKLM\COMPONENTS SUCCESS
8846 01:19:13,2824276 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
8848 01:19:13,2824880 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:18:50, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
8850 01:19:13,2826436 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\DockShellHook.dll SUCCESS
8853 01:19:13,2828028 Explorer.EXE 35152 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\DockShellHook.dll NAME NOT FOUND Length: 1.024
9006 01:19:13,2890609 Explorer.EXE 35152 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
9448 01:19:13,3128921 Explorer.EXE 35152 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
9520 01:19:13,3157925 Explorer.EXE 35152 RegOpenKey HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
9521 01:19:13,3158216 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
9522 01:19:13,3158383 Explorer.EXE 35152 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS SUCCESS Desired Access: Query Value
9523 01:19:13,3158693 Explorer.EXE 35152 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS\UpdateCount SUCCESS Type: REG_DWORD, Length: 4, Data: 0
9524 01:19:13,3158861 Explorer.EXE 35152 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS SUCCESS
9525 01:19:13,3158981 Explorer.EXE 35152 RegOpenKey HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
9526 01:19:13,3159121 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
9529 01:19:13,3185688 Explorer.EXE 35152 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
9530 01:19:13,3584876 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\AppEvents\Schemes\Apps\Explorer\MenuPopup\.current NAME NOT FOUND Desired Access: Query Value
9549 01:19:13,3656779 Explorer.EXE 35152 QueryOpen C:\Windows\System32\msctf.dll FAST IO DISALLOWED
9550 01:19:13,3657511 Explorer.EXE 35152 CreateFile C:\Windows\System32\msctf.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
9551 01:19:13,3658503 Explorer.EXE 35152 QueryBasicInformationFile C:\Windows\System32\msctf.dll SUCCESS CreationTime: 02-11-2006 09:39:18, LastAccessTime: 02-11-2006 11:40:45, LastWriteTime: 02-11-2006 10:46:06, ChangeTime: 17-02-2008 23:57:06, FileAttributes: A
9552 01:19:13,3658617 Explorer.EXE 35152 CloseFile C:\Windows\System32\msctf.dll SUCCESS
14146 01:19:48,0202262 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
14164 01:19:48,1210575 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
14165 01:19:48,1212061 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14166 01:19:48,1213173 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
14167 01:19:48,1213352 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14169 01:19:48,1215570 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
14170 01:19:48,1216869 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14171 01:19:48,1217484 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
14172 01:19:48,1217640 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14174 01:19:48,1219554 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
14182 01:19:48,1225197 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x3160000, Image Size: 0x10000
14183 01:19:48,1225703 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14188 01:19:48,1228544 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
14191 01:19:48,1229848 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14193 01:19:48,1230910 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
14195 01:19:48,1231097 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14199 01:19:48,1232905 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
14210 01:19:48,1235036 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14217 01:19:48,1239302 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x3160000, Image Size: 0x10000
14219 01:19:48,1242900 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide SUCCESS Desired Access: Read
14220 01:19:48,1244272 ObjectDock.exe 5220 RegQueryValue HKLM\COMPONENTS\PreferExternalManifest NAME NOT FOUND Length: 20
14221 01:19:48,1244574 ObjectDock.exe 5220 RegCloseKey HKLM\COMPONENTS SUCCESS
14222 01:19:48,1249940 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
14223 01:19:48,1251533 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
14225 01:19:48,1253374 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14227 01:19:48,1256120 ObjectDock.exe 5220 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\StartMenuPosition.dll NAME NOT FOUND Length: 1.024
14235 01:19:48,1262294 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Name: \Program Files\Stardock\ObjectDock\StartMenuPosition.dll
14238 01:19:48,1263165 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\CrashRpt.dll SUCCESS Name: \PROGRA~1\Stardock\OBJECT~1\CrashRpt.dll
14239 01:19:48,1266982 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
14240 01:19:48,1268258 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14241 01:19:48,1269247 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
14242 01:19:48,1269423 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
14387 01:19:48,4332176 Explorer.EXE 35152 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
14388 01:19:48,5129844 Explorer.EXE 35152 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
14397 01:19:48,5276271 Explorer.EXE 35152 RegOpenKey HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
14398 01:19:48,5276636 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
14399 01:19:48,5276807 Explorer.EXE 35152 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS SUCCESS Desired Access: Query Value
14400 01:19:48,5277151 Explorer.EXE 35152 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS\UpdateCount SUCCESS Type: REG_DWORD, Length: 4, Data: 0
14401 01:19:48,5277352 Explorer.EXE 35152 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS SUCCESS
14402 01:19:48,5277486 Explorer.EXE 35152 RegOpenKey HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
14403 01:19:48,5277631 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Policies\Microsoft\Windows\WindowsUpdate\AU NAME NOT FOUND Desired Access: Query Value
14404 01:19:48,5300017 Explorer.EXE 35152 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
14405 01:19:48,5437447 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\AppEvents\Schemes\Apps\Explorer\MenuPopup\.current NAME NOT FOUND Desired Access: Query Value
14406 01:19:49,4206313 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\Windows\Windows Error Reporting\Escalation NAME NOT FOUND Desired Access: Read
14407 01:19:49,4209752 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\SQMClient\Windows\DisabledSessions SUCCESS Desired Access: Read
14408 01:19:49,4210649 ObjectDock.exe 5220 RegQueryValue HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession NAME NOT FOUND Length: 20
14409 01:19:49,4210951 ObjectDock.exe 5220 RegCloseKey HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions SUCCESS
14410 01:19:49,4221061 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback SUCCESS Desired Access: Query Value, Enumerate Sub Keys
14411 01:19:49,4222125 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI NAME NOT FOUND Desired Access: Query Value
14412 01:19:49,4222913 ObjectDock.exe 5220 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback SUCCESS
14427 01:19:49,4303652 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
14451 01:19:49,4439153 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NAME NOT FOUND Desired Access: Query Value
14452 01:19:49,4440332 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer NAME NOT FOUND Desired Access: Query Value
14453 01:19:49,4462360 Explorer.EXE 35152 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Name: \Program Files\Stardock\ObjectDock\ObjectDock.exe
14454 01:19:49,4467522 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
14455 01:19:49,4467958 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14456 01:19:49,4468330 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14457 01:19:49,4471325 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
14458 01:19:49,4472624 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14459 01:19:49,4473291 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
14460 01:19:49,4473487 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
14462 01:19:49,4475051 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
14463 01:19:49,4475356 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14464 01:19:49,4475621 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14465 01:19:49,4477155 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
14466 01:19:49,4478633 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14467 01:19:49,4479125 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
14468 01:19:49,4479292 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
14470 01:19:49,4480113 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS Desired Access: Read
14471 01:19:49,4480574 Explorer.EXE 35152 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Type: REG_SZ, Length: 22, Data: ObjectDock
14472 01:19:49,4482041 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS
14473 01:19:49,4490444 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
14474 01:19:49,4490808 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14475 01:19:49,4491132 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14476 01:19:49,4493674 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
14477 01:19:49,4494945 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14478 01:19:49,4495599 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
14479 01:19:49,4495791 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
14481 01:19:49,4502242 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
14482 01:19:49,4502600 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14483 01:19:49,4502882 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
14484 01:19:49,4504843 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
14485 01:19:49,4506058 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
14486 01:19:49,4506606 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
14487 01:19:49,4506782 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
14489 01:19:49,4507880 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS Desired Access: Read
14490 01:19:49,4508327 Explorer.EXE 35152 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Type: REG_SZ, Length: 22, Data: ObjectDock
14491 01:19:49,4509486 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS
14492 01:19:49,4510860 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS Desired Access: Set Value
14493 01:19:49,4515325 Explorer.EXE 35152 RegSetValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation\ProgramCount SUCCESS Type: REG_DWORD, Length: 4, Data: 5
14494 01:19:49,4515780 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS
16446 01:19:55,6704097 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
16450 01:19:55,8616209 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS Desired Access: Set Value
16451 01:19:55,8620601 Explorer.EXE 35152 RegSetValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation\ProgramCount SUCCESS Type: REG_DWORD, Length: 4, Data: 4
16452 01:19:55,8621148 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS
16453 01:19:56,1306520 ehsched.exe 38072 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS Desired Access: Write
16454 01:19:56,1307738 ehsched.exe 38072 RegSetValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler\Heartbeat SUCCESS Type: REG_QWORD, Length: 8
16455 01:19:56,1309864 ehsched.exe 38072 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS
16456 01:19:56,1310130 ehsched.exe 38072 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS Desired Access: Read
16457 01:19:56,1310537 ehsched.exe 38072 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler\HeartbeatIntervalMs SUCCESS Type: REG_DWORD, Length: 4, Data: 30000
16458 01:19:56,1310923 ehsched.exe 38072 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS
16822 01:19:58,3203974 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
16823 01:19:58,4195678 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
16824 01:19:58,4197055 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16825 01:19:58,4198128 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
16826 01:19:58,4198312 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16828 01:19:58,4200421 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
16829 01:19:58,4201651 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16830 01:19:58,4202243 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
16831 01:19:58,4202397 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16833 01:19:58,4204171 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
16841 01:19:58,4210800 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x31c0000, Image Size: 0x10000
16842 01:19:58,4211300 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16844 01:19:58,4213177 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
16845 01:19:58,4214367 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16846 01:19:58,4215178 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
16847 01:19:58,4215334 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16849 01:19:58,4217636 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
16856 01:19:58,4219265 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16859 01:19:58,4223332 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x31a0000, Image Size: 0x10000
16860 01:19:58,4226517 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide SUCCESS Desired Access: Read
16861 01:19:58,4227830 ObjectDock.exe 5220 RegQueryValue HKLM\COMPONENTS\PreferExternalManifest NAME NOT FOUND Length: 20
16862 01:19:58,4228109 ObjectDock.exe 5220 RegCloseKey HKLM\COMPONENTS SUCCESS
16863 01:19:58,4231358 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
16864 01:19:58,4233797 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
16866 01:19:58,4236298 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16868 01:19:58,4238859 ObjectDock.exe 5220 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\StartMenuPosition.dll NAME NOT FOUND Length: 1.024
16870 01:19:58,4243329 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Name: \Program Files\Stardock\ObjectDock\StartMenuPosition.dll
16873 01:19:58,4244137 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\CrashRpt.dll SUCCESS Name: \PROGRA~1\Stardock\OBJECT~1\CrashRpt.dll
16880 01:19:58,4248291 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
16881 01:19:58,4249528 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16882 01:19:58,4250568 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
16883 01:19:58,4250749 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
16942 01:19:58,7539181 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
16943 01:19:58,7719299 Explorer.EXE 35152 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Name: \Program Files\Stardock\ObjectDock\ObjectDock.exe
16944 01:19:58,7729124 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
16945 01:19:58,7729462 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16946 01:19:58,7729708 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16947 01:19:58,7732200 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
16948 01:19:58,7732912 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16949 01:19:58,7733354 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
16950 01:19:58,7733465 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
16952 01:19:58,7734312 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
16953 01:19:58,7734480 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16954 01:19:58,7734625 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16955 01:19:58,7735471 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
16956 01:19:58,7736103 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16957 01:19:58,7736349 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
16958 01:19:58,7736444 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
16960 01:19:58,7736893 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS Desired Access: Read
16961 01:19:58,7737150 Explorer.EXE 35152 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Type: REG_SZ, Length: 22, Data: ObjectDock
16962 01:19:58,7738106 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS
16963 01:19:58,7749948 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
16964 01:19:58,7750230 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16965 01:19:58,7750456 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16966 01:19:58,7752661 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
16967 01:19:58,7753356 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16968 01:19:58,7753823 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
16969 01:19:58,7753940 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
16971 01:19:58,7758119 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
16972 01:19:58,7758321 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16973 01:19:58,7758483 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
16974 01:19:58,7759745 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
16975 01:19:58,7760402 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
16976 01:19:58,7760704 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
16977 01:19:58,7760804 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
16979 01:19:58,7761357 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS Desired Access: Read
16980 01:19:58,7761614 Explorer.EXE 35152 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Type: REG_SZ, Length: 22, Data: ObjectDock
16981 01:19:58,7762424 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS
16982 01:19:58,7763212 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS Desired Access: Set Value
16983 01:19:58,7765743 Explorer.EXE 35152 RegSetValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation\ProgramCount SUCCESS Type: REG_DWORD, Length: 4, Data: 5
16984 01:19:58,7766017 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS
17028 01:20:02,0574195 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
17029 01:20:02,0730676 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
17031 01:20:02,2346250 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS Desired Access: Set Value
17032 01:20:02,2350795 Explorer.EXE 35152 RegSetValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation\ProgramCount SUCCESS Type: REG_DWORD, Length: 4, Data: 4
17033 01:20:02,2351340 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS
17037 01:20:02,9460495 ObjectDock.exe 5220 Thread Create SUCCESS Thread ID: 40228
17594 01:28:52,0413852 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
17596 01:28:52,1402030 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
17597 01:28:52,1403371 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17598 01:28:52,1406771 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
17599 01:28:52,1406958 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17601 01:28:52,1409333 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
17602 01:28:52,1410529 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17603 01:28:52,1411124 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
17604 01:28:52,1411277 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17606 01:28:52,1413546 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
17614 01:28:52,1419404 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x2fd0000, Image Size: 0x10000
17615 01:28:52,1420373 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17617 01:28:52,1424086 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
17618 01:28:52,1425802 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17619 01:28:52,1426846 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
17620 01:28:52,1427036 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17622 01:28:52,1429023 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
17629 01:28:52,1430794 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17632 01:28:52,1434331 ObjectDock.exe 5220 Load Image C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Image Base: 0x2fd0000, Image Size: 0x10000
17633 01:28:52,1438471 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Policies\Microsoft\MUI\Settings NAME NOT FOUND Desired Access: Read
17634 01:28:52,1439814 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152 SUCCESS Desired Access: Maximum Allowed, Granted Access: All Access
17635 01:28:52,1440270 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Software\Policies\Microsoft\Control Panel\Desktop NAME NOT FOUND Desired Access: Read
17636 01:28:52,1440599 ObjectDock.exe 5220 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Control Panel\Desktop SUCCESS Desired Access: Read
17637 01:28:52,1440940 ObjectDock.exe 5220 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152 SUCCESS
17638 01:28:52,1441225 ObjectDock.exe 5220 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Control Panel\Desktop\PreferredUILanguages NAME NOT FOUND Length: 12
17639 01:28:52,1441695 ObjectDock.exe 5220 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\Control Panel\Desktop SUCCESS
17640 01:28:52,1443533 ObjectDock.exe 5220 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide SUCCESS Desired Access: Read
17641 01:28:52,1444323 ObjectDock.exe 5220 RegQueryValue HKLM\COMPONENTS\PreferExternalManifest NAME NOT FOUND Length: 20
17642 01:28:52,1444586 ObjectDock.exe 5220 RegCloseKey HKLM\COMPONENTS SUCCESS
17650 01:28:52,1447986 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
17653 01:28:52,1449257 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
17655 01:28:52,1451154 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17657 01:28:52,1454199 ObjectDock.exe 5220 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\StartMenuPosition.dll NAME NOT FOUND Length: 1.024
17658 01:28:52,1458920 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Name: \Program Files\Stardock\ObjectDock\StartMenuPosition.dll
17659 01:28:52,1459789 ObjectDock.exe 5220 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\CrashRpt.dll SUCCESS Name: \PROGRA~1\Stardock\OBJECT~1\CrashRpt.dll
17660 01:28:52,1463658 ObjectDock.exe 5220 QueryOpen C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll FAST IO DISALLOWED
17661 01:28:52,1464913 ObjectDock.exe 5220 CreateFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17662 01:28:52,1465809 ObjectDock.exe 5220 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 23-04-2007 16:56:20, ChangeTime: 21-02-2008 22:30:10, FileAttributes: A
17663 01:28:52,1465980 ObjectDock.exe 5220 CloseFile C:\Program Files\Stardock\ObjectDock\StartMenuPosition.dll SUCCESS
17719 01:28:52,5315729 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
17720 01:28:52,6947453 Explorer.EXE 35152 QueryNameInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Name: \Program Files\Stardock\ObjectDock\ObjectDock.exe
17721 01:28:52,6968509 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
17722 01:28:52,6968844 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17723 01:28:52,6969151 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17724 01:28:52,6971383 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
17725 01:28:52,6972247 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17726 01:28:52,6972666 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
17727 01:28:52,6972783 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
17729 01:28:52,6973624 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
17730 01:28:52,6973786 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17731 01:28:52,6973926 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17732 01:28:52,6974761 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
17733 01:28:52,6975448 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17734 01:28:52,6975694 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
17735 01:28:52,6975786 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
17737 01:28:52,6976228 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS Desired Access: Read
17738 01:28:52,6976487 Explorer.EXE 35152 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Type: REG_SZ, Length: 22, Data: ObjectDock
17739 01:28:52,6977583 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS
17740 01:28:52,6985156 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
17741 01:28:52,6985427 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17742 01:28:52,6985620 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17743 01:28:52,6987235 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
17744 01:28:52,6988031 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17745 01:28:52,6988394 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
17746 01:28:52,6988500 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
17748 01:28:52,6991995 Explorer.EXE 35152 RegQueryKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES SUCCESS Query: Name
17749 01:28:52,6992193 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17750 01:28:52,6992361 Explorer.EXE 35152 RegOpenKey HKCR\Applications\ObjectDock.exe NAME NOT FOUND Desired Access: Read
17751 01:28:52,6993453 Explorer.EXE 35152 QueryOpen C:\Program Files\Stardock\ObjectDock\ObjectDock.exe FAST IO DISALLOWED
17752 01:28:52,6994149 Explorer.EXE 35152 CreateFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
17753 01:28:52,6994437 Explorer.EXE 35152 QueryBasicInformationFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS CreationTime: 21-02-2008 22:30:10, LastAccessTime: 21-02-2008 22:30:10, LastWriteTime: 30-04-2007 19:43:54, ChangeTime: 22-02-2008 12:37:29, FileAttributes: A
17754 01:28:52,6994529 Explorer.EXE 35152 CloseFile C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS
17756 01:28:52,6994962 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS Desired Access: Read
17757 01:28:52,6995197 Explorer.EXE 35152 RegQueryValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files\Stardock\ObjectDock\ObjectDock.exe SUCCESS Type: REG_SZ, Length: 22, Data: ObjectDock
17758 01:28:52,6995923 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache SUCCESS
17759 01:28:52,6996853 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS Desired Access: Set Value
17760 01:28:52,6999320 Explorer.EXE 35152 RegSetValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation\ProgramCount SUCCESS Type: REG_DWORD, Length: 4, Data: 5
17761 01:28:52,6999831 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS
17927 01:28:56,0957287 ehsched.exe 38072 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS Desired Access: Write
17928 01:28:56,0958298 ehsched.exe 38072 RegSetValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler\Heartbeat SUCCESS Type: REG_QWORD, Length: 8
17929 01:28:56,0960022 ehsched.exe 38072 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS
17930 01:28:56,0960279 ehsched.exe 38072 RegOpenKey HKLM\Software\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS Desired Access: Read
17931 01:28:56,0960684 ehsched.exe 38072 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler\HeartbeatIntervalMs SUCCESS Type: REG_DWORD, Length: 4, Data: 30000
17932 01:28:56,0961027 ehsched.exe 38072 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler SUCCESS
17933 01:28:56,4932803 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
17934 01:28:56,5079657 ObjectDock.exe 5220 RegOpenKey HKLM\SOFTWARE\Microsoft\CTF\KnownClasses NAME NOT FOUND Desired Access: Read
17935 01:28:56,6726280 Explorer.EXE 35152 RegOpenKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS Desired Access: Set Value
17936 01:28:56,6730682 Explorer.EXE 35152 RegSetValue HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation\ProgramCount SUCCESS Type: REG_DWORD, Length: 4, Data: 4
17937 01:28:56,6731216 Explorer.EXE 35152 RegCloseKey HKU\S-1-5-21-2243429757-1675716134-3129586969-1152\SessionInformation SUCCESS