--- Process 5628 created --- Process 5628 loaded C:\Windows\System32\ntdll.dll at 00007ffa5ca80000 --- Process 5628 loaded C:\Windows\SysWOW64\ntdll.dll at 00000000775a0000 --- Process 5628 loaded C:\Windows\System32\wow64.dll at 00000000529b0000 --- Process 5628 loaded C:\Windows\System32\wow64win.dll at 0000000052a10000 --- Process 5628 loaded C:\Windows\System32\kernel32.dll at 0000000000900000 --- Process 5628 unloaded DLL at 0000000000900000 --- Process 5628 loaded C:\Windows\SysWOW64\kernel32.dll at 00000000767c0000 --- Process 5628 unloaded DLL at 00000000767c0000 --- Process 5628 loaded C:\Windows\System32\kernel32.dll at 0000000000900000 --- Process 5628 unloaded DLL at 0000000000900000 --- Process 5628 loaded C:\Windows\System32\user32.dll at 0000000000900000 --- Process 5628 unloaded DLL at 0000000000900000 --- Process 5628 loaded C:\Windows\System32\wow64cpu.dll at 00000000529a0000 --- Process 5628 loaded C:\Windows\SysWOW64\kernel32.dll at 00000000767c0000 --- Process 5628 loaded C:\Windows\SysWOW64\KernelBase.dll at 00000000746c0000 --- Process 5628 thread 8312 created --- Process 5628 loaded C:\Windows\SysWOW64\ole32.dll at 0000000076fb0000 --- Process 5628 loaded C:\Windows\SysWOW64\combase.dll at 00000000761e0000 --- Process 5628 loaded C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll at 0000000071a50000 --- Process 5628 loaded C:\Windows\SysWOW64\ucrtbase.dll at 00000000764d0000 --- Process 5628 thread 12908 created --- Process 5628 loaded C:\Windows\SysWOW64\rpcrt4.dll at 0000000077470000 --- Process 5628 loaded C:\Windows\SysWOW64\sspicli.dll at 0000000074040000 --- Process 5628 loaded C:\Windows\SysWOW64\cryptbase.dll at 0000000074030000 --- Process 5628 loaded C:\Windows\SysWOW64\bcryptprimitives.dll at 0000000077150000 --- Process 5628 loaded C:\Windows\SysWOW64\sechost.dll at 0000000074480000 --- Process 5628 loaded C:\Windows\SysWOW64\gdi32.dll at 00000000743b0000 --- Process 5628 loaded C:\Windows\SysWOW64\gdi32full.dll at 00000000771d0000 --- Process 5628 loaded C:\Windows\SysWOW64\win32u.dll at 00000000743e0000 --- Process 5628 loaded C:\Windows\SysWOW64\oleaut32.dll at 00000000770a0000 --- Process 5628 loaded C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll at 0000000073820000 --- Process 5628 loaded C:\Windows\SysWOW64\msvcp_win.dll at 0000000074400000 --- Process 5628 loaded C:\Windows\SysWOW64\user32.dll at 00000000744d0000 --- Process 5628 loaded C:\Windows\SysWOW64\advapi32.dll at 0000000074150000 --- Process 5628 loaded C:\Windows\SysWOW64\msvcrt.dll at 00000000765b0000 --- Process 5628 loaded C:\Windows\SysWOW64\shell32.dll at 0000000074c80000 --- Process 5628 loaded C:\Windows\SysWOW64\cfgmgr32.dll at 0000000074270000 --- Process 5628 loaded C:\Windows\SysWOW64\vcruntime140.dll at 00000000725c0000 --- Process 5628 loaded C:\Windows\SysWOW64\windows.storage.dll at 00000000768a0000 --- Process 5628 loaded C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll at 00000000717a0000 --- Process 5628 loaded C:\Windows\SysWOW64\powrprof.dll at 0000000076670000 --- Process 5628 loaded C:\Windows\SysWOW64\shlwapi.dll at 00000000742b0000 --- Process 5628 loaded C:\Windows\SysWOW64\kernel.appcore.dll at 0000000076fa0000 --- Process 5628 loaded C:\Windows\SysWOW64\SHCore.dll at 0000000074310000 --- Process 5628 loaded C:\Windows\SysWOW64\profapi.dll at 0000000077140000 --- Process 5628 loaded C:\Windows\SysWOW64\userenv.dll at 00000000736a0000 --- Process 5628, exception 4000001f at 000000007764748c --- Process 5628 loaded C:\Windows\SysWOW64\imm32.dll at 0000000076720000 --- Process 5628, exception e06d7363 at 000000007479a9f2 --- Process 5628 thread 8312 exited with status 0x0 --- Process 5628 thread 12908 exited with status 0x0 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\Office16\Wordcnv.dll at 0000000066ad0000 --- Process 5628 loaded C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.953_none_baad48403594ab3f\GdiPlus.dll at 0000000071ef0000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\Office16\OART.DLL at 000000006fd30000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\SystemX86\msvcp140.dll at 0000000068910000 --- Process 5628 loaded C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171\comctl32.dll at 00000000733f0000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Mso20win32client.dll at 00000000711c0000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Mso30win32client.dll at 0000000070d80000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Mso40UIwin32client.dll at 0000000002910000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\SystemX86\concrt140.dll at 00000000737e0000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Mso50win32client.dll at 0000000073780000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Mso98win32client.dll at 000000006f0f0000 --- Process 5628 loaded C:\Windows\SysWOW64\wtsapi32.dll at 0000000073000000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Mso99Lwin32client.dll at 000000006ebf0000 --- Process 5628 loaded C:\Windows\SysWOW64\msimg32.dll at 0000000073680000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\MSO.DLL at 000000006dc80000 --- Process 5628 loaded C:\Windows\SysWOW64\version.dll at 0000000072fe0000 --- Process 5628 loaded C:\Windows\SysWOW64\msi.dll at 0000000072210000 --- Process 5628 loaded C:\Windows\SysWOW64\bcrypt.dll at 00000000721f0000 --- Process 5628 loaded C:\Windows\SysWOW64\d2d1.dll at 000000006d7a0000 --- Process 5628 loaded C:\Windows\SysWOW64\crypt32.dll at 0000000076060000 --- Process 5628 loaded C:\Windows\SysWOW64\msasn1.dll at 0000000076e10000 --- Process 5628 loaded C:\Windows\SysWOW64\uxtheme.dll at 0000000073600000 --- Process 5628 loaded C:\Windows\SysWOW64\msctf.dll at 0000000077330000 --- Process 5628 loaded C:\Windows\SysWOW64\winsta.dll at 000000006c2b0000 --- Process 5628 loaded C:\Windows\SysWOW64\dxgi.dll at 0000000070820000 --- Process 5628 loaded C:\Windows\SysWOW64\ResourcePolicyClient.dll at 0000000069c60000 --- Process 5628 unloaded DLL at 0000000069c60000 --- Process 5628 thread 15172 created --- Process 5628 loaded C:\Windows\SysWOW64\mscoree.dll at 0000000071680000 --- Process 5628 loaded C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll at 0000000071600000 --- Process 5628 loaded C:\Windows\SysWOW64\DWrite.dll at 0000000069a60000 --- Process 5628 thread 13496 created --- Process 5628 thread 13492 created --- Process 5628 loaded C:\Windows\SysWOW64\dwmapi.dll at 0000000072f80000 --- Process 5628 loaded C:\Windows\SysWOW64\d3d10_1.dll at 0000000073750000 --- Process 5628 loaded C:\Windows\SysWOW64\d3d10_1core.dll at 0000000071740000 --- Process 5628 loaded C:\Windows\SysWOW64\d3d11.dll at 00000000709d0000 --- Process 5628 loaded C:\Windows\SysWOW64\d3d10warp.dll at 000000006d560000 --- Process 5628 loaded C:\Windows\SysWOW64\igdumd32.dll at 000000006d1b0000 --- Process 5628 loaded C:\Windows\SysWOW64\d3d10level9.dll at 0000000071de0000 --- Process 5628 thread 14216 created --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\RICHED20.DLL at 000000006cfd0000 --- Process 5628 thread 12156 created --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\Office16\CHART.DLL at 000000006c5c0000 --- Process 5628 loaded C:\Program Files (x86)\Microsoft Office\root\Office16\IVY.DLL at 000000006c440000 --- Process 5628 loaded C:\Windows\SysWOW64\coml2.dll at 00000000766c0000 --- Process 5628 thread 15264 created --- Process 5628 thread 8568 created --- Process 5628 thread 1948 created --- Process 5628 loaded C:\Windows\SysWOW64\propsys.dll at 0000000072e30000 --- Process 5628 loaded C:\Windows\SysWOW64\clbcatq.dll at 0000000074630000 --- Process 5628 loaded C:\Windows\SysWOW64\msxml6.dll at 0000000065930000 --- Process 5628 loaded C:\Windows\SysWOW64\secur32.dll at 00000000736e0000 --- Process 5628 thread 13496 exited with status 0x1 --- Process 5628 thread 12156 exited with status 0x0 --- Process 5628 thread 15172 exited with status 0x0 --- Process 5628 unloaded DLL at 0000000065930000 --- Process 5628 thread 14216 exited with status 0x0 --- Process 5628 unloaded DLL at 000000006d1b0000 --- Process 5628 unloaded DLL at 0000000071de0000 --- Process 5628 thread 13492 exited with status 0x0 --- Process 5628 unloaded DLL at 0000000071600000 --- Process 5628 unloaded DLL at 0000000071680000 --- Process 5628 unloaded DLL at 000000006d560000 --- Process 5628, exception 0000071a at 000000007479a9f2 --- Process 5628 unloaded DLL at 000000006cfd0000 --- Process 5628 unloaded DLL at 0000000066ad0000 --- Process 5628 thread 1948 exited with status 0x0 --- Process 5628 thread 8568 exited with status 0x0 --- Process 5628 thread 15264 exited with status 0x0 --- Process 5628, exception c0000005 at 000000006fdca6fd --- Process 5628 exited with status 0xc0000005