Process: iexplore.exe Pid: 988 Handle Type Access Name 0x14 Directory 0x00000003 \KnownDlls 0x18 File 0x00100001 \Device\KsecDD 0x20 Directory 0x000F000F \Windows 0x30 WindowStation 0x000F037F \Windows\WindowStations\WinSta0 0x34 Desktop 0x000F01FF \Default 0x38 WindowStation 0x000F037F \Windows\WindowStations\WinSta0 0x3C Key 0x000F003F HKLM 0x44 Key 0x000F003F HKCU 0x48 Directory 0x0002000F \BaseNamedObjects 0x4C Key 0x000F003F HKCU 0x50 Semaphore 0x001F0003 \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D} 0x54 File 0x00100020 F:\Documents and Settings\ikuznetsov\Рабочий стол 0x60 Section 0x000F0007 \BaseNamedObjects\CiceroSharedMem Default 0x64 Mutant 0x001F0001 \BaseNamedObjects\MSUIM.GlobalLangBarEventSink.Mutex 0x68 Mutant 0x001F0001 \BaseNamedObjects\MSUIM.GlobalCompartment.Mutex 0x6C Mutant 0x001F0001 \BaseNamedObjects\MSUIM.Assembly.Mutex 0x70 Mutant 0x001F0001 \BaseNamedObjects\MSUIM.Layouts.Mutex 0x74 Mutant 0x001F0001 \BaseNamedObjects\MSUIM.MarshalInterfaceMutex.TMD 0x78 Mutant 0x001F0001 \BaseNamedObjects\MSCTF.TimListMUTEX. 0x7C Section 0x000F001F \BaseNamedObjects\MSCTF.TimListSFM. 0x80 Semaphore 0x001F0003 \BaseNamedObjects\shell.{6D5313C0-8C62-11D1-B2CD-006097DF8C11} 0x84 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Explorer 0x88 Semaphore 0x001F0003 \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1} 0x8C Semaphore 0x001F0003 \BaseNamedObjects\shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57} 0x90 Key 0x000F003F HKCR 0x98 Key 0x000F003F HKCU 0xA0 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\COM3 0xA8 Key 0x00000010 HKU 0xB0 Key 0x000F003F HKCR 0xB8 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\COM3 0xC0 Key 0x00000010 HKU 0xC8 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\COM3 0xD0 Key 0x000F003F HKCR\ClsID 0xD8 Key 0x000F003F HKCR 0xE0 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\COM3 0xE8 Key 0x00000010 HKU 0xF0 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\COM3 0xF8 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\COM3 0x100 Key 0x000F003F HKCR\ClsID 0x10C Key 0x00020019 HKCU 0x11C Thread 0x001F03FF iexplore.exe(988): 1868 0x128 Port 0x001F0001 \RPC Control\OLE5B11925ECAE64A4AA7F0C3E9740F 0x134 Thread 0x001F03FF iexplore.exe(988): 2680 0x13C Thread 0x001F03FF iexplore.exe(988): 3000 0x140 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Internet Explorer\SECURITY\P3Global 0x144 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Internet Explorer\SECURITY\P3Sites 0x148 Semaphore 0x001F0003 \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1} 0x150 Key 0x00020019 HKCU 0x154 Key 0x0002001F HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings 0x158 Event 0x00100000 \BaseNamedObjects\crypt32LogoffEvent 0x15C File 0x0012019F F:\Documents and Settings\ikuznetsov\Local Settings\Temporary Internet Files\Content.IE5\index.dat 0x160 Mutant 0x00100000 \BaseNamedObjects\_!MSFTHISTORY!_ 0x164 Mutant 0x00100000 \BaseNamedObjects\f:!documents and settings!ikuznetsov!local settings!temporary internet files!content.ie5! 0x168 Section 0x00000002 \BaseNamedObjects\F:_Documents and Settings_ikuznetsov_Local Settings_Temporary Internet Files_Content.IE5_index.dat_3588096 0x16C Mutant 0x00100000 \BaseNamedObjects\f:!documents and settings!ikuznetsov!cookies! 0x170 File 0x0012019F F:\Documents and Settings\ikuznetsov\Cookies\index.dat 0x174 Mutant 0x00100000 \BaseNamedObjects\f:!documents and settings!ikuznetsov!local settings!history!history.ie5! 0x178 File 0x0012019F F:\Documents and Settings\ikuznetsov\Local Settings\History\History.IE5\index.dat 0x17C Section 0x00000002 \BaseNamedObjects\F:_Documents and Settings_ikuznetsov_Local Settings_History_History.IE5_index.dat_491520 0x180 Mutant 0x00100000 \BaseNamedObjects\WininetStartupMutex 0x188 Section 0x00000002 \BaseNamedObjects\F:_Documents and Settings_ikuznetsov_Cookies_index.dat_212992 0x18C Mutant 0x00100000 \BaseNamedObjects\WininetConnectionMutex 0x194 Mutant 0x00100000 \BaseNamedObjects\WininetProxyRegistryMutex 0x198 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Explorer 0x19C Key 0x00020019 HKCU 0x1A4 Key 0x00020019 HKCU 0x1A8 Key 0x00020019 HKCU 0x1AC Semaphore 0x001F0003 \BaseNamedObjects\shell.{090851A5-EB96-11D2-8BE4-00C04FA31A66} 0x1B0 Key 0x0002001F HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Explorer\RunMRU 0x1B4 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Internet Explorer\TypedURLs 0x1B8 Mutant 0x001F0001 \BaseNamedObjects\ZonesCacheCounterMutex 0x1BC Key 0x00020019 HKLM\SOFTWARE\MICROSOFT\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383} 0x1C0 Key 0x00020019 HKCU 0x1C4 Key 0x00020019 HKCU 0x1C8 Semaphore 0x001F0003 \BaseNamedObjects\shell._ie_sessioncount 0x1D0 Mutant 0x001F0001 \BaseNamedObjects\ZonesCounterMutex 0x1D4 Key 0x00020019 HKCU 0x1D8 Key 0x00020019 HKLM\SOFTWARE\MICROSOFT\Internet Explorer\Extensions\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} 0x1DC Section 0x000F0007 \BaseNamedObjects\UrlZonesSM_ikuznetsov 0x1E0 Key 0x00020019 HKCU 0x1E4 Thread 0x001F03FF iexplore.exe(988): 1868 0x1F4 Key 0x000F003F HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 0x1FC Key 0x000F003F HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 0x200 Thread 0x001F03FF iexplore.exe(988): 1860 0x204 Key 0x00020019 HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings\ZoneMap 0x210 Key 0x00020019 HKCU 0x214 Key 0x00020019 HKCU 0x228 Key 0x00020019 HKCU 0x22C Mutant 0x00100000 \BaseNamedObjects\RasPbFile 0x230 Key 0x00020019 HKCU 0x240 Thread 0x001F03FF iexplore.exe(988): 1860 0x268 Key 0x00020019 HKLM\SOFTWARE\MICROSOFT\Tracing\RASAPI32 0x278 Section 0x00000004 \BaseNamedObjects\SENS Information Cache 0x284 File 0x0012019F \Device\NamedPipe\ROUTER 0x288 Key 0x000F003F HKU 0x290 Key 0x00000003 HKCU 0x294 Key 0x000F003F HKLM\SYSTEM\ControlSet001\Hardware Profiles\0001 0x2A0 Event 0x001F0003 \BaseNamedObjects\userenv: User Profile setup event 0x2BC Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH..DDAJGD 0x2C0 File 0x00100001 \Device\KsecDD 0x2C4 Mutant 0x001F0001 \BaseNamedObjects\MSCTF.Shared.MUTEX.MGG 0x2C8 Section 0x000F001F \BaseNamedObjects\MSCTF.Shared.SFM.MGG 0x2CC Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.BH.PENCKD 0x2D0 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.DH.PENCKD 0x2D8 Key 0x00020019 HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\DRIVERS32 0x2DC Key 0x0000000C HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings\P3P\History 0x2E8 File 0x001F01FF \Device\Afd\Endpoint 0x2EC Thread 0x001F03FF iexplore.exe(988): 2608 0x2F0 File 0x001F01FF \Device\WS2IFSL\NifsPvd 0x2F4 File 0x001F01FF \Device\WS2IFSL\NifsSct 0x2F8 File 0x001F01FF \Device\Udp 0x2FC Thread 0x001F03FF iexplore.exe(988): 1864 0x304 Thread 0x001F03FF iexplore.exe(988): 1864 0x324 File 0x001F01FF \Device\Tcp 0x328 File 0x001F01FF \Device\Tcp 0x32C File 0x001200A0 \Device\Ip 0x330 File 0x00100003 \Device\Ip 0x334 File 0x00100081 \Device\Ip 0x338 Key 0x00020019 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage 0x33C Key 0x00020019 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters 0x340 Key 0x00020019 HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters\Interfaces 0x344 Key 0x00020019 HKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters 0x348 File 0x001F01FF \Device\Tcp 0x350 Thread 0x001F03FF iexplore.exe(988): 1864 0x35C Key 0x00020019 HKLM\SOFTWARE\MICROSOFT\Tracing\RASADHLP 0x364 Key 0x00020019 HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings\ZoneMap 0x36C Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.CH.PENCKD 0x374 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.HH.PENCKD 0x378 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.FH.PENCKD 0x384 File 0x001F01FF \Device\Afd\AsyncConnectHlp 0x388 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.AH.PENCKD 0x38C Key 0x00020019 HKCU 0x394 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.IH.PENCKD 0x398 Key 0x00020019 HKCU 0x39C File 0x00120089 F:\WINNT\system32\mlang.dat 0x3A0 Key 0x00020019 HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings\ZoneMap 0x3A4 Key 0x00020019 HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings\ZoneMap 0x3A8 Key 0x00020019 HKCU 0x3B0 Key 0x00020019 HKCU 0x3B4 Key 0x00020019 HKLM\SYSTEM\ControlSet001\Control\Nls\Codepage 0x3C8 Key 0x00020019 HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Internet Settings\ZoneMap 0x3CC Key 0x00020019 HKCU 0x3D4 Key 0x00020019 HKCU 0x3D8 Mutant 0x001F0001 \BaseNamedObjects\MSCTF.GCompartListMUTEX. 0x3DC Key 0x00020019 HKCU 0x3E0 Key 0x00020019 HKCU 0x3E4 Section 0x000F001F \BaseNamedObjects\MSCTF.GCompartListSFM. 0x3EC Key 0x00020019 HKCU 0x3F4 Key 0x00020019 HKCU 0x3F8 Key 0x00020019 HKCU 0x3FC Key 0x00020019 HKCU 0x408 Key 0x00020019 HKCU 0x40C Key 0x00020019 HKLM\SYSTEM\ControlSet001\Control\Nls\Locale 0x410 File 0x0012019F \Device\NamedPipe\ntsvcs 0x414 File 0x0012019F \Device\NamedPipe\WMIEP_3dc 0x418 File 0x0012019F \Device\NamedPipe\WMIEP_3dc 0x41C Key 0x00020019 HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts 0x420 Key 0x00020019 HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups 0x424 File 0x00120089 F:\WINNT\system32\mshtml.tlb 0x438 Key 0x00020019 HKCR\MIME\Database\Content Type 0x43C Key 0x00020019 HKCR\MIME\Database\Content Type 0x440 Section 0x000F0007 \BaseNamedObjects\MSIMGSIZECacheMap 0x448 Mutant 0x001F0001 \BaseNamedObjects\DDrawWindowListMutex 0x44C Key 0x00020019 HKCU 0x454 Key 0x00020019 HKCU 0x458 Key 0x00020019 HKCU 0x45C Key 0x00020019 HKCU 0x460 Mutant 0x001F0001 \BaseNamedObjects\DDrawDriverObjectListMutex 0x464 Mutant 0x001F0001 \BaseNamedObjects\__DDrawExclMode__ 0x468 Mutant 0x001F0001 \BaseNamedObjects\__DDrawCheckExclMode__ 0x470 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\DirectDraw 0x478 Key 0x00020019 HKCU 0x47C Key 0x00020019 HKCU 0x480 Thread 0x001F03FF iexplore.exe(988): 2152 0x484 Thread 0x001F03FF iexplore.exe(988): 2520 0x494 Key 0x00020019 HKCU 0x498 Key 0x000F003F HKLM\SOFTWARE\MICROSOFT\DirectDraw 0x49C Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.AI.PENCKD 0x4A0 Key 0x00020019 HKCU 0x4A8 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.PH.PENCKD 0x4AC File 0x00120089 F:\Documents and Settings\ikuznetsov\Local Settings\Temporary Internet Files\Content.IE5\KW0RSHEL\nonplus[1].htm 0x4B0 Key 0x00020019 HKCU 0x4BC Key 0x00020019 HKCU 0x4C0 Key 0x00020019 HKCU 0x4C4 Key 0x00020019 HKCU 0x4E4 Thread 0x001F03FF iexplore.exe(988): 2952 0x4E8 Key 0x000F003F HKCR\Excel.Sheet.8 0x504 Key 0x000F003F HKCR\Applications\notepad.exe 0x594 Key 0x00020019 HKCU 0x598 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.OH.PENCKD 0x5AC Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.EH.PENCKD 0x5EC Mutant 0x001F0001 \BaseNamedObjects\MSCTF.Shared.MUTEX.MEH 0x5F0 Section 0x000F0007 \BaseNamedObjects\MSCTF.Shared.SFM.MEH 0x5F8 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.GH.PENCKD 0x5FC Key 0x00020019 HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder 0x610 Key 0x00020019 HKCU 0x614 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.LH.PENCKD 0x618 Section 0x00000004 \BaseNamedObjects\RotHintTable 0x61C Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.JH.PENCKD 0x630 Mutant 0x001F0001 \BaseNamedObjects\f:!documents and settings!ikuznetsov!local settings!history!history.ie5!mshist012006011120060112! 0x634 File 0x0012019F F:\Documents and Settings\ikuznetsov\Local Settings\History\History.IE5\MSHist012006011120060112\index.dat 0x638 Mutant 0x001F0001 \BaseNamedObjects\_!SHMSFTHISTORY!_ 0x63C Section 0x000F0007 \BaseNamedObjects\F:_Documents and Settings_ikuznetsov_Local Settings_History_History.IE5_MSHist012006011120060112_index.dat_49152 0x640 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Windows\ShellNoRoam\MUICache 0x644 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Windows\ShellNoRoam 0x648 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.PG.PENCKD 0x64C Key 0x00020019 HKCU 0x650 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.KH.PENCKD 0x654 Token 0x0000000C NT AUTHORITY\SYSTEM 0x658 Event 0x00100002 \BaseNamedObjects\mixercallback 0x65C File 0x00100001 F:\Documents and Settings\ikuznetsov\Избранное 0x660 Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count 0x664 Key 0x00020019 HKCU 0x668 Mutant 0x001F0001 \BaseNamedObjects\_SHuassist.mtx 0x66C Key 0x000F003F HKCU\SOFTWARE\MICROSOFT\Windows\CURRENTVERSION\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count 0x670 Thread 0x001F03FF iexplore.exe(988): 1824 0x680 Key 0x00020019 HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\DRIVERS32 0x684 Event 0x00100002 \BaseNamedObjects\hardwaremixercallback 0x688 Mutant 0x00100000 \BaseNamedObjects\GuardMutexmmGlobalPnpInfoGuard 0x68C Event 0x00100002 \BaseNamedObjects\GuardEventmmGlobalPnpInfoGuard 0x690 Section 0x00000004 \BaseNamedObjects\mmGlobalPnpInfo 0x694 Semaphore 0x00100002 \BaseNamedObjects\GuardSemmmGlobalPnpInfoGuard 0x69C Mutant 0x00100000 \BaseNamedObjects\mxrapi 0x6A0 File 0x0012019F \Device\KSENUM#00000001\{9B365890-165F-11D0-A195-0020AFD156E4} 0x6A4 Section 0x00000006 \BaseNamedObjects\WDMAUD_Callbacks 0x6B0 File 0x0012019F \Device\NamedPipe\ntsvcs 0x6B4 Key 0x000F003F HKCR\Word.Document.8 0x6C8 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.MH.PENCKD 0x6D8 Section 0x000F0007 \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.MEH.NH.PENCKD