Summary:
NtGdiCreateBitmap(>) | 1 | NtOpenProcessToken(>) | 2 | NtQueryInformationProcess(>) | 9 | NtCreateSection(>) | 75 |
NtGdiInit(>) | 1 | NtQueryDefaultUILanguage(>) | 2 | NtQueryVirtualMemory(>) | 9 | NtContinue(>) | 99 |
NtGdiQueryFontAssocInfo(>) | 1 | NtSetInformationObject(>) | 2 | NtSetInformationThread(>) | 9 | NtQuerySystemInformation(>) | 125 |
NtGdiSelectBitmap(>) | 1 | NtUserGetProcessWindowStation(>) | 2 | NtUnmapViewOfSection(>) | 9 | NtOpenKey(>) | 134 |
NtOpenKeyedEvent(>) | 1 | NtCreateIoCompletion(>) | 3 | NtUserFindExistingCursorIcon(>) | 9 | NtResumeThread(>) | 139 |
NtOpenSymbolicLinkObject(>) | 1 | NtFreeVirtualMemory(>) | 3 | NtOpenThreadToken(>) | 10 | NtQueryInformationThread(>) | 140 |
NtQueryInstallUILanguage(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtSetInformationFile(>) | 10 | NtCreateThread(>) | 158 |
NtQueryObject(>) | 1 | NtOpenProcessTokenEx(>) | 3 | NtQuerySection(>) | 13 | NtRequestWaitReplyPort(>) | 174 |
NtQueryPerformanceCounter(>) | 1 | NtOpenThreadTokenEx(>) | 3 | NtQueryDirectoryFile(>) | 14 | NtTestAlert(>) | 185 |
NtQuerySymbolicLinkObject(>) | 1 | NtQueryDefaultLocale(>) | 3 | NtUserRegisterClassExWOW(>) | 14 | NtRegisterThreadTerminatePort(>) | 189 |
NtQuerySystemTime(>) | 1 | NtReadFile(>) | 3 | NtCreateFile(>) | 15 | NtDuplicateObject(>) | 195 |
NtRaiseException(>) | 1 | NtSecureConnectPort(>) | 3 | NtSetValueKey(>) | 16 | NtQueryValueKey(>) | 252 |
NtSetInformationProcess(>) | 1 | NtWriteFile(>) | 4 | NtCreateKey(>) | 18 | NtProtectVirtualMemory(>) | 258 |
NtUserCallNoParam(>) | 1 | NtGdiGetStockObject(>) | 5 | NtOpenSection(>) | 23 | NtClose(>) | 318 |
NtUserGetObjectInformation(>) | 1 | NtConnectPort(>) | 6 | NtOpenFile(>) | 25 | NtAllocateVirtualMemory(>) | 368 |
NtUserGetThreadDesktop(>) | 1 | NtCreateMutant(>) | 6 | NtDeviceIoControlFile(>) | 36 | NtSetEventBoostPriority(>) | 686 |
NtCallbackReturn(>) | 2 | NtQueryInformationToken(>) | 6 | NtMapViewOfSection(>) | 37 | NtWaitForSingleObject(>) | 958 |
NtGdiCreateSolidBrush(>) | 2 | NtQueryVolumeInformationFile(>) | 6 | NtQueryAttributesFile(>) | 41 | ||
NtNotifyChangeKey(>) | 2 | NtFsControlFile(>) | 8 | NtFlushInstructionCache(>) | 51 | ||
NtOpenDirectoryObject(>) | 2 |
!\226\265\277d\201\375\253\301\233\375\203;\310sZ\367\10\215>\23R\363\225B9\247\212\350\315\325\370i\356\364-\2\275\7\57$\257\33\31\310\\14\261\21\324\263Gb\322`Au\201\32)\367\264\375<\225\26", ) !\226\265\277d\201\375\253\301\233\375\203;\310sZ\367\10\215>\23R\363\225B9\247\212\350\315\325\370i\356\364-\2\275\7\57$\257\33\31\310\\14\261\21\324\263Gb\322`Au\201\32)\367\264\375<\225\26", ) == 0x0 01701 2016 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshtcpip.dll"}, 11072556, ... }, 11072556, ... 01702 384 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 01701 2016 NtQueryAttributesFile ... ) == 0x0 01702 384 NtCreateEvent ... 428, ) == 0x0 01703 2016 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshtcpip.dll"}, 5, 96, ... }, 5, 96, ... 01704 384 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 0}, 0x0, 0x0, 15527428, 188, ... , {12, 2, 1, 0}, 0x0, 0x0, 15527428, 188, ... 01703 2016 NtOpenFile ... 432, {status=0x0, info=1}, ) == 0x0 01704 384 NtConnectPort ... 436, 0x0, 0x0, 0x0, 188, ) == 0x0 01705 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81880, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81880, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\1\0\0\344\4\0\0L\2\0\0" ... ... 01706 2016 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 432, ... 01705 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81882, 0} ... {28, 56, reply, 0, 1252, 896, 81882, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\1\0\0\344\4\0\0L\2\0\0" ) ) == 0x0 01706 2016 NtCreateSection ... 440, ) == 0x0 01707 896 NtResumeThread (424, ... 01708 2016 NtClose (432, ... 01707 896 NtResumeThread ... 1, ) == 0x0 01708 2016 NtClose ... ) == 0x0 01709 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01710 2016 NtMapViewOfSection (440, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... 01711 384 NtRequestWaitReplyPort (436, {200, 224, new_msg, 0, 1384080, 12, 2, 1} (436, {200, 224, new_msg, 0, 1384080, 12, 2, 1} "\0\3\24\0\274\0\0\0\4>\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0@\3\24\0\4\0\0\0\1\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\1\0\0\0\341\324\200\323%\14\37\272\20\36\25\0`\1\24\0\12\0\0\0\0\0\0\0\0\0\0\2(\0\0\0\30\36\25\04\335\353sh\3\24\08\36\25\0`\1\24\0\0\0\0\0\0\0\0\08\36\25\0P\0\0\0@\36\25\0\360\6\221|@\3\24\0P\0\0\0\346\31\0\0\0\0\24\0\204\354\354\0\372\31\221|\30\364\354\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... ... 01712 588 NtWaitForSingleObject (88, 0, 0x0, ... 01710 2016 NtMapViewOfSection ... (0x860000), 0x0, 20480, ) == 0x0 01711 384 NtRequestWaitReplyPort ... {200, 224, reply, 0, 1252, 384, 81883, 0} ... {200, 224, reply, 0, 1252, 384, 81883, 0} "\7\3\24\0\274\0\0\0\4>\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\1\0\0\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\1\0\0\0\341\324\200\323%\14\37\272\20\36\25\0`\1\24\0\12\0\0\0\0\0\0\0\0\0\0\2(\0\0\0\30\36\25\04\335\353sh\3\24\08\36\25\0`\1\24\0\0\0\0\0\0\0\0\08\36\25\0P\0\0\0@\36\25\0\360\6\221|@\3\24\0P\0\0\0\346\31\0\0\0\0\24\0\204\354\354\0\372\31\221|\30\364\354\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 01709 896 NtAllocateVirtualMemory ... 49086464, 1048576, ) == 0x0 01713 384 NtRequestWaitReplyPort (436, {64, 88, new_msg, 0, 0, 0, 0, 0} (436, {64, 88, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\2\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... ... 01714 896 NtAllocateVirtualMemory (-1, 50126848, 0, 8192, 4096, 4, ... 50126848, 8192, ) == 0x0 01715 896 NtProtectVirtualMemory (-1, (0x2fce000), 4096, 260, ... (0x2fce000), 4096, 4, ) == 0x0 01716 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01713 384 NtRequestWaitReplyPort ... {52, 76, reply, 0, 1252, 384, 81884, 0} ... {52, 76, reply, 0, 1252, 384, 81884, 0} "\2\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\230\37\12\0\1\0\0\0\1\0\0\0\300\250|\207\377\377\377\0" ) ) == 0x0 01717 2016 NtClose (440, ... 01716 896 NtCreateThread ... 432, {1252, 1652}, ) == 0x0 01717 2016 NtClose ... ) == 0x0 01718 896 NtQueryInformationThread (432, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff94000,Pid=1252,Tid=1652,}, 0x0, ) == 0x0 01719 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81882, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81882, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0t\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81885, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0t\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81885, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81882, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0t\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81885, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0t\6\0\0" ) ) == 0x0 01720 2016 NtUnmapViewOfSection (-1, 0x860000, ... 01721 384 NtClose (428, ... 01720 2016 NtUnmapViewOfSection ... ) == 0x0 01721 384 NtClose ... ) == 0x0 01722 896 NtResumeThread (432, ... 01723 384 NtClose (436, ... 01722 896 NtResumeThread ... 1, ) == 0x0 01723 384 NtClose ... ) == 0x0 01724 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01725 384 NtWaitForSingleObject (88, 0, 0x0, ... 01724 896 NtAllocateVirtualMemory ... 50135040, 1048576, ) == 0x0 01726 896 NtAllocateVirtualMemory (-1, 51175424, 0, 8192, 4096, 4, ... 51175424, 8192, ) == 0x0 01727 896 NtProtectVirtualMemory (-1, (0x30ce000), 4096, 260, ... (0x30ce000), 4096, 4, ) == 0x0 01728 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 436, {1252, 1376}, ) == 0x0 01729 896 NtQueryInformationThread (436, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff93000,Pid=1252,Tid=1376,}, 0x0, ) == 0x0 01730 2016 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshtcpip.dll"}, 11072864, ... }, 11072864, ... 01731 1652 NtWaitForSingleObject (88, 0, 0x0, ... 01730 2016 NtQueryAttributesFile ... ) == 0x0 01732 2016 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshtcpip.dll"}, 5, 96, ... 428, {status=0x0, info=1}, ) }, 5, 96, ... 428, {status=0x0, info=1}, ) == 0x0 01733 2016 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 428, ... 440, ) == 0x0 01734 2016 NtQuerySection (440, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01735 2016 NtClose (428, ... ) == 0x0 01736 2016 NtMapViewOfSection (440, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71a90000), 0x0, 32768, ) == 0x0 01737 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81885, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81885, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0`\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81887, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0`\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81887, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81885, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0`\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81887, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0`\5\0\0" ) ) == 0x0 01738 896 NtResumeThread (436, ... 1, ) == 0x0 01739 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 51183616, 1048576, ) == 0x0 01740 896 NtAllocateVirtualMemory (-1, 52224000, 0, 8192, 4096, 4, ... 52224000, 8192, ) == 0x0 01741 896 NtProtectVirtualMemory (-1, (0x31ce000), 4096, 260, ... (0x31ce000), 4096, 4, ) == 0x0 01742 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01743 2016 NtClose (440, ... 01744 1376 NtWaitForSingleObject (88, 0, 0x0, ... 01743 2016 NtClose ... ) == 0x0 01745 2016 NtProtectVirtualMemory (-1, (0x71a91000), 128, 4, ... (0x71a91000), 4096, 32, ) == 0x0 01746 2016 NtProtectVirtualMemory (-1, (0x71a91000), 4096, 32, ... (0x71a91000), 4096, 4, ) == 0x0 01747 2016 NtFlushInstructionCache (-1, 1906905088, 128, ... ) == 0x0 01742 896 NtCreateThread ... 440, {1252, 1436}, ) == 0x0 01748 896 NtQueryInformationThread (440, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff92000,Pid=1252,Tid=1436,}, 0x0, ) == 0x0 01749 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81887, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81887, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\234\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81888, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\234\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81888, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81887, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\234\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81888, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\234\5\0\0" ) ) == 0x0 01750 896 NtResumeThread (440, ... 1, ) == 0x0 01751 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 52232192, 1048576, ) == 0x0 01752 896 NtAllocateVirtualMemory (-1, 53272576, 0, 8192, 4096, 4, ... 53272576, 8192, ) == 0x0 01753 2016 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshtcpip.dll"}, ... }, ... 01754 1436 NtWaitForSingleObject (88, 0, 0x0, ... 01753 2016 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01755 2016 NtSetEventBoostPriority (88, ... 01712 588 NtWaitForSingleObject ... ) == 0x0 01756 588 NtSetEventBoostPriority (88, ... 01725 384 NtWaitForSingleObject ... ) == 0x0 01757 384 NtSetEventBoostPriority (88, ... 01731 1652 NtWaitForSingleObject ... ) == 0x0 01758 1652 NtSetEventBoostPriority (88, ... 01744 1376 NtWaitForSingleObject ... ) == 0x0 01759 1376 NtSetEventBoostPriority (88, ... 01754 1436 NtWaitForSingleObject ... ) == 0x0 01760 1436 NtTestAlert (... ) == 0x0 01759 1376 NtSetEventBoostPriority ... ) == 0x0 01758 1652 NtSetEventBoostPriority ... ) == 0x0 01757 384 NtSetEventBoostPriority ... ) == 0x0 01756 588 NtSetEventBoostPriority ... ) == 0x0 01755 2016 NtSetEventBoostPriority ... ) == 0x0 01761 896 NtProtectVirtualMemory (-1, (0x32ce000), 4096, 260, ... 01762 1436 NtContinue (52231472, 1, ... 01763 1376 NtTestAlert (... 01764 1652 NtTestAlert (... 01765 384 NtCreateKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... }, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... , 0, ... 01766 588 NtTestAlert (... 01761 896 NtProtectVirtualMemory ... (0x32ce000), 4096, 4, ) == 0x0 01767 1436 NtRegisterThreadTerminatePort (24, ... 01763 1376 NtTestAlert ... ) == 0x0 01764 1652 NtTestAlert ... ) == 0x0 01765 384 NtCreateKey ... 428, 2, ) == 0x0 01766 588 NtTestAlert ... ) == 0x0 01768 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01767 1436 NtRegisterThreadTerminatePort ... ) == 0x0 01769 1376 NtContinue (51182896, 1, ... 01770 1652 NtContinue (50134320, 1, ... 01771 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... }, ... 01772 588 NtContinue (49085744, 1, ... 01768 896 NtCreateThread ... 444, {1252, 1368}, ) == 0x0 01773 1436 NtAllocateVirtualMemory (-1, 1384448, 0, 4096, 4096, 4, ... 01774 1376 NtRegisterThreadTerminatePort (24, ... 01775 1652 NtRegisterThreadTerminatePort (24, ... 01771 384 NtOpenKey ... 448, ) == 0x0 01776 588 NtRegisterThreadTerminatePort (24, ... 01777 896 NtQueryInformationThread (444, Basic, 28, ... 01773 1436 NtAllocateVirtualMemory ... 1384448, 4096, ) == 0x0 01774 1376 NtRegisterThreadTerminatePort ... ) == 0x0 01775 1652 NtRegisterThreadTerminatePort ... ) == 0x0 01778 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... }, ... 01776 588 NtRegisterThreadTerminatePort ... ) == 0x0 01777 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff91000,Pid=1252,Tid=1368,}, 0x0, ) == 0x0 01779 1436 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01780 1376 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01781 1652 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01778 384 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01782 588 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01783 2016 NtClose (408, ... 01784 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81888, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81888, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0X\5\0\0" ... ... 01779 1436 NtDuplicateObject ... 452, ) == 0x0 01780 1376 NtDuplicateObject ... 456, ) == 0x0 01781 1652 NtDuplicateObject ... 460, ) == 0x0 01785 384 NtQueryValueKey (428, (428, "Hostname", Partial, 144, ... , Partial, 144, ... 01783 2016 NtClose ... ) == 0x0 01784 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81889, 0} ... {28, 56, reply, 0, 1252, 896, 81889, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0X\5\0\0" ) ) == 0x0 01786 1436 NtWaitForSingleObject (64, 0, {0, 0}, ... 01787 1376 NtWaitForSingleObject (64, 0, {0, 0}, ... 01788 1652 NtWaitForSingleObject (64, 0, {0, 0}, ... 01785 384 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 28, ) }, 28, ) == 0x0 01789 2016 NtCreateFile (0xc0100000, {24, 0, 0x42, 0, 0, (0xc0100000, {24, 0, 0x42, 0, 0, "\Device\Afd\Endpoint"}, 0x0, 0, 3, 3, 0, 11075200, 67, ... }, 0x0, 0, 3, 3, 0, 11075200, 67, ... 01790 896 NtResumeThread (444, ... 01786 1436 NtWaitForSingleObject ... ) == 0x102 01787 1376 NtWaitForSingleObject ... ) == 0x102 01788 1652 NtWaitForSingleObject ... ) == 0x102 01791 384 NtQueryValueKey (428, (428, "Hostname", Partial, 144, ... , Partial, 144, ... 01789 2016 NtCreateFile ... 408, {status=0x0, info=0}, ) == 0x0 01790 896 NtResumeThread ... 1, ) == 0x0 01792 1436 NtWaitForSingleObject (124, 0, 0x0, ... 01793 1376 NtWaitForSingleObject (124, 0, 0x0, ... 01794 1652 NtWaitForSingleObject (124, 0, 0x0, ... 01791 384 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 28, ) }, 28, ) == 0x0 01795 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x1207b, (408, 108, 0x0, 0x0, 0x1207b, "\7\0\0\0x\1\24\0\340\0\0\0\216\326\220|", 16, 16, ... , 16, 16, ... 01796 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01797 384 NtClose (428, ... 01795 2016 NtDeviceIoControlFile ... {status=0x0, info=16}, ... {status=0x0, info=16}, "\7\0\0\00\207\273\201\0 \0\0\230\353s\201", ) , ) == 0x0 01782 588 NtDuplicateObject ... 464, ) == 0x0 01798 1368 NtTestAlert (... 01797 384 NtClose ... ) == 0x0 01796 896 NtAllocateVirtualMemory ... 53280768, 1048576, ) == 0x0 01799 588 NtWaitForSingleObject (64, 0, {0, 0}, ... 01798 1368 NtTestAlert ... ) == 0x0 01800 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x1207b, (408, 108, 0x0, 0x0, 0x1207b, "\6\0\0\00\207\273\201\0 \0\0\230\353s\201", 16, 16, ... , 16, 16, ... 01801 896 NtAllocateVirtualMemory (-1, 54321152, 0, 8192, 4096, 4, ... 01799 588 NtWaitForSingleObject ... ) == 0x102 01802 1368 NtContinue (53280048, 1, ... 01800 2016 NtDeviceIoControlFile ... {status=0x0, info=16}, ... {status=0x0, info=16}, "\6\0\0\00\207\273\201\0 \0\0\230\353s\201", ) , ) == 0x0 01801 896 NtAllocateVirtualMemory ... 54321152, 8192, ) == 0x0 01803 588 NtWaitForSingleObject (124, 0, 0x0, ... 01804 1368 NtRegisterThreadTerminatePort (24, ... 01805 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x12047, (408, 108, 0x0, 0x0, 0x12047, "\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\20\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \0\0\0 \0\0\0\0\0\0\1\0\0\0\351\3\0\0f\0\2\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0h\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\0 \0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0n\0t\0r\0o\0l\0S\0e\0t\0\0\1\0\0\0\1\0\0\1\0\0\0 \0\0\0s\0\\0T\0c\0p\0i\0p\0\\0P\0a\0r\0a\0m\0e\0t\0e\0r\0s\0\0\0\0\0", 248, 16, ... , 248, 16, ... 01806 896 NtProtectVirtualMemory (-1, (0x33ce000), 4096, 260, ... 01804 1368 NtRegisterThreadTerminatePort ... ) == 0x0 01805 2016 NtDeviceIoControlFile ... {status=0x0, info=0}, "", ) == 0x0 01806 896 NtProtectVirtualMemory ... (0x33ce000), 4096, 4, ) == 0x0 01807 384 NtClose (448, ... 01808 2016 NtWaitForSingleObject (56, 0, {0, 0}, ... 01809 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01807 384 NtClose ... ) == 0x0 01808 2016 NtWaitForSingleObject ... ) == 0x102 01810 1368 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01811 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\21\202\302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01812 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x12003, (408, 108, 0x0, 0x0, 0x12003, "\0\0\0\0\1\0\0\0\16\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0", 26, 26, ... , 26, 26, ... 01810 1368 NtDuplicateObject ... 448, ) == 0x0 01813 384 NtQuerySystemInformation (TimeOfDay, 48, ... 01812 2016 NtDeviceIoControlFile ... {status=0x0, info=428}, ... {status=0x0, info=428}, "\1\0\0\0\1\0\0\0\16\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 01814 1368 NtWaitForSingleObject (64, 0, {0, 0}, ... 01813 384 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 01815 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x12047, (408, 108, 0x0, 0x0, 0x12047, "\1\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\20\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \0\0\0 \0\0\0\0\0\0\1\0\0\0\351\3\0\0f\0\2\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0h\0\0\0(\0*\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\0 \0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0n\0t\0r\0o\0l\0S\0e\0t\0\0\1\0\0\0\1\0\0\1\0\0\0 \0\0\0s\0\\0T\0c\0p\0i\0p\0\\0P\0a\0r\0a\0m\0e\0t\0e\0r\0s\0\0\0\0\0", 248, 0, ... , 248, 0, ... 01814 1368 NtWaitForSingleObject ... ) == 0x102 01816 384 NtQuerySystemInformation (ProcessorTimes, 48, ... 01815 2016 NtDeviceIoControlFile ... {status=0x0, info=0}, 0x0, ) == 0x0 01817 1368 NtWaitForSingleObject (124, 0, 0x0, ... 01809 896 NtCreateThread ... 468, {1252, 724}, ) == 0x0 01816 384 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 01818 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x12037, (408, 108, 0x0, 0x0, 0x12037, "\2\0\0\0", 4, 8, ... , 4, 8, ... 01819 896 NtQueryInformationThread (468, Basic, 28, ... 01820 384 NtQuerySystemInformation (Performance, 312, ... 01818 2016 NtDeviceIoControlFile ... {status=0x0, info=8}, ... {status=0x0, info=8}, "\0\0\0\0\0\0\0\0", ) , ) == 0x0 01819 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff90000,Pid=1252,Tid=724,}, 0x0, ) == 0x0 01820 384 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 01821 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x1200b, (408, 108, 0x0, 0x0, 0x1200b, "\0\376\250\0\5\0\0\0\0\256\24\0", 12, 0, ... , 12, 0, ... 01822 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81889, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81889, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\1\0\0\344\4\0\0\324\2\0\0" ... ... 01823 384 NtQuerySystemInformation (Exception, 16, ... 01821 2016 NtDeviceIoControlFile ... {status=0x0, info=0}, 0x0, ) == 0x0 01822 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81890, 0} ... {28, 56, reply, 0, 1252, 896, 81890, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\1\0\0\344\4\0\0\324\2\0\0" ) ) == 0x0 01823 384 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 01824 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x12047, (408, 108, 0x0, 0x0, 0x12047, "\1\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\20\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \0\0\0 \0\0\1\0\0\0\1\0\0\0\351\3\0\0f\0\2\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0h\0\0\0\310\376\250\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\6\0\0\0\0 \0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0n\0t\0r\0o\0l\0S\0e\0t\0\0\1\0\0\0\1\0\0\1\0\0\0 \0\0\0s\0\\0T\0c\0p\0i\0p\0\\0P\0a\0r\0a\0m\0e\0t\0e\0r\0s\0\0\0\0\0", 248, 0, ... , 248, 0, ... 01825 384 NtQuerySystemInformation (Lookaside, 32, ... 01824 2016 NtDeviceIoControlFile ... {status=0x0, info=0}, 0x0, ) == 0x0 01826 896 NtResumeThread (468, ... 01825 384 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 01826 896 NtResumeThread ... 1, ) == 0x0 01827 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 01828 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01827 384 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 01828 896 NtAllocateVirtualMemory ... 54329344, 1048576, ) == 0x0 01829 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 01830 896 NtAllocateVirtualMemory (-1, 55369728, 0, 8192, 4096, 4, ... 01829 384 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 01830 896 NtAllocateVirtualMemory ... 55369728, 8192, ) == 0x0 01831 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 01832 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x1202f, 0x0, 0, 26, ... 01833 724 NtTestAlert (... 01834 896 NtProtectVirtualMemory (-1, (0x34ce000), 4096, 260, ... 01832 2016 NtDeviceIoControlFile ... {status=0x0, info=26}, ... {status=0x0, info=26}, "\1\0\0\0\1\0\0\0\16\0\2\0\25\262\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 01833 724 NtTestAlert ... ) == 0x0 01834 896 NtProtectVirtualMemory ... (0x34ce000), 4096, 4, ) == 0x0 01835 2016 NtCreateEvent (0x100003, 0x0, 1, 0, ... 01836 724 NtContinue (54328624, 1, ... 01837 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01835 2016 NtCreateEvent ... 472, ) == 0x0 01838 724 NtRegisterThreadTerminatePort (24, ... 01837 896 NtCreateThread ... 476, {1252, 1276}, ) == 0x0 01839 2016 NtWaitForSingleObject (472, 0, 0x0, ... 01838 724 NtRegisterThreadTerminatePort ... ) == 0x0 01840 896 NtQueryInformationThread (476, Basic, 28, ... 01831 384 NtCreateKey ... -2147482764, 2, ) == 0x0 01840 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff8f000,Pid=1252,Tid=1276,}, 0x0, ) == 0x0 01841 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "$\214\31\315\25\315"SFCH\301t*\30p\344E\206\234t\276\306\236\243\323\11\345\177\3562\273\345\267\340\225,\30\261}w\266F^\224\217\323.\275\271\302\251GI\321\266&\11\244\233\350\266,\204m\340\22\251^\207\211\300w\205\252\221Q\205\357#", 80, ... , 0, 3, (-2147482764, "Seed", 0, 3, "$\214\31\315\25\315"SFCH\301t*\30p\344E\206\234t\276\306\236\243\323\11\345\177\3562\273\345\267\340\225,\30\261}w\266F^\224\217\323.\275\271\302\251GI\321\266&\11\244\233\350\266,\204m\340\22\251^\207\211\300w\205\252\221Q\205\357#", 80, ... SFCH\301t*\30p\344E\206\234t\276\306\236\243\323\11\345\177\3562\273\345\267\340\225,\30\261}w\266F^\224\217\323.\275\271\302\251GI\321\266&\11\244\233\350\266,\204m\340\22\251^\207\211\300w\205\252\221Q\205\357#", 80, ... 01842 724 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01841 384 NtSetValueKey ... ) == 0x0 01842 724 NtDuplicateObject ... 480, ) == 0x0 01843 384 NtClose (-2147482764, ... 01844 724 NtWaitForSingleObject (64, 0, {0, 0}, ... 01843 384 NtClose ... ) == 0x0 01844 724 NtWaitForSingleObject ... ) == 0x102 01811 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\10N\221\341\260\372\340\215\351\347\211\212\246P^Ds\213\314jb\307\310.\17\311\202\334E.x$\334\310\273Al\217\242\337\321p\244\255\310\226_?_Oi\271\234g\202e\26`+kp\350\230\334\21k\347\310v\245\26\7C\25\274\233\304r\3777\3\21\375\243\210>\327\217\217\301j\267P\306%,\34\211,\35a0\3723\221\373_\221q\24}\16\263\310\25\204\314\353\301m\244\301\273\365\200\363\324\340\2166\35\315$?\237\216C\331\361#=\15\202{N]\305\177y\207\354\311\317\1\300\222S\323d\377\252\12t\216{\321\244\353\251Z\300M\247\221yc6\356Hd\250taT\305\5A\260\202\13\366H#\317\246(\254\304\10\35\0\362\355\336\24\372c\347\363>f\335'\263E\210\243\251\206\335\347\322\354FX]}\307\240{[n\24\32\275\3254\237\11]c\342<\361\370,\237\256P\310C\13H\12h", ) , ) == 0x0 01845 724 NtWaitForSingleObject (124, 0, 0x0, ... 01846 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81890, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81890, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\1\0\0\344\4\0\0\374\4\0\0" ... ... 01847 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\2\246\221\24r\226\232E\17 \302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01846 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81891, 0} ... {28, 56, reply, 0, 1252, 896, 81891, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\1\0\0\344\4\0\0\374\4\0\0" ) ) == 0x0 01848 384 NtQuerySystemInformation (TimeOfDay, 48, ... 01849 896 NtResumeThread (476, ... 01848 384 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 01849 896 NtResumeThread ... 1, ) == 0x0 01850 384 NtQuerySystemInformation (ProcessorTimes, 48, ... 01851 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01850 384 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 01852 1276 NtTestAlert (... 01853 384 NtQuerySystemInformation (Performance, 312, ... 01852 1276 NtTestAlert ... ) == 0x0 01851 896 NtAllocateVirtualMemory ... 55377920, 1048576, ) == 0x0 01854 1276 NtContinue (55377200, 1, ... 01855 896 NtAllocateVirtualMemory (-1, 56418304, 0, 8192, 4096, 4, ... 01856 1276 NtRegisterThreadTerminatePort (24, ... 01855 896 NtAllocateVirtualMemory ... 56418304, 8192, ) == 0x0 01856 1276 NtRegisterThreadTerminatePort ... ) == 0x0 01857 896 NtProtectVirtualMemory (-1, (0x35ce000), 4096, 260, ... 01853 384 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 01857 896 NtProtectVirtualMemory ... (0x35ce000), 4096, 4, ) == 0x0 01858 384 NtQuerySystemInformation (Exception, 16, ... 01859 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01858 384 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 01860 1276 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01861 384 NtQuerySystemInformation (Lookaside, 32, ... 01860 1276 NtDuplicateObject ... 484, ) == 0x0 01861 384 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 01862 1276 NtWaitForSingleObject (64, 0, {0, 0}, ... 01863 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 01862 1276 NtWaitForSingleObject ... ) == 0x102 01859 896 NtCreateThread ... 488, {1252, 220}, ) == 0x0 01864 1276 NtWaitForSingleObject (124, 0, 0x0, ... 01865 896 NtQueryInformationThread (488, Basic, 28, ... 01863 384 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 01865 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff8e000,Pid=1252,Tid=220,}, 0x0, ) == 0x0 01866 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 01867 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81891, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81891, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\1\0\0\344\4\0\0\334\0\0\0" ... ... 01866 384 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 01867 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81892, 0} ... {28, 56, reply, 0, 1252, 896, 81892, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\1\0\0\344\4\0\0\334\0\0\0" ) ) == 0x0 01868 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482764, 2, ) }, 0, 0x0, 0, ... -2147482764, 2, ) == 0x0 01869 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "\272Q\26Z\322g\211\322\341#\37f\17\11\330\363\272\330\33L\25\7\252+!\300\311*\242,\255Q\27T\314G8\276\245\224c\200\227\20\215\322\277\227\214\300e\226\303\317|$^\327>\272O\344\205I\316t0HL|\11\244\264w\274\214", 80, ... ) , 0, 3, (-2147482764, "Seed", 0, 3, "\272Q\26Z\322g\211\322\341#\37f\17\11\330\363\272\330\33L\25\7\252+!\300\311*\242,\255Q\27T\314G8\276\245\224c\200\227\20\215\322\277\227\214\300e\226\303\317|$^\327>\272O\344\205I\316t0HL|\11\244\264w\274\214", 80, ... ) , 80, ... ) == 0x0 01870 384 NtClose (-2147482764, ... ) == 0x0 01847 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "Z(\371\303\300,\350\255\211\341\260\263L\313x\226fy_twV}\255oP\360\334\341A\204\10\207\32\204WC\315N\352\267$\234\27m\357\12/\232;\231y\313\227\213\361\13\331$}\24\213l\234\352\263\24\257x\230kE\334\226\\223\224\274\313%$\236\373d\32\370r\17\375Z\36\261\330`\304\234\226uz\253\300\201\3379d]\210\202~\313\263\340\33\266\250\17/)\231\22\340`k\252\30@\26\2268\221m\336\2\1\4\306}\220e\22*\243\23\353\37h2\6\233\232\345!-$\3yp\5\14\244\346\14\365\346\11\377sM\263\241\326\241\247\311A\3\27<\346\273T-,\k\221\:\311oX\34)A\312\17*\255\341_\33\331[\357O\11\313\37\343\312P\354"O\257\349\34\377\371\245e{\5WJl^^0\357\17\205\241I\245\271\352[O`u257\349\34\377\371\245e{\5WJl^^0\357\17\205\241I\245\271\352[O`u305\345b\261-\216\17\374\261*\2137", ) == 0x0 01871 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\2\246\221\24r\226\232E\2303\24r\226\232E\17 \302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01872 384 NtQuerySystemInformation (TimeOfDay, 48, ... 01873 896 NtResumeThread (488, ... 1, ) == 0x0 01874 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 56426496, 1048576, ) == 0x0 01875 896 NtAllocateVirtualMemory (-1, 57466880, 0, 8192, 4096, 4, ... 57466880, 8192, ) == 0x0 01876 896 NtProtectVirtualMemory (-1, (0x36ce000), 4096, 260, ... (0x36ce000), 4096, 4, ) == 0x0 01877 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 492, {1252, 1328}, ) == 0x0 01878 896 NtQueryInformationThread (492, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff8d000,Pid=1252,Tid=1328,}, 0x0, ) == 0x0 01872 384 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 01879 220 NtTestAlert (... 01880 384 NtQuerySystemInformation (ProcessorTimes, 48, ... 01879 220 NtTestAlert ... ) == 0x0 01880 384 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 01881 220 NtContinue (56425776, 1, ... 01882 384 NtQuerySystemInformation (Performance, 312, ... 01883 220 NtRegisterThreadTerminatePort (24, ... 01882 384 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 01883 220 NtRegisterThreadTerminatePort ... ) == 0x0 01884 384 NtQuerySystemInformation (Exception, 16, ... 01885 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81892, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81892, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\1\0\0\344\4\0\00\5\0\0" ... ... 01886 220 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01885 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81893, 0} ... {28, 56, reply, 0, 1252, 896, 81893, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\1\0\0\344\4\0\00\5\0\0" ) ) == 0x0 01886 220 NtDuplicateObject ... 496, ) == 0x0 01887 896 NtResumeThread (492, ... 01888 220 NtWaitForSingleObject (64, 0, {0, 0}, ... 01887 896 NtResumeThread ... 1, ) == 0x0 01888 220 NtWaitForSingleObject ... ) == 0x102 01889 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01890 220 NtWaitForSingleObject (124, 0, 0x0, ... 01884 384 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 01891 1328 NtTestAlert (... 01889 896 NtAllocateVirtualMemory ... 57475072, 1048576, ) == 0x0 01892 384 NtQuerySystemInformation (Lookaside, 32, ... 01891 1328 NtTestAlert ... ) == 0x0 01893 896 NtAllocateVirtualMemory (-1, 58515456, 0, 8192, 4096, 4, ... 01892 384 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 01894 1328 NtContinue (57474352, 1, ... 01893 896 NtAllocateVirtualMemory ... 58515456, 8192, ) == 0x0 01895 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 01896 1328 NtRegisterThreadTerminatePort (24, ... 01897 896 NtProtectVirtualMemory (-1, (0x37ce000), 4096, 260, ... 01895 384 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 01896 1328 NtRegisterThreadTerminatePort ... ) == 0x0 01897 896 NtProtectVirtualMemory ... (0x37ce000), 4096, 4, ) == 0x0 01898 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 01899 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01900 1328 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01898 384 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 01900 1328 NtDuplicateObject ... 500, ) == 0x0 01901 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 01902 1328 NtAllocateVirtualMemory (-1, 1388544, 0, 4096, 4096, 4, ... 01901 384 NtCreateKey ... -2147482764, 2, ) == 0x0 01902 1328 NtAllocateVirtualMemory ... 1388544, 4096, ) == 0x0 01903 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "j\243\311(3\253\272\344~q\253\253\1a\232\324q\376\7}IG2\317\304\252\4&x\302?N\353:\320\305D\216z\117\214\33)\2776\222\321GIp\11\372\256\256\361\303\265h\25\263\371Y\203\324\314\21\6\254V\326Q\361\272\263\32+;\12\353", 80, ... , 0, 3, (-2147482764, "Seed", 0, 3, "j\243\311(3\253\272\344~q\253\253\1a\232\324q\376\7}IG2\317\304\252\4&x\302?N\353:\320\305D\216z\117\214\33)\2776\222\321GIp\11\372\256\256\361\303\265h\25\263\371Y\203\324\314\21\6\254V\326Q\361\272\263\32+;\12\353", 80, ... , 80, ... 01904 1328 NtWaitForSingleObject (64, 0, {0, 0}, ... 01903 384 NtSetValueKey ... ) == 0x0 01905 384 NtClose (-2147482764, ... ) == 0x0 01871 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\265\327A\375\241!\16k8\4 \246\344\363\336\235\245]\303\14\361b\262\244C@\27\237\2338\223\16\333\11\37\17\37\374*s\203=ce\341\10\372\1\215A\15\246=\214m\39\335+\236\260\225\371Q\34\372!G\20J\315cC\337\346\250\245\262\256%\305(\303\302\223;\305\300M\27\263\36\16\274\301\307X\253\25*\253(d;\177\17w>\346:\303\3332+\200}iG\36Z}4\255\327\325ja&\20\243N\244\236\341\264!\255m\270p\336\227O\3478\234\303\364\11/D\333\314\245\377\254\263)\206\306&\233\304\343\367\5\2Fi\330$.\367\21\2){\5\316\20'\245\225\335\246o\314\206\221\337\333\362\35\357\356PQ\220\217@\370\215&\204&\37\273\262\207\271c\301\351\327[\353\227\26\244\331\313\325\251\4\334\373\335\212K g\360 VT\364\324\242\320\272\365I9u\27\\213\332?\323\232\2100\2557", ) , ) == 0x0 01906 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\2\246\221\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\17 \302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01907 384 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01908 384 NtQuerySystemInformation (ProcessorTimes, 48, ... 01899 896 NtCreateThread ... 504, {1252, 1636}, ) == 0x0 01904 1328 NtWaitForSingleObject ... ) == 0x102 01909 896 NtQueryInformationThread (504, Basic, 28, ... 01910 1328 NtWaitForSingleObject (124, 0, 0x0, ... 01909 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff8c000,Pid=1252,Tid=1636,}, 0x0, ) == 0x0 01911 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81893, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81893, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0d\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0d\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81894, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81893, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0d\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0d\6\0\0" ) ) == 0x0 01912 896 NtResumeThread (504, ... 1, ) == 0x0 01913 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 58523648, 1048576, ) == 0x0 01914 896 NtAllocateVirtualMemory (-1, 59564032, 0, 8192, 4096, 4, ... 59564032, 8192, ) == 0x0 01908 384 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 01915 1636 NtTestAlert (... 01916 384 NtQuerySystemInformation (Performance, 312, ... 01915 1636 NtTestAlert ... ) == 0x0 01916 384 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 01917 1636 NtContinue (58522928, 1, ... 01918 384 NtQuerySystemInformation (Exception, 16, ... 01919 1636 NtRegisterThreadTerminatePort (24, ... 01918 384 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 01919 1636 NtRegisterThreadTerminatePort ... ) == 0x0 01920 384 NtQuerySystemInformation (Lookaside, 32, ... 01921 896 NtProtectVirtualMemory (-1, (0x38ce000), 4096, 260, ... 01922 1636 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01921 896 NtProtectVirtualMemory ... (0x38ce000), 4096, 4, ) == 0x0 01922 1636 NtDuplicateObject ... 508, ) == 0x0 01923 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01924 1636 NtWaitForSingleObject (64, 0, {0, 0}, ... ) == 0x102 01925 1636 NtWaitForSingleObject (124, 0, 0x0, ... 01923 896 NtCreateThread ... 512, {1252, 704}, ) == 0x0 01926 896 NtQueryInformationThread (512, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff8b000,Pid=1252,Tid=704,}, 0x0, ) == 0x0 01927 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81894, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0\300\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81897, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0\300\2\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81897, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0\300\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81897, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0\300\2\0\0" ) ) == 0x0 01920 384 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 01928 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01929 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01930 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482764, 2, ) }, 0, 0x0, 0, ... -2147482764, 2, ) == 0x0 01931 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "'\216\270\2765.\20\353\270\234h4)H.\275\322\204\267\2539\204!,\245\274\326\31]\277\26=\375\5'\347\331\376\365\357v^\13\364M\312\344\227\314{\15\1\274\257C\340\365\31=\311\13zi\1\200\335#\250\351as\351%\306\206\263>\331\244\326", 80, ... ) , 0, 3, (-2147482764, "Seed", 0, 3, "'\216\270\2765.\20\353\270\234h4)H.\275\322\204\267\2539\204!,\245\274\326\31]\277\26=\375\5'\347\331\376\365\357v^\13\364M\312\344\227\314{\15\1\274\257C\340\365\31=\311\13zi\1\200\335#\250\351as\351%\306\206\263>\331\244\326", 80, ... ) , 80, ... ) == 0x0 01932 384 NtClose (-2147482764, ... ) == 0x0 01906 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\3461\4\253\225d\27a\227;\372\267\15\32\272tS||z\303\35\6\215\36#\24\26{?p\371s/\267\27+\243\3272O\272\257\367\331\306\346\315x\340\221a\251\360\320\201oS\305\326\370\36\273\373\327ZwD\240\10\305\307ME\1|p$\364\23&\242\364\262~\245\237\343\352\321\252\263bH\270C\262\354Peb~\340\260\215\374(\374v\217\357#\213*\24\233N\27#\303\213\0\202t6Id\316\345\315\275\246}\237\0\227[e? \356\211\25,\1\6W\10\206&\253&n\372\205\252\360\305+\\245\361\341~\272w\310\223\332\30\336jr_\226\371\234]~\236B.t{\23\262\304esW=\365D\365\23\302j\35u\24\344\334(\341W\244:\237\3107\253^h\227\29S\210y`\346\304\5C\251\303p__\216\26\311\20\262\26\356\212\357f*B\335\345%ZP\327\321\7\2558?\206\247J", ) , ) == 0x0 01933 896 NtResumeThread (512, ... 1, ) == 0x0 01934 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 59572224, 1048576, ) == 0x0 01935 896 NtAllocateVirtualMemory (-1, 60612608, 0, 8192, 4096, 4, ... 60612608, 8192, ) == 0x0 01936 896 NtProtectVirtualMemory (-1, (0x39ce000), 4096, 260, ... (0x39ce000), 4096, 4, ) == 0x0 01937 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 516, {1252, 1152}, ) == 0x0 01938 896 NtQueryInformationThread (516, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff8a000,Pid=1252,Tid=1152,}, 0x0, ) == 0x0 01939 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\2\246\221\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\17 \302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01940 704 NtTestAlert (... 01941 384 NtQuerySystemInformation (TimeOfDay, 48, ... 01940 704 NtTestAlert ... ) == 0x0 01941 384 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 01942 704 NtContinue (59571504, 1, ... 01943 384 NtQuerySystemInformation (ProcessorTimes, 48, ... 01944 704 NtRegisterThreadTerminatePort (24, ... 01943 384 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 01944 704 NtRegisterThreadTerminatePort ... ) == 0x0 01945 384 NtQuerySystemInformation (Performance, 312, ... 01946 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81897, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81897, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\2\0\0\344\4\0\0\200\4\0\0" ... ... 01947 704 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01946 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81898, 0} ... {28, 56, reply, 0, 1252, 896, 81898, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\2\0\0\344\4\0\0\200\4\0\0" ) ) == 0x0 01947 704 NtDuplicateObject ... 520, ) == 0x0 01948 896 NtResumeThread (516, ... 01949 704 NtWaitForSingleObject (64, 0, {0, 0}, ... 01948 896 NtResumeThread ... 1, ) == 0x0 01949 704 NtWaitForSingleObject ... ) == 0x102 01950 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 01951 704 NtWaitForSingleObject (124, 0, 0x0, ... 01945 384 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 01952 1152 NtTestAlert (... 01950 896 NtAllocateVirtualMemory ... 60620800, 1048576, ) == 0x0 01953 384 NtQuerySystemInformation (Exception, 16, ... 01952 1152 NtTestAlert ... ) == 0x0 01954 896 NtAllocateVirtualMemory (-1, 61661184, 0, 8192, 4096, 4, ... 01953 384 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 01955 1152 NtContinue (60620080, 1, ... 01954 896 NtAllocateVirtualMemory ... 61661184, 8192, ) == 0x0 01956 384 NtQuerySystemInformation (Lookaside, 32, ... 01957 1152 NtRegisterThreadTerminatePort (24, ... 01958 896 NtProtectVirtualMemory (-1, (0x3ace000), 4096, 260, ... 01956 384 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 01957 1152 NtRegisterThreadTerminatePort ... ) == 0x0 01958 896 NtProtectVirtualMemory ... (0x3ace000), 4096, 4, ) == 0x0 01959 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 01960 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01961 1152 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01959 384 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 01961 1152 NtDuplicateObject ... 524, ) == 0x0 01962 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 01963 1152 NtWaitForSingleObject (64, 0, {0, 0}, ... 01962 384 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 01963 1152 NtWaitForSingleObject ... ) == 0x102 01964 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 01965 1152 NtWaitForSingleObject (124, 0, 0x0, ... 01964 384 NtCreateKey ... -2147482764, 2, ) == 0x0 01960 896 NtCreateThread ... 528, {1252, 1228}, ) == 0x0 01966 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "\265\275\360\256\247\12\251\324\330\367\7\224\16\216\3437vw\240\231\341.\234R\360\33NWJ~\365\344\11\340A\375\304\251\375\313\331\315:\307\200bo\377\264\341'\220\34\0\324\201\7Z\302?\7\232W\354\246\264\32\215\14O-(f~Bo\274%\341\247", 80, ... , 0, 3, (-2147482764, "Seed", 0, 3, "\265\275\360\256\247\12\251\324\330\367\7\224\16\216\3437vw\240\231\341.\234R\360\33NWJ~\365\344\11\340A\375\304\251\375\313\331\315:\307\200bo\377\264\341'\220\34\0\324\201\7Z\302?\7\232W\354\246\264\32\215\14O-(f~Bo\274%\341\247", 80, ... , 80, ... 01967 896 NtQueryInformationThread (528, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff89000,Pid=1252,Tid=1228,}, 0x0, ) == 0x0 01968 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81898, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81898, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\314\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81899, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\314\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81899, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81898, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\314\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81899, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\314\4\0\0" ) ) == 0x0 01969 896 NtResumeThread (528, ... 1, ) == 0x0 01970 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 61669376, 1048576, ) == 0x0 01971 896 NtAllocateVirtualMemory (-1, 62709760, 0, 8192, 4096, 4, ... 62709760, 8192, ) == 0x0 01966 384 NtSetValueKey ... ) == 0x0 01972 1228 NtTestAlert (... 01973 384 NtClose (-2147482764, ... 01972 1228 NtTestAlert ... ) == 0x0 01973 384 NtClose ... ) == 0x0 01974 1228 NtContinue (61668656, 1, ... 01939 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\312\254\320sE\231\247\226\23\251\13\334r\20\316?!\273g\202\58\353z'lI\36\27\300Z\25$\343\336\275J\21GN\335}%\316\312\1\272\304j9\346\234F\320G\373\11\325\353\263\275-\15\251\232\320\234\253\244\252\335w\344mC\322;\23\221\276\347+"\2\300\3\212\211\20L\235\26\242\217\1\254v\354\300 i\35{\10\256\211]%\6\302\2352\212\304\211\27\354/X\241\266\321\324>\4\277)\236Q\312\220*k]\260\325R;\367\305{\201\303\242*xDg534\303\231^-\224\272\33\215\240\211\21\360\321\223\352\257\34\223\265p\371\375j\10\310@5|o\351\353> \210\337`\227x\322\235\204\@\336\3727)?\201\4+\336~\357\10n\210#\342\274k\324\207z,AW\362e\311T\374>\p8O\340\300;>\177\314_#\32-`\234\230\203\213\232\352\30j\366\361y\255%^v7I", ) \2\300\3\212\211\20L\235\26\242\217\1\254v\354\300 i\35{\10\256\211]%\6\302\2352\212\304\211\27\354/X\241\266\321\324>\4\277)\236Q\312\220*k]\260\325R;\367\305{\201\303\242*xDg534\303\231^-\224\272\33\215\240\211\21\360\321\223\352\257\34\223\265p\371\375j\10\310@5|o\351\353> \210\337`\227x\322\235\204\@\336\3727)?\201\4+\336~\357\10n\210#\342\274k\324\207z,AW\362e\311T\374>\p8O\340\300;>\177\314_#\32-`\234\230\203\213\232\352\30j\366\361y\255%^v7I", ) == 0x0 01975 1228 NtRegisterThreadTerminatePort (24, ... 01976 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\2\246\221\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\17 \302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01975 1228 NtRegisterThreadTerminatePort ... ) == 0x0 01977 384 NtQuerySystemInformation (TimeOfDay, 48, ... 01978 896 NtProtectVirtualMemory (-1, (0x3bce000), 4096, 260, ... 01979 1228 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 01978 896 NtProtectVirtualMemory ... (0x3bce000), 4096, 4, ) == 0x0 01979 1228 NtDuplicateObject ... 532, ) == 0x0 01980 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01981 1228 NtWaitForSingleObject (64, 0, {0, 0}, ... 01980 896 NtCreateThread ... 536, {1252, 792}, ) == 0x0 01981 1228 NtWaitForSingleObject ... ) == 0x102 01982 896 NtQueryInformationThread (536, Basic, 28, ... 01983 1228 NtWaitForSingleObject (124, 0, 0x0, ... 01982 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff88000,Pid=1252,Tid=792,}, 0x0, ) == 0x0 01977 384 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 01984 384 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01985 384 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01986 384 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01987 384 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01988 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01989 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 01990 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81899, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81899, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\30\3\0\0" ... {28, 56, reply, 0, 1252, 896, 81900, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\30\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81900, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81899, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\30\3\0\0" ... {28, 56, reply, 0, 1252, 896, 81900, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\30\3\0\0" ) ) == 0x0 01991 896 NtResumeThread (536, ... 1, ) == 0x0 01992 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 62717952, 1048576, ) == 0x0 01993 896 NtAllocateVirtualMemory (-1, 63758336, 0, 8192, 4096, 4, ... 63758336, 8192, ) == 0x0 01994 896 NtProtectVirtualMemory (-1, (0x3cce000), 4096, 260, ... (0x3cce000), 4096, 4, ) == 0x0 01995 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 01989 384 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 01996 792 NtTestAlert (... 01997 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 01996 792 NtTestAlert ... ) == 0x0 01997 384 NtCreateKey ... -2147482764, 2, ) == 0x0 01998 792 NtContinue (62717232, 1, ... 01999 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "x\271&\347\221\27\325\277\355(r\344\334\362\370;\317\11y\2`\270o\365\365\337\21\200\37\366\345b\224\321\1g\1NK\316 D\221?\260\20\355\303\263\262\253\247\207\221S\364S\276O\256M\306\241\0B\345\30\21\261\2574/_\326^\370\366 \243,", 80, ... , 0, 3, (-2147482764, "Seed", 0, 3, "x\271&\347\221\27\325\277\355(r\344\334\362\370;\317\11y\2`\270o\365\365\337\21\200\37\366\345b\224\321\1g\1NK\316 D\221?\260\20\355\303\263\262\253\247\207\221S\364S\276O\256M\306\241\0B\345\30\21\261\2574/_\326^\370\366 \243,", 80, ... , 80, ... 02000 792 NtRegisterThreadTerminatePort (24, ... 01999 384 NtSetValueKey ... ) == 0x0 02000 792 NtRegisterThreadTerminatePort ... ) == 0x0 02001 384 NtClose (-2147482764, ... 01995 896 NtCreateThread ... 540, {1252, 1484}, ) == 0x0 02002 792 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02003 896 NtQueryInformationThread (540, Basic, 28, ... 02002 792 NtDuplicateObject ... 544, ) == 0x0 02003 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff87000,Pid=1252,Tid=1484,}, 0x0, ) == 0x0 02004 792 NtWaitForSingleObject (64, 0, {0, 0}, ... 02005 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81900, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81900, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\2\0\0\344\4\0\0\314\5\0\0" ... ... 02004 792 NtWaitForSingleObject ... ) == 0x102 02005 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81901, 0} ... {28, 56, reply, 0, 1252, 896, 81901, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\2\0\0\344\4\0\0\314\5\0\0" ) ) == 0x0 02006 792 NtWaitForSingleObject (124, 0, 0x0, ... 02001 384 NtClose ... ) == 0x0 02007 896 NtResumeThread (540, ... 01976 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "Y\24&\226\305\366f\255\305\\321\335\227\303\246\211C\203\340\305\242\302l\222\33\3\357\350x\376\316\247\370\243\25\303\200u{\321*[\355!\232,\365\314\21@2k\201\265\230\371\7a\343\254.P\2\240\316\244n
r\317\263\354\221T\355\377\313\231\2"", ) r\317\263\354\221T\355\377\313\231\2"", ) == 0x0 02007 896 NtResumeThread ... 1, ) == 0x0 02008 384 NtDeviceIoControlFile (404, 0, 0x0, 0x0, 0x390008, (404, 0, 0x0, 0x0, 0x390008, "\301\327\320\342\20\337\324\3006\253\305$\364\2\246\221\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\2303\24r\226\232E\17 \302\306/hhw*\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 02009 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02010 384 NtQuerySystemInformation (TimeOfDay, 48, ... 02009 896 NtAllocateVirtualMemory ... 63766528, 1048576, ) == 0x0 02010 384 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 02011 896 NtAllocateVirtualMemory (-1, 64806912, 0, 8192, 4096, 4, ... 02012 384 NtQuerySystemInformation (ProcessorTimes, 48, ... 02011 896 NtAllocateVirtualMemory ... 64806912, 8192, ) == 0x0 02013 1484 NtTestAlert (... 02012 384 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 02013 1484 NtTestAlert ... ) == 0x0 02014 384 NtQuerySystemInformation (Performance, 312, ... 02015 1484 NtContinue (63765808, 1, ... 02014 384 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 02016 1484 NtRegisterThreadTerminatePort (24, ... 02017 384 NtQuerySystemInformation (Exception, 16, ... 02016 1484 NtRegisterThreadTerminatePort ... ) == 0x0 02017 384 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 02018 896 NtProtectVirtualMemory (-1, (0x3dce000), 4096, 260, ... 02019 384 NtQuerySystemInformation (Lookaside, 32, ... 02018 896 NtProtectVirtualMemory ... (0x3dce000), 4096, 4, ) == 0x0 02020 1484 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02021 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02020 1484 NtDuplicateObject ... 548, ) == 0x0 02021 896 NtCreateThread ... 552, {1252, 888}, ) == 0x0 02022 1484 NtWaitForSingleObject (64, 0, {0, 0}, ... 02023 896 NtQueryInformationThread (552, Basic, 28, ... 02022 1484 NtWaitForSingleObject ... ) == 0x102 02023 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff86000,Pid=1252,Tid=888,}, 0x0, ) == 0x0 02024 1484 NtWaitForSingleObject (124, 0, 0x0, ... 02019 384 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 02025 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81901, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81901, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\2\0\0\344\4\0\0x\3\0\0" ... ... 02026 384 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 02025 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81902, 0} ... {28, 56, reply, 0, 1252, 896, 81902, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\2\0\0\344\4\0\0x\3\0\0" ) ) == 0x0 02026 384 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 02027 896 NtResumeThread (552, ... 02028 384 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 02027 896 NtResumeThread ... 1, ) == 0x0 02028 384 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 02029 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02030 384 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 02031 888 NtTestAlert (... 02029 896 NtAllocateVirtualMemory ... 64815104, 1048576, ) == 0x0 02031 888 NtTestAlert ... ) == 0x0 02032 896 NtAllocateVirtualMemory (-1, 65855488, 0, 8192, 4096, 4, ... 02033 888 NtContinue (64814384, 1, ... 02032 896 NtAllocateVirtualMemory ... 65855488, 8192, ) == 0x0 02034 888 NtRegisterThreadTerminatePort (24, ... 02035 896 NtProtectVirtualMemory (-1, (0x3ece000), 4096, 260, ... 02034 888 NtRegisterThreadTerminatePort ... ) == 0x0 02035 896 NtProtectVirtualMemory ... (0x3ece000), 4096, 4, ) == 0x0 02030 384 NtCreateKey ... -2147482764, 2, ) == 0x0 02036 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02037 384 NtSetValueKey (-2147482764, (-2147482764, "Seed", 0, 3, "\7kTO\7\262m\315\232P>x\316\237<]0\211\346\320\224\27\341\235\2076,[\21\367\332\213._\226\234\364\303\223\16\36\366\3o\317\346}\23\202\346\272\210\347>\243\236!~!R}=\353\305\6\257&\353\32\253\13\273\30\2\317\336\232\356\36\255", 80, ... , 0, 3, (-2147482764, "Seed", 0, 3, "\7kTO\7\262m\315\232P>x\316\237<]0\211\346\320\224\27\341\235\2076,[\21\367\332\213._\226\234\364\303\223\16\36\366\3o\317\346}\23\202\346\272\210\347>\243\236!~!R}=\353\305\6\257&\353\32\253\13\273\30\2\317\336\232\356\36\255", 80, ... , 80, ... 02038 888 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02037 384 NtSetValueKey ... ) == 0x0 02038 888 NtDuplicateObject ... 556, ) == 0x0 02039 384 NtClose (-2147482764, ... 02040 888 NtWaitForSingleObject (64, 0, {0, 0}, ... 02039 384 NtClose ... ) == 0x0 02040 888 NtWaitForSingleObject ... ) == 0x102 02008 384 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\4\226\261\377\262|p\230\7*|i~\255-}\330\21:\313\31\345\222\21@\32\273\375\377\241\215\356\367\7M\240Xc^\27\343\257`@P\344\301{G\266*\17DQ%\363\243\247\`l\250]\364\231:\355\255\337\342\200\343\235\230\37\34v(\313\3\250\213\20I\321\212(\2366\|\221\310d\227\276P_~\235\2353\2208\271\367u\250\367\177D\262\271)\342\351\211p\336\224\257\337\365\217VL)\6@\20\302\31W\270\372\22\376\370\5\215\270*\347tGy\22>\224\262TNV\3\37\323\15}\315\306\345\315\337\254\230\324\253\20\353K&A\372\324\332|Ro3\226\205\264\346\350\272\5\205\277\231]\342\253\263(\234\250\14\323r\272\15\3238?\326?\270\371\232@\263\375$\24\367f\376\351\336\26j\20)\266\344q<\221r\214V* A\22\234\204|\2543`\332\21cr7\340\335\250v\332\7\31\303", ) , ) == 0x0 02041 888 NtWaitForSingleObject (124, 0, 0x0, ... 02036 896 NtCreateThread ... 560, {1252, 1120}, ) == 0x0 02042 384 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02043 896 NtQueryInformationThread (560, Basic, 28, ... 02042 384 NtCreateEvent ... 564, ) == 0x0 02043 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff85000,Pid=1252,Tid=1120,}, 0x0, ) == 0x0 02044 384 NtSetEventBoostPriority (472, ... 02045 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81902, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81902, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\344\4\0\0`\4\0\0" ... ... 01839 2016 NtWaitForSingleObject ... ) == 0x0 02044 384 NtSetEventBoostPriority ... ) == 0x0 02046 2016 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 02045 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81903, 0} ... {28, 56, reply, 0, 1252, 896, 81903, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\344\4\0\0`\4\0\0" ) ) == 0x0 02046 2016 NtAllocateVirtualMemory ... 1392640, 4096, ) == 0x0 02047 384 NtWaitForSingleObject (284, 0, 0x0, ... 02048 896 NtResumeThread (560, ... 1, ) == 0x0 02049 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 65863680, 1048576, ) == 0x0 02050 896 NtAllocateVirtualMemory (-1, 66904064, 0, 8192, 4096, 4, ... 66904064, 8192, ) == 0x0 02051 896 NtProtectVirtualMemory (-1, (0x3fce000), 4096, 260, ... (0x3fce000), 4096, 4, ) == 0x0 02052 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 568, {1252, 840}, ) == 0x0 02053 896 NtQueryInformationThread (568, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff84000,Pid=1252,Tid=840,}, 0x0, ) == 0x0 02054 2016 NtSetEventBoostPriority (284, ... 02055 1120 NtAllocateVirtualMemory (-1, 8871936, 0, 4096, 4096, 4, ... 02047 384 NtWaitForSingleObject ... ) == 0x0 02054 2016 NtSetEventBoostPriority ... ) == 0x0 02056 384 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 0}, 0x0, 0x0, 15527276, 188, ... , {12, 2, 1, 0}, 0x0, 0x0, 15527276, 188, ... 02055 1120 NtAllocateVirtualMemory ... 8871936, 4096, ) == 0x0 02057 2016 NtAllocateVirtualMemory (-1, 1396736, 0, 4096, 4096, 4, ... 02058 1120 NtTestAlert (... 02057 2016 NtAllocateVirtualMemory ... 1396736, 4096, ) == 0x0 02058 1120 NtTestAlert ... ) == 0x0 02059 2016 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02060 1120 NtContinue (65862960, 1, ... 02059 2016 NtCreateEvent ... 572, ) == 0x0 02061 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81903, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81903, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\344\4\0\0H\3\0\0" ... ... 02056 384 NtConnectPort ... 576, 0x0, 0x0, 0x0, 188, ) == 0x0 02062 1120 NtRegisterThreadTerminatePort (24, ... 02061 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81905, 0} ... {28, 56, reply, 0, 1252, 896, 81905, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\344\4\0\0H\3\0\0" ) ) == 0x0 02063 384 NtRequestWaitReplyPort (576, {200, 224, new_msg, 0, 1384080, 12, 2, 1310721} (576, {200, 224, new_msg, 0, 1384080, 12, 2, 1310721} "\0\0\0\0\274\0\0\0$?\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\230`\347w\4\0\0\0x\1\24\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\08\13\340\12\17Fk\1\220G\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\0<\25\0\223\241\212\225x\1\24\0\210G\25\0h\1\24\0\0\0\0\0\0\0\0\0\210G\25\0P\0\0\0\220G\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\354\353\354\0\372\31\221|\200\363\354\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... ... 02062 1120 NtRegisterThreadTerminatePort ... ) == 0x0 02064 896 NtResumeThread (568, ... 02065 1120 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02064 896 NtResumeThread ... 1, ) == 0x0 02063 384 NtRequestWaitReplyPort ... {200, 224, reply, 0, 1252, 384, 81906, 0} ... {200, 224, reply, 0, 1252, 384, 81906, 0} "\7\0\0\0\274\0\0\0$?\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0x\1\24\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\08\13\340\12\17Fk\1\220G\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\0<\25\0\223\241\212\225x\1\24\0\210G\25\0h\1\24\0\0\0\0\0\0\0\0\0\210G\25\0P\0\0\0\220G\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\354\353\354\0\372\31\221|\200\363\354\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 02065 1120 NtDuplicateObject ... 580, ) == 0x0 02066 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02067 384 NtRequestWaitReplyPort (576, {44, 68, new_msg, 0, 1252, 384, 81884, 0} (576, {44, 68, new_msg, 0, 1252, 384, 81884, 0} "\1\0\0\0A\2\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0" ... ... 02068 1120 NtWaitForSingleObject (64, 0, {0, 0}, ... 02069 2016 NtConnectPort ( ("\RPC Control\epmapper", {12, 2, 1, 1}, 0x0, 0x0, 11072120, 188, ... , {12, 2, 1, 1}, 0x0, 0x0, 11072120, 188, ... 02070 840 NtTestAlert (... ) == 0x0 02071 840 NtContinue (66911536, 1, ... 02072 840 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02069 2016 NtConnectPort ... 584, 0x0, 0x0, 0x0, 188, ) == 0x0 02066 896 NtAllocateVirtualMemory ... 66912256, 1048576, ) == 0x0 02068 1120 NtWaitForSingleObject ... ) == 0x102 02067 384 NtRequestWaitReplyPort ... {40, 64, reply, 0, 1252, 384, 81907, 0} ... {40, 64, reply, 0, 1252, 384, 81907, 0} "\2\356Q\200\4\0\0\0@\14\250\201\0\320\372\177\220kt\367\370\37`\300lkt\367X\353Q\200\320\1\0\0X-\12\0" ) ) == 0x0 02073 2016 NtRequestWaitReplyPort (584, {200, 224, new_msg, 0, 2883626, 1355840, 12, 2} (584, {200, 224, new_msg, 0, 2883626, 1355840, 12, 2} "\0\1\24\0\10\0\0\0\274\0\0\0\10\203\257\341\37]\311\21\221\244\10\0+\24\240\372\3\0\0\0\1\0\0\0\1\0\4\0\4\0\0\0\240<\24\0x\1\24\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\25\0\3\0\0\0\311\325l=\314\135\256\220V\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0hV\25\0\350\273\313\363x\1\24\0\210V\25\0h\1\24\0\0\0\0\0\0\0\0\0\210V\25\0P\0\0\0\220V\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\370\360\250\0\372\31\221|\214\370\250\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ... ... 02074 896 NtAllocateVirtualMemory (-1, 67952640, 0, 8192, 4096, 4, ... 02075 1120 NtWaitForSingleObject (124, 0, 0x0, ... 02076 384 NtRequestWaitReplyPort (576, {64, 88, new_msg, 56, 1371720, 15527788, 15527888, 0} (576, {64, 88, new_msg, 56, 1371720, 15527788, 15527888, 0} "\10\357\354\0@\0\24\0\346\277\347w\320\357\354\0l\357\354\0\20\0\0\0\250.\362v\274\356\24\0\1\0\0\0\340V\25\0\320\1\0\0\320\1\0\0X-\12\0\0\0\0\0\0\0\0\0\300\332\24\0" ... ... 02074 896 NtAllocateVirtualMemory ... 67952640, 8192, ) == 0x0 02073 2016 NtRequestWaitReplyPort ... {200, 224, reply, 0, 1252, 2016, 81909, 0} ... {200, 224, reply, 0, 1252, 2016, 81909, 0} "\7\1\24\0\10\0\0\0\274\0\0\0\10\203\257\341\37]\311\21\221\244\10\0+\24\240\372\3\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\240<\24\0\377\377\377\377\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\25\0\3\0\0\0\311\325l=\314\135\256\220V\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0hV\25\0\350\273\313\363x\1\24\0\210V\25\0h\1\24\0\0\0\0\0\0\0\0\0\210V\25\0P\0\0\0\220V\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\370\360\250\0\372\31\221|\214\370\250\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ) ) == 0x0 02077 896 NtProtectVirtualMemory (-1, (0x40ce000), 4096, 260, ... 02078 840 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02076 384 NtRequestWaitReplyPort ... {64, 88, reply, 56, 1252, 384, 81910, 0} ... {64, 88, reply, 56, 1252, 384, 81910, 0} "\10\357\354\0@\0\24\0\346\277\347w\320\357\354\0l\357\354\0\20\0\0\0\250.\362v\274\356\24\0\1\0\0\0\340V\25\0\320\1\0\0\320\1\0\0X-\12\0\0\0\0\0\0\0\0\0\300\332\24\0" ) ) == 0x0 02077 896 NtProtectVirtualMemory ... (0x40ce000), 4096, 4, ) == 0x0 02078 840 NtDuplicateObject ... 588, ) == 0x0 02079 384 NtClose (564, ... 02080 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02081 840 NtWaitForSingleObject (64, 0, {0, 0}, ... 02079 384 NtClose ... ) == 0x0 02082 2016 NtRequestWaitReplyPort (584, {44, 68, new_msg, 56, 0, 0, 0, 0} (584, {44, 68, new_msg, 56, 0, 0, 0, 0} "\1\0\0\0B\2\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\1\0\0\0\340\\25\0\322\0\0\0" ... ... 02081 840 NtWaitForSingleObject ... ) == 0x102 02080 896 NtCreateThread ... 564, {1252, 876}, ) == 0x0 02083 840 NtWaitForSingleObject (124, 0, 0x0, ... 02084 896 NtQueryInformationThread (564, Basic, 28, ... 02082 2016 NtRequestWaitReplyPort ... {40, 64, reply, 0, 1252, 2016, 81911, 0} ... {40, 64, reply, 0, 1252, 2016, 81911, 0} "\2\356Q\200\4\0\0\0P\306\233\201\0\340\372\177\220\353\10\370\370\37`\300l\353\10\370X\353Q\200\323\1\0\0\350\370\14\0" ) ) == 0x0 02085 384 NtClose (576, ... 02084 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff83000,Pid=1252,Tid=876,}, 0x0, ) == 0x0 02086 2016 NtRequestWaitReplyPort (584, {64, 88, new_msg, 56, 1310720, 11071988, 1400024, 0} (584, {64, 88, new_msg, 56, 1310720, 11071988, 1400024, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\250\0\351\201\347w\214\370\250\0\30\356\220|p\5\221|\1\0\0\0\300]\25\0\323\1\0\0\323\1\0\0\350\370\14\0\0\0\0\0\0\0\0\0\273f\347w" ... ... 02085 384 NtClose ... ) == 0x0 02087 384 NtAllocateVirtualMemory (-1, 1400832, 0, 4096, 4096, 4, ... 1400832, 4096, ) == 0x0 02088 384 NtCreateKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 576, 2, ) }, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 576, 2, ) , 0, ... 576, 2, ) == 0x0 02086 2016 NtRequestWaitReplyPort ... {64, 88, reply, 56, 1252, 2016, 81913, 0} ... {64, 88, reply, 56, 1252, 2016, 81913, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\250\0\351\201\347w\214\370\250\0\30\356\220|p\5\221|\1\0\0\0\300]\25\0\323\1\0\0\323\1\0\0\350\370\14\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02089 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81905, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81905, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\2\0\0\344\4\0\0l\3\0\0" ... ... 02090 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... }, ... 02089 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81914, 0} ... {28, 56, reply, 0, 1252, 896, 81914, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\2\0\0\344\4\0\0l\3\0\0" ) ) == 0x0 02090 384 NtOpenKey ... 592, ) == 0x0 02091 896 NtResumeThread (564, ... 02092 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... }, ... 02091 896 NtResumeThread ... 1, ) == 0x0 02092 384 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02093 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02094 384 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\System\DNSClient"}, ... }, ... 02095 2016 NtRequestWaitReplyPort (584, {44, 68, new_msg, 56, 1252, 2016, 81911, 0} (584, {44, 68, new_msg, 56, 1252, 2016, 81911, 0} "\1\356\0\0B\2\3\0P\306\233\201\0\340\372\177\220\353\10\370\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\340\\25\0\322\0\0\0" ... ... 02096 876 NtTestAlert (... 02094 384 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02096 876 NtTestAlert ... ) == 0x0 02095 2016 NtRequestWaitReplyPort ... {40, 64, reply, 0, 1252, 2016, 81915, 0} ... {40, 64, reply, 0, 1252, 2016, 81915, 0} "\2\246\200|\4\0\0\0\0\0\0\0\4\377}\0(\345\12\0\0\0\0\0\230\376}\0\2\0\0\0\351\1\0\0\350\232\14\0" ) ) == 0x0 02093 896 NtAllocateVirtualMemory ... 67960832, 1048576, ) == 0x0 02097 876 NtContinue (67960112, 1, ... 02098 2016 NtRequestWaitReplyPort (584, {64, 88, new_msg, 56, 1310720, 11071988, 11072732, 0} (584, {64, 88, new_msg, 56, 1310720, 11071988, 11072732, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\250\0\351\201\347w\214\370\250\0\30\356\220|p\5\221|\1\0\0\0\30j\25\0\351\1\0\0\351\1\0\0\350\232\14\0\0\0\0\0\0\0\0\0\273f\347w" ... ... 02099 896 NtAllocateVirtualMemory (-1, 69001216, 0, 8192, 4096, 4, ... 02100 876 NtRegisterThreadTerminatePort (24, ... 02099 896 NtAllocateVirtualMemory ... 69001216, 8192, ) == 0x0 02100 876 NtRegisterThreadTerminatePort ... ) == 0x0 02098 2016 NtRequestWaitReplyPort ... {64, 88, reply, 56, 1252, 2016, 81916, 0} ... {64, 88, reply, 56, 1252, 2016, 81916, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\250\0\351\201\347w\214\370\250\0\30\356\220|p\5\221|\1\0\0\0\30j\25\0\351\1\0\0\351\1\0\0\350\232\14\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02101 896 NtProtectVirtualMemory (-1, (0x41ce000), 4096, 260, ... 02102 384 NtQueryValueKey (576, (576, "Domain", Partial, 144, ... , Partial, 144, ... 02103 876 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02101 896 NtProtectVirtualMemory ... (0x41ce000), 4096, 4, ) == 0x0 02102 384 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02103 876 NtDuplicateObject ... 596, ) == 0x0 02104 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02105 384 NtQueryValueKey (576, (576, "Domain", Partial, 144, ... , Partial, 144, ... 02106 876 NtWaitForSingleObject (64, 0, {0, 0}, ... 02107 2016 NtRequestWaitReplyPort (584, {44, 68, new_msg, 56, 1252, 2016, 81915, 0} (584, {44, 68, new_msg, 56, 1252, 2016, 81915, 0} "\1\246\0\0B\2\3\0\0\0\0\0\4\377}\0(\345\12\0\0\0\0\0\377\377\377\377\2\0\0\0\1\0\0\0\340\\25\0\322\0\0\0" ... ... 02105 384 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02106 876 NtWaitForSingleObject ... ) == 0x102 02108 384 NtClose (576, ... 02109 876 NtWaitForSingleObject (124, 0, 0x0, ... 02107 2016 NtRequestWaitReplyPort ... {40, 64, reply, 0, 1252, 2016, 81917, 0} ... {40, 64, reply, 0, 1252, 2016, 81917, 0} "\2\356Q\200\4\0\0\0\250\372\244\201\0\360\372\177\220\253S\371\370\37`\300l\253S\371X\353Q\200|\1\0\0h\236\14\0" ) ) == 0x0 02108 384 NtClose ... ) == 0x0 02104 896 NtCreateThread ... 576, {1252, 1104}, ) == 0x0 02110 2016 NtRequestWaitReplyPort (584, {64, 88, new_msg, 56, 1310720, 11071988, 11072732, 0} (584, {64, 88, new_msg, 56, 1310720, 11071988, 11072732, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\250\0\351\201\347w\214\370\250\0\30\356\220|p\5\221|\1\0\0\0\350l\25\0|\1\0\0|\1\0\0h\236\14\0\0\0\0\0\0\0\0\0\273f\347w" ... ... 02111 896 NtQueryInformationThread (576, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff82000,Pid=1252,Tid=1104,}, 0x0, ) == 0x0 02112 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81914, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81914, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0P\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0P\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81919, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81914, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0P\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0P\4\0\0" ) ) == 0x0 02110 2016 NtRequestWaitReplyPort ... {64, 88, reply, 56, 1252, 2016, 81918, 0} ... {64, 88, reply, 56, 1252, 2016, 81918, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\250\0\351\201\347w\214\370\250\0\30\356\220|p\5\221|\1\0\0\0\350l\25\0|\1\0\0|\1\0\0h\236\14\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02113 384 NtClose (592, ... 02114 896 NtResumeThread (576, ... 02113 384 NtClose ... ) == 0x0 02114 896 NtResumeThread ... 1, ) == 0x0 02115 384 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, ... }, ... 02116 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02115 384 NtOpenKey ... 592, ) == 0x0 02116 896 NtAllocateVirtualMemory ... 69009408, 1048576, ) == 0x0 02117 384 NtQueryValueKey (592, (592, "DnsNbtLookupOrder", Partial, 144, ... , Partial, 144, ... 02118 896 NtAllocateVirtualMemory (-1, 70049792, 0, 8192, 4096, 4, ... 02117 384 NtQueryValueKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02118 896 NtAllocateVirtualMemory ... 70049792, 8192, ) == 0x0 02119 2016 NtClose (572, ... 02120 1104 NtTestAlert (... 02121 384 NtClose (592, ... 02119 2016 NtClose ... ) == 0x0 02120 1104 NtTestAlert ... ) == 0x0 02121 384 NtClose ... ) == 0x0 02122 2016 NtClose (584, ... 02123 1104 NtContinue (69008688, 1, ... 02124 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 15526864, ... }, 15526864, ... 02122 2016 NtClose ... ) == 0x0 02125 1104 NtRegisterThreadTerminatePort (24, ... 02124 384 NtQueryAttributesFile ... ) == 0x0 02126 2016 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02125 1104 NtRegisterThreadTerminatePort ... ) == 0x0 02127 384 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 5, 96, ... }, 5, 96, ... 02126 2016 NtCreateEvent ... 584, ) == 0x0 02128 896 NtProtectVirtualMemory (-1, (0x42ce000), 4096, 260, ... 02127 384 NtOpenFile ... 592, {status=0x0, info=1}, ) == 0x0 02129 1104 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02128 896 NtProtectVirtualMemory ... (0x42ce000), 4096, 4, ) == 0x0 02130 2016 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... }, ... 02129 1104 NtDuplicateObject ... 572, ) == 0x0 02131 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02130 2016 NtOpenKey ... 600, ) == 0x0 02132 1104 NtWaitForSingleObject (64, 0, {0, 0}, ... 02131 896 NtCreateThread ... 604, {1252, 860}, ) == 0x0 02133 2016 NtOpenKey (0x20019, {24, 600, 0x40, 0, 0, (0x20019, {24, 600, 0x40, 0, 0, "ActiveComputerName"}, ... }, ... 02132 1104 NtWaitForSingleObject ... ) == 0x102 02134 896 NtQueryInformationThread (604, Basic, 28, ... 02133 2016 NtOpenKey ... 608, ) == 0x0 02135 1104 NtWaitForSingleObject (124, 0, 0x0, ... 02134 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff81000,Pid=1252,Tid=860,}, 0x0, ) == 0x0 02136 2016 NtQueryValueKey (608, (608, "ComputerName", Full, 108, ... , Full, 108, ... 02137 384 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 592, ... 02136 2016 NtQueryValueKey ... TitleIdx=0, Type=1, Name= ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 02137 384 NtCreateSection ... 612, ) == 0x0 02138 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\344\4\0\0\\3\0\0" ... ... 02139 384 NtClose (592, ... 02138 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81921, 0} ... {28, 56, reply, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\344\4\0\0\\3\0\0" ) ) == 0x0 02139 384 NtClose ... ) == 0x0 02140 896 NtResumeThread (604, ... 02141 384 NtMapViewOfSection (612, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... 02140 896 NtResumeThread ... 1, ) == 0x0 02141 384 NtMapViewOfSection ... (0x860000), 0x0, 20480, ) == 0x0 02142 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02143 2016 NtClose (608, ... 02144 860 NtWaitForSingleObject (88, 0, 0x0, ... 02145 384 NtClose (612, ... 02143 2016 NtClose ... ) == 0x0 02145 384 NtClose ... ) == 0x0 02146 2016 NtClose (600, ... ) == 0x0 02147 2016 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 600, ) == 0x0 02148 384 NtUnmapViewOfSection (-1, 0x860000, ... 02142 896 NtAllocateVirtualMemory ... 70057984, 1048576, ) == 0x0 02148 384 NtUnmapViewOfSection ... ) == 0x0 02149 896 NtAllocateVirtualMemory (-1, 71098368, 0, 8192, 4096, 4, ... 02150 2016 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 02149 896 NtAllocateVirtualMemory ... 71098368, 8192, ) == 0x0 02150 2016 NtCreateIoCompletion ... 612, ) == 0x0 02151 896 NtProtectVirtualMemory (-1, (0x43ce000), 4096, 260, ... 02152 2016 NtDuplicateObject (-1, 600, -1, 0x0, 0, 2, ... 02151 896 NtProtectVirtualMemory ... (0x43ce000), 4096, 4, ) == 0x0 02152 2016 NtDuplicateObject ... 608, ) == 0x0 02153 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02154 2016 NtOpenThreadToken (-2, 0xc, 1, ... 02155 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 15527172, ... }, 15527172, ... 02154 2016 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02155 384 NtQueryAttributesFile ... ) == 0x0 02153 896 NtCreateThread ... 592, {1252, 1516}, ) == 0x0 02156 384 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 5, 96, ... }, 5, 96, ... 02157 896 NtQueryInformationThread (592, Basic, 28, ... 02156 384 NtOpenFile ... 616, {status=0x0, info=1}, ) == 0x0 02157 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff80000,Pid=1252,Tid=1516,}, 0x0, ) == 0x0 02158 384 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 616, ... 02159 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81921, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\2\0\0\344\4\0\0\354\5\0\0" ... ... 02158 384 NtCreateSection ... 620, ) == 0x0 02159 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81922, 0} ... {28, 56, reply, 0, 1252, 896, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\2\0\0\344\4\0\0\354\5\0\0" ) ) == 0x0 02160 2016 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02161 384 NtQuerySection (620, Image, 48, ... 02160 2016 NtCreateEvent ... 624, ) == 0x0 02161 384 NtQuerySection ... {section info, class 1, size 48}, 0x0, ) == 0x0 02162 2016 NtOpenThreadToken (-2, 0xc, 1, ... 02163 384 NtClose (616, ... 02162 2016 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02163 384 NtClose ... ) == 0x0 02164 2016 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02165 384 NtMapViewOfSection (620, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... 02164 2016 NtSetInformationThread ... ) == 0x0 02165 384 NtMapViewOfSection ... (0x76fb0000), 0x0, 32768, ) == 0x0 02166 896 NtResumeThread (592, ... 02167 2016 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 11071680, (0xc0100080, {24, 0, 0x40, 0, 11071680, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... }, 0x0, 0, 3, 1, 64, 0, 0, ... 02166 896 NtResumeThread ... 1, ) == 0x0 02167 2016 NtCreateFile ... 616, {status=0x0, info=1}, ) == 0x0 02168 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02169 2016 NtSetInformationFile (616, 11071736, 8, Pipe, ... 02168 896 NtAllocateVirtualMemory ... 71106560, 1048576, ) == 0x0 02169 2016 NtSetInformationFile ... {status=0x0, info=0}, ) == 0x0 02170 896 NtAllocateVirtualMemory (-1, 72146944, 0, 8192, 4096, 4, ... 02171 2016 NtSetInformationFile (616, 11071724, 8, Completion, ... 02170 896 NtAllocateVirtualMemory ... 72146944, 8192, ) == 0x0 02171 2016 NtSetInformationFile ... {status=0x0, info=0}, ) == 0x0 02172 384 NtClose (620, ... 02173 1516 NtWaitForSingleObject (88, 0, 0x0, ... 02174 896 NtProtectVirtualMemory (-1, (0x44ce000), 4096, 260, ... 02172 384 NtClose ... ) == 0x0 02174 896 NtProtectVirtualMemory ... (0x44ce000), 4096, 4, ) == 0x0 02175 384 NtProtectVirtualMemory (-1, (0x76fb1000), 232, 4, ... 02176 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02175 384 NtProtectVirtualMemory ... (0x76fb1000), 4096, 32, ) == 0x0 02176 896 NtCreateThread ... 620, {1252, 780}, ) == 0x0 02177 896 NtQueryInformationThread (620, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7f000,Pid=1252,Tid=780,}, 0x0, ) == 0x0 02178 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81922, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\14\3\0\0" ... {28, 56, reply, 0, 1252, 896, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\14\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81923, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\14\3\0\0" ... {28, 56, reply, 0, 1252, 896, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\14\3\0\0" ) ) == 0x0 02179 896 NtResumeThread (620, ... 1, ) == 0x0 02180 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02181 2016 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02182 780 NtWaitForSingleObject (88, 0, 0x0, ... 02183 384 NtProtectVirtualMemory (-1, (0x76fb1000), 4096, 32, ... 02181 2016 NtSetInformationThread ... ) == 0x0 02183 384 NtProtectVirtualMemory ... (0x76fb1000), 4096, 4, ) == 0x0 02184 2016 NtWriteFile (616, 221, 0, 0, (616, 221, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... , 72, {0, 0}, 0, ... 02185 384 NtFlushInstructionCache (-1, 1996165120, 232, ... 02184 2016 NtWriteFile ... {status=0x0, info=72}, ) == 0x0 02185 384 NtFlushInstructionCache ... ) == 0x0 02186 2016 NtReadFile (616, 221, 0, 0, 1024, {0, 0}, 0, ... 02187 384 NtProtectVirtualMemory (-1, (0x76fb1000), 232, 4, ... 02186 2016 NtReadFile ... {status=0x0, info=68}, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20k+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02187 384 NtProtectVirtualMemory ... (0x76fb1000), 4096, 32, ) == 0x0 02180 896 NtAllocateVirtualMemory ... 72155136, 1048576, ) == 0x0 02188 2016 NtFsControlFile (616, 221, 0x0, 0x0, 0x11c017, (616, 221, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\210\367\250\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... , 64, 1024, ... 02189 896 NtAllocateVirtualMemory (-1, 73195520, 0, 8192, 4096, 4, ... 02188 2016 NtFsControlFile ... {status=0x103, info=68}, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20k+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02189 896 NtAllocateVirtualMemory ... 73195520, 8192, ) == 0x0 02190 2016 NtFsControlFile (616, 221, 0x0, 0x0, 0x11c017, (616, 221, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\210\0\0\0\2\0\0\0p\0\0\0\0\0D\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28\1\0\0\0\1\0\0\0&\0(\0Ho\25\0\24\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0u\0t\0h\0o\0r\0i\0t\0y\0\\0s\0y\0s\0t\0e\0m\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 136, 1024, ... , 136, 1024, ... 02191 896 NtProtectVirtualMemory (-1, (0x45ce000), 4096, 260, ... 02192 384 NtProtectVirtualMemory (-1, (0x76fb1000), 4096, 32, ... 02191 896 NtProtectVirtualMemory ... (0x45ce000), 4096, 4, ) == 0x0 02192 384 NtProtectVirtualMemory ... (0x76fb1000), 4096, 4, ) == 0x0 02193 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02194 384 NtFlushInstructionCache (-1, 1996165120, 232, ... 02190 2016 NtFsControlFile ... {status=0x103, info=48}, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28\0\0\0\0", ) , ) == 0x103 02194 384 NtFlushInstructionCache ... ) == 0x0 02195 2016 NtFsControlFile (616, 221, 0x0, 0x0, 0x11c017, (616, 221, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28", 44, 1024, ... , 44, 1024, ... 02196 384 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WLDAP32.dll"}, ... }, ... 02195 2016 NtFsControlFile ... {status=0x103, info=156}, ... {status=0x103, info=156}, "\5\0\2\3\20\0\0\0\234\0\0\0\2\0\0\0\204\0\0\0\0\0\0\0\300`\25\0\1\0\0\0\314`\25\0 \0\0\0\1\0\0\0\30\0\32\0\330`\25\0\364`\25\0\15\0\0\0\0\0\0\0\14\0\0\0N\0T\0 \0A\0U\0T\0H\0O\0R\0I\0T\0Y\0\0\0\0\0\1\0\0\0\0\0\0\5\1\0\0\0\370F\25\0\1\0\0\0\5\0i\0\10G\25\0\0\0\0\0\0\0\0\0\1\0\0\0\1\1\0\0\0\0\0\5\22\0\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 02196 384 NtOpenSection ... 628, ) == 0x0 02197 2016 NtClose (624, ... 02193 896 NtCreateThread ... 632, {1252, 940}, ) == 0x0 02197 2016 NtClose ... ) == 0x0 02198 896 NtQueryInformationThread (632, Basic, 28, ... 02199 2016 NtClose (616, ... 02198 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff7e000,Pid=1252,Tid=940,}, 0x0, ) == 0x0 02200 384 NtMapViewOfSection (628, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... 02201 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81923, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\344\4\0\0\254\3\0\0" ... ... 02200 384 NtMapViewOfSection ... (0x76f60000), 0x0, 180224, ) == 0x0 02201 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81924, 0} ... {28, 56, reply, 0, 1252, 896, 81924, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\344\4\0\0\254\3\0\0" ) ) == 0x0 02202 384 NtClose (628, ... 02199 2016 NtClose ... ) == 0x0 02202 384 NtClose ... ) == 0x0 02203 2016 NtSecureConnectPort ( ("\RPC Control\unimdmsvc", {12, 2, 1, 1}, 0x0, 1384080, 0x0, 11073604, 188, ... , {12, 2, 1, 1}, 0x0, 1384080, 0x0, 11073604, 188, ... 02204 384 NtProtectVirtualMemory (-1, (0x76f61000), 228, 4, ... 02203 2016 NtSecureConnectPort ... 628, 0x0, 0x0, 0x0, 188, ) == 0x0 02204 384 NtProtectVirtualMemory ... (0x76f61000), 4096, 32, ) == 0x0 02205 2016 NtOpenThreadToken (-2, 0xc, 1, ... 02206 896 NtResumeThread (632, ... 02205 2016 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02206 896 NtResumeThread ... 1, ) == 0x0 02207 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 73203712, 1048576, ) == 0x0 02208 896 NtAllocateVirtualMemory (-1, 74244096, 0, 8192, 4096, 4, ... 74244096, 8192, ) == 0x0 02209 896 NtProtectVirtualMemory (-1, (0x46ce000), 4096, 260, ... (0x46ce000), 4096, 4, ) == 0x0 02210 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 616, {1252, 1268}, ) == 0x0 02211 896 NtQueryInformationThread (616, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7d000,Pid=1252,Tid=1268,}, 0x0, ) == 0x0 02212 2016 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02213 940 NtWaitForSingleObject (88, 0, 0x0, ... 02214 384 NtProtectVirtualMemory (-1, (0x76f61000), 4096, 32, ... 02212 2016 NtSetInformationThread ... ) == 0x0 02214 384 NtProtectVirtualMemory ... (0x76f61000), 4096, 4, ) == 0x0 02215 2016 NtRequestWaitReplyPort (628, {200, 224, new_msg, 0, 1355840, 12, 2, 1310977} (628, {200, 224, new_msg, 0, 1355840, 12, 2, 1310977} "\0\0\0\0\274\0\0\0\0\0\0\03\242t\326)X\335I\220\360`\317\234\353q)\1\0\0\0\1\0\0\0\230`\347w\26\0\0\0\4\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0FmHq\324PG\367\177\253P\4\345\265\304\224\12\0\0\0hc\345\320\20%\305\0\0\0\0\330Y\25\0\200\303\233"\352H\221\365(\0\0\0\4\242\0\363\0\0\24\0\240\366\250\0\233b&%\0\0\0\0\220V\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\250\0\372\31\221|X\376\250\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... \352H\221\365(\0\0\0\4\242\0\363\0\0\24\0\240\366\250\0\233b&%\0\0\0\0\220V\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\250\0\372\31\221|X\376\250\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... 02216 384 NtFlushInstructionCache (-1, 1995837440, 228, ... ) == 0x0 02215 2016 NtRequestWaitReplyPort ... {200, 224, reply, 0, 1252, 2016, 81926, 0} ... {200, 224, reply, 0, 1252, 2016, 81926, 0} "\7\0\0\0\274\0\0\0\0\0\0\03\242t\326)X\335I\220\360`\317\234\353q)\1\0\0\0\1\0\0\0\0\0\0\0\26\0\0\0\4\0\0\0\0\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0FmHq\324PG\367\177\253P\4\345\265\304\224\12\0\0\0hc\345\320\20%\305\0\0\0\0\330Y\25\0\200\303\233"\352H\221\365(\0\0\0\4\242\0\363\0\0\24\0\240\366\250\0\233b&%\0\0\0\0\220V\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\250\0\372\31\221|X\376\250\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) \352H\221\365(\0\0\0\4\242\0\363\0\0\24\0\240\366\250\0\233b&%\0\0\0\0\220V\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\250\0\372\31\221|X\376\250\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) == 0x0 02217 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81924, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81924, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\2\0\0\344\4\0\0\364\4\0\0" ... ... 02218 2016 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02217 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81927, 0} ... {28, 56, reply, 0, 1252, 896, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\2\0\0\344\4\0\0\364\4\0\0" ) ) == 0x0 02219 384 NtProtectVirtualMemory (-1, (0x76f61000), 228, 4, ... 02220 896 NtResumeThread (616, ... 02219 384 NtProtectVirtualMemory ... (0x76f61000), 4096, 32, ) == 0x0 02220 896 NtResumeThread ... 1, ) == 0x0 02221 384 NtProtectVirtualMemory (-1, (0x76f61000), 4096, 32, ... 02222 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02221 384 NtProtectVirtualMemory ... (0x76f61000), 4096, 4, ) == 0x0 02218 2016 NtSetInformationThread ... ) == 0x0 02223 1268 NtWaitForSingleObject (88, 0, 0x0, ... 02224 384 NtFlushInstructionCache (-1, 1995837440, 228, ... 02225 2016 NtRequestWaitReplyPort (628, {56, 80, new_msg, 0, 44, 3, 20, 0} (628, {56, 80, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\2\0gS\263F\252\227\2L\355h\28\1\0\0\0\0\0\0\0&\0(\0\230\1\0\0\0\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0" ... ... 02224 384 NtFlushInstructionCache ... ) == 0x0 02222 896 NtAllocateVirtualMemory ... 74252288, 1048576, ) == 0x0 02226 896 NtAllocateVirtualMemory (-1, 75292672, 0, 8192, 4096, 4, ... 75292672, 8192, ) == 0x0 02227 896 NtProtectVirtualMemory (-1, (0x47ce000), 4096, 260, ... (0x47ce000), 4096, 4, ) == 0x0 02228 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 624, {1252, 644}, ) == 0x0 02229 896 NtQueryInformationThread (624, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7c000,Pid=1252,Tid=644,}, 0x0, ) == 0x0 02230 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81927, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\204\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\204\2\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81929, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\204\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\204\2\0\0" ) ) == 0x0 02231 384 NtProtectVirtualMemory (-1, (0x76fb1000), 232, 4, ... (0x76fb1000), 4096, 32, ) == 0x0 02232 384 NtProtectVirtualMemory (-1, (0x76fb1000), 4096, 32, ... (0x76fb1000), 4096, 4, ) == 0x0 02233 384 NtFlushInstructionCache (-1, 1996165120, 232, ... ) == 0x0 02234 896 NtResumeThread (624, ... 1, ) == 0x0 02235 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 75300864, 1048576, ) == 0x0 02236 896 NtAllocateVirtualMemory (-1, 76341248, 0, 8192, 4096, 4, ... 76341248, 8192, ) == 0x0 02225 2016 NtRequestWaitReplyPort ... {44, 68, reply, 0, 1252, 2016, 81928, 0} ... {44, 68, reply, 0, 1252, 2016, 81928, 0} "\4\376\255\201\0\0\0\0\200Y\274\201\356\12$\342\264\311\275\201:\332R\200X\253v\367\324\376\255\201\2\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 02237 644 NtWaitForSingleObject (88, 0, 0x0, ... 02238 384 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WLDAP32.dll"}, ... }, ... 02239 2016 NtRaiseException (11074064, 11073324, 1, ... 02238 384 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02240 2016 NtQueryVirtualMemory (-1, 0x77ea0470, BasicVlm, 16, ... 02241 384 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02242 896 NtProtectVirtualMemory (-1, (0x48ce000), 4096, 260, ... 02241 384 NtCreateEvent ... 636, ) == 0x0 02242 896 NtProtectVirtualMemory ... (0x48ce000), 4096, 4, ) == 0x0 02240 2016 NtQueryVirtualMemory ... {memory info, class 3, size 16}, 0x0, ) == 0x0 02243 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02244 2016 NtQueryVirtualMemory (-1, 0x77e7a298, Basic, 28, ... 02243 896 NtCreateThread ... 640, {1252, 1736}, ) == 0x0 02244 2016 NtQueryVirtualMemory ... {BaseAddress=0x77e7a000,AllocationBase=0x77e70000,AllocationProtect=0x80,RegionSize=0x80000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 02245 896 NtQueryInformationThread (640, Basic, 28, ... 02246 2016 NtContinue (11072292, 0, ... 02245 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff7b000,Pid=1252,Tid=1736,}, 0x0, ) == 0x0 02247 2016 NtDeviceIoControlFile (408, 108, 0x0, 0x0, 0x1200c, 0x0, 0, 26, ... 02248 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\LDAP"}, ... }, ... 02247 2016 NtDeviceIoControlFile ... {status=0x0, info=0}, "", ) == 0x103 02248 384 NtOpenKey ... 644, ) == 0x0 02249 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81929, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\344\4\0\0\310\6\0\0" ... ... 02250 384 NtQueryValueKey (644, (644, "LdapClientIntegrity", Partial, 144, ... , Partial, 144, ... 02249 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81930, 0} ... {28, 56, reply, 0, 1252, 896, 81930, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\344\4\0\0\310\6\0\0" ) ) == 0x0 02251 2016 NtWaitForSingleObject (108, 1, {-5000000, -1}, ... 02252 896 NtResumeThread (640, ... 1, ) == 0x0 02253 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 76349440, 1048576, ) == 0x0 02254 896 NtAllocateVirtualMemory (-1, 77389824, 0, 8192, 4096, 4, ... 77389824, 8192, ) == 0x0 02255 896 NtProtectVirtualMemory (-1, (0x49ce000), 4096, 260, ... (0x49ce000), 4096, 4, ) == 0x0 02256 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02250 384 NtQueryValueKey ... TitleIdx=0, Type=4, Data= ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02257 1736 NtWaitForSingleObject (88, 0, 0x0, ... 02258 384 NtClose (644, ... ) == 0x0 02259 384 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrnr.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02260 384 NtQueryPerformanceCounter (... {-1439036388, 16}, {3579545, 0}, ) == 0x0 02261 384 NtSetEventBoostPriority (88, ... 02144 860 NtWaitForSingleObject ... ) == 0x0 02262 860 NtSetEventBoostPriority (88, ... 02173 1516 NtWaitForSingleObject ... ) == 0x0 02263 1516 NtSetEventBoostPriority (88, ... 02182 780 NtWaitForSingleObject ... ) == 0x0 02264 780 NtSetEventBoostPriority (88, ... 02213 940 NtWaitForSingleObject ... ) == 0x0 02265 940 NtSetEventBoostPriority (88, ... 02223 1268 NtWaitForSingleObject ... ) == 0x0 02266 1268 NtSetEventBoostPriority (88, ... 02237 644 NtWaitForSingleObject ... ) == 0x0 02267 644 NtSetEventBoostPriority (88, ... 02257 1736 NtWaitForSingleObject ... ) == 0x0 02268 1736 NtTestAlert (... ) == 0x0 02267 644 NtSetEventBoostPriority ... ) == 0x0 02266 1268 NtSetEventBoostPriority ... ) == 0x0 02265 940 NtSetEventBoostPriority ... ) == 0x0 02264 780 NtSetEventBoostPriority ... ) == 0x0 02263 1516 NtSetEventBoostPriority ... ) == 0x0 02262 860 NtSetEventBoostPriority ... ) == 0x0 02261 384 NtSetEventBoostPriority ... ) == 0x0 02256 896 NtCreateThread ... 644, {1252, 320}, ) == 0x0 02269 1736 NtContinue (76348720, 1, ... 02270 644 NtTestAlert (... 02271 1268 NtTestAlert (... 02272 940 NtTestAlert (... 02273 780 NtTestAlert (... 02274 1516 NtTestAlert (... 02275 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\mswsock.dll"}, 15526864, ... }, 15526864, ... 02276 896 NtQueryInformationThread (644, Basic, 28, ... 02277 1736 NtRegisterThreadTerminatePort (24, ... 02270 644 NtTestAlert ... ) == 0x0 02271 1268 NtTestAlert ... ) == 0x0 02272 940 NtTestAlert ... ) == 0x0 02273 780 NtTestAlert ... ) == 0x0 02274 1516 NtTestAlert ... ) == 0x0 02278 860 NtTestAlert (... 02276 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff7a000,Pid=1252,Tid=320,}, 0x0, ) == 0x0 02277 1736 NtRegisterThreadTerminatePort ... ) == 0x0 02279 644 NtContinue (75300144, 1, ... 02280 1268 NtContinue (74251568, 1, ... 02281 940 NtContinue (73202992, 1, ... 02282 780 NtContinue (72154416, 1, ... 02283 1516 NtContinue (71105840, 1, ... 02278 860 NtTestAlert ... ) == 0x0 02284 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81930, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81930, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\344\4\0\0@\1\0\0" ... ... 02285 1736 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02286 644 NtRegisterThreadTerminatePort (24, ... 02287 1268 NtRegisterThreadTerminatePort (24, ... 02288 940 NtRegisterThreadTerminatePort (24, ... 02289 780 NtRegisterThreadTerminatePort (24, ... 02290 1516 NtRegisterThreadTerminatePort (24, ... 02291 860 NtContinue (70057264, 1, ... 02284 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81931, 0} ... {28, 56, reply, 0, 1252, 896, 81931, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\344\4\0\0@\1\0\0" ) ) == 0x0 02285 1736 NtDuplicateObject ... 648, ) == 0x0 02286 644 NtRegisterThreadTerminatePort ... ) == 0x0 02287 1268 NtRegisterThreadTerminatePort ... ) == 0x0 02288 940 NtRegisterThreadTerminatePort ... ) == 0x0 02289 780 NtRegisterThreadTerminatePort ... ) == 0x0 02290 1516 NtRegisterThreadTerminatePort ... ) == 0x0 02292 860 NtRegisterThreadTerminatePort (24, ... 02275 384 NtQueryAttributesFile ... ) == 0x0 02293 1736 NtWaitForSingleObject (64, 0, {0, 0}, ... 02294 644 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02295 1268 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02296 940 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02297 780 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02298 1516 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02292 860 NtRegisterThreadTerminatePort ... ) == 0x0 02299 384 NtQuerySystemInformation (Basic, 44, ... 02300 896 NtResumeThread (644, ... 02293 1736 NtWaitForSingleObject ... ) == 0x102 02294 644 NtDuplicateObject ... 652, ) == 0x0 02295 1268 NtDuplicateObject ... 656, ) == 0x0 02296 940 NtDuplicateObject ... 660, ) == 0x0 02297 780 NtDuplicateObject ... 664, ) == 0x0 02301 860 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02299 384 NtQuerySystemInformation ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02300 896 NtResumeThread ... 1, ) == 0x0 02302 1736 NtWaitForSingleObject (124, 0, 0x0, ... 02303 644 NtWaitForSingleObject (64, 0, {0, 0}, ... 02304 1268 NtWaitForSingleObject (64, 0, {0, 0}, ... 02305 940 NtAllocateVirtualMemory (-1, 1404928, 0, 4096, 4096, 4, ... 02306 780 NtWaitForSingleObject (284, 0, 0x0, ... 02298 1516 NtDuplicateObject ... 668, ) == 0x0 02307 320 NtWaitForSingleObject (284, 0, 0x0, ... 02308 384 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 02309 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02303 644 NtWaitForSingleObject ... ) == 0x102 02304 1268 NtWaitForSingleObject ... ) == 0x102 02305 940 NtAllocateVirtualMemory ... 1404928, 4096, ) == 0x0 02310 1516 NtWaitForSingleObject (284, 0, 0x0, ... 02308 384 NtAllocateVirtualMemory ... 8781824, 65536, ) == 0x0 02309 896 NtAllocateVirtualMemory ... 77398016, 1048576, ) == 0x0 02311 644 NtWaitForSingleObject (284, 0, 0x0, ... 02312 1268 NtWaitForSingleObject (284, 0, 0x0, ... 02313 940 NtSetEventBoostPriority (284, ... 02314 384 NtAllocateVirtualMemory (-1, 8781824, 0, 4096, 4096, 4, ... 02315 896 NtAllocateVirtualMemory (-1, 78438400, 0, 8192, 4096, 4, ... 02306 780 NtWaitForSingleObject ... ) == 0x0 02313 940 NtSetEventBoostPriority ... ) == 0x0 02301 860 NtDuplicateObject ... 672, ) == 0x0 02316 780 NtSetEventBoostPriority (284, ... 02315 896 NtAllocateVirtualMemory ... 78438400, 8192, ) == 0x0 02317 940 NtWaitForSingleObject (284, 0, 0x0, ... 02307 320 NtWaitForSingleObject ... ) == 0x0 02316 780 NtSetEventBoostPriority ... ) == 0x0 02318 860 NtWaitForSingleObject (284, 0, 0x0, ... 02314 384 NtAllocateVirtualMemory ... 8781824, 4096, ) == 0x0 02319 896 NtProtectVirtualMemory (-1, (0x4ace000), 4096, 260, ... 02320 320 NtSetEventBoostPriority (284, ... 02321 384 NtWaitForSingleObject (356, 0, 0x0, ... 02310 1516 NtWaitForSingleObject ... ) == 0x0 02320 320 NtSetEventBoostPriority ... ) == 0x0 02319 896 NtProtectVirtualMemory ... (0x4ace000), 4096, 4, ) == 0x0 02322 1516 NtSetEventBoostPriority (284, ... 02323 780 NtWaitForSingleObject (284, 0, 0x0, ... 02311 644 NtWaitForSingleObject ... ) == 0x0 02322 1516 NtSetEventBoostPriority ... ) == 0x0 02324 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02325 644 NtSetEventBoostPriority (284, ... 02326 320 NtTestAlert (... 02312 1268 NtWaitForSingleObject ... ) == 0x0 02325 644 NtSetEventBoostPriority ... ) == 0x0 02324 896 NtCreateThread ... 676, {1252, 380}, ) == 0x0 02327 1268 NtSetEventBoostPriority (284, ... 02326 320 NtTestAlert ... ) == 0x0 02328 1516 NtWaitForSingleObject (284, 0, 0x0, ... 02317 940 NtWaitForSingleObject ... ) == 0x0 02327 1268 NtSetEventBoostPriority ... ) == 0x0 02329 896 NtQueryInformationThread (676, Basic, 28, ... 02330 320 NtContinue (77397296, 1, ... 02331 940 NtSetEventBoostPriority (284, ... 02332 644 NtWaitForSingleObject (124, 0, 0x0, ... 02329 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff79000,Pid=1252,Tid=380,}, 0x0, ) == 0x0 02318 860 NtWaitForSingleObject ... ) == 0x0 02333 320 NtRegisterThreadTerminatePort (24, ... 02331 940 NtSetEventBoostPriority ... ) == 0x0 02334 1268 NtWaitForSingleObject (124, 0, 0x0, ... 02335 860 NtSetEventBoostPriority (284, ... 02333 320 NtRegisterThreadTerminatePort ... ) == 0x0 02336 940 NtSetEventBoostPriority (356, ... 02323 780 NtWaitForSingleObject ... ) == 0x0 02335 860 NtSetEventBoostPriority ... ) == 0x0 02337 320 NtWaitForSingleObject (284, 0, 0x0, ... 02338 780 NtSetEventBoostPriority (284, ... 02321 384 NtWaitForSingleObject ... ) == 0x0 02336 940 NtSetEventBoostPriority ... ) == 0x0 02339 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81931, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81931, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\344\4\0\0|\1\0\0" ... ... 02340 860 NtWaitForSingleObject (284, 0, 0x0, ... 02328 1516 NtWaitForSingleObject ... ) == 0x0 02341 384 NtWaitForSingleObject (284, 0, 0x0, ... 02338 780 NtSetEventBoostPriority ... ) == 0x0 02339 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81932, 0} ... {28, 56, reply, 0, 1252, 896, 81932, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\344\4\0\0|\1\0\0" ) ) == 0x0 02342 1516 NtSetEventBoostPriority (284, ... 02343 780 NtWaitForSingleObject (356, 0, 0x0, ... 02337 320 NtWaitForSingleObject ... ) == 0x0 02342 1516 NtSetEventBoostPriority ... ) == 0x0 02344 896 NtResumeThread (676, ... 02345 940 NtWaitForSingleObject (64, 0, {0, 0}, ... 02346 320 NtSetEventBoostPriority (284, ... 02347 1516 NtWaitForSingleObject (356, 0, 0x0, ... 02344 896 NtResumeThread ... 1, ) == 0x0 02341 384 NtWaitForSingleObject ... ) == 0x0 02345 940 NtWaitForSingleObject ... ) == 0x102 02346 320 NtSetEventBoostPriority ... ) == 0x0 02348 380 NtWaitForSingleObject (284, 0, 0x0, ... 02349 384 NtSetEventBoostPriority (284, ... 02350 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02351 940 NtWaitForSingleObject (124, 0, 0x0, ... 02352 320 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02340 860 NtWaitForSingleObject ... ) == 0x0 02349 384 NtSetEventBoostPriority ... ) == 0x0 02353 860 NtSetEventBoostPriority (284, ... 02352 320 NtDuplicateObject ... 680, ) == 0x0 02350 896 NtAllocateVirtualMemory ... 78446592, 1048576, ) == 0x0 02348 380 NtWaitForSingleObject ... ) == 0x0 02353 860 NtSetEventBoostPriority ... ) == 0x0 02354 384 NtSetEventBoostPriority (356, ... 02355 380 NtTestAlert (... 02356 896 NtAllocateVirtualMemory (-1, 79486976, 0, 8192, 4096, 4, ... 02357 860 NtWaitForSingleObject (356, 0, 0x0, ... 02355 380 NtTestAlert ... ) == 0x0 02343 780 NtWaitForSingleObject ... ) == 0x0 02354 384 NtSetEventBoostPriority ... ) == 0x0 02356 896 NtAllocateVirtualMemory ... 79486976, 8192, ) == 0x0 02358 320 NtWaitForSingleObject (356, 0, 0x0, ... 02359 780 NtSetEventBoostPriority (356, ... 02360 384 NtAllocateVirtualMemory (-1, 8785920, 0, 8192, 4096, 4, ... 02361 896 NtProtectVirtualMemory (-1, (0x4bce000), 4096, 260, ... 02347 1516 NtWaitForSingleObject ... ) == 0x0 02360 384 NtAllocateVirtualMemory ... 8785920, 8192, ) == 0x0 02361 896 NtProtectVirtualMemory ... (0x4bce000), 4096, 4, ) == 0x0 02362 1516 NtSetEventBoostPriority (356, ... 02363 384 NtWaitForSingleObject (356, 0, 0x0, ... 02364 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02357 860 NtWaitForSingleObject ... ) == 0x0 02362 1516 NtSetEventBoostPriority ... ) == 0x0 02359 780 NtSetEventBoostPriority ... ) == 0x0 02365 380 NtContinue (78445872, 1, ... 02366 860 NtSetEventBoostPriority (356, ... 02367 1516 NtWaitForSingleObject (64, 0, {0, 0}, ... 02368 780 NtWaitForSingleObject (64, 0, {0, 0}, ... 02369 380 NtRegisterThreadTerminatePort (24, ... 02358 320 NtWaitForSingleObject ... ) == 0x0 02369 380 NtRegisterThreadTerminatePort ... ) == 0x0 02370 320 NtSetEventBoostPriority (356, ... 02371 380 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02363 384 NtWaitForSingleObject ... ) == 0x0 02370 320 NtSetEventBoostPriority ... ) == 0x0 02372 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshbth.dll"}, 15526864, ... }, 15526864, ... 02371 380 NtDuplicateObject ... 684, ) == 0x0 02372 384 NtQueryAttributesFile ... ) == 0x0 02373 320 NtWaitForSingleObject (64, 0, {0, 0}, ... 02374 380 NtWaitForSingleObject (64, 0, {0, 0}, ... 02366 860 NtSetEventBoostPriority ... ) == 0x0 02364 896 NtCreateThread ... 688, {1252, 1332}, ) == 0x0 02367 1516 NtWaitForSingleObject ... ) == 0x102 02368 780 NtWaitForSingleObject ... ) == 0x102 02375 384 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshbth.dll"}, 5, 96, ... }, 5, 96, ... 02373 320 NtWaitForSingleObject ... ) == 0x102 02376 860 NtWaitForSingleObject (64, 0, {0, 0}, ... 02377 896 NtQueryInformationThread (688, Basic, 28, ... 02378 1516 NtWaitForSingleObject (124, 0, 0x0, ... 02379 780 NtWaitForSingleObject (124, 0, 0x0, ... 02375 384 NtOpenFile ... 692, {status=0x0, info=1}, ) == 0x0 02380 320 NtWaitForSingleObject (124, 0, 0x0, ... 02377 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff78000,Pid=1252,Tid=1332,}, 0x0, ) == 0x0 02381 384 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 692, ... 02382 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81932, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81932, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\344\4\0\04\5\0\0" ... ... 02381 384 NtCreateSection ... 696, ) == 0x0 02382 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81933, 0} ... {28, 56, reply, 0, 1252, 896, 81933, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\344\4\0\04\5\0\0" ) ) == 0x0 02383 384 NtClose (692, ... 02374 380 NtWaitForSingleObject ... ) == 0x102 02376 860 NtWaitForSingleObject ... ) == 0x102 02383 384 NtClose ... ) == 0x0 02384 380 NtWaitForSingleObject (124, 0, 0x0, ... 02385 860 NtWaitForSingleObject (124, 0, 0x0, ... 02386 896 NtResumeThread (688, ... 1, ) == 0x0 02387 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 79495168, 1048576, ) == 0x0 02388 896 NtAllocateVirtualMemory (-1, 80535552, 0, 8192, 4096, 4, ... 80535552, 8192, ) == 0x0 02389 896 NtProtectVirtualMemory (-1, (0x4cce000), 4096, 260, ... (0x4cce000), 4096, 4, ) == 0x0 02390 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 692, {1252, 1336}, ) == 0x0 02391 896 NtQueryInformationThread (692, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff77000,Pid=1252,Tid=1336,}, 0x0, ) == 0x0 02392 384 NtMapViewOfSection (696, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... 02393 1332 NtWaitForSingleObject (88, 0, 0x0, ... 02392 384 NtMapViewOfSection ... (0xb90000), 0x0, 110592, ) == 0x0 02394 384 NtClose (696, ... ) == 0x0 02395 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81933, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81933, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\344\4\0\08\5\0\0" ... ... 02396 384 NtUnmapViewOfSection (-1, 0xb90000, ... ) == 0x0 02397 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshbth.dll"}, 15527172, ... ) }, 15527172, ... ) == 0x0 02398 384 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshbth.dll"}, 5, 96, ... 696, {status=0x0, info=1}, ) }, 5, 96, ... 696, {status=0x0, info=1}, ) == 0x0 02395 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81934, 0} ... {28, 56, reply, 0, 1252, 896, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\344\4\0\08\5\0\0" ) ) == 0x0 02399 896 NtResumeThread (692, ... 1, ) == 0x0 02400 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 80543744, 1048576, ) == 0x0 02401 896 NtAllocateVirtualMemory (-1, 81584128, 0, 8192, 4096, 4, ... 81584128, 8192, ) == 0x0 02402 896 NtProtectVirtualMemory (-1, (0x4dce000), 4096, 260, ... (0x4dce000), 4096, 4, ) == 0x0 02403 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02404 384 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 696, ... 02405 1336 NtWaitForSingleObject (88, 0, 0x0, ... 02404 384 NtCreateSection ... 700, ) == 0x0 02406 384 NtQuerySection (700, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02407 384 NtClose (696, ... ) == 0x0 02408 384 NtMapViewOfSection (700, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x751d0000), 0x0, 122880, ) == 0x0 02409 384 NtClose (700, ... ) == 0x0 02410 384 NtProtectVirtualMemory (-1, (0x751d1000), 224, 4, ... (0x751d1000), 4096, 32, ) == 0x0 02403 896 NtCreateThread ... 700, {1252, 1808}, ) == 0x0 02411 896 NtQueryInformationThread (700, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff76000,Pid=1252,Tid=1808,}, 0x0, ) == 0x0 02412 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81934, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\20\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\20\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81935, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\20\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\20\7\0\0" ) ) == 0x0 02413 896 NtResumeThread (700, ... 1, ) == 0x0 02414 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 81592320, 1048576, ) == 0x0 02415 896 NtAllocateVirtualMemory (-1, 82632704, 0, 8192, 4096, 4, ... 82632704, 8192, ) == 0x0 02416 384 NtProtectVirtualMemory (-1, (0x751d1000), 4096, 32, ... 02417 1808 NtWaitForSingleObject (88, 0, 0x0, ... 02416 384 NtProtectVirtualMemory ... (0x751d1000), 4096, 4, ) == 0x0 02418 384 NtFlushInstructionCache (-1, 1964838912, 224, ... ) == 0x0 02419 384 NtProtectVirtualMemory (-1, (0x751d1000), 224, 4, ... (0x751d1000), 4096, 32, ) == 0x0 02420 384 NtProtectVirtualMemory (-1, (0x751d1000), 4096, 32, ... (0x751d1000), 4096, 4, ) == 0x0 02421 384 NtFlushInstructionCache (-1, 1964838912, 224, ... ) == 0x0 02422 896 NtProtectVirtualMemory (-1, (0x4ece000), 4096, 260, ... (0x4ece000), 4096, 4, ) == 0x0 02423 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 696, {1252, 468}, ) == 0x0 02424 896 NtQueryInformationThread (696, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff75000,Pid=1252,Tid=468,}, 0x0, ) == 0x0 02425 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81935, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\324\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\324\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81936, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\324\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\324\1\0\0" ) ) == 0x0 02426 896 NtResumeThread (696, ... 1, ) == 0x0 02427 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02428 384 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SETUPAPI.dll"}, ... }, ... 02429 468 NtWaitForSingleObject (88, 0, 0x0, ... 02428 384 NtOpenSection ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02430 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\SETUPAPI.dll"}, 15526348, ... }, 15526348, ... 02427 896 NtAllocateVirtualMemory ... 82640896, 1048576, ) == 0x0 02431 896 NtAllocateVirtualMemory (-1, 83681280, 0, 8192, 4096, 4, ... 83681280, 8192, ) == 0x0 02432 896 NtProtectVirtualMemory (-1, (0x4fce000), 4096, 260, ... (0x4fce000), 4096, 4, ) == 0x0 02433 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 704, {1252, 752}, ) == 0x0 02434 896 NtQueryInformationThread (704, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff74000,Pid=1252,Tid=752,}, 0x0, ) == 0x0 02435 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81936, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0\360\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0\360\2\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81937, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0\360\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0\360\2\0\0" ) ) == 0x0 02436 896 NtResumeThread (704, ... 1, ) == 0x0 02437 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 83689472, 1048576, ) == 0x0 02438 896 NtAllocateVirtualMemory (-1, 84729856, 0, 8192, 4096, 4, ... 84729856, 8192, ) == 0x0 02439 752 NtWaitForSingleObject (88, 0, 0x0, ... 02440 896 NtProtectVirtualMemory (-1, (0x50ce000), 4096, 260, ... (0x50ce000), 4096, 4, ) == 0x0 02441 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 708, {1252, 1512}, ) == 0x0 02442 896 NtQueryInformationThread (708, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff73000,Pid=1252,Tid=1512,}, 0x0, ) == 0x0 02443 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81937, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\350\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\350\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81938, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\350\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\350\5\0\0" ) ) == 0x0 02444 896 NtResumeThread (708, ... 1, ) == 0x0 02445 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02430 384 NtQueryAttributesFile ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02446 1512 NtWaitForSingleObject (88, 0, 0x0, ... 02447 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SETUPAPI.dll"}, 15526348, ... ) }, 15526348, ... ) == 0x0 02448 384 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SETUPAPI.dll"}, 5, 96, ... 712, {status=0x0, info=1}, ) }, 5, 96, ... 712, {status=0x0, info=1}, ) == 0x0 02449 384 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 712, ... 716, ) == 0x0 02450 384 NtQuerySection (716, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02451 384 NtClose (712, ... ) == 0x0 02452 384 NtMapViewOfSection (716, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... 02445 896 NtAllocateVirtualMemory ... 84738048, 1048576, ) == 0x0 02453 896 NtAllocateVirtualMemory (-1, 85778432, 0, 8192, 4096, 4, ... 85778432, 8192, ) == 0x0 02454 896 NtProtectVirtualMemory (-1, (0x51ce000), 4096, 260, ... (0x51ce000), 4096, 4, ) == 0x0 02455 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 712, {1252, 1380}, ) == 0x0 02456 896 NtQueryInformationThread (712, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff72000,Pid=1252,Tid=1380,}, 0x0, ) == 0x0 02452 384 NtMapViewOfSection ... (0x77920000), 0x0, 995328, ) == 0x0 02457 384 NtClose (716, ... ) == 0x0 02458 384 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02459 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81938, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0d\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0d\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81939, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0d\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0d\5\0\0" ) ) == 0x0 02460 896 NtResumeThread (712, ... 1, ) == 0x0 02461 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02462 384 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... 02463 1380 NtWaitForSingleObject (88, 0, 0x0, ... 02462 384 NtProtectVirtualMemory ... (0x77921000), 4096, 4, ) == 0x0 02464 384 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02465 384 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02466 384 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02467 384 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02468 384 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... 02461 896 NtAllocateVirtualMemory ... 85786624, 1048576, ) == 0x0 02469 896 NtAllocateVirtualMemory (-1, 86827008, 0, 8192, 4096, 4, ... 86827008, 8192, ) == 0x0 02470 896 NtProtectVirtualMemory (-1, (0x52ce000), 4096, 260, ... (0x52ce000), 4096, 4, ) == 0x0 02471 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 716, {1252, 1564}, ) == 0x0 02472 896 NtQueryInformationThread (716, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff71000,Pid=1252,Tid=1564,}, 0x0, ) == 0x0 02473 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81939, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0\34\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0\34\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81940, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0\34\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0\34\6\0\0" ) ) == 0x0 02468 384 NtProtectVirtualMemory ... (0x77921000), 4096, 32, ) == 0x0 02474 384 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02475 384 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02476 384 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02477 384 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02478 384 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02479 384 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... 02480 896 NtResumeThread (716, ... 1, ) == 0x0 02481 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 86835200, 1048576, ) == 0x0 02482 896 NtAllocateVirtualMemory (-1, 87875584, 0, 8192, 4096, 4, ... 87875584, 8192, ) == 0x0 02483 896 NtProtectVirtualMemory (-1, (0x53ce000), 4096, 260, ... (0x53ce000), 4096, 4, ) == 0x0 02484 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 720, {1252, 164}, ) == 0x0 02485 896 NtQueryInformationThread (720, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff70000,Pid=1252,Tid=164,}, 0x0, ) == 0x0 02479 384 NtProtectVirtualMemory ... (0x77921000), 4096, 32, ) == 0x0 02486 1564 NtWaitForSingleObject (88, 0, 0x0, ... 02487 384 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02488 384 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02489 384 NtProtectVirtualMemory (-1, (0x751d1000), 224, 4, ... (0x751d1000), 4096, 32, ) == 0x0 02490 384 NtProtectVirtualMemory (-1, (0x751d1000), 4096, 32, ... (0x751d1000), 4096, 4, ) == 0x0 02491 384 NtFlushInstructionCache (-1, 1964838912, 224, ... ) == 0x0 02492 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81940, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\244\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\244\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81941, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\244\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\244\0\0\0" ) ) == 0x0 02493 896 NtResumeThread (720, ... 1, ) == 0x0 02494 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02495 164 NtWaitForSingleObject (88, 0, 0x0, ... 02494 896 NtAllocateVirtualMemory ... 87883776, 1048576, ) == 0x0 02496 896 NtAllocateVirtualMemory (-1, 88924160, 0, 8192, 4096, 4, ... 88924160, 8192, ) == 0x0 02497 896 NtProtectVirtualMemory (-1, (0x54ce000), 4096, 260, ... (0x54ce000), 4096, 4, ) == 0x0 02498 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02499 384 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02500 384 NtQueryDefaultUILanguage (2090319928, ... 02501 384 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02502 384 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482764, ) == 0x0 02503 384 NtQueryInformationToken (-2147482764, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02498 896 NtCreateThread ... 724, {1252, 312}, ) == 0x0 02504 896 NtQueryInformationThread (724, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6f000,Pid=1252,Tid=312,}, 0x0, ) == 0x0 02505 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81941, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\08\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\08\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81942, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\08\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\08\1\0\0" ) ) == 0x0 02506 896 NtResumeThread (724, ... 1, ) == 0x0 02507 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 88932352, 1048576, ) == 0x0 02508 896 NtAllocateVirtualMemory (-1, 89972736, 0, 8192, 4096, 4, ... 89972736, 8192, ) == 0x0 02509 384 NtClose (-2147482764, ... 02510 312 NtWaitForSingleObject (88, 0, 0x0, ... 02509 384 NtClose ... ) == 0x0 02511 384 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482764, ) }, ... -2147482764, ) == 0x0 02512 384 NtOpenKey (0x80000000, {24, -2147482764, 0x240, 0, 0, (0x80000000, {24, -2147482764, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02513 384 NtOpenKey (0x80000000, {24, -2147482764, 0x640, 0, 0, (0x80000000, {24, -2147482764, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482688, ) }, ... -2147482688, ) == 0x0 02514 384 NtQueryValueKey (-2147482688, (-2147482688, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02515 384 NtClose (-2147482688, ... ) == 0x0 02516 896 NtProtectVirtualMemory (-1, (0x55ce000), 4096, 260, ... (0x55ce000), 4096, 4, ) == 0x0 02517 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 728, {1252, 1964}, ) == 0x0 02518 896 NtQueryInformationThread (728, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6e000,Pid=1252,Tid=1964,}, 0x0, ) == 0x0 02519 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81942, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\0\254\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\0\254\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81943, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\0\254\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\0\254\7\0\0" ) ) == 0x0 02520 896 NtResumeThread (728, ... 1, ) == 0x0 02521 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02522 384 NtClose (-2147482764, ... 02523 1964 NtWaitForSingleObject (88, 0, 0x0, ... 02522 384 NtClose ... ) == 0x0 02500 384 NtQueryDefaultUILanguage ... ) == 0x0 02524 384 NtAllocateVirtualMemory (-1, 15515648, 0, 4096, 4096, 260, ... 15515648, 4096, ) == 0x0 02525 384 NtQueryInstallUILanguage (2090319930, ... ) == 0x0 02526 384 NtQueryDefaultLocale (1, 15527068, ... ) == 0x0 02527 384 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 02528 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\Setup"}, ... }, ... 02521 896 NtAllocateVirtualMemory ... 89980928, 1048576, ) == 0x0 02529 896 NtAllocateVirtualMemory (-1, 91021312, 0, 8192, 4096, 4, ... 91021312, 8192, ) == 0x0 02530 896 NtProtectVirtualMemory (-1, (0x56ce000), 4096, 260, ... (0x56ce000), 4096, 4, ) == 0x0 02531 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 732, {1252, 1568}, ) == 0x0 02532 896 NtQueryInformationThread (732, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6d000,Pid=1252,Tid=1568,}, 0x0, ) == 0x0 02533 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81943, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0 \6\0\0" ... {28, 56, reply, 0, 1252, 896, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0 \6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81944, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0 \6\0\0" ... {28, 56, reply, 0, 1252, 896, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0 \6\0\0" ) ) == 0x0 02528 384 NtOpenKey ... 736, ) == 0x0 02534 384 NtQueryValueKey (736, (736, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (736, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02535 384 NtClose (736, ... ) == 0x0 02536 384 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 736, ) == 0x0 02537 384 NtCallbackReturn (0, 0, 0, ... 02538 384 NtUserGetProcessWindowStation (... 02539 896 NtResumeThread (732, ... 1, ) == 0x0 02540 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 91029504, 1048576, ) == 0x0 02541 896 NtAllocateVirtualMemory (-1, 92069888, 0, 8192, 4096, 4, ... 92069888, 8192, ) == 0x0 02542 896 NtProtectVirtualMemory (-1, (0x57ce000), 4096, 260, ... (0x57ce000), 4096, 4, ) == 0x0 02543 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 740, {1252, 1624}, ) == 0x0 02544 896 NtQueryInformationThread (740, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6c000,Pid=1252,Tid=1624,}, 0x0, ) == 0x0 02538 384 NtUserGetProcessWindowStation ... ) == 0x20 02545 1568 NtWaitForSingleObject (88, 0, 0x0, ... 02546 384 NtUserGetObjectInformation (32, 1, 15526664, 12, 15526676, ... ) == 0x1 02547 384 NtOpenKey (0xf003f, {24, 28, 0x40, 0, 0, (0xf003f, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\MiniNT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02548 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\WPA\PnP"}, ... 744, ) }, ... 744, ) == 0x0 02549 384 NtQueryValueKey (744, (744, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\240d\351\211"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (744, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\240d\351\211"}, 16, ) }, 16, ) == 0x0 02550 384 NtClose (744, ... ) == 0x0 02551 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... }, ... 02552 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81944, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0X\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0X\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81945, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0X\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0X\6\0\0" ) ) == 0x0 02553 896 NtResumeThread (740, ... 1, ) == 0x0 02554 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 92078080, 1048576, ) == 0x0 02555 896 NtAllocateVirtualMemory (-1, 93118464, 0, 8192, 4096, 4, ... 93118464, 8192, ) == 0x0 02556 896 NtProtectVirtualMemory (-1, (0x58ce000), 4096, 260, ... (0x58ce000), 4096, 4, ) == 0x0 02557 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02551 384 NtOpenKey ... 744, ) == 0x0 02558 1624 NtWaitForSingleObject (88, 0, 0x0, ... 02559 384 NtQueryValueKey (744, (744, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (744, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 02560 384 NtQueryValueKey (744, (744, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (744, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 02561 384 NtClose (744, ... ) == 0x0 02562 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 744, ) }, ... 744, ) == 0x0 02563 384 NtQueryValueKey (744, (744, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (744, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 02564 384 NtQueryValueKey (744, (744, "SystemPartition", Partial, 144, ... , Partial, 144, ... 02557 896 NtCreateThread ... 748, {1252, 1716}, ) == 0x0 02565 896 NtQueryInformationThread (748, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6b000,Pid=1252,Tid=1716,}, 0x0, ) == 0x0 02566 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81945, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\264\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\264\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81946, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\264\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\264\6\0\0" ) ) == 0x0 02567 896 NtResumeThread (748, ... 1, ) == 0x0 02568 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 93126656, 1048576, ) == 0x0 02569 896 NtAllocateVirtualMemory (-1, 94167040, 0, 8192, 4096, 4, ... 94167040, 8192, ) == 0x0 02564 384 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 02570 1716 NtWaitForSingleObject (88, 0, 0x0, ... 02571 384 NtClose (744, ... ) == 0x0 02572 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 744, ) }, ... 744, ) == 0x0 02573 384 NtQueryValueKey (744, (744, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (744, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02574 384 NtQueryValueKey (744, (744, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (744, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02575 384 NtClose (744, ... ) == 0x0 02576 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... }, ... 02577 896 NtProtectVirtualMemory (-1, (0x59ce000), 4096, 260, ... (0x59ce000), 4096, 4, ) == 0x0 02578 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 744, {1252, 1440}, ) == 0x0 02579 896 NtQueryInformationThread (744, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6a000,Pid=1252,Tid=1440,}, 0x0, ) == 0x0 02580 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81946, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0\240\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0\240\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81947, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0\240\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0\240\5\0\0" ) ) == 0x0 02581 896 NtResumeThread (744, ... 1, ) == 0x0 02582 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02576 384 NtOpenKey ... 752, ) == 0x0 02583 1440 NtWaitForSingleObject (88, 0, 0x0, ... 02584 384 NtQueryValueKey (752, (752, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (752, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02585 384 NtQueryValueKey (752, (752, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (752, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02586 384 NtClose (752, ... ) == 0x0 02587 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 752, ) }, ... 752, ) == 0x0 02588 384 NtQueryValueKey (752, (752, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (752, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) }, 102, ) == 0x0 02589 384 NtQueryValueKey (752, (752, "ServicePackCachePath", Partial, 144, ... , Partial, 144, ... 02582 896 NtAllocateVirtualMemory ... 94175232, 1048576, ) == 0x0 02590 896 NtAllocateVirtualMemory (-1, 95215616, 0, 8192, 4096, 4, ... 95215616, 8192, ) == 0x0 02591 896 NtProtectVirtualMemory (-1, (0x5ace000), 4096, 260, ... (0x5ace000), 4096, 4, ) == 0x0 02592 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 756, {1252, 1664}, ) == 0x0 02593 896 NtQueryInformationThread (756, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff69000,Pid=1252,Tid=1664,}, 0x0, ) == 0x0 02594 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81947, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0\200\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0\200\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81948, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0\200\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0\200\6\0\0" ) ) == 0x0 02589 384 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) }, 102, ) == 0x0 02595 384 NtClose (752, ... ) == 0x0 02596 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 752, ) }, ... 752, ) == 0x0 02597 384 NtQueryValueKey (752, (752, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (752, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 02598 384 NtQueryValueKey (752, (752, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (752, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 02599 384 NtClose (752, ... ) == 0x0 02600 384 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... }, ... 02601 896 NtResumeThread (756, ... 1, ) == 0x0 02602 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 95223808, 1048576, ) == 0x0 02603 896 NtAllocateVirtualMemory (-1, 96264192, 0, 8192, 4096, 4, ... 96264192, 8192, ) == 0x0 02604 896 NtProtectVirtualMemory (-1, (0x5bce000), 4096, 260, ... (0x5bce000), 4096, 4, ) == 0x0 02605 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 752, {1252, 1972}, ) == 0x0 02606 896 NtQueryInformationThread (752, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff68000,Pid=1252,Tid=1972,}, 0x0, ) == 0x0 02600 384 NtOpenKey ... 760, ) == 0x0 02607 1664 NtWaitForSingleObject (88, 0, 0x0, ... 02608 384 NtQueryValueKey (760, (760, "DevicePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02609 384 NtQueryValueKey (760, (760, "DevicePath", Partial, 346, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0c\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0r\0i\0c\0h\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0c\0e\0r\0c\0s\0r\06\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\03\02\00\0r\0a\0i\0d\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0i\0a\0s\0t\0o\0r\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0n\0v\0r\0a\0i\0d\0\0\0"}, 346, ) , Partial, 346, ... TitleIdx=0, Type=2, Data= (760, "DevicePath", Partial, 346, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0c\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0r\0i\0c\0h\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0c\0e\0r\0c\0s\0r\06\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\03\02\00\0r\0a\0i\0d\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0i\0a\0s\0t\0o\0r\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0n\0v\0r\0a\0i\0d\0\0\0"}, 346, ) }, 346, ) == 0x0 02610 384 NtAllocateVirtualMemory (-1, 1409024, 0, 4096, 4096, 4, ... 1409024, 4096, ) == 0x0 02611 384 NtClose (760, ... ) == 0x0 02612 384 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 760, ) == 0x0 02613 384 NtCreateMutant (0x1f0001, 0x0, 0, ... 02614 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81948, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\264\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\264\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81949, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\264\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\264\7\0\0" ) ) == 0x0 02615 896 NtResumeThread (752, ... 1, ) == 0x0 02616 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 96272384, 1048576, ) == 0x0 02617 896 NtAllocateVirtualMemory (-1, 97312768, 0, 8192, 4096, 4, ... 97312768, 8192, ) == 0x0 02618 896 NtProtectVirtualMemory (-1, (0x5cce000), 4096, 260, ... (0x5cce000), 4096, 4, ) == 0x0 02619 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02613 384 NtCreateMutant ... 764, ) == 0x0 02620 1972 NtWaitForSingleObject (88, 0, 0x0, ... 02621 384 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 768, ) == 0x0 02622 384 NtCreateMutant (0x1f0001, 0x0, 0, ... 772, ) == 0x0 02623 384 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 776, ) == 0x0 02624 384 NtCreateMutant (0x1f0001, 0x0, 0, ... 780, ) == 0x0 02625 384 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 784, ) }, ... 784, ) == 0x0 02626 384 NtQueryValueKey (784, (784, "LogLevel", Partial, 144, ... , Partial, 144, ... 02619 896 NtCreateThread ... 788, {1252, 1036}, ) == 0x0 02627 896 NtQueryInformationThread (788, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff67000,Pid=1252,Tid=1036,}, 0x0, ) == 0x0 02628 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81949, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\344\4\0\0\14\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\344\4\0\0\14\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81950, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\344\4\0\0\14\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\344\4\0\0\14\4\0\0" ) ) == 0x0 02629 896 NtResumeThread (788, ... 1, ) == 0x0 02630 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 97320960, 1048576, ) == 0x0 02631 896 NtAllocateVirtualMemory (-1, 98361344, 0, 8192, 4096, 4, ... 98361344, 8192, ) == 0x0 02626 384 NtQueryValueKey ... TitleIdx=0, Type=4, Data= ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02632 1036 NtWaitForSingleObject (88, 0, 0x0, ... 02633 384 NtQueryValueKey (784, (784, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (784, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02634 384 NtQueryValueKey (784, (784, "LogPath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02635 384 NtOpenKey (0x1, {24, 784, 0x40, 0, 0, (0x1, {24, 784, 0x40, 0, 0, "AppLogLevels"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02636 384 NtClose (784, ... ) == 0x0 02637 384 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 15526580, ... ) }, 15526580, ... ) == 0x0 02638 384 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName"}, ... }, ... 02639 896 NtProtectVirtualMemory (-1, (0x5dce000), 4096, 260, ... (0x5dce000), 4096, 4, ) == 0x0 02640 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 784, {1252, 1248}, ) == 0x0 02641 896 NtQueryInformationThread (784, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff66000,Pid=1252,Tid=1248,}, 0x0, ) == 0x0 02642 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81950, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\344\4\0\0\340\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\344\4\0\0\340\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81951, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\344\4\0\0\340\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\344\4\0\0\340\4\0\0" ) ) == 0x0 02643 896 NtResumeThread (784, ... 1, ) == 0x0 02644 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02638 384 NtOpenKey ... 792, ) == 0x0 02645 1248 NtWaitForSingleObject (88, 0, 0x0, ... 02646 384 NtQueryValueKey (792, (792, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (792, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (792, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 02647 384 NtClose (792, ... ) == 0x0 02648 384 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 792, ) }, ... 792, ) == 0x0 02649 384 NtQueryValueKey (792, (792, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (792, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) , Data= (792, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) }, 52, ) == 0x0 02650 384 NtClose (792, ... ) == 0x0 02651 384 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\System\DNSclient"}, ... }, ... 02644 896 NtAllocateVirtualMemory ... 98369536, 1048576, ) == 0x0 02652 896 NtAllocateVirtualMemory (-1, 99409920, 0, 8192, 4096, 4, ... 99409920, 8192, ) == 0x0 02653 896 NtProtectVirtualMemory (-1, (0x5ece000), 4096, 260, ... (0x5ece000), 4096, 4, ) == 0x0 02654 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 792, {1252, 1656}, ) == 0x0 02655 896 NtQueryInformationThread (792, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff65000,Pid=1252,Tid=1656,}, 0x0, ) == 0x0 02656 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81951, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\344\4\0\0x\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\344\4\0\0x\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81952, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\344\4\0\0x\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\344\4\0\0x\6\0\0" ) ) == 0x0 02651 384 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02657 384 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 796, ) }, ... 796, ) == 0x0 02658 384 NtQueryValueKey (796, (796, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (796, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Data= (796, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) }, 34, ) == 0x0 02659 384 NtClose (796, ... ) == 0x0 02660 384 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshbth.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02661 384 NtSetEventBoostPriority (88, ... 02393 1332 NtWaitForSingleObject ... ) == 0x0 02662 1332 NtSetEventBoostPriority (88, ... 02405 1336 NtWaitForSingleObject ... ) == 0x0 02663 1336 NtSetEventBoostPriority (88, ... 02417 1808 NtWaitForSingleObject ... ) == 0x0 02664 1808 NtSetEventBoostPriority (88, ... 02429 468 NtWaitForSingleObject ... ) == 0x0 02665 468 NtSetEventBoostPriority (88, ... 02439 752 NtWaitForSingleObject ... ) == 0x0 02666 752 NtSetEventBoostPriority (88, ... 02446 1512 NtWaitForSingleObject ... ) == 0x0 02667 1512 NtSetEventBoostPriority (88, ... 02463 1380 NtWaitForSingleObject ... ) == 0x0 02668 1380 NtSetEventBoostPriority (88, ... 02486 1564 NtWaitForSingleObject ... ) == 0x0 02669 1564 NtSetEventBoostPriority (88, ... 02495 164 NtWaitForSingleObject ... ) == 0x0 02670 164 NtSetEventBoostPriority (88, ... 02510 312 NtWaitForSingleObject ... ) == 0x0 02671 312 NtSetEventBoostPriority (88, ... 02523 1964 NtWaitForSingleObject ... ) == 0x0 02672 1964 NtSetEventBoostPriority (88, ... 02545 1568 NtWaitForSingleObject ... ) == 0x0 02673 1568 NtSetEventBoostPriority (88, ... 02558 1624 NtWaitForSingleObject ... ) == 0x0 02674 1624 NtSetEventBoostPriority (88, ... 02570 1716 NtWaitForSingleObject ... ) == 0x0 02675 1716 NtAllocateVirtualMemory (-1, 8876032, 0, 4096, 4096, 4, ... 8876032, 4096, ) == 0x0 02674 1624 NtSetEventBoostPriority ... ) == 0x0 02673 1568 NtSetEventBoostPriority ... ) == 0x0 02672 1964 NtSetEventBoostPriority ... ) == 0x0 02671 312 NtSetEventBoostPriority ... ) == 0x0 02670 164 NtSetEventBoostPriority ... ) == 0x0 02669 1564 NtSetEventBoostPriority ... ) == 0x0 02668 1380 NtSetEventBoostPriority ... ) == 0x0 02667 1512 NtSetEventBoostPriority ... ) == 0x0 02666 752 NtSetEventBoostPriority ... ) == 0x0 02665 468 NtSetEventBoostPriority ... ) == 0x0 02664 1808 NtSetEventBoostPriority ... ) == 0x0 02663 1336 NtSetEventBoostPriority ... ) == 0x0 02662 1332 NtSetEventBoostPriority ... ) == 0x0 02661 384 NtSetEventBoostPriority ... ) == 0x0 02676 896 NtResumeThread (792, ... 02677 1716 NtSetEventBoostPriority (88, ... 02678 1624 NtTestAlert (... 02679 1568 NtTestAlert (... 02680 1964 NtTestAlert (... 02681 312 NtTestAlert (... 02682 164 NtTestAlert (... 02683 1564 NtTestAlert (... 02684 1380 NtTestAlert (... 02685 1512 NtTestAlert (... 02686 752 NtTestAlert (... 02687 468 NtTestAlert (... 02688 1808 NtTestAlert (... 02689 1336 NtTestAlert (... 02690 384 NtWaitForSingleObject (88, 0, 0x0, ... 02676 896 NtResumeThread ... 1, ) == 0x0 02583 1440 NtWaitForSingleObject ... ) == 0x0 02677 1716 NtSetEventBoostPriority ... ) == 0x0 02678 1624 NtTestAlert ... ) == 0x0 02679 1568 NtTestAlert ... ) == 0x0 02680 1964 NtTestAlert ... ) == 0x0 02681 312 NtTestAlert ... ) == 0x0 02682 164 NtTestAlert ... ) == 0x0 02683 1564 NtTestAlert ... ) == 0x0 02684 1380 NtTestAlert ... ) == 0x0 02685 1512 NtTestAlert ... ) == 0x0 02686 752 NtTestAlert ... ) == 0x0 02687 468 NtTestAlert ... ) == 0x0 02688 1808 NtTestAlert ... ) == 0x0 02689 1336 NtTestAlert ... ) == 0x0 02691 1332 NtTestAlert (... 02692 1656 NtWaitForSingleObject (88, 0, 0x0, ... 02693 1440 NtSetEventBoostPriority (88, ... 02694 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02695 1716 NtTestAlert (... 02696 1624 NtContinue (92077360, 1, ... 02697 1568 NtContinue (91028784, 1, ... 02698 1964 NtContinue (89980208, 1, ... 02699 312 NtContinue (88931632, 1, ... 02700 164 NtContinue (87883056, 1, ... 02701 1564 NtContinue (86834480, 1, ... 02702 1380 NtContinue (85785904, 1, ... 02703 1512 NtContinue (84737328, 1, ... 02704 752 NtContinue (83688752, 1, ... 02705 468 NtContinue (82640176, 1, ... 02706 1808 NtContinue (81591600, 1, ... 02707 1336 NtContinue (80543024, 1, ... 02691 1332 NtTestAlert ... ) == 0x0 02607 1664 NtWaitForSingleObject ... ) == 0x0 02693 1440 NtSetEventBoostPriority ... ) == 0x0 02694 896 NtAllocateVirtualMemory ... 99418112, 1048576, ) == 0x0 02695 1716 NtTestAlert ... ) == 0x0 02708 1624 NtRegisterThreadTerminatePort (24, ... 02709 1568 NtRegisterThreadTerminatePort (24, ... 02710 1964 NtRegisterThreadTerminatePort (24, ... 02711 312 NtRegisterThreadTerminatePort (24, ... 02712 164 NtRegisterThreadTerminatePort (24, ... 02713 1564 NtRegisterThreadTerminatePort (24, ... 02714 1380 NtRegisterThreadTerminatePort (24, ... 02715 1512 NtRegisterThreadTerminatePort (24, ... 02716 752 NtRegisterThreadTerminatePort (24, ... 02717 468 NtRegisterThreadTerminatePort (24, ... 02718 1808 NtRegisterThreadTerminatePort (24, ... 02719 1336 NtRegisterThreadTerminatePort (24, ... 02720 1664 NtSetEventBoostPriority (88, ... 02721 1332 NtContinue (79494448, 1, ... 02722 896 NtAllocateVirtualMemory (-1, 100458496, 0, 8192, 4096, 4, ... 02723 1716 NtContinue (93125936, 1, ... 02708 1624 NtRegisterThreadTerminatePort ... ) == 0x0 02709 1568 NtRegisterThreadTerminatePort ... ) == 0x0 02710 1964 NtRegisterThreadTerminatePort ... ) == 0x0 02711 312 NtRegisterThreadTerminatePort ... ) == 0x0 02712 164 NtRegisterThreadTerminatePort ... ) == 0x0 02713 1564 NtRegisterThreadTerminatePort ... ) == 0x0 02714 1380 NtRegisterThreadTerminatePort ... ) == 0x0 02715 1512 NtRegisterThreadTerminatePort ... ) == 0x0 02716 752 NtRegisterThreadTerminatePort ... ) == 0x0 02717 468 NtRegisterThreadTerminatePort ... ) == 0x0 02718 1808 NtRegisterThreadTerminatePort ... ) == 0x0 02620 1972 NtWaitForSingleObject ... ) == 0x0 02720 1664 NtSetEventBoostPriority ... ) == 0x0 02719 1336 NtRegisterThreadTerminatePort ... ) == 0x0 02724 1332 NtRegisterThreadTerminatePort (24, ... 02722 896 NtAllocateVirtualMemory ... 100458496, 8192, ) == 0x0 02725 1716 NtRegisterThreadTerminatePort (24, ... 02726 1624 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02727 1568 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02728 1964 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02729 312 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02730 164 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02731 1564 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02732 1380 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02733 1512 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02734 752 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02735 468 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02736 1972 NtSetEventBoostPriority (88, ... 02737 1808 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02738 1440 NtTestAlert (... 02739 1336 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02724 1332 NtRegisterThreadTerminatePort ... ) == 0x0 02740 1664 NtTestAlert (... 02741 896 NtProtectVirtualMemory (-1, (0x5fce000), 4096, 260, ... 02725 1716 NtRegisterThreadTerminatePort ... ) == 0x0 02726 1624 NtDuplicateObject ... 796, ) == 0x0 02727 1568 NtDuplicateObject ... 800, ) == 0x0 02728 1964 NtDuplicateObject ... 804, ) == 0x0 02729 312 NtDuplicateObject ... 808, ) == 0x0 02730 164 NtDuplicateObject ... 812, ) == 0x0 02731 1564 NtDuplicateObject ... 816, ) == 0x0 02732 1380 NtDuplicateObject ... 820, ) == 0x0 02733 1512 NtDuplicateObject ... 824, ) == 0x0 02734 752 NtDuplicateObject ... 828, ) == 0x0 02632 1036 NtWaitForSingleObject ... ) == 0x0 02736 1972 NtSetEventBoostPriority ... ) == 0x0 02735 468 NtDuplicateObject ... 832, ) == 0x0 02738 1440 NtTestAlert ... ) == 0x0 02737 1808 NtDuplicateObject ... 836, ) == 0x0 02742 1332 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02740 1664 NtTestAlert ... ) == 0x0 02741 896 NtProtectVirtualMemory ... (0x5fce000), 4096, 4, ) == 0x0 02743 1716 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02744 1624 NtWaitForSingleObject (64, 0, {0, 0}, ... 02745 1568 NtWaitForSingleObject (64, 0, {0, 0}, ... 02746 1964 NtWaitForSingleObject (64, 0, {0, 0}, ... 02747 312 NtWaitForSingleObject (64, 0, {0, 0}, ... 02748 164 NtWaitForSingleObject (64, 0, {0, 0}, ... 02749 1564 NtWaitForSingleObject (64, 0, {0, 0}, ... 02750 1380 NtWaitForSingleObject (64, 0, {0, 0}, ... 02751 1512 NtWaitForSingleObject (64, 0, {0, 0}, ... 02752 1036 NtSetEventBoostPriority (88, ... 02753 752 NtWaitForSingleObject (64, 0, {0, 0}, ... 02739 1336 NtDuplicateObject ... 840, ) == 0x0 02754 468 NtWaitForSingleObject (64, 0, {0, 0}, ... 02755 1440 NtContinue (94174512, 1, ... 02756 1808 NtWaitForSingleObject (64, 0, {0, 0}, ... 02757 1972 NtTestAlert (... 02758 1664 NtContinue (95223088, 1, ... 02759 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02743 1716 NtDuplicateObject ... 844, ) == 0x0 02744 1624 NtWaitForSingleObject ... ) == 0x102 02745 1568 NtWaitForSingleObject ... ) == 0x102 02746 1964 NtWaitForSingleObject ... ) == 0x102 02747 312 NtWaitForSingleObject ... ) == 0x102 02748 164 NtWaitForSingleObject ... ) == 0x102 02749 1564 NtWaitForSingleObject ... ) == 0x102 02750 1380 NtWaitForSingleObject ... ) == 0x102 02645 1248 NtWaitForSingleObject ... ) == 0x0 02752 1036 NtSetEventBoostPriority ... ) == 0x0 02751 1512 NtWaitForSingleObject ... ) == 0x102 02753 752 NtWaitForSingleObject ... ) == 0x102 02760 1336 NtAllocateVirtualMemory (-1, 1413120, 0, 4096, 4096, 4, ... 02754 468 NtWaitForSingleObject ... ) == 0x102 02761 1440 NtRegisterThreadTerminatePort (24, ... 02756 1808 NtWaitForSingleObject ... ) == 0x102 02757 1972 NtTestAlert ... ) == 0x0 02762 1664 NtRegisterThreadTerminatePort (24, ... 02759 896 NtCreateThread ... 848, {1252, 760}, ) == 0x0 02763 1716 NtWaitForSingleObject (284, 0, 0x0, ... 02764 1624 NtWaitForSingleObject (284, 0, 0x0, ... 02765 1568 NtWaitForSingleObject (284, 0, 0x0, ... 02766 1964 NtWaitForSingleObject (284, 0, 0x0, ... 02767 312 NtWaitForSingleObject (284, 0, 0x0, ... 02768 164 NtWaitForSingleObject (284, 0, 0x0, ... 02769 1564 NtWaitForSingleObject (284, 0, 0x0, ... 02770 1248 NtWaitForSingleObject (284, 0, 0x0, ... 02771 1380 NtWaitForSingleObject (284, 0, 0x0, ... 02742 1332 NtDuplicateObject ... 852, ) == 0x0 02772 1512 NtWaitForSingleObject (284, 0, 0x0, ... 02773 752 NtWaitForSingleObject (284, 0, 0x0, ... 02760 1336 NtAllocateVirtualMemory ... 1413120, 4096, ) == 0x0 02774 468 NtWaitForSingleObject (284, 0, 0x0, ... 02761 1440 NtRegisterThreadTerminatePort ... ) == 0x0 02775 1808 NtWaitForSingleObject (284, 0, 0x0, ... 02776 1972 NtContinue (96271664, 1, ... 02762 1664 NtRegisterThreadTerminatePort ... ) == 0x0 02777 896 NtQueryInformationThread (848, Basic, 28, ... 02778 1332 NtWaitForSingleObject (284, 0, 0x0, ... 02779 1336 NtSetEventBoostPriority (284, ... 02780 1440 NtWaitForSingleObject (284, 0, 0x0, ... 02781 1972 NtRegisterThreadTerminatePort (24, ... 02782 1664 NtWaitForSingleObject (284, 0, 0x0, ... 02777 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff64000,Pid=1252,Tid=760,}, 0x0, ) == 0x0 02763 1716 NtWaitForSingleObject ... ) == 0x0 02779 1336 NtSetEventBoostPriority ... ) == 0x0 02783 1036 NtTestAlert (... 02781 1972 NtRegisterThreadTerminatePort ... ) == 0x0 02784 1716 NtSetEventBoostPriority (284, ... 02785 1336 NtWaitForSingleObject (284, 0, 0x0, ... 02783 1036 NtTestAlert ... ) == 0x0 02764 1624 NtWaitForSingleObject ... ) == 0x0 02784 1716 NtSetEventBoostPriority ... ) == 0x0 02786 1972 NtWaitForSingleObject (284, 0, 0x0, ... 02787 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81952, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\3\0\0\344\4\0\0\370\2\0\0" ... ... 02788 1624 NtSetEventBoostPriority (284, ... 02789 1036 NtContinue (97320240, 1, ... 02790 1716 NtWaitForSingleObject (284, 0, 0x0, ... 02765 1568 NtWaitForSingleObject ... ) == 0x0 02788 1624 NtSetEventBoostPriority ... ) == 0x0 02787 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81953, 0} ... {28, 56, reply, 0, 1252, 896, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\3\0\0\344\4\0\0\370\2\0\0" ) ) == 0x0 02791 1036 NtRegisterThreadTerminatePort (24, ... 02792 1568 NtSetEventBoostPriority (284, ... 02793 896 NtResumeThread (848, ... 02766 1964 NtWaitForSingleObject ... ) == 0x0 02792 1568 NtSetEventBoostPriority ... ) == 0x0 02791 1036 NtRegisterThreadTerminatePort ... ) == 0x0 02794 1964 NtSetEventBoostPriority (284, ... 02793 896 NtResumeThread ... 1, ) == 0x0 02795 1624 NtWaitForSingleObject (124, 0, 0x0, ... 02767 312 NtWaitForSingleObject ... ) == 0x0 02794 1964 NtSetEventBoostPriority ... ) == 0x0 02796 1036 NtWaitForSingleObject (284, 0, 0x0, ... 02797 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02798 312 NtSetEventBoostPriority (284, ... 02799 1568 NtWaitForSingleObject (124, 0, 0x0, ... 02800 760 NtWaitForSingleObject (88, 0, 0x0, ... 02801 1964 NtWaitForSingleObject (124, 0, 0x0, ... 02768 164 NtWaitForSingleObject ... ) == 0x0 02798 312 NtSetEventBoostPriority ... ) == 0x0 02802 164 NtSetEventBoostPriority (284, ... 02797 896 NtAllocateVirtualMemory ... 100466688, 1048576, ) == 0x0 02770 1248 NtWaitForSingleObject ... ) == 0x0 02802 164 NtSetEventBoostPriority ... ) == 0x0 02803 1248 NtSetEventBoostPriority (284, ... 02804 896 NtAllocateVirtualMemory (-1, 101507072, 0, 8192, 4096, 4, ... 02805 312 NtWaitForSingleObject (124, 0, 0x0, ... 02769 1564 NtWaitForSingleObject ... ) == 0x0 02803 1248 NtSetEventBoostPriority ... ) == 0x0 02804 896 NtAllocateVirtualMemory ... 101507072, 8192, ) == 0x0 02806 1564 NtSetEventBoostPriority (284, ... 02807 164 NtWaitForSingleObject (124, 0, 0x0, ... 02771 1380 NtWaitForSingleObject ... ) == 0x0 02806 1564 NtSetEventBoostPriority ... ) == 0x0 02808 896 NtProtectVirtualMemory (-1, (0x60ce000), 4096, 260, ... 02809 1380 NtSetEventBoostPriority (284, ... 02810 1248 NtSetEventBoostPriority (88, ... 02772 1512 NtWaitForSingleObject ... ) == 0x0 02809 1380 NtSetEventBoostPriority ... ) == 0x0 02808 896 NtProtectVirtualMemory ... (0x60ce000), 4096, 4, ) == 0x0 02811 1512 NtSetEventBoostPriority (284, ... 02692 1656 NtWaitForSingleObject ... ) == 0x0 02810 1248 NtSetEventBoostPriority ... ) == 0x0 02812 1564 NtWaitForSingleObject (124, 0, 0x0, ... 02773 752 NtWaitForSingleObject ... ) == 0x0 02813 1656 NtWaitForSingleObject (284, 0, 0x0, ... 02811 1512 NtSetEventBoostPriority ... ) == 0x0 02814 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02815 1248 NtTestAlert (... 02816 752 NtSetEventBoostPriority (284, ... 02817 1380 NtWaitForSingleObject (124, 0, 0x0, ... 02818 1512 NtWaitForSingleObject (124, 0, 0x0, ... 02774 468 NtWaitForSingleObject ... ) == 0x0 02816 752 NtSetEventBoostPriority ... ) == 0x0 02815 1248 NtTestAlert ... ) == 0x0 02819 468 NtSetEventBoostPriority (284, ... 02814 896 NtCreateThread ... 856, {1252, 484}, ) == 0x0 02775 1808 NtWaitForSingleObject ... ) == 0x0 02819 468 NtSetEventBoostPriority ... ) == 0x0 02820 1248 NtContinue (98368816, 1, ... 02821 1808 NtSetEventBoostPriority (284, ... 02822 896 NtQueryInformationThread (856, Basic, 28, ... 02823 752 NtWaitForSingleObject (124, 0, 0x0, ... 02778 1332 NtWaitForSingleObject ... ) == 0x0 02821 1808 NtSetEventBoostPriority ... ) == 0x0 02824 1248 NtRegisterThreadTerminatePort (24, ... 02822 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff63000,Pid=1252,Tid=484,}, 0x0, ) == 0x0 02825 1332 NtSetEventBoostPriority (284, ... 02826 468 NtWaitForSingleObject (124, 0, 0x0, ... 02827 1808 NtWaitForSingleObject (124, 0, 0x0, ... 02780 1440 NtWaitForSingleObject ... ) == 0x0 02825 1332 NtSetEventBoostPriority ... ) == 0x0 02828 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81953, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\3\0\0\344\4\0\0\344\1\0\0" ... ... 02829 1440 NtSetEventBoostPriority (284, ... 02824 1248 NtRegisterThreadTerminatePort ... ) == 0x0 02782 1664 NtWaitForSingleObject ... ) == 0x0 02828 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81954, 0} ... {28, 56, reply, 0, 1252, 896, 81954, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\3\0\0\344\4\0\0\344\1\0\0" ) ) == 0x0 02830 1248 NtWaitForSingleObject (284, 0, 0x0, ... 02831 1664 NtSetEventBoostPriority (284, ... 02829 1440 NtSetEventBoostPriority ... ) == 0x0 02832 1332 NtWaitForSingleObject (284, 0, 0x0, ... 02785 1336 NtWaitForSingleObject ... ) == 0x0 02833 1440 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02834 1336 NtSetEventBoostPriority (284, ... 02833 1440 NtDuplicateObject ... 860, ) == 0x0 02790 1716 NtWaitForSingleObject ... ) == 0x0 02834 1336 NtSetEventBoostPriority ... ) == 0x0 02831 1664 NtSetEventBoostPriority ... ) == 0x0 02835 896 NtResumeThread (856, ... 02836 1716 NtSetEventBoostPriority (284, ... 02837 1336 NtWaitForSingleObject (64, 0, {0, 0}, ... 02838 1664 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02835 896 NtResumeThread ... 1, ) == 0x0 02786 1972 NtWaitForSingleObject ... ) == 0x0 02836 1716 NtSetEventBoostPriority ... ) == 0x0 02838 1664 NtDuplicateObject ... 864, ) == 0x0 02839 1972 NtSetEventBoostPriority (284, ... 02840 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02841 1716 NtWaitForSingleObject (284, 0, 0x0, ... 02842 1440 NtWaitForSingleObject (284, 0, 0x0, ... 02843 484 NtWaitForSingleObject (88, 0, 0x0, ... 02837 1336 NtWaitForSingleObject ... ) == 0x102 02796 1036 NtWaitForSingleObject ... ) == 0x0 02840 896 NtAllocateVirtualMemory ... 101515264, 1048576, ) == 0x0 02839 1972 NtSetEventBoostPriority ... ) == 0x0 02844 1664 NtWaitForSingleObject (284, 0, 0x0, ... 02845 1336 NtWaitForSingleObject (284, 0, 0x0, ... 02846 1036 NtSetEventBoostPriority (284, ... 02847 896 NtAllocateVirtualMemory (-1, 102555648, 0, 8192, 4096, 4, ... 02848 1972 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02813 1656 NtWaitForSingleObject ... ) == 0x0 02847 896 NtAllocateVirtualMemory ... 102555648, 8192, ) == 0x0 02849 1656 NtSetEventBoostPriority (284, ... 02848 1972 NtDuplicateObject ... 868, ) == 0x0 02846 1036 NtSetEventBoostPriority ... ) == 0x0 02830 1248 NtWaitForSingleObject ... ) == 0x0 02849 1656 NtSetEventBoostPriority ... ) == 0x0 02850 896 NtProtectVirtualMemory (-1, (0x61ce000), 4096, 260, ... 02851 1248 NtSetEventBoostPriority (284, ... 02852 1036 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02853 1972 NtWaitForSingleObject (284, 0, 0x0, ... 02832 1332 NtWaitForSingleObject ... ) == 0x0 02851 1248 NtSetEventBoostPriority ... ) == 0x0 02850 896 NtProtectVirtualMemory ... (0x61ce000), 4096, 4, ) == 0x0 02852 1036 NtDuplicateObject ... 872, ) == 0x0 02854 1332 NtSetEventBoostPriority (284, ... 02855 1656 NtSetEventBoostPriority (88, ... 02856 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02857 1248 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02842 1440 NtWaitForSingleObject ... ) == 0x0 02854 1332 NtSetEventBoostPriority ... ) == 0x0 02690 384 NtWaitForSingleObject ... ) == 0x0 02855 1656 NtSetEventBoostPriority ... ) == 0x0 02856 896 NtCreateThread ... 876, {1252, 1580}, ) == 0x0 02858 1440 NtSetEventBoostPriority (284, ... 02857 1248 NtDuplicateObject ... 880, ) == 0x0 02859 384 NtSetEventBoostPriority (88, ... 02860 1332 NtWaitForSingleObject (356, 0, 0x0, ... 02861 1656 NtTestAlert (... 02844 1664 NtWaitForSingleObject ... ) == 0x0 02858 1440 NtSetEventBoostPriority ... ) == 0x0 02862 896 NtQueryInformationThread (876, Basic, 28, ... 02800 760 NtWaitForSingleObject ... ) == 0x0 02863 1248 NtWaitForSingleObject (284, 0, 0x0, ... 02859 384 NtSetEventBoostPriority ... ) == 0x0 02864 1036 NtWaitForSingleObject (284, 0, 0x0, ... 02865 1664 NtSetEventBoostPriority (284, ... 02861 1656 NtTestAlert ... ) == 0x0 02866 1440 NtWaitForSingleObject (284, 0, 0x0, ... 02862 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff62000,Pid=1252,Tid=1580,}, 0x0, ) == 0x0 02867 760 NtWaitForSingleObject (284, 0, 0x0, ... 02868 384 NtWaitForSingleObject (284, 0, 0x0, ... 02845 1336 NtWaitForSingleObject ... ) == 0x0 02865 1664 NtSetEventBoostPriority ... ) == 0x0 02869 1656 NtContinue (99417392, 1, ... 02870 1336 NtSetEventBoostPriority (284, ... 02871 1664 NtWaitForSingleObject (284, 0, 0x0, ... 02841 1716 NtWaitForSingleObject ... ) == 0x0 02870 1336 NtSetEventBoostPriority ... ) == 0x0 02872 1656 NtRegisterThreadTerminatePort (24, ... 02873 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81954, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81954, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\3\0\0\344\4\0\0,\6\0\0" ... ... 02874 1716 NtSetEventBoostPriority (284, ... 02875 1336 NtWaitForSingleObject (124, 0, 0x0, ... 02853 1972 NtWaitForSingleObject ... ) == 0x0 02873 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81955, 0} ... {28, 56, reply, 0, 1252, 896, 81955, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\3\0\0\344\4\0\0,\6\0\0" ) ) == 0x0 02876 1972 NtSetEventBoostPriority (284, ... 02877 896 NtResumeThread (876, ... 02863 1248 NtWaitForSingleObject ... ) == 0x0 02876 1972 NtSetEventBoostPriority ... ) == 0x0 02878 1248 NtSetEventBoostPriority (284, ... 02877 896 NtResumeThread ... 1, ) == 0x0 02864 1036 NtWaitForSingleObject ... ) == 0x0 02878 1248 NtSetEventBoostPriority ... ) == 0x0 02879 1972 NtWaitForSingleObject (284, 0, 0x0, ... 02880 1036 NtSetEventBoostPriority (284, ... 02881 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02874 1716 NtSetEventBoostPriority ... ) == 0x0 02872 1656 NtRegisterThreadTerminatePort ... ) == 0x0 02882 1580 NtWaitForSingleObject (88, 0, 0x0, ... 02883 1248 NtWaitForSingleObject (284, 0, 0x0, ... 02866 1440 NtWaitForSingleObject ... ) == 0x0 02880 1036 NtSetEventBoostPriority ... ) == 0x0 02884 1716 NtSetEventBoostPriority (356, ... 02885 1656 NtWaitForSingleObject (284, 0, 0x0, ... 02886 1440 NtSetEventBoostPriority (284, ... 02887 1036 NtWaitForSingleObject (284, 0, 0x0, ... 02860 1332 NtWaitForSingleObject ... ) == 0x0 02884 1716 NtSetEventBoostPriority ... ) == 0x0 02867 760 NtWaitForSingleObject ... ) == 0x0 02886 1440 NtSetEventBoostPriority ... ) == 0x0 02881 896 NtAllocateVirtualMemory ... 102563840, 1048576, ) == 0x0 02888 1332 NtWaitForSingleObject (284, 0, 0x0, ... 02889 760 NtSetEventBoostPriority (284, ... 02890 1440 NtWaitForSingleObject (356, 0, 0x0, ... 02891 896 NtAllocateVirtualMemory (-1, 103604224, 0, 8192, 4096, 4, ... 02868 384 NtWaitForSingleObject ... ) == 0x0 02889 760 NtSetEventBoostPriority ... ) == 0x0 02892 384 NtSetEventBoostPriority (284, ... 02891 896 NtAllocateVirtualMemory ... 103604224, 8192, ) == 0x0 02893 1716 NtWaitForSingleObject (64, 0, {0, 0}, ... 02871 1664 NtWaitForSingleObject ... ) == 0x0 02892 384 NtSetEventBoostPriority ... ) == 0x0 02894 896 NtProtectVirtualMemory (-1, (0x62ce000), 4096, 260, ... 02895 1664 NtSetEventBoostPriority (284, ... 02893 1716 NtWaitForSingleObject ... ) == 0x102 02896 760 NtSetEventBoostPriority (88, ... 02879 1972 NtWaitForSingleObject ... ) == 0x0 02894 896 NtProtectVirtualMemory ... (0x62ce000), 4096, 4, ) == 0x0 02897 1716 NtWaitForSingleObject (124, 0, 0x0, ... 02843 484 NtWaitForSingleObject ... ) == 0x0 02896 760 NtSetEventBoostPriority ... ) == 0x0 02898 1972 NtSetEventBoostPriority (284, ... 02899 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02900 484 NtWaitForSingleObject (284, 0, 0x0, ... 02901 760 NtTestAlert (... 02883 1248 NtWaitForSingleObject ... ) == 0x0 02898 1972 NtSetEventBoostPriority ... ) == 0x0 02895 1664 NtSetEventBoostPriority ... ) == 0x0 02902 384 NtSetEventBoostPriority (124, ... 02901 760 NtTestAlert ... ) == 0x0 02903 1248 NtSetEventBoostPriority (284, ... 02904 1972 NtWaitForSingleObject (356, 0, 0x0, ... 02905 1664 NtWaitForSingleObject (356, 0, 0x0, ... 00856 420 NtWaitForSingleObject ... ) == 0x0 02902 384 NtSetEventBoostPriority ... ) == 0x0 02906 760 NtContinue (100465968, 1, ... 02885 1656 NtWaitForSingleObject ... ) == 0x0 02903 1248 NtSetEventBoostPriority ... ) == 0x0 02907 420 NtWaitForSingleObject (284, 0, 0x0, ... 02908 384 NtWaitForSingleObject (284, 0, 0x0, ... 02909 1656 NtSetEventBoostPriority (284, ... 02910 760 NtRegisterThreadTerminatePort (24, ... 02911 1248 NtWaitForSingleObject (356, 0, 0x0, ... 02887 1036 NtWaitForSingleObject ... ) == 0x0 02909 1656 NtSetEventBoostPriority ... ) == 0x0 02899 896 NtCreateThread ... 884, {1252, 1756}, ) == 0x0 02910 760 NtRegisterThreadTerminatePort ... ) == 0x0 02912 1036 NtSetEventBoostPriority (284, ... 02913 896 NtQueryInformationThread (884, Basic, 28, ... 02888 1332 NtWaitForSingleObject ... ) == 0x0 02914 760 NtWaitForSingleObject (284, 0, 0x0, ... 02915 1332 NtSetEventBoostPriority (284, ... 02913 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff61000,Pid=1252,Tid=1756,}, 0x0, ) == 0x0 02900 484 NtWaitForSingleObject ... ) == 0x0 02916 484 NtSetEventBoostPriority (284, ... 02907 420 NtWaitForSingleObject ... ) == 0x0 02917 420 NtSetEventBoostPriority (284, ... 02908 384 NtWaitForSingleObject ... ) == 0x0 02918 384 NtAllocateVirtualMemory (-1, 1417216, 0, 4096, 4096, 4, ... 1417216, 4096, ) == 0x0 02917 420 NtSetEventBoostPriority ... ) == 0x0 02916 484 NtSetEventBoostPriority ... ) == 0x0 02919 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81955, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81955, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\3\0\0\344\4\0\0\334\6\0\0" ... ... 02915 1332 NtSetEventBoostPriority ... ) == 0x0 02912 1036 NtSetEventBoostPriority ... ) == 0x0 02920 1656 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02921 384 NtSetEventBoostPriority (284, ... 02922 420 NtWaitForSingleObject (284, 0, 0x0, ... 02919 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81956, 0} ... {28, 56, reply, 0, 1252, 896, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\3\0\0\344\4\0\0\334\6\0\0" ) ) == 0x0 02923 484 NtSetEventBoostPriority (88, ... 02924 1036 NtWaitForSingleObject (356, 0, 0x0, ... 02920 1656 NtDuplicateObject ... 888, ) == 0x0 02914 760 NtWaitForSingleObject ... ) == 0x0 02921 384 NtSetEventBoostPriority ... ) == 0x0 02925 1332 NtSetEventBoostPriority (356, ... 02882 1580 NtWaitForSingleObject ... ) == 0x0 02923 484 NtSetEventBoostPriority ... ) == 0x0 02926 760 NtSetEventBoostPriority (284, ... 02927 1656 NtWaitForSingleObject (284, 0, 0x0, ... 02928 384 NtWaitForSingleObject (284, 0, 0x0, ... 02929 1580 NtWaitForSingleObject (284, 0, 0x0, ... 02890 1440 NtWaitForSingleObject ... ) == 0x0 02925 1332 NtSetEventBoostPriority ... ) == 0x0 02922 420 NtWaitForSingleObject ... ) == 0x0 02926 760 NtSetEventBoostPriority ... ) == 0x0 02930 484 NtTestAlert (... 02931 1440 NtWaitForSingleObject (284, 0, 0x0, ... 02932 420 NtSetEventBoostPriority (284, ... 02933 1332 NtWaitForSingleObject (64, 0, {0, 0}, ... 02934 896 NtResumeThread (884, ... 02927 1656 NtWaitForSingleObject ... ) == 0x0 02932 420 NtSetEventBoostPriority ... ) == 0x0 02930 484 NtTestAlert ... ) == 0x0 02933 1332 NtWaitForSingleObject ... ) == 0x102 02935 1656 NtSetEventBoostPriority (284, ... 02934 896 NtResumeThread ... 1, ) == 0x0 02936 420 NtWaitForSingleObject (284, 0, 0x0, ... 02937 484 NtContinue (101514544, 1, ... 02929 1580 NtWaitForSingleObject ... ) == 0x0 02935 1656 NtSetEventBoostPriority ... ) == 0x0 02938 1332 NtWaitForSingleObject (284, 0, 0x0, ... 02939 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02940 760 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02941 1756 NtWaitForSingleObject (88, 0, 0x0, ... 02942 1580 NtSetEventBoostPriority (284, ... 02943 484 NtRegisterThreadTerminatePort (24, ... 02944 1656 NtWaitForSingleObject (284, 0, 0x0, ... 02939 896 NtAllocateVirtualMemory ... 103612416, 1048576, ) == 0x0 02940 760 NtDuplicateObject ... 892, ) == 0x0 02928 384 NtWaitForSingleObject ... ) == 0x0 02942 1580 NtSetEventBoostPriority ... ) == 0x0 02945 896 NtAllocateVirtualMemory (-1, 104652800, 0, 8192, 4096, 4, ... 02946 384 NtSetEventBoostPriority (284, ... 02947 760 NtWaitForSingleObject (284, 0, 0x0, ... 02943 484 NtRegisterThreadTerminatePort ... ) == 0x0 02931 1440 NtWaitForSingleObject ... ) == 0x0 02946 384 NtSetEventBoostPriority ... ) == 0x0 02945 896 NtAllocateVirtualMemory ... 104652800, 8192, ) == 0x0 02948 1440 NtSetEventBoostPriority (284, ... 02949 484 NtWaitForSingleObject (284, 0, 0x0, ... 02950 1580 NtSetEventBoostPriority (88, ... 02951 384 NtWaitForSingleObject (284, 0, 0x0, ... 02936 420 NtWaitForSingleObject ... ) == 0x0 02948 1440 NtSetEventBoostPriority ... ) == 0x0 02941 1756 NtWaitForSingleObject ... ) == 0x0 02950 1580 NtSetEventBoostPriority ... ) == 0x0 02952 420 NtSetEventBoostPriority (284, ... 02953 896 NtProtectVirtualMemory (-1, (0x63ce000), 4096, 260, ... 02954 1756 NtWaitForSingleObject (284, 0, 0x0, ... 02938 1332 NtWaitForSingleObject ... ) == 0x0 02955 1580 NtTestAlert (... 02953 896 NtProtectVirtualMemory ... (0x63ce000), 4096, 4, ) == 0x0 02956 1332 NtSetEventBoostPriority (284, ... 02955 1580 NtTestAlert ... ) == 0x0 02957 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02944 1656 NtWaitForSingleObject ... ) == 0x0 02958 1580 NtContinue (102563120, 1, ... 02957 896 NtCreateThread ... 896, {1252, 1304}, ) == 0x0 02959 1656 NtSetEventBoostPriority (284, ... 02960 1580 NtRegisterThreadTerminatePort (24, ... 02961 896 NtQueryInformationThread (896, Basic, 28, ... 02947 760 NtWaitForSingleObject ... ) == 0x0 02959 1656 NtSetEventBoostPriority ... ) == 0x0 02956 1332 NtSetEventBoostPriority ... ) == 0x0 02952 420 NtSetEventBoostPriority ... ) == 0x0 02962 1440 NtSetEventBoostPriority (356, ... 02963 760 NtSetEventBoostPriority (284, ... 02961 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff60000,Pid=1252,Tid=1304,}, 0x0, ) == 0x0 02964 1656 NtWaitForSingleObject (284, 0, 0x0, ... 02965 1332 NtWaitForSingleObject (124, 0, 0x0, ... 02966 420 NtSetEventBoostPriority (124, ... 02949 484 NtWaitForSingleObject ... ) == 0x0 02963 760 NtSetEventBoostPriority ... ) == 0x0 02904 1972 NtWaitForSingleObject ... ) == 0x0 02962 1440 NtSetEventBoostPriority ... ) == 0x0 02960 1580 NtRegisterThreadTerminatePort ... ) == 0x0 02967 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81956, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\3\0\0\344\4\0\0\30\5\0\0" ... ... 02968 484 NtSetEventBoostPriority (284, ... 00858 596 NtWaitForSingleObject ... ) == 0x0 02966 420 NtSetEventBoostPriority ... ) == 0x0 02969 1972 NtWaitForSingleObject (284, 0, 0x0, ... 02970 1440 NtWaitForSingleObject (64, 0, {0, 0}, ... 02971 1580 NtWaitForSingleObject (284, 0, 0x0, ... 02951 384 NtWaitForSingleObject ... ) == 0x0 02972 596 NtWaitForSingleObject (284, 0, 0x0, ... 02968 484 NtSetEventBoostPriority ... ) == 0x0 02967 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81957, 0} ... {28, 56, reply, 0, 1252, 896, 81957, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\3\0\0\344\4\0\0\30\5\0\0" ) ) == 0x0 02973 760 NtWaitForSingleObject (284, 0, 0x0, ... 02970 1440 NtWaitForSingleObject ... ) == 0x102 02974 384 NtSetEventBoostPriority (284, ... 02975 420 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 02976 896 NtResumeThread (896, ... 02954 1756 NtWaitForSingleObject ... ) == 0x0 02974 384 NtSetEventBoostPriority ... ) == 0x0 02977 1440 NtWaitForSingleObject (124, 0, 0x0, ... 02975 420 NtCreateEvent ... 900, ) == 0x0 02978 1756 NtSetEventBoostPriority (284, ... 02976 896 NtResumeThread ... 1, ) == 0x0 02979 384 NtWaitForSingleObject (284, 0, 0x0, ... 02980 484 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02981 1304 NtWaitForSingleObject (88, 0, 0x0, ... 02964 1656 NtWaitForSingleObject ... ) == 0x0 02978 1756 NtSetEventBoostPriority ... ) == 0x0 02982 420 NtWaitForSingleObject (284, 0, 0x0, ... 02983 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02980 484 NtDuplicateObject ... 904, ) == 0x0 02984 1656 NtSetEventBoostPriority (284, ... 02985 1756 NtSetEventBoostPriority (88, ... 02969 1972 NtWaitForSingleObject ... ) == 0x0 02986 484 NtWaitForSingleObject (284, 0, 0x0, ... 02987 1972 NtSetEventBoostPriority (284, ... 02981 1304 NtWaitForSingleObject ... ) == 0x0 02985 1756 NtSetEventBoostPriority ... ) == 0x0 02972 596 NtWaitForSingleObject ... ) == 0x0 02988 1304 NtWaitForSingleObject (284, 0, 0x0, ... 02987 1972 NtSetEventBoostPriority ... ) == 0x0 02989 596 NtSetEventBoostPriority (284, ... 02990 1756 NtTestAlert (... 02984 1656 NtSetEventBoostPriority ... ) == 0x0 02983 896 NtAllocateVirtualMemory ... 104660992, 1048576, ) == 0x0 02971 1580 NtWaitForSingleObject ... ) == 0x0 02989 596 NtSetEventBoostPriority ... ) == 0x0 02990 1756 NtTestAlert ... ) == 0x0 02991 1656 NtWaitForSingleObject (356, 0, 0x0, ... 02992 1580 NtSetEventBoostPriority (284, ... 02993 896 NtAllocateVirtualMemory (-1, 105701376, 0, 8192, 4096, 4, ... 02994 1972 NtSetEventBoostPriority (356, ... 02995 1756 NtContinue (103611696, 1, ... 02973 760 NtWaitForSingleObject ... ) == 0x0 02992 1580 NtSetEventBoostPriority ... ) == 0x0 02993 896 NtAllocateVirtualMemory ... 105701376, 8192, ) == 0x0 02905 1664 NtWaitForSingleObject ... ) == 0x0 02994 1972 NtSetEventBoostPriority ... ) == 0x0 02996 760 NtSetEventBoostPriority (284, ... 02997 1756 NtRegisterThreadTerminatePort (24, ... 02998 596 NtWaitForSingleObject (284, 0, 0x0, ... 02999 1664 NtWaitForSingleObject (284, 0, 0x0, ... 03000 896 NtProtectVirtualMemory (-1, (0x64ce000), 4096, 260, ... 02979 384 NtWaitForSingleObject ... ) == 0x0 02996 760 NtSetEventBoostPriority ... ) == 0x0 03001 1972 NtWaitForSingleObject (64, 0, {0, 0}, ... 03002 1580 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03003 384 NtSetEventBoostPriority (284, ... 03000 896 NtProtectVirtualMemory ... (0x64ce000), 4096, 4, ) == 0x0 03004 760 NtWaitForSingleObject (356, 0, 0x0, ... 03001 1972 NtWaitForSingleObject ... ) == 0x102 02982 420 NtWaitForSingleObject ... ) == 0x0 03002 1580 NtDuplicateObject ... 908, ) == 0x0 03005 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03003 384 NtSetEventBoostPriority ... ) == 0x0 02997 1756 NtRegisterThreadTerminatePort ... ) == 0x0 03006 1972 NtWaitForSingleObject (284, 0, 0x0, ... 03007 420 NtSetEventBoostPriority (284, ... 03008 1580 NtWaitForSingleObject (284, 0, 0x0, ... 03009 384 NtWaitForSingleObject (284, 0, 0x0, ... 03010 1756 NtWaitForSingleObject (284, 0, 0x0, ... 03005 896 NtCreateThread ... 912, {1252, 2052}, ) == 0x0 02986 484 NtWaitForSingleObject ... ) == 0x0 03007 420 NtSetEventBoostPriority ... ) == 0x0 03011 484 NtSetEventBoostPriority (284, ... 03012 896 NtQueryInformationThread (912, Basic, 28, ... 02988 1304 NtWaitForSingleObject ... ) == 0x0 03011 484 NtSetEventBoostPriority ... ) == 0x0 03013 1304 NtSetEventBoostPriority (284, ... 03012 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff5f000,Pid=1252,Tid=2052,}, 0x0, ) == 0x0 03014 420 NtWaitForSingleObject (284, 0, 0x0, ... 02999 1664 NtWaitForSingleObject ... ) == 0x0 03013 1304 NtSetEventBoostPriority ... ) == 0x0 03015 484 NtWaitForSingleObject (284, 0, 0x0, ... 03016 1664 NtSetEventBoostPriority (284, ... 03017 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81957, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81957, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\3\0\0\344\4\0\0\4\10\0\0" ... ... 02998 596 NtWaitForSingleObject ... ) == 0x0 03016 1664 NtSetEventBoostPriority ... ) == 0x0 03018 596 NtSetEventBoostPriority (284, ... 03017 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81958, 0} ... {28, 56, reply, 0, 1252, 896, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\3\0\0\344\4\0\0\4\10\0\0" ) ) == 0x0 03019 1304 NtTestAlert (... 03008 1580 NtWaitForSingleObject ... ) == 0x0 03018 596 NtSetEventBoostPriority ... ) == 0x0 03020 896 NtResumeThread (912, ... 03021 1580 NtSetEventBoostPriority (284, ... 03019 1304 NtTestAlert ... ) == 0x0 03022 596 NtWaitForSingleObject (284, 0, 0x0, ... 03009 384 NtWaitForSingleObject ... ) == 0x0 03021 1580 NtSetEventBoostPriority ... ) == 0x0 03020 896 NtResumeThread ... 1, ) == 0x0 03023 1304 NtContinue (104660272, 1, ... 03024 1664 NtSetEventBoostPriority (356, ... 03025 2052 NtWaitForSingleObject (284, 0, 0x0, ... 03026 384 NtSetEventBoostPriority (284, ... 03027 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03028 1304 NtRegisterThreadTerminatePort (24, ... 02911 1248 NtWaitForSingleObject ... ) == 0x0 03024 1664 NtSetEventBoostPriority ... ) == 0x0 03010 1756 NtWaitForSingleObject ... ) == 0x0 03026 384 NtSetEventBoostPriority ... ) == 0x0 03029 1580 NtWaitForSingleObject (284, 0, 0x0, ... 03030 1248 NtWaitForSingleObject (284, 0, 0x0, ... 03028 1304 NtRegisterThreadTerminatePort ... ) == 0x0 03031 1756 NtSetEventBoostPriority (284, ... 03032 1664 NtWaitForSingleObject (64, 0, {0, 0}, ... 03027 896 NtAllocateVirtualMemory ... 105709568, 1048576, ) == 0x0 03006 1972 NtWaitForSingleObject ... ) == 0x0 03031 1756 NtSetEventBoostPriority ... ) == 0x0 03033 1304 NtWaitForSingleObject (284, 0, 0x0, ... 03032 1664 NtWaitForSingleObject ... ) == 0x102 03034 1972 NtSetEventBoostPriority (284, ... 03035 896 NtAllocateVirtualMemory (-1, 106749952, 0, 8192, 4096, 4, ... 03036 384 NtWaitForSingleObject (284, 0, 0x0, ... 03037 1756 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03014 420 NtWaitForSingleObject ... ) == 0x0 03038 1664 NtWaitForSingleObject (124, 0, 0x0, ... 03035 896 NtAllocateVirtualMemory ... 106749952, 8192, ) == 0x0 03037 1756 NtDuplicateObject ... 916, ) == 0x0 03039 420 NtSetEventBoostPriority (284, ... 03034 1972 NtSetEventBoostPriority ... ) == 0x0 03040 896 NtProtectVirtualMemory (-1, (0x65ce000), 4096, 260, ... 03041 1756 NtWaitForSingleObject (284, 0, 0x0, ... 03015 484 NtWaitForSingleObject ... ) == 0x0 03039 420 NtSetEventBoostPriority ... ) == 0x0 03042 1972 NtWaitForSingleObject (124, 0, 0x0, ... 03040 896 NtProtectVirtualMemory ... (0x65ce000), 4096, 4, ) == 0x0 03043 484 NtSetEventBoostPriority (284, ... 03044 420 NtWaitForSingleObject (284, 0, 0x0, ... 03022 596 NtWaitForSingleObject ... ) == 0x0 03043 484 NtSetEventBoostPriority ... ) == 0x0 03045 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03046 596 NtSetEventBoostPriority (284, ... 03047 484 NtWaitForSingleObject (356, 0, 0x0, ... 03025 2052 NtWaitForSingleObject ... ) == 0x0 03046 596 NtSetEventBoostPriority ... ) == 0x0 03045 896 NtCreateThread ... 920, {1252, 2056}, ) == 0x0 03048 2052 NtSetEventBoostPriority (284, ... 03049 596 NtSetEventBoostPriority (124, ... 03050 896 NtQueryInformationThread (920, Basic, 28, ... 03030 1248 NtWaitForSingleObject ... ) == 0x0 03048 2052 NtSetEventBoostPriority ... ) == 0x0 00867 376 NtWaitForSingleObject ... ) == 0x0 03049 596 NtSetEventBoostPriority ... ) == 0x0 03051 1248 NtSetEventBoostPriority (284, ... 03050 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff5e000,Pid=1252,Tid=2056,}, 0x0, ) == 0x0 03052 376 NtWaitForSingleObject (284, 0, 0x0, ... 03053 2052 NtTestAlert (... 03029 1580 NtWaitForSingleObject ... ) == 0x0 03054 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81958, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\3\0\0\344\4\0\0\10\10\0\0" ... ... 03053 2052 NtTestAlert ... ) == 0x0 03055 1580 NtSetEventBoostPriority (284, ... 03054 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81959, 0} ... {28, 56, reply, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\3\0\0\344\4\0\0\10\10\0\0" ) ) == 0x0 03056 2052 NtContinue (105708848, 1, ... 03036 384 NtWaitForSingleObject ... ) == 0x0 03055 1580 NtSetEventBoostPriority ... ) == 0x0 03051 1248 NtSetEventBoostPriority ... ) == 0x0 03057 596 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 03058 384 NtSetEventBoostPriority (284, ... 03059 2052 NtRegisterThreadTerminatePort (24, ... 03060 1580 NtWaitForSingleObject (356, 0, 0x0, ... 03061 896 NtResumeThread (920, ... 03033 1304 NtWaitForSingleObject ... ) == 0x0 03058 384 NtSetEventBoostPriority ... ) == 0x0 03057 596 NtCreateEvent ... 924, ) == 0x0 03059 2052 NtRegisterThreadTerminatePort ... ) == 0x0 03062 1248 NtSetEventBoostPriority (356, ... 03063 1304 NtSetEventBoostPriority (284, ... 03061 896 NtResumeThread ... 1, ) == 0x0 03064 384 NtWaitForSingleObject (284, 0, 0x0, ... 03065 596 NtWaitForSingleObject (284, 0, 0x0, ... 03066 2052 NtWaitForSingleObject (284, 0, 0x0, ... 03041 1756 NtWaitForSingleObject ... ) == 0x0 02924 1036 NtWaitForSingleObject ... ) == 0x0 03062 1248 NtSetEventBoostPriority ... ) == 0x0 03067 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03063 1304 NtSetEventBoostPriority ... ) == 0x0 03068 2056 NtWaitForSingleObject (284, 0, 0x0, ... 03069 1036 NtWaitForSingleObject (284, 0, 0x0, ... 03070 1756 NtSetEventBoostPriority (284, ... 03071 1248 NtWaitForSingleObject (64, 0, {0, 0}, ... 03067 896 NtAllocateVirtualMemory ... 106758144, 1048576, ) == 0x0 03072 1304 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03044 420 NtWaitForSingleObject ... ) == 0x0 03070 1756 NtSetEventBoostPriority ... ) == 0x0 03071 1248 NtWaitForSingleObject ... ) == 0x102 03073 896 NtAllocateVirtualMemory (-1, 107798528, 0, 8192, 4096, 4, ... 03074 420 NtAllocateVirtualMemory (-1, 1421312, 0, 4096, 4096, 4, ... 03072 1304 NtDuplicateObject ... 928, ) == 0x0 03075 1248 NtWaitForSingleObject (284, 0, 0x0, ... 03074 420 NtAllocateVirtualMemory ... 1421312, 4096, ) == 0x0 03073 896 NtAllocateVirtualMemory ... 107798528, 8192, ) == 0x0 03076 1756 NtWaitForSingleObject (284, 0, 0x0, ... 03077 1304 NtWaitForSingleObject (284, 0, 0x0, ... 03078 420 NtSetEventBoostPriority (284, ... 03052 376 NtWaitForSingleObject ... ) == 0x0 03079 376 NtSetEventBoostPriority (284, ... 03065 596 NtWaitForSingleObject ... ) == 0x0 03080 596 NtSetEventBoostPriority (284, ... 03064 384 NtWaitForSingleObject ... ) == 0x0 03081 384 NtSetEventBoostPriority (284, ... 03069 1036 NtWaitForSingleObject ... ) == 0x0 03082 1036 NtSetEventBoostPriority (284, ... 03068 2056 NtWaitForSingleObject ... ) == 0x0 03083 2056 NtSetEventBoostPriority (284, ... 03066 2052 NtWaitForSingleObject ... ) == 0x0 03084 2052 NtSetEventBoostPriority (284, ... 03075 1248 NtWaitForSingleObject ... ) == 0x0 03085 1248 NtSetEventBoostPriority (284, ... 03076 1756 NtWaitForSingleObject ... ) == 0x0 03086 1756 NtSetEventBoostPriority (284, ... ) == 0x0 03087 1756 NtWaitForSingleObject (284, 0, 0x0, ... 03083 2056 NtSetEventBoostPriority ... ) == 0x0 03082 1036 NtSetEventBoostPriority ... ) == 0x0 03080 596 NtSetEventBoostPriority ... ) == 0x0 03079 376 NtSetEventBoostPriority ... ) == 0x0 03077 1304 NtWaitForSingleObject ... ) == 0x0 03085 1248 NtSetEventBoostPriority ... ) == 0x0 03084 2052 NtSetEventBoostPriority ... ) == 0x0 03081 384 NtSetEventBoostPriority ... ) == 0x0 03078 420 NtSetEventBoostPriority ... ) == 0x0 03088 896 NtProtectVirtualMemory (-1, (0x66ce000), 4096, 260, ... 03089 2056 NtTestAlert (... 03090 1036 NtSetEventBoostPriority (356, ... 03091 596 NtWaitForSingleObject (284, 0, 0x0, ... 03092 1304 NtSetEventBoostPriority (284, ... 03093 1248 NtWaitForSingleObject (124, 0, 0x0, ... 03094 2052 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03095 384 NtWaitForSingleObject (284, 0, 0x0, ... 03096 376 NtWaitForSingleObject (284, 0, 0x0, ... 03088 896 NtProtectVirtualMemory ... (0x66ce000), 4096, 4, ) == 0x0 03089 2056 NtTestAlert ... ) == 0x0 02991 1656 NtWaitForSingleObject ... ) == 0x0 03090 1036 NtSetEventBoostPriority ... ) == 0x0 03087 1756 NtWaitForSingleObject ... ) == 0x0 03092 1304 NtSetEventBoostPriority ... ) == 0x0 03094 2052 NtDuplicateObject ... 932, ) == 0x0 03097 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03098 1656 NtWaitForSingleObject (284, 0, 0x0, ... 03099 2056 NtContinue (106757424, 1, ... 03100 1756 NtSetEventBoostPriority (284, ... 03101 1036 NtWaitForSingleObject (64, 0, {0, 0}, ... 03102 1304 NtWaitForSingleObject (284, 0, 0x0, ... 03103 420 NtWaitForSingleObject (284, 0, 0x0, ... 03097 896 NtCreateThread ... 936, {1252, 2060}, ) == 0x0 03091 596 NtWaitForSingleObject ... ) == 0x0 03104 2056 NtRegisterThreadTerminatePort (24, ... 03101 1036 NtWaitForSingleObject ... ) == 0x102 03100 1756 NtSetEventBoostPriority ... ) == 0x0 03105 2052 NtWaitForSingleObject (284, 0, 0x0, ... 03106 896 NtQueryInformationThread (936, Basic, 28, ... 03107 596 NtAllocateVirtualMemory (-1, 1425408, 0, 4096, 4096, 4, ... 03104 2056 NtRegisterThreadTerminatePort ... ) == 0x0 03108 1036 NtWaitForSingleObject (284, 0, 0x0, ... 03109 1756 NtWaitForSingleObject (284, 0, 0x0, ... 03106 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff5d000,Pid=1252,Tid=2060,}, 0x0, ) == 0x0 03107 596 NtAllocateVirtualMemory ... 1425408, 4096, ) == 0x0 03110 2056 NtWaitForSingleObject (284, 0, 0x0, ... 03111 596 NtSetEventBoostPriority (284, ... 03112 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81959, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\344\4\0\0\14\10\0\0" ... {28, 56, reply, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\344\4\0\0\14\10\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81960, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\344\4\0\0\14\10\0\0" ... {28, 56, reply, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\344\4\0\0\14\10\0\0" ) ) == 0x0 03113 896 NtResumeThread (936, ... 1, ) == 0x0 03114 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 107806720, 1048576, ) == 0x0 03115 896 NtAllocateVirtualMemory (-1, 108847104, 0, 8192, 4096, 4, ... 108847104, 8192, ) == 0x0 03116 896 NtProtectVirtualMemory (-1, (0x67ce000), 4096, 260, ... (0x67ce000), 4096, 4, ) == 0x0 03117 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03095 384 NtWaitForSingleObject ... ) == 0x0 03111 596 NtSetEventBoostPriority ... ) == 0x0 03118 2060 NtWaitForSingleObject (284, 0, 0x0, ... 03119 384 NtSetEventBoostPriority (284, ... 03120 596 NtWaitForSingleObject (284, 0, 0x0, ... 03096 376 NtWaitForSingleObject ... ) == 0x0 03119 384 NtSetEventBoostPriority ... ) == 0x0 03121 376 NtSetEventBoostPriority (284, ... 03117 896 NtCreateThread ... 940, {1252, 2064}, ) == 0x0 03098 1656 NtWaitForSingleObject ... ) == 0x0 03121 376 NtSetEventBoostPriority ... ) == 0x0 03122 1656 NtSetEventBoostPriority (284, ... 03123 896 NtQueryInformationThread (940, Basic, 28, ... 03103 420 NtWaitForSingleObject ... ) == 0x0 03122 1656 NtSetEventBoostPriority ... ) == 0x0 03124 376 NtWaitForSingleObject (284, 0, 0x0, ... 03125 420 NtSetEventBoostPriority (284, ... 03123 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff5c000,Pid=1252,Tid=2064,}, 0x0, ) == 0x0 03126 384 NtWaitForSingleObject (284, 0, 0x0, ... 03127 1656 NtSetEventBoostPriority (356, ... 03105 2052 NtWaitForSingleObject ... ) == 0x0 03125 420 NtSetEventBoostPriority ... ) == 0x0 03128 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81960, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\3\0\0\344\4\0\0\20\10\0\0" ... ... 03129 2052 NtSetEventBoostPriority (284, ... 03004 760 NtWaitForSingleObject ... ) == 0x0 03127 1656 NtSetEventBoostPriority ... ) == 0x0 03130 420 NtWaitForSingleObject (284, 0, 0x0, ... 03102 1304 NtWaitForSingleObject ... ) == 0x0 03131 760 NtWaitForSingleObject (284, 0, 0x0, ... 03129 2052 NtSetEventBoostPriority ... ) == 0x0 03128 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81961, 0} ... {28, 56, reply, 0, 1252, 896, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\3\0\0\344\4\0\0\20\10\0\0" ) ) == 0x0 03132 1656 NtWaitForSingleObject (64, 0, {0, 0}, ... 03133 1304 NtSetEventBoostPriority (284, ... 03134 2052 NtWaitForSingleObject (284, 0, 0x0, ... 03109 1756 NtWaitForSingleObject ... ) == 0x0 03132 1656 NtWaitForSingleObject ... ) == 0x102 03133 1304 NtSetEventBoostPriority ... ) == 0x0 03135 896 NtResumeThread (940, ... 03136 1756 NtSetEventBoostPriority (284, ... 03137 1656 NtWaitForSingleObject (124, 0, 0x0, ... 03138 1304 NtWaitForSingleObject (284, 0, 0x0, ... 03135 896 NtResumeThread ... 1, ) == 0x0 03108 1036 NtWaitForSingleObject ... ) == 0x0 03136 1756 NtSetEventBoostPriority ... ) == 0x0 03139 2064 NtWaitForSingleObject (88, 0, 0x0, ... 03140 1036 NtSetEventBoostPriority (284, ... 03141 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03110 2056 NtWaitForSingleObject ... ) == 0x0 03141 896 NtAllocateVirtualMemory ... 108855296, 1048576, ) == 0x0 03142 2056 NtSetEventBoostPriority (284, ... 03143 896 NtAllocateVirtualMemory (-1, 109895680, 0, 8192, 4096, 4, ... 03118 2060 NtWaitForSingleObject ... ) == 0x0 03143 896 NtAllocateVirtualMemory ... 109895680, 8192, ) == 0x0 03144 2060 NtSetEventBoostPriority (284, ... 03142 2056 NtSetEventBoostPriority ... ) == 0x0 03140 1036 NtSetEventBoostPriority ... ) == 0x0 03145 1756 NtWaitForSingleObject (356, 0, 0x0, ... 03120 596 NtWaitForSingleObject ... ) == 0x0 03144 2060 NtSetEventBoostPriority ... ) == 0x0 03146 2056 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03147 1036 NtWaitForSingleObject (124, 0, 0x0, ... 03148 596 NtSetEventBoostPriority (284, ... 03149 896 NtProtectVirtualMemory (-1, (0x68ce000), 4096, 260, ... 03146 2056 NtDuplicateObject ... 944, ) == 0x0 03126 384 NtWaitForSingleObject ... ) == 0x0 03148 596 NtSetEventBoostPriority ... ) == 0x0 03149 896 NtProtectVirtualMemory ... (0x68ce000), 4096, 4, ) == 0x0 03150 2060 NtSetEventBoostPriority (88, ... 03151 384 NtSetEventBoostPriority (284, ... 03152 2056 NtWaitForSingleObject (284, 0, 0x0, ... 03153 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03124 376 NtWaitForSingleObject ... ) == 0x0 03151 384 NtSetEventBoostPriority ... ) == 0x0 03139 2064 NtWaitForSingleObject ... ) == 0x0 03150 2060 NtSetEventBoostPriority ... ) == 0x0 03154 376 NtSetEventBoostPriority (284, ... 03153 896 NtCreateThread ... 948, {1252, 2068}, ) == 0x0 03155 2064 NtWaitForSingleObject (284, 0, 0x0, ... 03156 384 NtWaitForSingleObject (284, 0, 0x0, ... 03131 760 NtWaitForSingleObject ... ) == 0x0 03157 2060 NtTestAlert (... 03158 896 NtQueryInformationThread (948, Basic, 28, ... 03154 376 NtSetEventBoostPriority ... ) == 0x0 03159 596 NtWaitForSingleObject (284, 0, 0x0, ... 03160 760 NtSetEventBoostPriority (284, ... 03157 2060 NtTestAlert ... ) == 0x0 03158 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff5b000,Pid=1252,Tid=2068,}, 0x0, ) == 0x0 03161 376 NtSetEventBoostPriority (124, ... 03130 420 NtWaitForSingleObject ... ) == 0x0 03162 2060 NtContinue (107806000, 1, ... 03160 760 NtSetEventBoostPriority ... ) == 0x0 00963 1028 NtWaitForSingleObject ... ) == 0x0 03161 376 NtSetEventBoostPriority ... ) == 0x0 03163 420 NtSetEventBoostPriority (284, ... 03164 2060 NtRegisterThreadTerminatePort (24, ... 03165 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81961, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\3\0\0\344\4\0\0\24\10\0\0" ... ... 03166 1028 NtWaitForSingleObject (284, 0, 0x0, ... 03167 760 NtSetEventBoostPriority (356, ... 03134 2052 NtWaitForSingleObject ... ) == 0x0 03163 420 NtSetEventBoostPriority ... ) == 0x0 03168 376 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 03165 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81962, 0} ... {28, 56, reply, 0, 1252, 896, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\3\0\0\344\4\0\0\24\10\0\0" ) ) == 0x0 03047 484 NtWaitForSingleObject ... ) == 0x0 03167 760 NtSetEventBoostPriority ... ) == 0x0 03169 2052 NtSetEventBoostPriority (284, ... 03170 420 NtWaitForSingleObject (284, 0, 0x0, ... 03168 376 NtCreateEvent ... 952, ) == 0x0 03171 484 NtWaitForSingleObject (284, 0, 0x0, ... 03172 896 NtResumeThread (948, ... 03173 760 NtWaitForSingleObject (64, 0, {0, 0}, ... 03138 1304 NtWaitForSingleObject ... ) == 0x0 03174 376 NtWaitForSingleObject (284, 0, 0x0, ... 03172 896 NtResumeThread ... 1, ) == 0x0 03173 760 NtWaitForSingleObject ... ) == 0x102 03175 1304 NtSetEventBoostPriority (284, ... 03176 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03177 760 NtWaitForSingleObject (124, 0, 0x0, ... 03152 2056 NtWaitForSingleObject ... ) == 0x0 03175 1304 NtSetEventBoostPriority ... ) == 0x0 03169 2052 NtSetEventBoostPriority ... ) == 0x0 03164 2060 NtRegisterThreadTerminatePort ... ) == 0x0 03178 2068 NtWaitForSingleObject (88, 0, 0x0, ... 03176 896 NtAllocateVirtualMemory ... 109903872, 1048576, ) == 0x0 03179 2056 NtSetEventBoostPriority (284, ... 03180 2052 NtWaitForSingleObject (356, 0, 0x0, ... 03181 2060 NtWaitForSingleObject (284, 0, 0x0, ... 03155 2064 NtWaitForSingleObject ... ) == 0x0 03179 2056 NtSetEventBoostPriority ... ) == 0x0 03182 896 NtAllocateVirtualMemory (-1, 110944256, 0, 8192, 4096, 4, ... 03183 2064 NtSetEventBoostPriority (284, ... 03184 2056 NtWaitForSingleObject (284, 0, 0x0, ... 03159 596 NtWaitForSingleObject ... ) == 0x0 03183 2064 NtSetEventBoostPriority ... ) == 0x0 03182 896 NtAllocateVirtualMemory ... 110944256, 8192, ) == 0x0 03185 1304 NtWaitForSingleObject (356, 0, 0x0, ... 03186 596 NtSetEventBoostPriority (284, ... 03187 896 NtProtectVirtualMemory (-1, (0x69ce000), 4096, 260, ... 03156 384 NtWaitForSingleObject ... ) == 0x0 03186 596 NtSetEventBoostPriority ... ) == 0x0 03188 384 NtSetEventBoostPriority (284, ... 03187 896 NtProtectVirtualMemory ... (0x69ce000), 4096, 4, ) == 0x0 03166 1028 NtWaitForSingleObject ... ) == 0x0 03189 596 NtWaitForSingleObject (284, 0, 0x0, ... 03190 1028 NtSetEventBoostPriority (284, ... 03191 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03188 384 NtSetEventBoostPriority ... ) == 0x0 03192 2064 NtSetEventBoostPriority (88, ... 03170 420 NtWaitForSingleObject ... ) == 0x0 03190 1028 NtSetEventBoostPriority ... ) == 0x0 03193 384 NtWaitForSingleObject (356, 0, 0x0, ... 03194 420 NtSetEventBoostPriority (284, ... 03178 2068 NtWaitForSingleObject ... ) == 0x0 03192 2064 NtSetEventBoostPriority ... ) == 0x0 03191 896 NtCreateThread ... 956, {1252, 2072}, ) == 0x0 03171 484 NtWaitForSingleObject ... ) == 0x0 03195 2068 NtWaitForSingleObject (284, 0, 0x0, ... 03194 420 NtSetEventBoostPriority ... ) == 0x0 03196 2064 NtTestAlert (... 03197 484 NtSetEventBoostPriority (284, ... 03198 896 NtQueryInformationThread (956, Basic, 28, ... 03199 1028 NtWaitForSingleObject (284, 0, 0x0, ... 03174 376 NtWaitForSingleObject ... ) == 0x0 03196 2064 NtTestAlert ... ) == 0x0 03198 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff5a000,Pid=1252,Tid=2072,}, 0x0, ) == 0x0 03200 376 NtAllocateVirtualMemory (-1, 1429504, 0, 4096, 4096, 4, ... 03201 2064 NtContinue (108854576, 1, ... 03202 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81962, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\3\0\0\344\4\0\0\30\10\0\0" ... ... 03200 376 NtAllocateVirtualMemory ... 1429504, 4096, ) == 0x0 03203 2064 NtRegisterThreadTerminatePort (24, ... 03202 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81963, 0} ... {28, 56, reply, 0, 1252, 896, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\3\0\0\344\4\0\0\30\10\0\0" ) ) == 0x0 03197 484 NtSetEventBoostPriority ... ) == 0x0 03204 420 NtWaitForSingleObject (284, 0, 0x0, ... 03205 376 NtSetEventBoostPriority (284, ... 03203 2064 NtRegisterThreadTerminatePort ... ) == 0x0 03206 896 NtResumeThread (956, ... 03181 2060 NtWaitForSingleObject ... ) == 0x0 03205 376 NtSetEventBoostPriority ... ) == 0x0 03207 2064 NtWaitForSingleObject (284, 0, 0x0, ... 03208 2060 NtSetEventBoostPriority (284, ... 03206 896 NtResumeThread ... 1, ) == 0x0 03209 376 NtWaitForSingleObject (284, 0, 0x0, ... 03184 2056 NtWaitForSingleObject ... ) == 0x0 03208 2060 NtSetEventBoostPriority ... ) == 0x0 03210 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03211 2056 NtSetEventBoostPriority (284, ... 03212 484 NtSetEventBoostPriority (356, ... 03213 2072 NtWaitForSingleObject (88, 0, 0x0, ... 03189 596 NtWaitForSingleObject ... ) == 0x0 03210 896 NtAllocateVirtualMemory ... 110952448, 1048576, ) == 0x0 03060 1580 NtWaitForSingleObject ... ) == 0x0 03212 484 NtSetEventBoostPriority ... ) == 0x0 03214 596 NtSetEventBoostPriority (284, ... 03215 1580 NtWaitForSingleObject (284, 0, 0x0, ... 03216 896 NtAllocateVirtualMemory (-1, 111992832, 0, 8192, 4096, 4, ... 03217 484 NtWaitForSingleObject (64, 0, {0, 0}, ... 03195 2068 NtWaitForSingleObject ... ) == 0x0 03216 896 NtAllocateVirtualMemory ... 111992832, 8192, ) == 0x0 03218 2068 NtSetEventBoostPriority (284, ... 03217 484 NtWaitForSingleObject ... ) == 0x102 03214 596 NtSetEventBoostPriority ... ) == 0x0 03211 2056 NtSetEventBoostPriority ... ) == 0x0 03219 2060 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03199 1028 NtWaitForSingleObject ... ) == 0x0 03218 2068 NtSetEventBoostPriority ... ) == 0x0 03220 484 NtWaitForSingleObject (124, 0, 0x0, ... 03221 596 NtWaitForSingleObject (284, 0, 0x0, ... 03222 2056 NtWaitForSingleObject (356, 0, 0x0, ... 03223 1028 NtSetEventBoostPriority (284, ... 03219 2060 NtDuplicateObject ... 960, ) == 0x0 03224 896 NtProtectVirtualMemory (-1, (0x6ace000), 4096, 260, ... 03225 2068 NtSetEventBoostPriority (88, ... 03204 420 NtWaitForSingleObject ... ) == 0x0 03223 1028 NtSetEventBoostPriority ... ) == 0x0 03226 2060 NtWaitForSingleObject (284, 0, 0x0, ... 03224 896 NtProtectVirtualMemory ... (0x6ace000), 4096, 4, ) == 0x0 03227 420 NtSetEventBoostPriority (284, ... 03213 2072 NtWaitForSingleObject ... ) == 0x0 03225 2068 NtSetEventBoostPriority ... ) == 0x0 03228 1028 NtSetEventBoostPriority (124, ... 03207 2064 NtWaitForSingleObject ... ) == 0x0 03229 2072 NtWaitForSingleObject (284, 0, 0x0, ... 03227 420 NtSetEventBoostPriority ... ) == 0x0 03230 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03231 2068 NtTestAlert (... 03232 2064 NtSetEventBoostPriority (284, ... 03233 420 NtWaitForSingleObject (284, 0, 0x0, ... 03230 896 NtCreateThread ... 964, {1252, 2076}, ) == 0x0 03209 376 NtWaitForSingleObject ... ) == 0x0 03232 2064 NtSetEventBoostPriority ... ) == 0x0 03231 2068 NtTestAlert ... ) == 0x0 00965 2012 NtWaitForSingleObject ... ) == 0x0 03228 1028 NtSetEventBoostPriority ... ) == 0x0 03234 376 NtSetEventBoostPriority (284, ... 03235 896 NtQueryInformationThread (964, Basic, 28, ... 03236 2068 NtContinue (109903152, 1, ... 03237 2012 NtWaitForSingleObject (284, 0, 0x0, ... 03215 1580 NtWaitForSingleObject ... ) == 0x0 03234 376 NtSetEventBoostPriority ... ) == 0x0 03238 1028 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 03235 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff59000,Pid=1252,Tid=2076,}, 0x0, ) == 0x0 03239 2068 NtRegisterThreadTerminatePort (24, ... 03240 1580 NtSetEventBoostPriority (284, ... 03241 2064 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03238 1028 NtCreateEvent ... 968, ) == 0x0 03242 376 NtWaitForSingleObject (284, 0, 0x0, ... 03243 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81963, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\3\0\0\344\4\0\0\34\10\0\0" ... ... 03221 596 NtWaitForSingleObject ... ) == 0x0 03241 2064 NtDuplicateObject ... 972, ) == 0x0 03244 1028 NtWaitForSingleObject (284, 0, 0x0, ... 03243 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81964, 0} ... {28, 56, reply, 0, 1252, 896, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\3\0\0\344\4\0\0\34\10\0\0" ) ) == 0x0 03245 596 NtSetEventBoostPriority (284, ... 03246 2064 NtWaitForSingleObject (284, 0, 0x0, ... 03247 896 NtResumeThread (964, ... 03226 2060 NtWaitForSingleObject ... ) == 0x0 03245 596 NtSetEventBoostPriority ... ) == 0x0 03248 2060 NtSetEventBoostPriority (284, ... 03247 896 NtResumeThread ... 1, ) == 0x0 03240 1580 NtSetEventBoostPriority ... ) == 0x0 03239 2068 NtRegisterThreadTerminatePort ... ) == 0x0 03229 2072 NtWaitForSingleObject ... ) == 0x0 03248 2060 NtSetEventBoostPriority ... ) == 0x0 03249 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03250 596 NtWaitForSingleObject (284, 0, 0x0, ... 03251 2076 NtWaitForSingleObject (88, 0, 0x0, ... 03252 2072 NtSetEventBoostPriority (284, ... 03253 2068 NtWaitForSingleObject (284, 0, 0x0, ... 03254 1580 NtSetEventBoostPriority (356, ... 03255 2060 NtWaitForSingleObject (284, 0, 0x0, ... 03233 420 NtWaitForSingleObject ... ) == 0x0 03252 2072 NtSetEventBoostPriority ... ) == 0x0 03145 1756 NtWaitForSingleObject ... ) == 0x0 03254 1580 NtSetEventBoostPriority ... ) == 0x0 03256 420 NtSetEventBoostPriority (284, ... 03249 896 NtAllocateVirtualMemory ... 112001024, 1048576, ) == 0x0 03257 1756 NtWaitForSingleObject (284, 0, 0x0, ... 03237 2012 NtWaitForSingleObject ... ) == 0x0 03258 1580 NtWaitForSingleObject (64, 0, {0, 0}, ... 03259 896 NtAllocateVirtualMemory (-1, 113041408, 0, 8192, 4096, 4, ... 03260 2012 NtSetEventBoostPriority (284, ... 03258 1580 NtWaitForSingleObject ... ) == 0x102 03259 896 NtAllocateVirtualMemory ... 113041408, 8192, ) == 0x0 03242 376 NtWaitForSingleObject ... ) == 0x0 03260 2012 NtSetEventBoostPriority ... ) == 0x0 03261 1580 NtWaitForSingleObject (124, 0, 0x0, ... 03262 376 NtSetEventBoostPriority (284, ... 03263 896 NtProtectVirtualMemory (-1, (0x6bce000), 4096, 260, ... 03256 420 NtSetEventBoostPriority ... ) == 0x0 03264 2072 NtSetEventBoostPriority (88, ... 03265 2012 NtSetEventBoostPriority (124, ... 03244 1028 NtWaitForSingleObject ... ) == 0x0 03262 376 NtSetEventBoostPriority ... ) == 0x0 03263 896 NtProtectVirtualMemory ... (0x6bce000), 4096, 4, ) == 0x0 03266 420 NtWaitForSingleObject (284, 0, 0x0, ... 03251 2076 NtWaitForSingleObject ... ) == 0x0 03264 2072 NtSetEventBoostPriority ... ) == 0x0 03267 1028 NtSetEventBoostPriority (284, ... 00969 1168 NtWaitForSingleObject ... ) == 0x0 03265 2012 NtSetEventBoostPriority ... ) == 0x0 03268 376 NtWaitForSingleObject (284, 0, 0x0, ... 03269 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03270 2076 NtWaitForSingleObject (284, 0, 0x0, ... 03246 2064 NtWaitForSingleObject ... ) == 0x0