Summary:

NtCallbackReturn(>) 1 NtUserDrawIconEx(>) 2 NtGdiCreateRectRgn(>) 6 NtUserSelectPalette(>) 16
NtConnectPort(>) 1 NtUserGetIconSize(>) 2 NtGdiGetStockObject(>) 6 NtQueryDirectoryFile(>) 17
NtCreateKey(>) 1 NtUserGetImeInfoEx(>) 2 NtOpenThreadToken(>) 6 NtUserRegisterClassExWOW(>) 17
NtDuplicateObject(>) 1 NtUserQueryInputContext(>) 2 NtUserCalcMenuBar(>) 6 NtGdiCreateCompatibleDC(>) 18
NtFlushVirtualMemory(>) 1 NtUserSetTimer(>) 2 NtUserEndPaint(>) 6 NtQueryInformationFile(>) 19
NtFsControlFile(>) 1 NtUserSetWindowRgn(>) 2 NtUserGetClassInfo(>) 6 NtSetInformationProcess(>) 19
NtGdiExtCreateRegion(>) 1 NtUserSetWindowsHookEx(>) 2 NtUserGetTitleBarInfo(>) 6 NtUserFindExistingCursorIcon(>) 19
NtGdiInit(>) 1 NtUserShowWindow(>) 2 NtUserSetCursorIconData(>) 6 NtUserRemoveProp(>) 20
NtGdiOffsetRgn(>) 1 NtUserUnhookWindowsHookEx(>) 2 NtUserSetWindowPos(>) 6 NtUserWaitMessage(>) 20
NtGdiQueryFontAssocInfo(>) 1 NtUserUnregisterClass(>) 2 NtCreateMutant(>) 7 NtUserPostThreadMessage(>) 21
NtOpenKeyedEvent(>) 1 NtCreateEvent(>) 3 NtGdiGetCharSet(>) 7 NtOpenSection(>) 22
NtOpenMutant(>) 1 NtGdiGetWidthTable(>) 3 NtSetInformationThread(>) 7 NtUserRegisterWindowMessage(>) 22
NtQueryKey(>) 1 NtOpenSymbolicLinkObject(>) 3 NtUserSetProp(>) 7 NtGdiDrawStream(>) 24
NtQueryObject(>) 1 NtQuerySymbolicLinkObject(>) 3 NtEnumerateKey(>) 8 NtQuerySystemInformation(>) 24
NtRegisterThreadTerminatePort(>) 1 NtSetInformationFile(>) 3 NtGdiCreateBitmap(>) 8 NtSetEvent(>) 24
NtSecureConnectPort(>) 1 NtSetInformationObject(>) 3 NtGdiGetBitmapBits(>) 8 NtOpenEvent(>) 25
NtSetValueKey(>) 1 NtUserFillWindow(>) 3 NtGdiGetDCforBitmap(>) 8 NtUserCallMsgFilter(>) 25
NtTestAlert(>) 1 NtUserGetAncestor(>) 3 NtGdiRestoreDC(>) 8 NtUserGetWindowDC(>) 26
NtUserBuildNameList(>) 1 NtUserGetObjectInformation(>) 3 NtGdiSaveDC(>) 8 NtGdiIntersectClipRect(>) 28
NtUserCallHwnd(>) 1 NtUserGetThreadDesktop(>) 3 NtGdiSetDIBitsToDeviceInternal(>) 8 NtGdiExtGetObjectW(>) 30
NtUserCloseDesktop(>) 1 NtUserOpenDesktop(>) 3 NtQueryDefaultUILanguage(>) 8 NtOpenProcessTokenEx(>) 30
NtUserFindWindowEx(>) 1 NtUserSetCursor(>) 3 NtQueryVirtualMemory(>) 8 NtOpenThreadTokenEx(>) 30
NtUserGetCursorFrameInfo(>) 1 NtUserSystemParametersInfo(>) 3 NtUserDispatchMessage(>) 8 NtQueryDefaultLocale(>) 33
NtUserGetGUIThreadInfo(>) 1 NtUserUpdateInputContext(>) 3 NtWriteVirtualMemory(>) 8 NtQueryInformationProcess(>) 34
NtUserInvalidateRect(>) 1 NtAccessCheck(>) 4 NtGdiCreateCompatibleBitmap(>) 9 NtUnmapViewOfSection(>) 34
NtUserModifyUserStartupInfoFlags(>) 1 NtContinue(>) 4 NtGdiGetDCObject(>) 9 NtCreateSection(>) 35
NtUserNotifyIMEStatus(>) 1 NtDuplicateToken(>) 4 NtQuerySection(>) 9 NtFlushInstructionCache(>) 41
NtUserSetCapture(>) 1 NtFreeVirtualMemory(>) 4 NtQueryVolumeInformationFile(>) 9 NtOpenFile(>) 41
NtUserSetImeOwnerWindow(>) 1 NtGdiExcludeClipRect(>) 4 NtUserSetWindowFNID(>) 9 NtQueryInformationToken(>) 41
NtUserSetThreadState(>) 1 NtGdiGetDIBitsInternal(>) 4 NtGdiBitBlt(>) 10 NtAllocateVirtualMemory(>) 42
NtUserTranslateMessage(>) 1 NtGdiGetTextMetricsW(>) 4 NtOpenProcessToken(>) 10 NtUserPeekMessage(>) 44
NtCreateProcessEx(>) 2 NtReadVirtualMemory(>) 4 NtUserDestroyCursor(>) 10 NtQueryAttributesFile(>) 47
NtCreateThread(>) 2 NtUserCallHwndLock(>) 4 NtUserGetIconInfo(>) 10 NtGdiDeleteObjectApp(>) 53
NtDeviceIoControlFile(>) 2 NtUserGetAtomName(>) 4 NtUserInternalGetWindowText(>) 10 NtMapViewOfSection(>) 54
NtGdiCreatePatternBrushInternal(>) 2 NtUserGetClassName(>) 4 NtUserCallNoParam(>) 11 NtWaitForSingleObject(>) 59
NtGdiCreateSolidBrush(>) 2 NtUserGetKeyboardLayoutList(>) 4 NtUserSetWindowLong(>) 11 NtReleaseMutant(>) 61
NtGdiDoPalette(>) 2 NtUserWaitForInputIdle(>) 4 NtRequestWaitReplyPort(>) 12 NtQueryValueKey(>) 70
NtGdiGetDCDword(>) 2 NtGdiGetTextCharsetInfo(>) 5 NtUserBeginPaint(>) 12 NtGdiSelectBitmap(>) 71
NtGdiStretchDIBitsInternal(>) 2 NtGdiHfontCreate(>) 5 NtUserCreateWindowEx(>) 12 NtUserCallOneParam(>) 73
NtOpenDirectoryObject(>) 2 NtUserGetDCEx(>) 5 NtUserGetControlBrush(>) 12 NtProtectVirtualMemory(>) 84
NtQueryDebugFilterState(>) 2 NtUserGetForegroundWindow(>) 5 NtUserGetDC(>) 14 NtUserMessageCall(>) 91
NtQueryInformationJobObject(>) 2 NtUserGetProcessWindowStation(>) 5 NtUserGetThreadState(>) 15 NtOpenKey(>) 129
NtQueryInstallUILanguage(>) 2 NtUserPostMessage(>) 5 NtUserKillTimer(>) 15 NtUserQueryWindow(>) 209
NtResumeThread(>) 2 NtUserSetFocus(>) 5 NtCreateFile(>) 16 NtClose(>) 245
NtTerminateProcess(>) 2 NtWriteFile(>) 5 NtGdiExtSelectClipRgn(>) 16 NtUserValidateHandleSecure(>) 465
NtUserCallHwndParam(>) 2 NtGdiCombineRgn(>) 6 NtGdiGetRandomRgn(>) 16
NtUserDestroyWindow(>) 2 NtGdiCreateDIBitmapInternal(>) 6

Trace:

00001 1356 NtOpenFile (0x80100000, {24, 0, 0x240, 0, 0, (0x80100000, {24, 0, 0x240, 0, 0, "\SystemRoot\Prefetch\PACKED.EXE-09ED06A1.pf"}, 0, 32, ... ) }, 0, 32, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00003 1356 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00004 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00005 1356 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 1310720, 1048576, ) == 0x0 00006 1356 NtAllocateVirtualMemory (-1, 1310720, 0, 4096, 4096, 4, ... 1310720, 4096, ) == 0x0 00007 1356 NtAllocateVirtualMemory (-1, 1314816, 0, 8192, 4096, 4, ... 1314816, 8192, ) == 0x0 00008 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00009 1356 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2359296, 65536, ) == 0x0 00010 1356 NtAllocateVirtualMemory (-1, 2359296, 0, 24576, 4096, 4, ... 2359296, 24576, ) == 0x0 00011 1356 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00012 1356 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00013 1356 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00014 1356 NtClose (12, ... ) == 0x0 00015 1356 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\C:\scripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00016 1356 NtQueryVolumeInformationFile (12, 1243852, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00017 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local"}, 1243804, ... ) }, 1243804, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00018 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00019 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7c800000), 0x0, 1003520, ) == 0x0 00020 1356 NtClose (16, ... ) == 0x0 00021 1356 NtProtectVirtualMemory (-1, (0x7c801000), 1568, 4, ... (0x7c801000), 4096, 32, ) == 0x0 00022 1356 NtProtectVirtualMemory (-1, (0x7c801000), 4096, 32, ... (0x7c801000), 4096, 4, ) == 0x0 00023 1356 NtFlushInstructionCache (-1, 2088767488, 1568, ... ) == 0x0 00024 1356 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00025 1356 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00026 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00027 1356 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00028 1356 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1241944, 44, ... 24, {24, 16, 0, 65536, 2424832, 19136512}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1241944, 44, ... 24, {24, 16, 0, 65536, 2424832, 19136512}, {0, 0, 0}, 200, 44, ) == 0x0 00029 1356 NtClose (16, ... ) == 0x0 00030 1356 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00031 1356 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00032 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00033 1356 NtQueryVirtualMemory (-1, 0x250000, Basic, 28, ... {BaseAddress=0x250000,AllocationBase=0x250000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00034 1356 NtAllocateVirtualMemory (-1, 2424832, 0, 4096, 4096, 4, ... 2424832, 4096, ) == 0x0 00035 1356 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} "\210\6$\1\0\0\0\0eZ\221|\0\0\0\0\1\0\0\0\234\6$\1\4\0\0\0" ... {28, 56, reply, 0, 220, 1356, 75521, 0} "\330<\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6$\1\4\0\0\0" ) ... {28, 56, reply, 0, 220, 1356, 75521, 0} (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} "\210\6$\1\0\0\0\0eZ\221|\0\0\0\0\1\0\0\0\234\6$\1\4\0\0\0" ... {28, 56, reply, 0, 220, 1356, 75521, 0} "\330<\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6$\1\4\0\0\0" ) ) == 0x0 00036 1356 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00037 1356 NtAllocateVirtualMemory (-1, 1232896, 0, 4096, 4096, 260, ... 1232896, 4096, ) == 0x0 00038 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00039 1356 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00040 1356 NtClose (16, ... ) == 0x0 00041 1356 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 16, ) }, ... 16, ) == 0x0 00042 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x260000), 0x0, 90112, ) == 0x0 00043 1356 NtClose (16, ... ) == 0x0 00044 1356 NtQueryDefaultLocale (0, 2089305000, ... ) == 0x0 00045 1356 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 16, ) }, ... 16, ) == 0x0 00046 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x280000), 0x0, 249856, ) == 0x0 00047 1356 NtClose (16, ... ) == 0x0 00048 1356 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 16, ) }, ... 16, ) == 0x0 00049 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2c0000), 0x0, 266240, ) == 0x0 00050 1356 NtQuerySection (16, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00051 1356 NtClose (16, ... ) == 0x0 00052 1356 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 16, ) }, ... 16, ) == 0x0 00053 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x310000), 0x0, 24576, ) == 0x0 00054 1356 NtClose (16, ... ) == 0x0 00055 1356 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00056 1356 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00057 1356 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00058 1356 NtAllocateVirtualMemory (-1, 2428928, 0, 8192, 4096, 4, ... 2428928, 8192, ) == 0x0 00059 1356 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} "\210\6$\1\36\0\1\0\0\0\0\0\377\377\377\377\234\6$\1p\30\0\0" ... {24, 52, reply, 0, 220, 1356, 75522, 0} "\10P\30\0\36\0\1\0\0\0\0\0\377\377\377\377\234\6$\1p\30\0\0" ) ... {24, 52, reply, 0, 220, 1356, 75522, 0} (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} "\210\6$\1\36\0\1\0\0\0\0\0\377\377\377\377\234\6$\1p\30\0\0" ... {24, 52, reply, 0, 220, 1356, 75522, 0} "\10P\30\0\36\0\1\0\0\0\0\0\377\377\377\377\234\6$\1p\30\0\0" ) ) == 0x0 00060 1356 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} "\210\6$\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6$\18\6\0\0" ... {28, 56, reply, 0, 220, 1356, 75523, 0} "\250\202\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6$\18\6\0\0" ) ... {28, 56, reply, 0, 220, 1356, 75523, 0} (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} "\210\6$\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6$\18\6\0\0" ... {28, 56, reply, 0, 220, 1356, 75523, 0} "\250\202\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6$\18\6\0\0" ) ) == 0x0 00061 1356 NtProtectVirtualMemory (-1, (0x40d000), 40960, 4, ... (0x40d000), 40960, 8, ) == 0x0 00062 1356 NtProtectVirtualMemory (-1, (0x40d000), 40960, 8, ... (0x40d000), 40960, 8, ) == 0x0 00063 1356 NtFlushInstructionCache (-1, 4247552, 40960, ... ) == 0x0 00064 1356 NtQueryInformationProcess (-1, 37, 48, ... {process info, class 37, size 48}, 0x0, ) == 0x0 00065 1356 NtSetInformationProcess (-1, 34, {process info, class 34, size 4}, 4, ... ) == 0x0 00066 1356 NtOpenProcessToken (-1, 0x8, ... 16, ) == 0x0 00067 1356 NtQueryInformationToken (16, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00068 1356 NtClose (16, ... ) == 0x0 00069 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00070 1356 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00071 1356 NtClose (16, ... ) == 0x0 00072 1356 NtTestAlert (... ) == 0x0 00073 1356 NtContinue (1244464, 1, ... 00074 1356 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x416c5d,}, 4, ... ) == 0x0 00075 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 16, ) }, ... 16, ) == 0x0 00076 1356 NtQueryValueKey (16, (16, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00077 1356 NtClose (16, ... ) == 0x0 00078 1356 NtAllocateVirtualMemory (-1, 1323008, 0, 4096, 4096, 4, ... 1323008, 4096, ) == 0x0 00079 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "USER32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00080 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7e410000), 0x0, 589824, ) == 0x0 00081 1356 NtClose (16, ... ) == 0x0 00082 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00083 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77f10000), 0x0, 290816, ) == 0x0 00084 1356 NtClose (16, ... ) == 0x0 00085 1356 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00086 1356 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00087 1356 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00088 1356 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00089 1356 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00090 1356 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00091 1356 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00092 1356 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00093 1356 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00094 1356 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00095 1356 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00096 1356 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00097 1356 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00098 1356 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00099 1356 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00100 1356 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00101 1356 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00102 1356 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00103 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00104 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USER32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00105 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00106 1356 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2089900645, 127, 2090320576, 1241696} (24, {28, 56, new_msg, 0, 2089900645, 127, 2090320576, 1241696} "\210\6$\1\0\0\0\0\344\0\23\0\4\0\0\0\3\0\0\0\234\6$\1$\1\0\0" ... {28, 56, reply, 0, 220, 1356, 75524, 0} "\320G\26\0\0\0\0\0\0\0\0\0\4\0\0\0\3\0\0\0\234\6$\1$\1\0\0" ) ... {28, 56, reply, 0, 220, 1356, 75524, 0} (24, {28, 56, new_msg, 0, 2089900645, 127, 2090320576, 1241696} "\210\6$\1\0\0\0\0\344\0\23\0\4\0\0\0\3\0\0\0\234\6$\1$\1\0\0" ... {28, 56, reply, 0, 220, 1356, 75524, 0} "\320G\26\0\0\0\0\0\0\0\0\0\4\0\0\0\3\0\0\0\234\6$\1$\1\0\0" ) ) == 0x0 00107 1356 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... {status=0x0, info=0}, 0x0, ) == 0x0 00108 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239088, ... ) }, 1239088, ... ) == 0x0 00109 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 16, {status=0x0, info=1}, ) }, 5, 96, ... 16, {status=0x0, info=1}, ) == 0x0 00110 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 16, ... 28, ) == 0x0 00111 1356 NtClose (16, ... ) == 0x0 00112 1356 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x420000), 0x0, 110592, ) == 0x0 00113 1356 NtClose (28, ... ) == 0x0 00114 1356 NtUnmapViewOfSection (-1, 0x420000, ... ) == 0x0 00115 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1238996, ... ) }, 1238996, ... ) == 0x0 00116 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 28, {status=0x0, info=1}, ) }, 5, 96, ... 28, {status=0x0, info=1}, ) == 0x0 00117 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 28, ... 16, ) == 0x0 00118 1356 NtClose (28, ... ) == 0x0 00119 1356 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x420000), 0x0, 110592, ) == 0x0 00120 1356 NtClose (16, ... ) == 0x0 00121 1356 NtUnmapViewOfSection (-1, 0x420000, ... ) == 0x0 00122 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239304, ... ) }, 1239304, ... ) == 0x0 00123 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 16, {status=0x0, info=1}, ) }, 5, 96, ... 16, {status=0x0, info=1}, ) == 0x0 00124 1356 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 16, ... 28, ) == 0x0 00125 1356 NtQuerySection (28, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00126 1356 NtOpenProcessToken (-1, 0x8, ... 32, ) == 0x0 00127 1356 NtQueryInformationToken (32, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00128 1356 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00129 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 36, ) }, ... 36, ) == 0x0 00130 1356 NtQueryValueKey (36, (36, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (36, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00131 1356 NtClose (36, ... ) == 0x0 00132 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00133 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 36, ) == 0x0 00134 1356 NtQueryInformationToken (36, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00135 1356 NtClose (36, ... ) == 0x0 00136 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00137 1356 NtClose (32, ... ) == 0x0 00138 1356 NtClose (16, ... ) == 0x0 00139 1356 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76390000), 0x0, 118784, ) == 0x0 00140 1356 NtClose (28, ... ) == 0x0 00141 1356 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00142 1356 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00143 1356 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00144 1356 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00145 1356 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00146 1356 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00147 1356 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00148 1356 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00149 1356 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00150 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00151 1356 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 634880, ) == 0x0 00152 1356 NtClose (28, ... ) == 0x0 00153 1356 NtProtectVirtualMemory (-1, (0x77dd1000), 1700, 4, ... (0x77dd1000), 4096, 32, ) == 0x0 00154 1356 NtProtectVirtualMemory (-1, (0x77dd1000), 4096, 32, ... (0x77dd1000), 4096, 4, ) == 0x0 00155 1356 NtFlushInstructionCache (-1, 2010976256, 1700, ... ) == 0x0 00156 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 28, ) }, ... 28, ) == 0x0 00157 1356 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e70000), 0x0, 593920, ) == 0x0 00158 1356 NtClose (28, ... ) == 0x0 00159 1356 NtAllocateVirtualMemory (-1, 1228800, 0, 4096, 4096, 260, ... 1228800, 4096, ) == 0x0 00160 1356 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00161 1356 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00162 1356 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00163 1356 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00164 1356 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00165 1356 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00166 1356 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00167 1356 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00168 1356 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00169 1356 NtProtectVirtualMemory (-1, (0x77dd1000), 1700, 4, ... (0x77dd1000), 4096, 32, ) == 0x0 00170 1356 NtProtectVirtualMemory (-1, (0x77dd1000), 4096, 32, ... (0x77dd1000), 4096, 4, ) == 0x0 00171 1356 NtFlushInstructionCache (-1, 2010976256, 1700, ... ) == 0x0 00172 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00173 1356 NtAllocateVirtualMemory (-1, 1327104, 0, 4096, 4096, 4, ... 1327104, 4096, ) == 0x0 00174 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00175 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00176 1356 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00177 1356 NtQueryValueKey (28, (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00178 1356 NtClose (28, ... ) == 0x0 00179 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 28, ) }, ... 28, ) == 0x0 00180 1356 NtQueryValueKey (28, (28, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00181 1356 NtClose (28, ... ) == 0x0 00182 1356 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 28, ) }, ... 28, ) == 0x0 00183 1356 NtSetInformationObject (28, Handle, {Inherit=0,ProtectFromClose=1,}, 2011431168, ... ) == 0x0 00184 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00185 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00186 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00187 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1236220, ... ) }, 1236220, ... ) == 0x0 00188 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00189 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernel32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00190 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239624, ... ) }, 1239624, ... ) == 0x0 00191 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00192 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 16, ) }, ... 16, ) == 0x0 00193 1356 NtQueryValueKey (16, (16, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00194 1356 NtClose (16, ... ) == 0x0 00195 1356 NtMapViewOfSection (-2147482576, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x420000), 0x0, 1060864, ) == 0x0 00196 1356 NtClose (-2147482576, ... ) == 0x0 00197 1356 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 16, ) == 0x0 00198 1356 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00199 1356 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482576, ) == 0x0 00200 1356 NtQueryInformationToken (-2147482576, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00201 1356 NtQueryInformationToken (-2147482576, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00202 1356 NtClose (-2147482576, ... ) == 0x0 00203 1356 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 4128768, 4096, ) == 0x0 00204 1356 NtFreeVirtualMemory (-1, (0x3f0000), 4096, 32768, ... (0x3f0000), 4096, ) == 0x0 00205 1356 NtDuplicateObject (-1, 32, -1, 0x0, 0, 2, ... 40, ) == 0x0 00206 1356 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482576, ) }, ... -2147482576, ) == 0x0 00207 1356 NtQueryValueKey (-2147482576, (-2147482576, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00208 1356 NtClose (-2147482576, ... ) == 0x0 00209 1356 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482576, ) }, ... -2147482576, ) == 0x0 00210 1356 NtQueryValueKey (-2147482576, (-2147482576, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00211 1356 NtClose (-2147482576, ... ) == 0x0 00212 1356 NtQueryDefaultLocale (0, -140691124, ... ) == 0x0 00213 1356 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00214 1356 NtUserCallNoParam (24, ... ) == 0x0 00215 1356 NtGdiCreateCompatibleDC (0, ... 00216 1356 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 4128768, 4096, ) == 0x0 00215 1356 NtGdiCreateCompatibleDC ... ) == 0x70010651 00217 1356 NtGdiGetStockObject (0, ... ) == 0x1900010 00218 1356 NtGdiGetStockObject (4, ... ) == 0x1900011 00219 1356 NtGdiCreateBitmap (8, 8, 1, 1, 2118200212, ... ) == 0x560504d6 00220 1356 NtGdiCreateSolidBrush (0, 0, ... 00221 1356 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 8585216, 4096, ) == 0x0 00220 1356 NtGdiCreateSolidBrush ... ) == 0x541007cc 00222 1356 NtGdiGetStockObject (13, ... ) == 0x18a0021 00223 1356 NtGdiCreateCompatibleDC (0, ... ) == 0x45010482 00224 1356 NtGdiSelectBitmap (1157694594, 1443169494, ... ) == 0x185000f 00225 1356 NtUserGetThreadDesktop (1356, 0, ... ) == 0x24 00226 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 44, ) }, ... 44, ) == 0x0 00227 1356 NtQueryValueKey (44, (44, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (44, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00228 1356 NtClose (44, ... ) == 0x0 00229 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00230 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 673, 128, 0, ... ) == 0x8173c017 00231 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00232 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 674, 128, 0, ... ) == 0x8173c01c 00233 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00234 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 675, 128, 0, ... ) == 0x8173c01e 00235 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00236 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 676, 128, 0, ... ) == 0x81738002 00237 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10013 00238 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 677, 128, 0, ... ) == 0x8173c018 00239 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00240 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 678, 128, 0, ... ) == 0x8173c01a 00241 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00242 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 679, 128, 0, ... ) == 0x8173c01d 00243 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00244 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 681, 128, 0, ... ) == 0x8173c026 00245 1356 NtUserFindExistingCursorIcon (1240800, 1240816, 1240864, ... ) == 0x10011 00246 1356 NtUserRegisterClassExWOW (1240812, 1240880, 1240896, 1240912, 680, 128, 0, ... ) == 0x8173c019 00247 1356 NtUserRegisterClassExWOW (1240764, 1240832, 1240848, 1240864, 0, 128, 0, ... ) == 0x8173c020 00248 1356 NtUserRegisterClassExWOW (1241020, 1241116, 1241100, 1241088, 0, 130, 0, ... ) == 0x8173c022 00249 1356 NtUserRegisterClassExWOW (1240764, 1240832, 1240848, 1240864, 0, 128, 0, ... ) == 0x8173c023 00250 1356 NtUserRegisterClassExWOW (1241020, 1241116, 1241100, 1241088, 0, 130, 0, ... ) == 0x8173c024 00251 1356 NtUserRegisterClassExWOW (1240764, 1240832, 1240848, 1240864, 0, 128, 0, ... ) == 0x8173c025 00252 1356 NtCallbackReturn (0, 0, 0, ... 00253 1356 NtGdiInit (... ) == 0x1 00254 1356 NtGdiGetStockObject (18, ... ) == 0x290001c 00255 1356 NtGdiGetStockObject (19, ... ) == 0x1b00019 00256 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSVCRT.dll"}, ... 44, ) }, ... 44, ) == 0x0 00257 1356 NtMapViewOfSection (44, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 360448, ) == 0x0 00258 1356 NtClose (44, ... ) == 0x0 00259 1356 NtProtectVirtualMemory (-1, (0x77c11000), 632, 4, ... (0x77c11000), 4096, 32, ) == 0x0 00260 1356 NtProtectVirtualMemory (-1, (0x77c11000), 4096, 32, ... (0x77c11000), 4096, 4, ) == 0x0 00261 1356 NtFlushInstructionCache (-1, 2009141248, 632, ... ) == 0x0 00262 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSVCRT.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00263 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00264 1356 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 8650752, 65536, ) == 0x0 00265 1356 NtAllocateVirtualMemory (-1, 8650752, 0, 4096, 4096, 4, ... 8650752, 4096, ) == 0x0 00266 1356 NtAllocateVirtualMemory (-1, 8654848, 0, 8192, 4096, 4, ... 8654848, 8192, ) == 0x0 00267 1356 NtAllocateVirtualMemory (-1, 8663040, 0, 4096, 4096, 4, ... 8663040, 4096, ) == 0x0 00268 1356 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 44, ) }, ... 44, ) == 0x0 00269 1356 NtMapViewOfSection (44, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x850000), 0x0, 12288, ) == 0x0 00270 1356 NtClose (44, ... ) == 0x0 00271 1356 NtAllocateVirtualMemory (-1, 8667136, 0, 4096, 4096, 4, ... 8667136, 4096, ) == 0x0 00272 1356 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 00273 1356 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00274 1356 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00275 1356 NtQueryVirtualMemory (-1, 0x0, Basic, 28, ... {BaseAddress=0x0,AllocationBase=0x0,AllocationProtect=0x0,RegionSize=0x10000,State=0x10000,Protect=0x1,Type=0x0,}, 28, ) == 0x0 00276 1356 NtUserModifyUserStartupInfoFlags (1, 0, ... ) == 0x81734078 00277 1356 NtUserGetDCEx (0, 0, 3, ... ) == 0x1010050 00278 1356 NtUserGetForegroundWindow (... ) == 0x13010c 00279 1356 NtUserQueryWindow (1245452, 0, ... ) == 0x5e8 00280 1356 NtUserQueryWindow (1245452, 1, ... ) == 0x534 00281 1356 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 00282 1356 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x300403ba 00283 1356 NtGdiGetRandomRgn (16842832, 805569466, 1, ... ) == 0x0 00284 1356 NtGdiIntersectClipRect (16842832, 0, 0, 565, 738, ... ) == 0x3 00285 1356 NtGdiExtSelectClipRgn (16842832, 0, 5, ... ) == 0x2 00286 1356 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 00287 1356 NtGdiGetRandomRgn (16842832, 822346682, 1, ... ) == 0x0 00288 1356 NtGdiIntersectClipRect (16842832, 0, 0, 147, 738, ... ) == 0x3 00289 1356 NtGdiExtSelectClipRgn (16842832, 0, 5, ... ) == 0x2 00290 1356 NtUserCallOneParam (16842832, 57, ... ) == 0x1 00291 1356 NtAllocateVirtualMemory (-1, 1331200, 0, 4096, 4096, 4, ... 1331200, 4096, ) == 0x0 00292 1356 NtUserFindExistingCursorIcon (1241636, 1241652, 1241700, ... ) == 0x10011 00293 1356 NtUserSetCursor (65553, ... ) == 0x10015 00294 1356 NtUserCallOneParam (1, 50, ... ) == 0x1 00295 1356 NtUserFindExistingCursorIcon (1241588, 1241604, 1241652, ... ) == 0x10015 00296 1356 NtUserSetCursor (65557, ... ) == 0x10011 00297 1356 NtGdiCreateCompatibleDC (0, ... ) == 0xe90104a8 00298 1356 NtGdiExtGetObjectW (50987262, 92, 1241876, ... ) == 0x5c 00299 1356 NtGdiHfontCreate (1241348, 356, 0, 0, 1331320, ... ) == 0x330a069c 00300 1356 NtGdiGetTextMetricsW (-385809240, 1241872, 68, ... ) == 0x1 00301 1356 NtGdiGetWidthTable (-385809240, 52, 1332024, 308, 1332640, 1331392, 1331408, ... ) == 0x1 00302 1356 NtGdiDeleteObjectApp (-385809240, ... ) == 0x1 00303 1356 NtUserGetForegroundWindow (... ) == 0x13010c 00304 1356 NtUserQueryWindow (1245452, 0, ... ) == 0x5e8 00305 1356 NtUserQueryWindow (1245452, 1, ... ) == 0x534 00306 1356 NtUserGetAtomName (32770, 1240848, ... ) == 0x6 00307 1356 NtUserCreateWindowEx (65793, 32770, 32770, (65793, 32770, 32770, "Error", -2134375995, 404, 335, 222, 126, 0, 0, 2118189056, 0, 1073742848, 0, ... , -2134375995, 404, 335, 222, 126, 0, 0, 2118189056, 0, 1073742848, 0, ... 00308 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1238320, ... ) }, 1238320, ... ) == 0x0 00309 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 44, {status=0x0, info=1}, ) }, 5, 96, ... 44, {status=0x0, info=1}, ) == 0x0 00310 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 44, ... 48, ) == 0x0 00311 1356 NtClose (44, ... ) == 0x0 00312 1356 NtMapViewOfSection (48, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x860000), 0x0, 221184, ) == 0x0 00313 1356 NtClose (48, ... ) == 0x0 00314 1356 NtUnmapViewOfSection (-1, 0x860000, ... ) == 0x0 00315 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1238628, ... ) }, 1238628, ... ) == 0x0 00316 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 48, {status=0x0, info=1}, ) }, 5, 96, ... 48, {status=0x0, info=1}, ) == 0x0 00317 1356 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 48, ... 44, ) == 0x0 00318 1356 NtQuerySection (44, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00319 1356 NtClose (48, ... ) == 0x0 00320 1356 NtMapViewOfSection (44, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5ad70000), 0x0, 229376, ) == 0x0 00321 1356 NtClose (44, ... ) == 0x0 00322 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00323 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00324 1356 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00325 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00326 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00327 1356 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00328 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00329 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00330 1356 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00331 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 00332 1356 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 00333 1356 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 00334 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uxtheme.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00335 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00336 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00337 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00338 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 44, ) == 0x0 00339 1356 NtQueryInformationToken (44, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00340 1356 NtClose (44, ... ) == 0x0 00341 1356 NtOpenKey (0x2001f, {24, 0, 0x640, 0, 0, (0x2001f, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 44, ) }, ... 44, ) == 0x0 00342 1356 NtOpenKey (0x1, {24, 44, 0x40, 0, 0, (0x1, {24, 44, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\ThemeManager"}, ... 48, ) }, ... 48, ) == 0x0 00343 1356 NtQueryValueKey (48, (48, "Compositing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00344 1356 NtClose (48, ... ) == 0x0 00345 1356 NtClose (44, ... ) == 0x0 00346 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00347 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 44, ) == 0x0 00348 1356 NtQueryInformationToken (44, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00349 1356 NtClose (44, ... ) == 0x0 00350 1356 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 44, ) }, ... 44, ) == 0x0 00351 1356 NtOpenKey (0x1, {24, 44, 0x40, 0, 0, (0x1, {24, 44, 0x40, 0, 0, "Control Panel\Desktop"}, ... 48, ) }, ... 48, ) == 0x0 00352 1356 NtQueryValueKey (48, (48, "LameButtonText", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00353 1356 NtClose (48, ... ) == 0x0 00354 1356 NtClose (44, ... ) == 0x0 00355 1356 NtUserGetProcessWindowStation (... ) == 0x20 00356 1356 NtUserGetObjectInformation (32, 2, 1240416, 64, 1240412, ... ) == 0x1 00357 1356 NtUserGetGUIThreadInfo (1356, 1240436, ... ) == 0x1 00358 1356 NtConnectPort ( ("\ThemeApiPort", {12, 2, 1, 1}, 0x0, 0x0, 1240280, 64, ... 44, 0x0, 0x0, 0x0, 64, ) , {12, 2, 1, 1}, 0x0, 0x0, 1240280, 64, ... 44, 0x0, 0x0, 0x0, 64, ) == 0x0 00359 1356 NtRequestWaitReplyPort (44, {32, 56, new_msg, 0, 0, 0, 0, 0} (44, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 220, 1356, 75536, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 220, 1356, 75536, 0} (44, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 220, 1356, 75536, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00360 1356 NtRequestWaitReplyPort (44, {32, 56, new_msg, 0, 0, 0, 0, 0} (44, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 220, 1356, 75537, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 220, 1356, 75537, 0} (44, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 220, 1356, 75537, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00361 1356 NtUserCallNoParam (29, ... 00362 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1237676, ... ) }, 1237676, ... ) == 0x0 00361 1356 NtUserCallNoParam ... ) == 0x0 00363 1356 NtUserSystemParametersInfo (41, 0, 1524240760, 0, ... ) == 0x1 00364 1356 NtGdiHfontCreate (1239804, 356, 0, 0, 1331312, ... ) == 0xea0a04a8 00365 1356 NtGdiHfontCreate (1239804, 356, 0, 0, 1331304, ... ) == 0x6c0a07a9 00366 1356 NtRequestWaitReplyPort (44, {32, 56, new_msg, 0, 0, 0, 0, 0} (44, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 220, 1356, 75538, 0} "\0\0\0\0\0\0\0\00\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 220, 1356, 75538, 0} (44, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 220, 1356, 75538, 0} "\0\0\0\0\0\0\0\00\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 00367 1356 NtMapViewOfSection (48, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x860000), {0, 0}, 327680, ) == 0x0 00368 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00369 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00370 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00371 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00372 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00373 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00374 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00375 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00376 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00377 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00378 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00379 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00380 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00381 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00382 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00383 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00384 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00385 1356 NtGdiCreatePatternBrushInternal (59048383, 0, 0, ... ) == 0x4510066c 00386 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00387 1356 NtUserCallNoParam (29, ... 00388 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1237116, ... ) }, 1237116, ... ) == 0x0 00387 1356 NtUserCallNoParam ... ) == 0x0 00389 1356 NtUserCallNoParam (29, ... 00390 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1237112, ... ) }, 1237112, ... ) == 0x0 00389 1356 NtUserCallNoParam ... ) == 0x0 00391 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 1238324, ... ) }, 1238324, ... ) == 0x0 00392 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 5, 96, ... 52, {status=0x0, info=1}, ) }, 5, 96, ... 52, {status=0x0, info=1}, ) == 0x0 00393 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 52, ... 56, ) == 0x0 00394 1356 NtClose (52, ... ) == 0x0 00395 1356 NtMapViewOfSection (56, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x8b0000), 0x0, 294912, ) == 0x0 00396 1356 NtClose (56, ... ) == 0x0 00397 1356 NtUnmapViewOfSection (-1, 0x8b0000, ... ) == 0x0 00398 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 1238632, ... ) }, 1238632, ... ) == 0x0 00399 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 5, 96, ... 56, {status=0x0, info=1}, ) }, 5, 96, ... 56, {status=0x0, info=1}, ) == 0x0 00400 1356 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 56, ... 52, ) == 0x0 00401 1356 NtQuerySection (52, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00402 1356 NtClose (56, ... ) == 0x0 00403 1356 NtMapViewOfSection (52, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x74720000), 0x0, 307200, ) == 0x0 00404 1356 NtClose (52, ... ) == 0x0 00405 1356 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 00406 1356 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 00407 1356 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 00408 1356 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 00409 1356 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 00410 1356 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 00411 1356 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 00412 1356 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 00413 1356 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 00414 1356 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 00415 1356 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 00416 1356 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 00417 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSCTF.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00418 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ntdll.dll"}, 1235988, ... ) }, 1235988, ... ) == 0x0 00419 1356 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 00420 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 00421 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.Private", ... ) , ... ) == 0xc0a1 00422 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.SetFocus", ... ) , ... ) == 0xc0a2 00423 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ThreadTerminate", ... ) , ... ) == 0xc0a3 00424 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ThreadItemChange", ... ) , ... ) == 0xc0a4 00425 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.LangBarModal", ... ) , ... ) == 0xc0a5 00426 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.RpcSendReceive", ... ) , ... ) == 0xc0a6 00427 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ThreadMarshal", ... ) , ... ) == 0xc0a7 00428 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.CheckThreadInputIdel", ... ) , ... ) == 0xc0a8 00429 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.StubCleanUp", ... ) , ... ) == 0xc0a9 00430 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ShowFloating", ... ) , ... ) == 0xc0aa 00431 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.LBUpdate", ... ) , ... ) == 0xc0ab 00432 1356 NtUserRegisterWindowMessage ( ("MSUIM.Msg.MuiMgrDirtyUpdate", ... ) , ... ) == 0xc0ac 00433 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\imm32.dll"}, 1235996, ... ) }, 1235996, ... ) == 0x0 00434 1356 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 3998, 1238388, 0, 0} (24, {24, 52, new_msg, 0, 3998, 1238388, 0, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0L\5\0\0\0\0\0\0" ... {24, 52, reply, 0, 220, 1356, 75541, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0L\5\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 220, 1356, 75541, 0} (24, {24, 52, new_msg, 0, 3998, 1238388, 0, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0L\5\0\0\0\0\0\0" ... {24, 52, reply, 0, 220, 1356, 75541, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0L\5\0\0\0\0\0\0" ) ) == 0x0 00435 1356 NtUserGetThreadDesktop (1356, 0, ... ) == 0x24 00436 1356 NtUserGetObjectInformation (36, 2, 1318544, 520, 1238296, ... ) == 0x1 00437 1356 NtOpenProcessToken (-1, 0x8, ... 52, ) == 0x0 00438 1356 NtQueryInformationToken (52, User, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00439 1356 NtQueryInformationToken (52, User, 36, ... {token info, class 1, size 36}, 36, ) == 0x0 00440 1356 NtClose (52, ... ) == 0x0 00441 1356 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 52, ) }, ... 52, ) == 0x0 00442 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "CiceroSharedMemDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, {3240, 0}, 4, 134217728, 0, ... 56, ) }, {3240, 0}, 4, 134217728, 0, ... 56, ) == STATUS_OBJECT_NAME_EXISTS 00443 1356 NtMapViewOfSection (56, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x8b0000), {0, 0}, 4096, ) == 0x0 00444 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\Compatibility\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00445 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\SystemShared\"}, ... 60, ) }, ... 60, ) == 0x0 00446 1356 NtQueryValueKey (60, (60, "CUAS", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (60, "CUAS", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00447 1356 NtClose (60, ... ) == 0x0 00448 1356 NtUserFindExistingCursorIcon (1237828, 1237844, 1237892, ... ) == 0x10011 00449 1356 NtUserRegisterClassExWOW (1238100, 1238196, 1238180, 1238168, 0, 386, 0, ... ) == 0x8173c0ad 00450 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "CTF.LBES.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 60, ) }, 0, ... 60, ) == STATUS_OBJECT_NAME_EXISTS 00451 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "CTF.Compart.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 64, ) }, 0, ... 64, ) == STATUS_OBJECT_NAME_EXISTS 00452 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "CTF.Asm.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 68, ) }, 0, ... 68, ) == STATUS_OBJECT_NAME_EXISTS 00453 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "CTF.Layouts.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 72, ) }, 0, ... 72, ) == STATUS_OBJECT_NAME_EXISTS 00454 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "CTF.TMD.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 76, ) }, 0, ... 76, ) == STATUS_OBJECT_NAME_EXISTS 00455 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00456 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 80, ) == 0x0 00457 1356 NtQueryInformationToken (80, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00458 1356 NtClose (80, ... ) == 0x0 00459 1356 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 80, ) }, ... 80, ) == 0x0 00460 1356 NtSetInformationObject (80, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 00461 1356 NtOpenKey (0x20019, {24, 80, 0x40, 0, 0, (0x20019, {24, 80, 0x40, 0, 0, "Keyboard Layout\Toggle"}, ... 84, ) }, ... 84, ) == 0x0 00462 1356 NtQueryValueKey (84, (84, "Language Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00463 1356 NtQueryValueKey (84, (84, "Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00464 1356 NtQueryValueKey (84, (84, "Layout Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00465 1356 NtClose (84, ... ) == 0x0 00466 1356 NtAllocateVirtualMemory (-1, 1335296, 0, 4096, 4096, 4, ... 1335296, 4096, ) == 0x0 00467 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\KERNEL32.dll"}, 1235816, ... ) }, 1235816, ... ) == 0x0 00468 1356 NtQueryDefaultUILanguage (1238376, ... 00469 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00470 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482576, ) == 0x0 00471 1356 NtQueryInformationToken (-2147482576, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00472 1356 NtClose (-2147482576, ... ) == 0x0 00473 1356 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482644, ) }, ... -2147482644, ) == 0x0 00474 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x240, 0, 0, (0x80000000, {24, -2147482644, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00475 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x640, 0, 0, (0x80000000, {24, -2147482644, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482640, ) }, ... -2147482640, ) == 0x0 00476 1356 NtQueryValueKey (-2147482640, (-2147482640, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00477 1356 NtClose (-2147482640, ... ) == 0x0 00478 1356 NtClose (-2147482644, ... ) == 0x0 00468 1356 NtQueryDefaultUILanguage ... ) == 0x0 00479 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\"}, ... 84, ) }, ... 84, ) == 0x0 00480 1356 NtQueryValueKey (84, (84, "EnableAnchorContext", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00481 1356 NtClose (84, ... ) == 0x0 00482 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "CTF.TimListCache.FMPDefaultS-1-5-21-1292428093-1383384898-725345543-1003MUTEX.DefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 84, ) }, 0, ... 84, ) == STATUS_OBJECT_NAME_EXISTS 00483 1356 NtOpenSection (0xf001f, {24, 52, 0x0, 0, 0, (0xf001f, {24, 52, 0x0, 0, 0, "CTF.TimListCache.FMPDefaultS-1-5-21-1292428093-1383384898-725345543-1003SFM.DefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, ... 88, ) }, ... 88, ) == 0x0 00484 1356 NtMapViewOfSection (88, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x8c0000), {0, 0}, 262144, ) == 0x0 00485 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 00486 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 00487 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 00488 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 00489 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 00490 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 00491 1356 NtUserSetWindowsHookEx (1953628160, 1239852, 1356, 2, 1953694283, 2, ... ) == 0x39019f 00492 1356 NtUserSetWindowsHookEx (1953628160, 1239852, 1356, 7, 1953693577, 2, ... ) == 0x1401e3 00493 1356 NtUserSetWindowFNID (524612, 676, ... ) == 0x1 00494 1356 NtUserCallHwndParam (524612, 1335020, 79, ... ) == 0x145eec 00495 1356 NtUserMessageCall (0x80144, WM_NCCREATE, 0x0, 0x12eebc, 0, 670, 0, ... ) == 0x1 00496 1356 NtUserSetWindowFNID (1048740, 681, ... ) == 0x1 00497 1356 NtUserSetWindowLong (1048740, 0, 1332968, 0, ... ) == 0x0 00498 1356 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\IMM"}, ... 92, ) }, ... 92, ) == 0x0 00499 1356 NtQueryValueKey (92, (92, "Ime File", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0s\0c\0t\0f\0i\0m\0e\0.\0i\0m\0e\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (92, "Ime File", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0s\0c\0t\0f\0i\0m\0e\0.\0i\0m\0e\0\0\0"}, 38, ) }, 38, ) == 0x0 00500 1356 NtClose (92, ... ) == 0x0 00501 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "version.dll"}, ... 92, ) }, ... 92, ) == 0x0 00502 1356 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c00000), 0x0, 32768, ) == 0x0 00503 1356 NtClose (92, ... ) == 0x0 00504 1356 NtProtectVirtualMemory (-1, (0x77c01000), 304, 4, ... (0x77c01000), 4096, 32, ) == 0x0 00505 1356 NtProtectVirtualMemory (-1, (0x77c01000), 4096, 32, ... (0x77c01000), 4096, 4, ) == 0x0 00506 1356 NtFlushInstructionCache (-1, 2009075712, 304, ... ) == 0x0 00507 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\version.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00508 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00509 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00510 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1237116, ... ) }, 1237116, ... ) == 0x0 00511 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00512 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 92, ... 96, ) == 0x0 00513 1356 NtClose (92, ... ) == 0x0 00514 1356 NtMapViewOfSection (96, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x900000), 0x0, 180224, ) == 0x0 00515 1356 NtClose (96, ... ) == 0x0 00516 1356 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 00517 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1236712, ... ) }, 1236712, ... ) == 0x0 00518 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1237456, (0x80100080, {24, 0, 0x40, 0, 1237456, "\??\C:\WINDOWS\system32\msctfime.ime"}, 0x0, 0, 5, 1, 96, 0, 0, ... 96, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 96, {status=0x0, info=1}, ) == 0x0 00519 1356 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 96, ... 92, ) == 0x0 00520 1356 NtClose (96, ... ) == 0x0 00521 1356 NtMapViewOfSection (92, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x900000), {0, 0}, 180224, ) == 0x0 00522 1356 NtClose (92, ... ) == 0x0 00523 1356 NtQueryDefaultUILanguage (2090319928, ... 00524 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00525 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482644, ) == 0x0 00526 1356 NtQueryInformationToken (-2147482644, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00527 1356 NtClose (-2147482644, ... ) == 0x0 00528 1356 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482644, ) }, ... -2147482644, ) == 0x0 00529 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x240, 0, 0, (0x80000000, {24, -2147482644, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00530 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x640, 0, 0, (0x80000000, {24, -2147482644, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482640, ) }, ... -2147482640, ) == 0x0 00531 1356 NtQueryValueKey (-2147482640, (-2147482640, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00532 1356 NtClose (-2147482640, ... ) == 0x0 00533 1356 NtClose (-2147482644, ... ) == 0x0 00523 1356 NtQueryDefaultUILanguage ... ) == 0x0 00534 1356 NtQueryInstallUILanguage (2090319930, ... ) == 0x0 00535 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00536 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00537 1356 NtQueryDefaultLocale (1, 1238076, ... ) == 0x0 00538 1356 NtQueryVirtualMemory (-1, 0x900000, Basic, 28, ... {BaseAddress=0x900000,AllocationBase=0x900000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00539 1356 NtQueryVirtualMemory (-1, 0x900000, Basic, 28, ... {BaseAddress=0x900000,AllocationBase=0x900000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00540 1356 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 00541 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00542 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00543 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1237108, ... ) }, 1237108, ... ) == 0x0 00544 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00545 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 92, ... 96, ) == 0x0 00546 1356 NtClose (92, ... ) == 0x0 00547 1356 NtMapViewOfSection (96, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x900000), 0x0, 180224, ) == 0x0 00548 1356 NtClose (96, ... ) == 0x0 00549 1356 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 00550 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1236704, ... ) }, 1236704, ... ) == 0x0 00551 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1237448, (0x80100080, {24, 0, 0x40, 0, 1237448, "\??\C:\WINDOWS\system32\msctfime.ime"}, 0x0, 0, 5, 1, 96, 0, 0, ... 96, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 96, {status=0x0, info=1}, ) == 0x0 00552 1356 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 96, ... 92, ) == 0x0 00553 1356 NtClose (96, ... ) == 0x0 00554 1356 NtMapViewOfSection (92, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x900000), {0, 0}, 180224, ) == 0x0 00555 1356 NtClose (92, ... ) == 0x0 00556 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00557 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00558 1356 NtQueryDefaultLocale (1, 1238068, ... ) == 0x0 00559 1356 NtQueryVirtualMemory (-1, 0x900000, Basic, 28, ... {BaseAddress=0x900000,AllocationBase=0x900000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00560 1356 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 00561 1356 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 00562 1356 NtUnmapViewOfSection (-1, 0x77c00000, ... ) == 0x0 00563 1356 NtOpenMutant (0x120001, {24, 52, 0x0, 0, 0, (0x120001, {24, 52, 0x0, 0, 0, "ShimCacheMutex"}, ... 92, ) }, ... 92, ) == 0x0 00564 1356 NtWaitForSingleObject (92, 0, {-1000000, -1}, ... ) == 0x0 00565 1356 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "ShimSharedMemory"}, ... 96, ) }, ... 96, ) == 0x0 00566 1356 NtMapViewOfSection (96, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x900000), {0, 0}, 57344, ) == 0x0 00567 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00568 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 100, ) == 0x0 00569 1356 NtQueryInformationToken (100, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00570 1356 NtClose (100, ... ) == 0x0 00571 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00572 1356 NtReleaseMutant (92, ... 0x0, ) == 0x0 00573 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1237088, ... ) }, 1237088, ... ) == 0x0 00574 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 5, 96, ... 100, {status=0x0, info=1}, ) }, 5, 96, ... 100, {status=0x0, info=1}, ) == 0x0 00575 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 100, ... 104, ) == 0x0 00576 1356 NtClose (100, ... ) == 0x0 00577 1356 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x910000), 0x0, 180224, ) == 0x0 00578 1356 NtClose (104, ... ) == 0x0 00579 1356 NtUnmapViewOfSection (-1, 0x910000, ... ) == 0x0 00580 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1237396, ... ) }, 1237396, ... ) == 0x0 00581 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 00582 1356 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 104, ... 100, ) == 0x0 00583 1356 NtQuerySection (100, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00584 1356 NtClose (104, ... ) == 0x0 00585 1356 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x755c0000), 0x0, 188416, ) == 0x0 00586 1356 NtClose (100, ... ) == 0x0 00587 1356 NtProtectVirtualMemory (-1, (0x755c1000), 860, 4, ... (0x755c1000), 4096, 32, ) == 0x0 00588 1356 NtProtectVirtualMemory (-1, (0x755c1000), 4096, 32, ... (0x755c1000), 4096, 4, ) == 0x0 00589 1356 NtFlushInstructionCache (-1, 1968967680, 860, ... ) == 0x0 00590 1356 NtProtectVirtualMemory (-1, (0x755c1000), 860, 4, ... (0x755c1000), 4096, 32, ) == 0x0 00591 1356 NtProtectVirtualMemory (-1, (0x755c1000), 4096, 32, ... (0x755c1000), 4096, 4, ) == 0x0 00592 1356 NtFlushInstructionCache (-1, 1968967680, 860, ... ) == 0x0 00593 1356 NtProtectVirtualMemory (-1, (0x755c1000), 860, 4, ... (0x755c1000), 4096, 32, ) == 0x0 00594 1356 NtProtectVirtualMemory (-1, (0x755c1000), 4096, 32, ... (0x755c1000), 4096, 4, ) == 0x0 00595 1356 NtFlushInstructionCache (-1, 1968967680, 860, ... ) == 0x0 00596 1356 NtProtectVirtualMemory (-1, (0x755c1000), 860, 4, ... (0x755c1000), 4096, 32, ) == 0x0 00597 1356 NtProtectVirtualMemory (-1, (0x755c1000), 4096, 32, ... (0x755c1000), 4096, 4, ) == 0x0 00598 1356 NtFlushInstructionCache (-1, 1968967680, 860, ... ) == 0x0 00599 1356 NtProtectVirtualMemory (-1, (0x755c1000), 860, 4, ... (0x755c1000), 4096, 32, ) == 0x0 00600 1356 NtProtectVirtualMemory (-1, (0x755c1000), 4096, 32, ... (0x755c1000), 4096, 4, ) == 0x0 00601 1356 NtFlushInstructionCache (-1, 1968967680, 860, ... ) == 0x0 00602 1356 NtProtectVirtualMemory (-1, (0x755c1000), 860, 4, ... (0x755c1000), 4096, 32, ) == 0x0 00603 1356 NtProtectVirtualMemory (-1, (0x755c1000), 4096, 32, ... (0x755c1000), 4096, 4, ) == 0x0 00604 1356 NtFlushInstructionCache (-1, 1968967680, 860, ... ) == 0x0 00605 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msctfime.ime"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00606 1356 NtUserGetDC (0, ... ) == 0x1010050 00607 1356 NtUserSystemParametersInfo (66, 12, 1237584, 0, ... ) == 0x1 00608 1356 NtUserCallOneParam (16842832, 57, ... ) == 0x1 00609 1356 NtGdiCreateCompatibleDC (0, ... ) == 0x8f0104e1 00610 1356 NtGdiCreateCompatibleDC (0, ... ) == 0x7d0106b6 00611 1356 NtGdiCreateCompatibleDC (0, ... ) == 0x6c0104f4 00612 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ole32.dll"}, 1234916, ... ) }, 1234916, ... ) == 0x0 00613 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ole32.dll"}, 5, 96, ... 100, {status=0x0, info=1}, ) }, 5, 96, ... 100, {status=0x0, info=1}, ) == 0x0 00614 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 100, ... 104, ) == 0x0 00615 1356 NtClose (100, ... ) == 0x0 00616 1356 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x910000), 0x0, 1286144, ) == 0x0 00617 1356 NtClose (104, ... ) == 0x0 00618 1356 NtUnmapViewOfSection (-1, 0x910000, ... ) == 0x0 00619 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ole32.dll"}, 1235224, ... ) }, 1235224, ... ) == 0x0 00620 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ole32.dll"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 00621 1356 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 104, ... 100, ) == 0x0 00622 1356 NtQuerySection (100, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00623 1356 NtClose (104, ... ) == 0x0 00624 1356 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x774e0000), 0x0, 1298432, ) == 0x0 00625 1356 NtClose (100, ... ) == 0x0 00626 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00627 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00628 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00629 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00630 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00631 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00632 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00633 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00634 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00635 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00636 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00637 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00638 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00639 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00640 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00641 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00642 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00643 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00644 1356 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 00645 1356 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 00646 1356 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 00647 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00648 1356 NtAllocateVirtualMemory (-1, 1339392, 0, 4096, 4096, 4, ... 1339392, 4096, ) == 0x0 00649 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\Device\KsecDD"}, 7, 16, ... 100, {status=0x0, info=0}, ) }, 7, 16, ... 100, {status=0x0, info=0}, ) == 0x0 00650 1356 NtDeviceIoControlFile (100, 0, 0x0, 0x0, 0x390008, (100, 0, 0x0, 0x0, 0x390008, "\334\217)@\312v\370D`\260\334\257\20#\\251\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00651 1356 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00652 1356 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00653 1356 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00654 1356 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00655 1356 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00656 1356 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00657 1356 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00658 1356 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482644, 2, ) }, 0, 0x0, 0, ... -2147482644, 2, ) == 0x0 00659 1356 NtSetValueKey (-2147482644, (-2147482644, "Seed", 0, 3, "G\3\372\310r)\34\236\4U\303\36g\341\247\336\305L\243~\22\216\245\4\365\212\213\210q\375e\267\351\10\350-\347$\216x{\357\357\15\12\13\305\334\340\204\36\207JU\215\226?\220\6\5\275\246\26\200\224\230!NYm\331\245\321$\303\255\212\312z\273", 80, ... ) , 0, 3, (-2147482644, "Seed", 0, 3, "G\3\372\310r)\34\236\4U\303\36g\341\247\336\305L\243~\22\216\245\4\365\212\213\210q\375e\267\351\10\350-\347$\216x{\357\357\15\12\13\305\334\340\204\36\207JU\215\226?\220\6\5\275\246\26\200\224\230!NYm\331\245\321$\303\255\212\312z\273", 80, ... ) , 80, ... ) == 0x0 00660 1356 NtClose (-2147482644, ... ) == 0x0 00650 1356 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\310\247\26\3009\207\235[\214\255!\353=J+J\240\207K\\271\365f.b\350=\301\265r\22i\226\353E\267\217\23\207&jW7\277N\367\35\3433yM\23\33\267\362\375\343\213#\316\301G-/\370\276\313\15Fp\220\374\265\251\251<`\366\231\356\265\305e\2*`B\367\215\333\237\220\231\225W\327=\374\32\203OD~\273\371&\37227\365\373\322s!\212bX\362:\230C\373\341\24\303\347\272\13qi8\361\363X\271\2536\343\277`2\354\334\232\3460.\212\231\234o\215Q\204\] <\26\340\270\273\30Y\361\204#E\265'\353\352\320Y\277\225;\310\11\316,\263\313\35\376YS\271\211u\216\330O\363\215q\257\321e\335\276X\202\354\306\300!J\326\371\274\301Y\222\343\227\320b\353\227\222R\344\32\267\33\300\301\20g`\206\256MP\337\376\7\366\3538\332\362)\30\362b\346\366\10Kz!\266\365\345", ) , ) == 0x0 00661 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00662 1356 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00663 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 104, ) }, ... 104, ) == 0x0 00664 1356 NtQueryValueKey (104, (104, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (104, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 00665 1356 NtClose (104, ... ) == 0x0 00666 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Ole"}, ... 104, ) }, ... 104, ) == 0x0 00667 1356 NtQueryValueKey (104, (104, "RWLockResourceTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00668 1356 NtClose (104, ... ) == 0x0 00669 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00670 1356 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00671 1356 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00672 1356 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00673 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 104, ) }, ... 104, ) == 0x0 00674 1356 NtQueryValueKey (104, (104, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00675 1356 NtQueryValueKey (104, (104, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00676 1356 NtQueryValueKey (104, (104, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00677 1356 NtClose (104, ... ) == 0x0 00678 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 104, ) }, ... 104, ) == 0x0 00679 1356 NtQueryValueKey (104, (104, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00680 1356 NtQueryValueKey (104, (104, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00681 1356 NtClose (104, ... ) == 0x0 00682 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00683 1356 NtUserFindExistingCursorIcon (1236856, 1236872, 1236920, ... ) == 0x10003 00684 1356 NtUserFindExistingCursorIcon (1236856, 1236872, 1236920, ... ) == 0x10011 00685 1356 NtGdiGetStockObject (5, ... ) == 0x1900015 00686 1356 NtUserGetClassInfo (1968963584, 1236988, 1237552, 1236984, 0, ... ) == 0x0 00687 1356 NtUserRegisterClassExWOW (1236872, 1236940, 1236956, 1236972, 0, 384, 0, ... ) == 0x8173c079 00688 1356 NtUserFindExistingCursorIcon (1236856, 1236872, 1236920, ... ) == 0x10013 00689 1356 NtUserGetClassInfo (1968963584, 1236988, 1237552, 1236984, 0, ... ) == 0x0 00690 1356 NtUserRegisterClassExWOW (1236872, 1236940, 1236956, 1236972, 0, 384, 0, ... ) == 0x8173c07a 00691 1356 NtUserRegisterWindowMessage ( ("MSIMEService", ... ) , ... ) == 0xc07b 00692 1356 NtUserRegisterWindowMessage ( ("MSIMEUIReady", ... ) , ... ) == 0xc07c 00693 1356 NtUserRegisterWindowMessage ( ("MSIMEReconvertRequest", ... ) , ... ) == 0xc07d 00694 1356 NtUserRegisterWindowMessage ( ("MSIMEReconvert", ... ) , ... ) == 0xc07e 00695 1356 NtUserRegisterWindowMessage ( ("MSIMEDocumentFeed", ... ) , ... ) == 0xc07f 00696 1356 NtUserRegisterWindowMessage ( ("MSIMEQueryPosition", ... ) , ... ) == 0xc080 00697 1356 NtUserRegisterWindowMessage ( ("MSIMEModeBias", ... ) , ... ) == 0xc081 00698 1356 NtUserRegisterWindowMessage ( ("MSIMEShowImePad", ... ) , ... ) == 0xc082 00699 1356 NtUserRegisterWindowMessage ( ("MSIMEMouseOperation", ... ) , ... ) == 0xc083 00700 1356 NtUserRegisterWindowMessage ( ("MSIMEKeyMap", ... ) , ... ) == 0xc084 00701 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ntdll.dll"}, 1237748, ... ) }, 1237748, ... ) == 0x0 00702 1356 NtUserMessageCall (0x1000a4, WM_NCCREATE, 0x0, 0x12eea0, 0, 670, 0, ... ) == 0x1 00703 1356 NtUserMessageCall (0x1000a4, WM_NCCALCSIZE, 0x0, 0x12eee4, 0, 670, 0, ... ) == 0x0 00704 1356 NtUserSetProp (1048740, 43288, -1, ... ) == 0x1 00705 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00706 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00707 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00708 1356 NtUserUpdateInputContext (2490903, 1, 1048740, ... ) == 0x1 00709 1356 NtOpenKey (0x2000000, {24, 80, 0x40, 0, 0, (0x2000000, {24, 80, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF"}, ... 104, ) }, ... 104, ) == 0x0 00710 1356 NtQueryValueKey (104, (104, "Disable Thread Input Manager", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00711 1356 NtClose (104, ... ) == 0x0 00712 1356 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 00713 1356 NtOpenProcessToken (-1, 0xa, ... 104, ) == 0x0 00714 1356 NtDuplicateToken (104, 0xc, {24, 0, 0x0, 0, 1239580, 0x0}, 0, 2, ... 108, ) == 0x0 00715 1356 NtClose (104, ... ) == 0x0 00716 1356 NtAccessCheck (1341080, 108, 0x1, 1239656, 1239708, 56, 1239688, ... (0x1), ) == 0x0 00717 1356 NtClose (108, ... ) == 0x0 00718 1356 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\CTF\SystemShared"}, ... 108, ) }, ... 108, ) == 0x0 00719 1356 NtQueryValueKey (108, (108, "CUAS", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (108, "CUAS", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00720 1356 NtClose (108, ... ) == 0x0 00721 1356 NtUserGetImeInfoEx (1239472, 0, ... ) == 0x1 00722 1356 NtWaitForSingleObject (92, 0, {-1000000, -1}, ... ) == 0x0 00723 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00724 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 108, ) == 0x0 00725 1356 NtQueryInformationToken (108, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00726 1356 NtClose (108, ... ) == 0x0 00727 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00728 1356 NtReleaseMutant (92, ... 0x0, ) == 0x0 00729 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\msctfime.ime"}, 1236504, ... ) }, 1236504, ... ) == 0x0 00730 1356 NtUserGetThreadState (16, ... ) == 0x0 00731 1356 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 00732 1356 NtOpenProcessToken (-1, 0xa, ... 108, ) == 0x0 00733 1356 NtDuplicateToken (108, 0xc, {24, 0, 0x0, 0, 1238504, 0x0}, 0, 2, ... 104, ) == 0x0 00734 1356 NtClose (108, ... ) == 0x0 00735 1356 NtAccessCheck (1341080, 104, 0x1, 1238580, 1238632, 56, 1238612, ... (0x1), ) == 0x0 00736 1356 NtClose (104, ... ) == 0x0 00737 1356 NtUserGetClassInfo (1968963584, 1238224, 1238168, 1238216, 0, ... ) == 0xc079 00738 1356 NtUserMessageCall (0x80144, WM_NCCALCSIZE, 0x0, 0x12eee4, 0, 670, 0, ... ) == 0x0 00739 1356 NtUserGetClassName (524612, 0, 1239972, ... ) == 0x6 00740 1356 NtUserRemoveProp (524612, 43282, ... ) == 0x0 00741 1356 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 2, 327681, 262144, 6881357} (24, {24, 52, new_msg, 0, 2, 327681, 262144, 6881357} "\0\0\0\0\5\4\3\0o\0f\0t\0 \0L\5\0\0,\352\22\0" ... {24, 52, reply, 0, 220, 1356, 75654, 0} "\0\0\0\0\5\4\3\0\0\0\0\0t\0 \0L\5\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 220, 1356, 75654, 0} (24, {24, 52, new_msg, 0, 2, 327681, 262144, 6881357} "\0\0\0\0\5\4\3\0o\0f\0t\0 \0L\5\0\0,\352\22\0" ... {24, 52, reply, 0, 220, 1356, 75654, 0} "\0\0\0\0\5\4\3\0\0\0\0\0t\0 \0L\5\0\0\0\0\0\0" ) ) == 0x0 00742 1356 NtUserGetThreadDesktop (1356, 0, ... ) == 0x24 00743 1356 NtUserGetObjectInformation (36, 2, 1239656, 520, 0, ... ) == 0x1 00744 1356 NtGdiDeleteObjectApp (1158678124, ... ) == 0x1 00745 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00746 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00747 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00748 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00749 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00750 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00751 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00752 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00753 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00754 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00755 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00756 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00757 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00758 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00759 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00760 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00761 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 00762 1356 NtGdiCreatePatternBrushInternal (59048383, 0, 0, ... ) == 0x4610066c 00763 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 00764 1356 NtUserSetProp (524612, 43288, 8661168, ... ) == 0x1 00307 1356 NtUserCreateWindowEx ... ) == 0x80144 00765 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00766 1356 NtUserCallHwndLock (524612, 90, ... ) == 0x1 00767 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00768 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00769 1356 NtUserGetAtomName (49175, 1240848, ... ) == 0x6 00770 1356 NtUserCreateWindowEx (4, 49175, 49175, (4, 49175, 49175, "OK", 1342373889, 71, 60, 75, 23, 524612, 1, 2118189056, 0, 1073742848, 0, ... , 1342373889, 71, 60, 75, 23, 524612, 1, 2118189056, 0, 1073742848, 0, ... 00771 1356 NtUserSetWindowFNID (393512, 673, ... ) == 0x1 00772 1356 NtUserSetWindowLong (393512, 0, 1341492, 0, ... ) == 0x0 00773 1356 NtUserMessageCall (0x60128, WM_NCCREATE, 0x0, 0x12eebc, 0, 670, 0, ... ) == 0x1 00774 1356 NtUserMessageCall (0x60128, WM_NCCALCSIZE, 0x0, 0x12eee4, 0, 670, 0, ... ) == 0x0 00775 1356 NtUserSetProp (393512, 43288, -1, ... ) == 0x1 00770 1356 NtUserCreateWindowEx ... ) == 0x60128 00776 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00777 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00778 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00779 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00780 1356 NtUserGetAtomName (49177, 1240848, ... ) == 0x6 00781 1356 NtUserCreateWindowEx (4, 49177, 49177, "1342308355, 11, 11, 0, 0, 524612, 20, 2118189056, 0, 1073742848, 0, ... 00782 1356 NtUserSetWindowFNID (1114352, 680, ... ) == 0x1 00783 1356 NtUserSetWindowLong (1114352, 0, 1341696, 0, ... ) == 0x0 00784 1356 NtUserMessageCall (0x1100f0, WM_NCCREATE, 0x0, 0x12eebc, 0, 670, 0, ... ) == 0x1 00785 1356 NtUserMessageCall (0x1100f0, WM_NCCALCSIZE, 0x0, 0x12eee4, 0, 670, 0, ... ) == 0x0 00786 1356 NtUserSetProp (1114352, 43288, -1, ... ) == 0x1 00787 1356 NtUserFindExistingCursorIcon (1239596, 1239612, 1239660, ... ) == 0x0 00788 1356 NtUserFindExistingCursorIcon (1239596, 1239612, 1239660, ... ) == 0x0 00789 1356 NtUserFindExistingCursorIcon (1239596, 1239612, 1239660, ... ) == 0x10009 00790 1356 NtUserGetIconSize (65545, 0, 1240216, 1240220, ... ) == 0x1 00791 1356 NtUserGetCursorFrameInfo (65545, 0, 1240252, 1240228, ... ) == 0x10009 00792 1356 NtUserSetWindowPos (1114352, 0, 0, 0, 32, 32, 22, ... 00793 1356 NtUserMessageCall (0x1100f0, WM_WINDOWPOSCHANGING, 0x0, 0x12ec14, 0, 670, 0, ... ) == 0x0 00794 1356 NtUserMessageCall (0x1100f0, WM_NCCALCSIZE, 0x1, 0x12ebe8, 0, 670, 0, ... ) == 0x0 00795 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 00792 1356 NtUserSetWindowPos ... ) == 0x1 00781 1356 NtUserCreateWindowEx ... ) == 0x1100f0 00796 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 00797 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 00798 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 00799 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 00800 1356 NtUserGetAtomName (49177, 1240848, ... ) == 0x6 00801 1356 NtUserCreateWindowEx (4, 49177, 49177, (4, 49177, 49177, "Pack method not implemented.", 1342316672, 62, 20, 149, 15, 524612, 65535, 2118189056, 0, 1073742848, 0, ... , 1342316672, 62, 20, 149, 15, 524612, 65535, 2118189056, 0, 1073742848, 0, ... 00802 1356 NtUserSetWindowFNID (393520, 680, ... ) == 0x1 00803 1356 NtUserSetWindowLong (393520, 0, 1341672, 0, ... ) == 0x0 00804 1356 NtUserMessageCall (0x60130, WM_NCCREATE, 0x0, 0x12eebc, 0, 670, 0, ... ) == 0x1 00805 1356 NtUserMessageCall (0x60130, WM_NCCALCSIZE, 0x0, 0x12eee4, 0, 670, 0, ... ) == 0x0 00806 1356 NtUserSetProp (393520, 43288, -1, ... ) == 0x1 00801 1356 NtUserCreateWindowEx ... ) == 0x60130 00807 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 00808 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 00809 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 00810 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 00811 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00812 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00813 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00814 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00815 1356 NtUserSetWindowLong (524612, -21, 1243324, 0, ... ) == 0x0 00816 1356 NtUserCallHwnd (524612, 73, ... ) == 0xbc660168 00817 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00818 1356 NtUserSetFocus (393512, ... 00819 1356 NtUserPostThreadMessage (1356, 49313, 17, 393512, ... ) == 0x1 00820 1356 NtUserGetForegroundWindow (... ) == 0x800b2 00821 1356 NtUserMessageCall (0x80144, WM_NCACTIVATE, 0x0, 0xffffffff, 0, 670, 0, ... ) == 0x1 00822 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 00823 1356 NtUserGetWindowDC (524612, ... ) == 0x1010051 00824 1356 NtGdiGetTextMetricsW (16842833, 1239856, 68, ... ) == 0x1 00825 1356 NtGdiGetRandomRgn (16842833, 839123898, 1, ... ) == 0x0 00826 1356 NtGdiIntersectClipRect (16842833, 0, 0, 0, 0, ... ) == 0x3 00827 1356 NtGdiGetWidthTable (16842833, 5, 1342416, 261, 1342938, 1341784, 1341800, ... ) == 0x1 00828 1356 NtGdiExtSelectClipRgn (16842833, 0, 5, ... ) == 0x1 00829 1356 NtUserCallOneParam (16842833, 57, ... ) == 0x1 00830 1356 NtUserCalcMenuBar (524612, 3, 3, 29, 8661352, ... ) == 0x0 00831 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 1239816, 690, 0, ... 00832 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 00831 1356 NtUserMessageCall ... ) == 0x0 00833 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 1239816, 690, 0, ... 00834 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 00833 1356 NtUserMessageCall ... ) == 0x0 00835 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 1239816, 690, 0, ... 00836 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 00835 1356 NtUserMessageCall ... ) == 0x0 00837 1356 NtUserGetTitleBarInfo (524612, 1240448, ... ) == 0x1 00838 1356 NtUserGetDCEx (524612, 0, 66561, ... ) == 0x1010050 00839 1356 NtGdiExcludeClipRect (16842832, 3, 29, 219, 123, ... ) == 0x3 00840 1356 NtGdiDrawStream (16842832, 96, 1239932, ... ) == 0x1 00841 1356 NtGdiDrawStream (16842832, 96, 1239932, ... ) == 0x1 00842 1356 NtGdiDrawStream (16842832, 96, 1239932, ... ) == 0x1 00843 1356 NtGdiCreateCompatibleBitmap (16842832, 222, 29, ... ) == 0x6f05056a 00844 1356 NtGdiCreateCompatibleDC (16842832, ... ) == 0x980105d4 00845 1356 NtGdiSelectBitmap (-1744763436, 1862600042, ... ) == 0x185000f 00846 1356 NtGdiDrawStream (-1744763436, 96, 1239824, ... ) == 0x1 00847 1356 NtGdiDrawStream (-1744763436, 96, 1239780, ... ) == 0x1 00848 1356 NtGdiDrawStream (-1744763436, 96, 1239780, ... ) == 0x1 00849 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 00850 1356 NtGdiGetRandomRgn (-1744763436, 855901114, 1, ... ) == 0x0 00851 1356 NtGdiIntersectClipRect (-1744763436, 7, 7, 193, 25, ... ) == 0x3 00852 1356 NtGdiExtSelectClipRgn (-1744763436, 0, 5, ... ) == 0x2 00853 1356 NtGdiBitBlt (16842832, 0, 0, 222, 29, -1744763436, 0, 0, 13369376, -1, 0, ... ) == 0x1 00854 1356 NtGdiSelectBitmap (-1744763436, 25493519, ... ) == 0x6f05056a 00855 1356 NtGdiDeleteObjectApp (-1744763436, ... ) == 0x1 00856 1356 NtGdiDeleteObjectApp (1862600042, ... ) == 0x1 00857 1356 NtUserCallOneParam (16842832, 57, ... ) == 0x1 00858 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00859 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00860 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00861 1356 NtUserQueryWindow (393512, 8, ... ) == 0x260217 00862 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00863 1356 NtUserGetThreadState (13, ... ) == 0x0 00864 1356 NtUserUpdateInputContext (2490903, 0, 1319624, ... ) == 0x1 00865 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00866 1356 NtUserQueryInputContext (2490903, 1, ... ) == 0x54c 00867 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 00868 1356 NtUserQueryInputContext (2490903, 2, ... ) == 0x1000a4 00869 1356 NtAllocateVirtualMemory (-1, 0, 0, 524280, 8192, 4, ... 9502720, 524288, ) == 0x0 00870 1356 NtAllocateVirtualMemory (-1, 9502720, 0, 4096, 4096, 4, ... 9502720, 4096, ) == 0x0 00871 1356 NtUserCallOneParam (1356, 40, ... ) == 0x4090409 00872 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00873 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00874 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00875 1356 NtAllocateVirtualMemory (-1, 1343488, 0, 4096, 4096, 4, ... 1343488, 4096, ) == 0x0 00876 1356 NtUserGetDC (0, ... ) == 0x1010053 00877 1356 NtGdiGetDCObject (16842835, 655360, ... ) == 0x18a0021 00878 1356 NtGdiExtGetObjectW (25821217, 92, 1240308, ... ) == 0x5c 00879 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 00880 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00881 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00882 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00883 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00884 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 00885 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 00886 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00887 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00888 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00889 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00890 1356 NtUserQueryWindow (393512, 7, ... ) == 0x1000a4 00891 1356 NtUserGetImeInfoEx (1239348, 0, ... ) == 0x1 00892 1356 NtUserGetClassInfo (1968963584, 1238732, 1238676, 1238724, 0, ... ) == 0xc079 00893 1356 NtUserCreateWindowEx (0, 1239128, 1237892, (0, 1239128, 1237892, "MSCTFIME UI", -2013265920, 0, 0, 0, 0, 1048740, 0, 1968963584, 0, 1073742848, 0, ... , -2013265920, 0, 0, 0, 0, 1048740, 0, 1968963584, 0, 1073742848, 0, ... 00894 1356 NtUserGetIconSize (65539, 0, 1236652, 1236656, ... ) == 0x1 00895 1356 NtUserGetIconInfo (65539, 1236628, 1236620, 1236612, 1236648, 1, ... ) == 0x1 00896 1356 NtUserFindExistingCursorIcon (1236392, 1236408, 1236584, ... ) == 0x10003 00897 1356 NtGdiExtGetObjectW (1879377258, 24, 1236392, ... ) == 0x18 00898 1356 NtGdiGetDIBitsInternal (1879115345, 1879377258, 0, 64, 1345232, 1345184, 0, 256, 0, ... ) == 0x40 00899 1356 NtUserGetDC (0, ... ) == 0x1010053 00900 1356 NtGdiCreateDIBitmapInternal (16842835, 16, 32, 2, 0, 2118583256, 0, 48, 0, 0, 0, ... ) == 0x5705032f 00901 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 00902 1356 NtGdiSelectBitmap (1879115345, 1459946287, ... ) == 0x185000f 00903 1356 NtGdiDoPalette (1879115345, 0, 1, 1236252, 4, 0, ... ) == 0x1 00904 1356 NtGdiStretchDIBitsInternal (1879115345, 0, 0, 16, 32, 0, 0, 32, 64, 1345232, 1342944, 0, 13369376, 48, 256, 0, ... ) == 0x40 00905 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x5705032f 00906 1356 NtGdiCreateCompatibleDC (1879115345, ... ) == 0x9d0104ac 00907 1356 NtGdiExtGetObjectW (1459946287, 24, 1236276, ... ) == 0x18 00908 1356 NtGdiCreateBitmap (16, 32, 1, 1, 0, ... ) == 0x61050672 00909 1356 NtGdiSelectBitmap (1879115345, 1459946287, ... ) == 0x185000f 00910 1356 NtGdiSelectBitmap (-1660877652, 1627719282, ... ) == 0x185000f 00911 1356 NtGdiBitBlt (-1660877652, 0, 0, 16, 32, 1879115345, 0, 0, 13369376, -1, 0, ... ) == 0x1 00912 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x5705032f 00913 1356 NtGdiSelectBitmap (-1660877652, 25493519, ... ) == 0x61050672 00914 1356 NtGdiDeleteObjectApp (1459946287, ... ) == 0x1 00915 1356 NtGdiDeleteObjectApp (-1660877652, ... ) == 0x1 00916 1356 NtGdiExtGetObjectW (2013595042, 24, 1236392, ... ) == 0x18 00917 1356 NtAllocateVirtualMemory (-1, 1347584, 0, 8192, 4096, 4, ... 1347584, 8192, ) == 0x0 00918 1356 NtGdiGetDIBitsInternal (1879115345, 2013595042, 0, 32, 1345548, 1345496, 0, 4096, 0, ... ) == 0x20 00919 1356 NtUserGetDC (0, ... ) == 0x1010053 00920 1356 NtGdiCreateCompatibleBitmap (16842835, 16, 16, ... ) == 0x9f0504ac 00921 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 00922 1356 NtGdiSelectBitmap (1879115345, -1627061076, ... ) == 0x185000f 00923 1356 NtGdiDoPalette (1879115345, 0, 1, 1236252, 4, 0, ... ) == 0x0 00924 1356 NtGdiStretchDIBitsInternal (1879115345, 0, 0, 16, 16, 0, 0, 32, 32, 1345548, 1342944, 0, 13369376, 40, 4096, 0, ... ) == 0x20 00925 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x9f0504ac 00926 1356 NtGdiDeleteObjectApp (1879377258, ... ) == 0x1 00927 1356 NtGdiDeleteObjectApp (2013595042, ... ) == 0x1 00928 1356 NtUserCallOneParam (0, 33, ... ) == 0x3b0201 00929 1356 NtUserSetCursorIconData (3867137, 1236436, 1236452, 1236496, ... ) == 0x1 00930 1356 NtUserMessageCall (0x6012e, WM_NCCREATE, 0x0, 0x12e2fc, 0, 670, 1, ... ) == 0x1 00931 1356 NtUserMessageCall (0x6012e, WM_NCCALCSIZE, 0x0, 0x12e324, 0, 670, 1, ... ) == 0x0 00932 1356 NtUserSetProp (393518, 43288, -1, ... ) == 0x1 00933 1356 NtUserSetWindowLong (393518, 4, 1341056, 1, ... ) == 0x0 00893 1356 NtUserCreateWindowEx ... ) == 0x6012e 00934 1356 NtUserSetWindowLong (393518, 0, 2490903, 0, ... ) == 0x0 00935 1356 NtUserGetThreadState (17, ... ) == 0x0 00936 1356 NtUserQueryWindow (1048740, 3, ... ) == 0x60128 00937 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00938 1356 NtUserValidateHandleSecure (2490903, ... ) == 0x1 00939 1356 NtUserUpdateInputContext (2490903, 1, 0, ... ) == 0x1 00940 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 00941 1356 NtUserSetWindowLong (393518, 0, 0, 0, ... ) == 0x260217 00942 1356 NtUserSetImeOwnerWindow (1048740, 0, ... ) == 0x1 00943 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 00944 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 00945 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 00946 1356 NtUserKillTimer (393518, 1, ... ) == 0x0 00947 1356 NtUserSetTimer (393518, 1, 300, 0, ... ) == 0x1 00948 1356 NtUserCallNoParam (7, ... ) == 0x1 00949 1356 NtUserQueryWindow (1048740, 3, ... ) == 0x60128 00950 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00951 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00952 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00953 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00954 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00955 1356 NtUserQueryWindow (393512, 7, ... ) == 0x1000a4 00956 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00957 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 00958 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 00959 1356 NtUserCallHwndLock (1048740, 86, ... ) == 0x1 00960 1356 NtUserNotifyIMEStatus (393512, 0, 0, ... ) == 0x81734078 00818 1356 NtUserSetFocus ... ) == 0x0 00961 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00962 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00963 1356 NtUserSetWindowLong (393512, -12, 2, 0, ... ) == 0x1 00964 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00965 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00966 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00967 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00968 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00969 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00970 1356 NtUserGetClassName (393512, 0, 1241340, ... ) == 0x6 00971 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 00972 1356 NtUserGetClassName (1114352, 0, 1241340, ... ) == 0x6 00973 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 00974 1356 NtUserGetClassName (393520, 0, 1241340, ... ) == 0x6 00975 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 00976 1356 NtUserGetAncestor (524612, 1, ... ) == 0x10014 00977 1356 NtUserValidateHandleSecure (65556, ... ) == 0x1 00978 1356 NtUserSetWindowPos (524612, 0, 404, 335, 222, 126, 1047, ... ) == 0x1 00979 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00980 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00981 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00982 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00983 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00984 1356 NtUserMessageCall (0x80144, 0x128, 0x30001, 0x0, 0, 670, 0, ... 00985 1356 NtUserMessageCall (0x60128, 0x128, 0x30001, 0x0, 0, 670, 0, ... ) == 0x0 00986 1356 NtUserMessageCall (0x1100f0, 0x128, 0x30001, 0x0, 0, 670, 0, ... ) == 0x0 00987 1356 NtUserMessageCall (0x60130, 0x128, 0x30001, 0x0, 0, 670, 0, ... ) == 0x0 00984 1356 NtUserMessageCall ... ) == 0x0 00988 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 00989 1356 NtUserPeekMessage (0, 0, 0, 1, ... 00990 1356 NtUserGetThreadState (0, ... ) == 0x60128 00991 1356 NtUserGetForegroundWindow (... ) == 0x800b2 00992 1356 NtUserValidateHandleSecure (524466, ... ) == 0x1 00993 1356 NtUserFindWindowEx (0, 0, (0, 0, "Shell_TrayWnd", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x20052 00994 1356 NtUserBuildHwndList (0, 131154, 1, 0, 64, ... (0x3003e, 0x3003c, 0x30040, 0x30042, 0x30044, 0x30046, 0x10076, 0x10082, 0x1007a, 0x1007e, 0x1, ), 11, ) == 0x0 00995 1356 NtUserValidateHandleSecure (196670, ... ) == 0x1 00996 1356 NtUserValidateHandleSecure (196670, ... ) == 0x1 00997 1356 NtUserValidateHandleSecure (196668, ... ) == 0x1 00998 1356 NtUserValidateHandleSecure (196668, ... ) == 0x1 00999 1356 NtUserValidateHandleSecure (196672, ... ) == 0x1 01000 1356 NtUserValidateHandleSecure (196672, ... ) == 0x1 01001 1356 NtUserValidateHandleSecure (196674, ... ) == 0x1 01002 1356 NtUserValidateHandleSecure (196674, ... ) == 0x1 01003 1356 NtUserValidateHandleSecure (196676, ... ) == 0x1 01004 1356 NtUserValidateHandleSecure (196676, ... ) == 0x1 01005 1356 NtUserValidateHandleSecure (196678, ... ) == 0x1 01006 1356 NtUserValidateHandleSecure (196678, ... ) == 0x1 01007 1356 NtUserValidateHandleSecure (65654, ... ) == 0x1 01008 1356 NtUserValidateHandleSecure (65654, ... ) == 0x1 01009 1356 NtUserValidateHandleSecure (65666, ... ) == 0x1 01010 1356 NtUserValidateHandleSecure (65666, ... ) == 0x1 01011 1356 NtUserValidateHandleSecure (65658, ... ) == 0x1 01012 1356 NtUserValidateHandleSecure (65658, ... ) == 0x1 01013 1356 NtUserValidateHandleSecure (65662, ... ) == 0x1 01014 1356 NtUserValidateHandleSecure (65662, ... ) == 0x1 01015 1356 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 01016 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01017 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01018 1356 NtUserQueryWindow (524466, 1, ... ) == 0x640 01019 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01020 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01021 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 00989 1356 NtUserPeekMessage ... {0x0, WM_USER+0xbca1, 0x11, 0x60128, 0x129c87b, {0, 0}}, ) == 0x1 01022 1356 NtOpenProcessToken (-1, 0x8, ... 104, ) == 0x0 01023 1356 NtQueryInformationToken (104, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01024 1356 NtClose (104, ... ) == 0x0 01025 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01026 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01027 1356 NtUserShowWindow (524612, 1, ... 01028 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01029 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01030 1356 NtUserGetWindowDC (524612, ... ) == 0x1010050 01031 1356 NtGdiGetRandomRgn (16842832, 872678330, 1, ... ) == 0x0 01032 1356 NtGdiIntersectClipRect (16842832, 0, 0, 0, 0, ... ) == 0x3 01033 1356 NtGdiGetCharSet (16842832, ... ) == 0x4e4 01034 1356 NtGdiExtSelectClipRgn (16842832, 0, 5, ... ) == 0x1 01035 1356 NtUserCallOneParam (16842832, 57, ... ) == 0x1 01036 1356 NtUserCalcMenuBar (524612, 3, 3, 29, 8661352, ... ) == 0x0 01037 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 1240436, 690, 0, ... 01038 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01037 1356 NtUserMessageCall ... ) == 0x0 01039 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 1240436, 690, 0, ... 01040 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01039 1356 NtUserMessageCall ... ) == 0x0 01041 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 1240436, 690, 0, ... 01042 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01041 1356 NtUserMessageCall ... ) == 0x0 01043 1356 NtUserGetTitleBarInfo (524612, 1241068, ... ) == 0x1 01044 1356 NtUserGetDCEx (524612, 0, 66561, ... ) == 0x1010051 01045 1356 NtGdiExcludeClipRect (16842833, 3, 29, 219, 123, ... ) == 0x3 01046 1356 NtGdiDrawStream (16842833, 96, 1240552, ... ) == 0x1 01047 1356 NtGdiDrawStream (16842833, 96, 1240552, ... ) == 0x1 01048 1356 NtGdiDrawStream (16842833, 96, 1240552, ... ) == 0x1 01049 1356 NtGdiCreateCompatibleBitmap (16842833, 222, 29, ... ) == 0x7505056a 01050 1356 NtGdiCreateCompatibleDC (16842833, ... ) == 0x5901032f 01051 1356 NtGdiSelectBitmap (1493238575, 1963263338, ... ) == 0x185000f 01052 1356 NtGdiDrawStream (1493238575, 96, 1240444, ... ) == 0x1 01053 1356 NtGdiDrawStream (1493238575, 96, 1240400, ... ) == 0x1 01054 1356 NtGdiDrawStream (1493238575, 96, 1240400, ... ) == 0x1 01055 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01056 1356 NtGdiGetRandomRgn (1493238575, 889455546, 1, ... ) == 0x0 01057 1356 NtGdiIntersectClipRect (1493238575, 8, 8, 194, 25, ... ) == 0x3 01058 1356 NtGdiExtSelectClipRgn (1493238575, 0, 5, ... ) == 0x2 01059 1356 NtGdiGetRandomRgn (1493238575, 906232762, 1, ... ) == 0x0 01060 1356 NtGdiIntersectClipRect (1493238575, 7, 7, 193, 25, ... ) == 0x3 01061 1356 NtGdiExtSelectClipRgn (1493238575, 0, 5, ... ) == 0x2 01062 1356 NtGdiBitBlt (16842833, 0, 0, 222, 29, 1493238575, 0, 0, 13369376, -1, 0, ... ) == 0x1 01063 1356 NtGdiSelectBitmap (1493238575, 25493519, ... ) == 0x7505056a 01064 1356 NtGdiDeleteObjectApp (1493238575, ... ) == 0x1 01065 1356 NtGdiDeleteObjectApp (1963263338, ... ) == 0x1 01066 1356 NtUserCallOneParam (16842833, 57, ... ) == 0x1 01067 1356 NtUserFillWindow (524612, 524612, 16842834, 4, ... ) == 0x1 01068 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01069 1356 NtUserGetWindowDC (524612, ... ) == 0x1010050 01070 1356 NtGdiGetRandomRgn (16842832, 923009978, 1, ... ) == 0x0 01071 1356 NtGdiIntersectClipRect (16842832, 0, 0, 0, 0, ... ) == 0x3 01072 1356 NtGdiGetCharSet (16842832, ... ) == 0x4e4 01073 1356 NtGdiExtSelectClipRgn (16842832, 0, 5, ... ) == 0x1 01074 1356 NtUserCallOneParam (16842832, 57, ... ) == 0x1 01075 1356 NtUserCalcMenuBar (524612, 3, 3, 29, 8661352, ... ) == 0x0 01076 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 1240728, 690, 0, ... 01077 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01076 1356 NtUserMessageCall ... ) == 0x0 01078 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 1240728, 690, 0, ... 01079 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01078 1356 NtUserMessageCall ... ) == 0x0 01080 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 1240728, 690, 0, ... 01081 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01080 1356 NtUserMessageCall ... ) == 0x0 01082 1356 NtUserGetTitleBarInfo (524612, 1241360, ... ) == 0x1 01083 1356 NtUserBuildHwndList (0, 524612, 1, 0, 64, ... (0x60128, 0x1100f0, 0x60130, 0x1, ), 4, ) == 0x0 01084 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01085 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01086 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01087 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01088 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01089 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01090 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01091 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01092 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01093 1356 NtUserGetWindowDC (0, ... ) == 0x1010054 01094 1356 NtUserCallOneParam (16842836, 57, ... ) == 0x1 01095 1356 NtGdiExtCreateRegion (0, 112, 8662840, ... ) == 0x7704056a 01096 1356 NtGdiOffsetRgn (1996752234, 0, 0, ... ) == 0x3 01097 1356 NtGdiCombineRgn (939787194, 1996752234, 939787194, 5, ... ) == 0x3 01098 1356 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x5a04032f 01099 1356 NtGdiCombineRgn (939787194, 1510212399, 939787194, 2, ... ) == 0x3 01100 1356 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x6e040565 01101 1356 NtGdiCombineRgn (939787194, 1845757285, 939787194, 2, ... ) == 0x3 01102 1356 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0xb40406dc 01103 1356 NtGdiCombineRgn (939787194, -1274804516, 939787194, 2, ... ) == 0x3 01104 1356 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0xb10407b5 01105 1356 NtGdiCombineRgn (939787194, -1325135947, 939787194, 2, ... ) == 0x3 01106 1356 NtGdiCreateRectRgn (0, 0, 1, 1, ... ) == 0x7e040687 01107 1356 NtGdiCombineRgn (2114193031, 939787194, 0, 5, ... ) == 0x3 01108 1356 NtUserSetWindowRgn (524612, 939787194, 1, ... 01109 1356 NtUserMessageCall (0x80144, WM_NCCALCSIZE, 0x1, 0x12f04c, 0, 670, 0, ... ) == 0x0 01108 1356 NtUserSetWindowRgn ... ) == 0x1 01027 1356 NtUserShowWindow ... ) == 0x0 01110 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01111 1356 NtUserCallHwndLock (524612, 94, ... 01112 1356 NtUserMessageCall (0x80144, WM_PAINT, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01113 1356 NtUserBeginPaint (0x60128, 1241748, ... 01114 1356 NtUserMessageCall (0x60128, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01113 1356 NtUserBeginPaint ... ) == 0x1010050 01115 1356 NtUserGetControlBrush (0x60128, 16842832, 309, ... ) == 0x1100056 01116 1356 NtGdiIntersectClipRect (16842832, 0, 0, 75, 23, ... ) == 0x3 01117 1356 NtGdiIntersectClipRect (16842832, 3, 3, 72, 20, ... ) == 0x3 01118 1356 NtUserEndPaint (0x60128, 1241748, ... ) == 0x1 01119 1356 NtUserBeginPaint (0x1100f0, 1241752, ... 01120 1356 NtUserMessageCall (0x1100f0, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01119 1356 NtUserBeginPaint ... ) == 0x1010050 01121 1356 NtGdiIntersectClipRect (16842832, 0, 0, 32, 32, ... ) == 0x3 01122 1356 NtUserGetControlBrush (0x1100f0, 16842832, 312, ... 01123 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01124 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01122 1356 NtUserGetControlBrush ... ) == 0x1100056 01125 1356 NtGdiGetDCDword (16842832, 7, 1241436, ... ) == 0x1 01126 1356 NtUserDrawIconEx (16842832, 0, 0, 65545, 32, 32, 0, 17825878, 3, 0, 1241488, ... ) == 0x1 01127 1356 NtUserEndPaint (0x1100f0, 1241752, ... ) == 0x1 01128 1356 NtUserBeginPaint (0x60130, 1241752, ... 01129 1356 NtUserMessageCall (0x60130, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01128 1356 NtUserBeginPaint ... ) == 0x1010050 01130 1356 NtGdiIntersectClipRect (16842832, 0, 0, 149, 15, ... ) == 0x3 01131 1356 NtUserGetControlBrush (0x60130, 16842832, 312, ... 01132 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01133 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01131 1356 NtUserGetControlBrush ... ) == 0x1100056 01134 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01135 1356 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 01136 1356 NtUserEndPaint (0x60130, 1241752, ... ) == 0x1 01111 1356 NtUserCallHwndLock ... ) == 0x1 01137 1356 NtUserWaitMessage (... ) == 0x1 01138 1356 NtUserPeekMessage (0, 0, 0, 1, ... 01139 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01138 1356 NtUserPeekMessage ... {0x0, WM_USER+0xbca1, 0x11, 0x60128, 0x129c87b, {0, 0}}, ) == 0x0 01140 1356 NtUserWaitMessage (... ) == 0x1 01141 1356 NtUserPeekMessage (0, 0, 0, 1, ... 01142 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01141 1356 NtUserPeekMessage ... {0x0, WM_USER+0xbca1, 0x11, 0x60128, 0x129c87b, {0, 0}}, ) == 0x0 01143 1356 NtUserWaitMessage (... ) == 0x1 01144 1356 NtUserPeekMessage (0, 0, 0, 1, ... 01145 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01144 1356 NtUserPeekMessage ... {0x0, WM_USER+0xbca1, 0x11, 0x60128, 0x129c87b, {0, 0}}, ) == 0x0 01146 1356 NtUserWaitMessage (... ) == 0x1 01147 1356 NtUserPeekMessage (0, 0, 0, 1, ... 01148 1356 NtUserMessageCall (0x80144, WM_SYNCPAINT, 0x4, 0x0, 0, 670, 0, ... 01149 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01150 1356 NtUserGetWindowDC (524612, ... ) == 0x1010052 01151 1356 NtGdiGetRandomRgn (16842834, -1308358731, 1, ... ) == 0x0 01152 1356 NtGdiIntersectClipRect (16842834, 0, 0, 0, 0, ... ) == 0x3 01153 1356 NtGdiGetCharSet (16842834, ... ) == 0x4e4 01154 1356 NtGdiExtSelectClipRgn (16842834, 0, 5, ... ) == 0x3 01155 1356 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01156 1356 NtUserCalcMenuBar (524612, 3, 3, 29, 8661352, ... ) == 0x0 01157 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 1239736, 690, 0, ... 01158 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01157 1356 NtUserMessageCall ... ) == 0x0 01159 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 1239736, 690, 0, ... 01160 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01159 1356 NtUserMessageCall ... ) == 0x0 01161 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 1239736, 690, 0, ... 01162 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01161 1356 NtUserMessageCall ... ) == 0x0 01163 1356 NtUserGetTitleBarInfo (524612, 1240368, ... ) == 0x1 01164 1356 NtUserGetDCEx (524612, 0, 66561, ... ) == 0x1010053 01165 1356 NtGdiExcludeClipRect (16842835, 3, 29, 219, 123, ... ) == 0x3 01166 1356 NtGdiDrawStream (16842835, 96, 1239852, ... ) == 0x1 01167 1356 NtGdiDrawStream (16842835, 96, 1239852, ... ) == 0x1 01168 1356 NtGdiDrawStream (16842835, 96, 1239852, ... ) == 0x1 01169 1356 NtGdiCreateCompatibleBitmap (16842835, 222, 29, ... ) == 0x3f0506e4 01170 1356 NtGdiCreateCompatibleDC (16842835, ... ) == 0x8f0106ac 01171 1356 NtGdiSelectBitmap (-1895758164, 1057294052, ... ) == 0x185000f 01172 1356 NtGdiDrawStream (-1895758164, 96, 1239744, ... ) == 0x1 01173 1356 NtGdiDrawStream (-1895758164, 96, 1239700, ... ) == 0x1 01174 1356 NtGdiDrawStream (-1895758164, 96, 1239700, ... ) == 0x1 01175 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01176 1356 NtGdiGetRandomRgn (-1895758164, -1291581515, 1, ... ) == 0x0 01177 1356 NtGdiIntersectClipRect (-1895758164, 8, 8, 194, 25, ... ) == 0x3 01178 1356 NtGdiExtSelectClipRgn (-1895758164, 0, 5, ... ) == 0x2 01179 1356 NtGdiGetRandomRgn (-1895758164, -1274804299, 1, ... ) == 0x0 01180 1356 NtGdiIntersectClipRect (-1895758164, 7, 7, 193, 25, ... ) == 0x3 01181 1356 NtGdiExtSelectClipRgn (-1895758164, 0, 5, ... ) == 0x2 01182 1356 NtGdiBitBlt (16842835, 0, 0, 222, 29, -1895758164, 0, 0, 13369376, -1, 0, ... ) == 0x1 01183 1356 NtGdiSelectBitmap (-1895758164, 25493519, ... ) == 0x3f0506e4 01184 1356 NtGdiDeleteObjectApp (-1895758164, ... ) == 0x1 01185 1356 NtGdiDeleteObjectApp (1057294052, ... ) == 0x1 01186 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01187 1356 NtUserFillWindow (524612, 524612, 16842832, 4, ... 01188 1356 NtUserGetAncestor (524612, 1, ... ) == 0x10014 01189 1356 NtUserValidateHandleSecure (65556, ... ) == 0x1 01190 1356 NtUserGetAncestor (65556, 1, ... ) == 0x0 01187 1356 NtUserFillWindow ... ) == 0x1 01148 1356 NtUserMessageCall ... ) == 0x0 01191 1356 NtUserMessageCall (0x80144, WM_NCACTIVATE, 0x1, 0xffffffff, 0, 670, 0, ... ) == 0x1 01192 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01193 1356 NtUserGetWindowDC (524612, ... ) == 0x1010052 01194 1356 NtGdiGetRandomRgn (16842834, -1258027083, 1, ... ) == 0x0 01195 1356 NtGdiIntersectClipRect (16842834, 0, 0, 0, 0, ... ) == 0x3 01196 1356 NtGdiGetCharSet (16842834, ... ) == 0x4e4 01197 1356 NtGdiExtSelectClipRgn (16842834, 0, 5, ... ) == 0x3 01198 1356 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01199 1356 NtUserCalcMenuBar (524612, 3, 3, 29, 8661352, ... ) == 0x0 01200 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 1240340, 690, 0, ... 01201 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 01200 1356 NtUserMessageCall ... ) == 0x0 01202 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 1240340, 690, 0, ... 01203 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01202 1356 NtUserMessageCall ... ) == 0x0 01204 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 1240340, 690, 0, ... 01205 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01204 1356 NtUserMessageCall ... ) == 0x0 01206 1356 NtUserGetTitleBarInfo (524612, 1240972, ... ) == 0x1 01207 1356 NtUserGetDCEx (524612, 0, 66561, ... ) == 0x1010053 01208 1356 NtGdiExcludeClipRect (16842835, 3, 29, 219, 123, ... ) == 0x3 01209 1356 NtGdiDrawStream (16842835, 96, 1240456, ... ) == 0x1 01210 1356 NtGdiDrawStream (16842835, 96, 1240456, ... ) == 0x1 01211 1356 NtGdiDrawStream (16842835, 96, 1240456, ... ) == 0x1 01212 1356 NtGdiCreateCompatibleBitmap (16842835, 222, 29, ... ) == 0x410506e4 01213 1356 NtGdiCreateCompatibleDC (16842835, ... ) == 0x900106ac 01214 1356 NtGdiSelectBitmap (-1878980948, 1090848484, ... ) == 0x185000f 01215 1356 NtGdiDrawStream (-1878980948, 96, 1240348, ... ) == 0x1 01216 1356 NtGdiDrawStream (-1878980948, 96, 1240304, ... ) == 0x1 01217 1356 NtGdiDrawStream (-1878980948, 96, 1240304, ... ) == 0x1 01218 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 01219 1356 NtGdiGetRandomRgn (-1878980948, -1241249867, 1, ... ) == 0x0 01220 1356 NtGdiIntersectClipRect (-1878980948, 8, 8, 194, 25, ... ) == 0x3 01221 1356 NtGdiExtSelectClipRgn (-1878980948, 0, 5, ... ) == 0x2 01222 1356 NtGdiGetRandomRgn (-1878980948, -1224472651, 1, ... ) == 0x0 01223 1356 NtGdiIntersectClipRect (-1878980948, 7, 7, 193, 25, ... ) == 0x3 01224 1356 NtGdiExtSelectClipRgn (-1878980948, 0, 5, ... ) == 0x2 01225 1356 NtGdiBitBlt (16842835, 0, 0, 222, 29, -1878980948, 0, 0, 13369376, -1, 0, ... ) == 0x1 01226 1356 NtGdiSelectBitmap (-1878980948, 25493519, ... ) == 0x410506e4 01227 1356 NtGdiDeleteObjectApp (-1878980948, ... ) == 0x1 01228 1356 NtGdiDeleteObjectApp (1090848484, ... ) == 0x1 01229 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01230 1356 NtUserGetThreadState (1, ... ) == 0x80144 01231 1356 NtUserGetThreadState (0, ... ) == 0x60128 01232 1356 NtUserGetForegroundWindow (... ) == 0x80144 01233 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01234 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01235 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01236 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 01237 1356 NtUserPostThreadMessage (1356, 49313, 0, 0, ... ) == 0x1 01238 1356 NtUserGetKeyboardLayoutList (0, 0, ... ) == 0x1 01239 1356 NtUserGetKeyboardLayoutList (1, 1333008, ... ) == 0x1 01240 1356 NtWaitForSingleObject (68, 0, {-50000000, -1}, ... ) == 0x0 01241 1356 NtOpenSection (0xf001f, {24, 52, 0x0, 0, 0, (0xf001f, {24, 52, 0x0, 0, 0, "CTF.AsmListCache.FMPDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, ... 104, ) }, ... 104, ) == 0x0 01242 1356 NtMapViewOfSection (104, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x990000), {0, 0}, 4096, ) == 0x0 01243 1356 NtFlushVirtualMemory (-1, (0x990000), 8, ... ) == STATUS_NOT_MAPPED_DATA 01244 1356 NtQueryInstallUILanguage (2089305898, ... ) == 0x0 01245 1356 NtQueryDefaultUILanguage (1239272, ... 01246 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01247 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482644, ) == 0x0 01248 1356 NtQueryInformationToken (-2147482644, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01249 1356 NtClose (-2147482644, ... ) == 0x0 01250 1356 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482644, ) }, ... -2147482644, ) == 0x0 01251 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x240, 0, 0, (0x80000000, {24, -2147482644, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01252 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x640, 0, 0, (0x80000000, {24, -2147482644, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482640, ) }, ... -2147482640, ) == 0x0 01253 1356 NtQueryValueKey (-2147482640, (-2147482640, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01254 1356 NtClose (-2147482640, ... ) == 0x0 01255 1356 NtClose (-2147482644, ... ) == 0x0 01245 1356 NtQueryDefaultUILanguage ... ) == 0x0 01256 1356 NtReleaseMutant (68, ... 0x0, ) == 0x0 01257 1356 NtUnmapViewOfSection (-1, 0x990000, ... ) == 0x0 01258 1356 NtClose (104, ... ) == 0x0 01259 1356 NtReleaseMutant (68, ... 01260 1356 NtContinue (-140696100, 0, ... 01259 1356 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 01261 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01262 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01263 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 01264 1356 NtUserCreateWindowEx (-2147483648, 1241308, 1240072, "-2013265920, 0, 0, 0, 0, -3, 0, 1953628160, 0, 1073742848, 0, ... 01265 1356 NtUserMessageCall (0x12010a, WM_NCCREATE, 0x0, 0x12eb68, 0, 670, 1, ... ) == 0x1 01266 1356 NtUserMessageCall (0x12010a, WM_NCCALCSIZE, 0x0, 0x12eba8, 0, 670, 1, ... ) == 0x0 01267 1356 NtUserSetProp (1179914, 43288, -1, ... ) == 0x1 01264 1356 NtUserCreateWindowEx ... ) == 0x12010a 01268 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01269 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01270 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01271 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01272 1356 NtWaitForSingleObject (60, 0, {-50000000, -1}, ... ) == 0x0 01273 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01274 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01275 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01276 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01277 1356 NtUserPostThreadMessage (1748, 49314, 0, 0, ... ) == 0x1 01278 1356 NtUserPostThreadMessage (416, 49314, 0, 0, ... ) == 0x1 01279 1356 NtReleaseMutant (60, ... 0x0, ) == 0x0 01147 1356 NtUserPeekMessage ... {0x80144, WM_PAINT, 0x0, 0x0, 0x129c956, {0, 0}}, ) == 0x1 01280 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01281 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01282 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01283 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01284 1356 NtUserDispatchMessage ({0x80144, WM_PAINT, 0x0, 0x0, 0x129c956, {0, 0}}, ... 01285 1356 NtUserMessageCall (0x80144, WM_PAINT, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 01284 1356 NtUserDispatchMessage ... ) == 0x0 01286 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x0, WM_USER+0xbca1, 0x0, 0x0, 0x129c956, {0, 0}}, ) == 0x1 01287 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01288 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01289 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca7, 0x0, 0x0, 0x129c956, {0, 0}}, ) == 0x1 01290 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01291 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01292 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01293 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01294 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "CTF.ThreadMIConnectionEvent.000006D4.00000000.0000001A"}, ... 104, ) }, ... 104, ) == 0x0 01295 1356 NtSetEvent (104, ... 0x0, ) == 0x0 01296 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01297 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01298 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01299 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01300 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01301 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01302 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01303 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01304 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01305 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01306 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01307 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01308 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01309 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01310 1356 NtOpenKey (0x20019, {24, 80, 0x40, 0, 0, (0x20019, {24, 80, 0x40, 0, 0, "Keyboard Layout\Toggle"}, ... 108, ) }, ... 108, ) == 0x0 01311 1356 NtQueryValueKey (108, (108, "Language Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01312 1356 NtQueryValueKey (108, (108, "Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01313 1356 NtQueryValueKey (108, (108, "Layout Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01314 1356 NtClose (108, ... ) == 0x0 01315 1356 NtQueryDefaultLocale (1, 1241128, ... ) == 0x0 01316 1356 NtQueryDefaultLocale (1, 1241128, ... ) == 0x0 01317 1356 NtUserGetKeyboardLayoutList (0, 0, ... ) == 0x1 01318 1356 NtUserGetKeyboardLayoutList (1, 1343080, ... ) == 0x1 01319 1356 NtWaitForSingleObject (60, 0, {-50000000, -1}, ... ) == 0x0 01320 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01321 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01322 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01323 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01324 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 01325 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 01326 1356 NtReleaseMutant (60, ... 0x0, ) == 0x0 01327 1356 NtQueryDefaultLocale (1, 1241128, ... ) == 0x0 01328 1356 NtQueryDefaultLocale (1, 1241128, ... ) == 0x0 01329 1356 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 01330 1356 NtOpenProcessToken (-1, 0xa, ... 108, ) == 0x0 01331 1356 NtDuplicateToken (108, 0xc, {24, 0, 0x0, 0, 1241096, 0x0}, 0, 2, ... 112, ) == 0x0 01332 1356 NtClose (108, ... ) == 0x0 01333 1356 NtAccessCheck (1341080, 112, 0x1, 1241172, 1241224, 56, 1241204, ... (0x1), ) == 0x0 01334 1356 NtClose (112, ... ) == 0x0 01335 1356 NtWaitForSingleObject (60, 0, {-50000000, -1}, ... ) == 0x0 01336 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01337 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01338 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01339 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01340 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 01341 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 01342 1356 NtReleaseMutant (60, ... 0x0, ) == 0x0 01343 1356 NtQueryDefaultLocale (1, 1241108, ... ) == 0x0 01344 1356 NtQueryDefaultLocale (1, 1241128, ... ) == 0x0 01345 1356 NtQueryDefaultLocale (1, 1241128, ... ) == 0x0 01346 1356 NtWaitForSingleObject (60, 0, {-50000000, -1}, ... ) == 0x0 01347 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01348 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01349 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01350 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01351 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 01352 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 01353 1356 NtReleaseMutant (60, ... 0x0, ) == 0x0 01354 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 01355 1356 NtUserSystemParametersInfo (31, 60, 1239840, 0, ... ) == 0x1 01356 1356 NtUserGetDC (0, ... ) == 0x1010052 01357 1356 NtGdiHfontCreate (1240848, 356, 0, 0, 1331296, ... ) == 0x960a06ac 01358 1356 NtGdiGetTextMetricsW (16842834, 1241088, 68, ... ) == 0x1 01359 1356 NtGdiDeleteObjectApp (-1777727828, ... ) == 0x1 01360 1356 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01361 1356 NtGdiHfontCreate (1240812, 356, 0, 0, 1331296, ... ) == 0x970a06ac 01362 1356 NtUserGetDC (0, ... ) == 0x1010052 01363 1356 NtGdiCreateCompatibleDC (16842834, ... ) == 0xef0106da 01364 1356 NtGdiCreateCompatibleBitmap (16842834, 16, 16, ... ) == 0x430506e4 01365 1356 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01366 1356 NtGdiCreateBitmap (16, 16, 1, 1, 0, ... ) == 0xb70507bb 01367 1356 NtGdiSelectBitmap (-285145382, 1124402916, ... ) == 0x185000f 01368 1356 NtGdiGetCharSet (-285145382, ... ) == 0x4e4 01369 1356 NtGdiGetCharSet (-285145382, ... ) == 0x4e4 01370 1356 NtGdiGetTextCharsetInfo (-285145382, 0, 0, ... ) == 0x0 01371 1356 NtGdiGetTextMetricsW (-285145382, 1240728, 68, ... ) == 0x1 01372 1356 NtGdiGetRandomRgn (-285145382, -1207695435, 1, ... ) == 0x0 01373 1356 NtGdiIntersectClipRect (-285145382, 0, 0, 16, 16, ... ) == 0x3 01374 1356 NtGdiGetWidthTable (-285145382, 2, 1352848, 258, 1353364, 1352216, 1352232, ... ) == 0x1 01375 1356 NtGdiExtSelectClipRgn (-285145382, 0, 5, ... ) == 0x2 01376 1356 NtGdiSelectBitmap (-285145382, -1224407109, ... ) == 0x430506e4 01377 1356 NtGdiExtGetObjectW (-1224407109, 24, 1241108, ... ) == 0x18 01378 1356 NtGdiExtGetObjectW (1124402916, 24, 1241084, ... ) == 0x18 01379 1356 NtUserCallOneParam (0, 33, ... ) == 0x220297 01380 1356 NtGdiExtGetObjectW (1124402916, 24, 1240980, ... ) == 0x18 01381 1356 NtGdiGetDIBitsInternal (1879115345, 1124402916, 0, 16, 1352900, 1352848, 0, 1024, 0, ... ) == 0x10 01382 1356 NtGdiCreateDIBitmapInternal (1879115345, 16, 16, 2, 0, 1342944, 0, 40, 0, 0, 0, ... ) == 0x18050497 01383 1356 NtGdiSelectBitmap (1879115345, 402982039, ... ) == 0x185000f 01384 1356 NtGdiGetDCforBitmap (402982039, ... ) == 0x70010651 01385 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01386 1356 NtGdiSelectBitmap (1879115345, 402982039, ... ) == 0x18050497 01387 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01388 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01389 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 16, 0, 0, 0, 16, 1352900, 1342944, 0, 1024, 40, 1, 0, ... ) == 0x10 01390 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01391 1356 NtGdiSelectBitmap (1879115345, 402982039, ... ) == 0x18050497 01392 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01393 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x18050497 01394 1356 NtGdiCreateBitmap (16, 32, 1, 1, 0, ... ) == 0xa20504b2 01395 1356 NtGdiCreateCompatibleDC (1879115345, ... ) == 0xe40103d2 01396 1356 NtGdiSelectBitmap (-469695534, -1576729422, ... ) == 0x185000f 01397 1356 NtGdiSelectBitmap (1879115345, -1224407109, ... ) == 0x0 01398 1356 NtGdiBitBlt (-469695534, 0, 0, 16, 16, 1879115345, 0, 0, 13369376, -1, 0, ... ) == 0x1 01399 1356 NtGdiSelectBitmap (-469695534, 25493519, ... ) == 0xa20504b2 01400 1356 NtGdiDeleteObjectApp (-469695534, ... ) == 0x1 01401 1356 NtUserSetCursorIconData (2228887, 1241024, 1241040, 1241132, ... ) == 0x1 01402 1356 NtGdiSelectBitmap (-285145382, 25493519, ... ) == 0xb70507bb 01403 1356 NtGdiDeleteObjectApp (-1224407109, ... ) == 0x1 01404 1356 NtGdiDeleteObjectApp (1124402916, ... ) == 0x1 01405 1356 NtGdiDeleteObjectApp (-285145382, ... ) == 0x1 01406 1356 NtGdiDeleteObjectApp (-1760950612, ... ) == 0x1 01407 1356 NtQueryDefaultUILanguage (1238572, ... 01408 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01409 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482644, ) == 0x0 01410 1356 NtQueryInformationToken (-2147482644, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01411 1356 NtClose (-2147482644, ... ) == 0x0 01412 1356 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482644, ) }, ... -2147482644, ) == 0x0 01413 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x240, 0, 0, (0x80000000, {24, -2147482644, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01414 1356 NtOpenKey (0x80000000, {24, -2147482644, 0x640, 0, 0, (0x80000000, {24, -2147482644, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482640, ) }, ... -2147482640, ) == 0x0 01415 1356 NtQueryValueKey (-2147482640, (-2147482640, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01416 1356 NtClose (-2147482640, ... ) == 0x0 01417 1356 NtClose (-2147482644, ... ) == 0x0 01407 1356 NtQueryDefaultUILanguage ... ) == 0x0 01418 1356 NtOpenKey (0x20019, {24, 80, 0x40, 0, 0, (0x20019, {24, 80, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\LangBarAddIn\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01419 1356 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\LangBarAddIn\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01420 1356 NtWaitForSingleObject (60, 0, {-50000000, -1}, ... ) == 0x0 01421 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01422 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01423 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01424 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01425 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 01426 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 01427 1356 NtReleaseMutant (60, ... 0x0, ) == 0x0 01428 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF..GFJMJCB"}, {20, 0}, 4, 134217728, 0, ... 112, ) }, {20, 0}, 4, 134217728, 0, ... 112, ) == 0x0 01429 1356 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x990000), {0, 0}, 4096, ) == 0x0 01430 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "CTF.ThreadMarshalInterfaceEvent.000006D4.00000000.0000001A"}, ... 108, ) }, ... 108, ) == 0x0 01431 1356 NtSetEvent (108, ... 0x0, ) == 0x0 01432 1356 NtClose (108, ... ) == 0x0 01433 1356 NtClose (104, ... ) == 0x0 01434 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01435 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x60128, WM_PAINT, 0x0, 0x0, 0x129c966, {0, 0}}, ) == 0x1 01436 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01437 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01438 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01439 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01440 1356 NtUserDispatchMessage ({0x60128, WM_PAINT, 0x0, 0x0, 0x129c966, {0, 0}}, ... 01441 1356 NtUserBeginPaint (0x60128, 1241640, ... 01442 1356 NtUserMessageCall (0x60128, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01441 1356 NtUserBeginPaint ... ) == 0x1010050 01443 1356 NtUserGetControlBrush (0x60128, 16842832, 309, ... ) == 0x1100056 01444 1356 NtGdiIntersectClipRect (16842832, 0, 0, 75, 23, ... ) == 0x3 01445 1356 NtGdiIntersectClipRect (16842832, 3, 3, 72, 20, ... ) == 0x3 01446 1356 NtUserEndPaint (0x60128, 1241640, ... ) == 0x1 01440 1356 NtUserDispatchMessage ... ) == 0x0 01447 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x1100f0, WM_PAINT, 0x0, 0x0, 0x129c966, {0, 0}}, ) == 0x1 01448 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01449 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01450 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01451 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01452 1356 NtUserDispatchMessage ({0x1100f0, WM_PAINT, 0x0, 0x0, 0x129c966, {0, 0}}, ... 01453 1356 NtUserBeginPaint (0x1100f0, 1241644, ... 01454 1356 NtUserMessageCall (0x1100f0, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01453 1356 NtUserBeginPaint ... ) == 0x1010050 01455 1356 NtGdiIntersectClipRect (16842832, 0, 0, 32, 32, ... ) == 0x3 01456 1356 NtUserGetControlBrush (0x1100f0, 16842832, 312, ... 01457 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01458 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 01456 1356 NtUserGetControlBrush ... ) == 0x1100056 01459 1356 NtGdiGetDCDword (16842832, 7, 1241328, ... ) == 0x1 01460 1356 NtUserDrawIconEx (16842832, 0, 0, 65545, 32, 32, 0, 17825878, 3, 0, 1241380, ... ) == 0x1 01461 1356 NtUserEndPaint (0x1100f0, 1241644, ... ) == 0x1 01452 1356 NtUserDispatchMessage ... ) == 0x0 01462 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x60130, WM_PAINT, 0x0, 0x0, 0x129c966, {0, 0}}, ) == 0x1 01463 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01464 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01465 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01466 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01467 1356 NtUserDispatchMessage ({0x60130, WM_PAINT, 0x0, 0x0, 0x129c966, {0, 0}}, ... 01468 1356 NtUserBeginPaint (0x60130, 1241644, ... 01469 1356 NtUserMessageCall (0x60130, WM_NCPAINT, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 01468 1356 NtUserBeginPaint ... ) == 0x1010050 01470 1356 NtGdiIntersectClipRect (16842832, 0, 0, 149, 15, ... ) == 0x3 01471 1356 NtUserGetControlBrush (0x60130, 16842832, 312, ... 01472 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01473 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 01471 1356 NtUserGetControlBrush ... ) == 0x1100056 01474 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01475 1356 NtGdiGetTextCharsetInfo (16842832, 0, 0, ... ) == 0x0 01476 1356 NtUserEndPaint (0x60130, 1241644, ... ) == 0x1 01467 1356 NtUserDispatchMessage ... ) == 0x0 01477 1356 NtUserWaitMessage (... ) == 0x1 01478 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01479 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01480 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01481 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01482 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01483 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 104, ) }, ... 104, ) == 0x0 01484 1356 NtSetEvent (104, ... 0x0, ) == 0x0 01485 1356 NtCreateMutant (0x1f0001, {24, 52, 0x80, 0, 0, (0x1f0001, {24, 52, 0x80, 0, 0, "MSCTF.Shared.MUTEX.ENG"}, 0, ... 108, ) }, 0, ... 108, ) == STATUS_OBJECT_NAME_EXISTS 01486 1356 NtOpenSection (0xf001f, {24, 52, 0x0, 0, 0, (0xf001f, {24, 52, 0x0, 0, 0, "MSCTF.Shared.SFM.ENG"}, ... 116, ) }, ... 116, ) == 0x0 01487 1356 NtMapViewOfSection (116, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x9a0000), {0, 0}, 524288, ) == 0x0 01488 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01489 1356 NtUnmapViewOfSection (-1, 0x990000, ... ) == 0x0 01490 1356 NtClose (112, ... ) == 0x0 01491 1356 NtAllocateVirtualMemory (-1, 1355776, 0, 8192, 4096, 4, ... 1355776, 8192, ) == 0x0 01492 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01493 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF.B.GGJMJCB"}, {20, 0}, 4, 134217728, 0, ... 112, ) }, {20, 0}, 4, 134217728, 0, ... 112, ) == 0x0 01494 1356 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x990000), {0, 0}, 4096, ) == 0x0 01495 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF.C.GGJMJCB"}, {20, 0}, 4, 134217728, 0, ... 120, ) }, {20, 0}, 4, 134217728, 0, ... 120, ) == 0x0 01496 1356 NtMapViewOfSection (120, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 4096, ) == 0x0 01497 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF.D.GGJMJCB"}, {20, 0}, 4, 134217728, 0, ... 124, ) }, {20, 0}, 4, 134217728, 0, ... 124, ) == 0x0 01498 1356 NtMapViewOfSection (124, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa30000), {0, 0}, 4096, ) == 0x0 01499 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01500 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01501 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01502 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01503 1356 NtClose (104, ... ) == 0x0 01504 1356 NtClose (128, ... ) == 0x0 01505 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01506 1356 NtUserWaitMessage (... ) == 0x1 01507 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01508 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01509 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01510 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01511 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01512 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01513 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01514 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01515 1356 NtUnmapViewOfSection (-1, 0x990000, ... ) == 0x0 01516 1356 NtClose (112, ... ) == 0x0 01517 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01518 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF.E.GGJMJCB"}, {20, 0}, 4, 134217728, 0, ... 112, ) }, {20, 0}, 4, 134217728, 0, ... 112, ) == 0x0 01519 1356 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x990000), {0, 0}, 4096, ) == 0x0 01520 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01521 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01522 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 104, ) }, ... 104, ) == 0x0 01523 1356 NtSetEvent (104, ... 0x0, ) == 0x0 01524 1356 NtClose (128, ... ) == 0x0 01525 1356 NtClose (104, ... ) == 0x0 01526 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01527 1356 NtUserWaitMessage (... ) == 0x1 01528 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca9, 0x129c966, 0x1, 0x129c966, {0, 0}}, ) == 0x1 01529 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01530 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01531 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01532 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01533 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ntdll.dll"}, 1238964, ... ) }, 1238964, ... ) == 0x0 01534 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01535 1356 NtUserWaitMessage (... ) == 0x1 01536 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01537 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01538 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01539 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01540 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01541 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 104, ) }, ... 104, ) == 0x0 01542 1356 NtSetEvent (104, ... 0x0, ) == 0x0 01543 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01544 1356 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01545 1356 NtClose (120, ... ) == 0x0 01546 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01547 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF.F.GGJMJCB"}, {20, 0}, 4, 134217728, 0, ... 120, ) }, {20, 0}, 4, 134217728, 0, ... 120, ) == 0x0 01548 1356 NtMapViewOfSection (120, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 4096, ) == 0x0 01549 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01550 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01551 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01552 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01553 1356 NtClose (104, ... ) == 0x0 01554 1356 NtClose (128, ... ) == 0x0 01555 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01556 1356 NtUserWaitMessage (... ) == 0x1 01557 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca9, 0x129c966, 0x2, 0x129c966, {0, 0}}, ) == 0x1 01558 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01559 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01560 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01561 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01562 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01563 1356 NtUserWaitMessage (... ) == 0x1 01564 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01565 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01566 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01567 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01568 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01569 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01570 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01571 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01572 1356 NtUnmapViewOfSection (-1, 0xa30000, ... ) == 0x0 01573 1356 NtClose (124, ... ) == 0x0 01574 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01575 1356 NtCreateSection (0xf0007, {24, 52, 0x80, 0, 0, (0xf0007, {24, 52, 0x80, 0, 0, "MSCTF.MarshalInterface.FileMap.MEF.G.GGJMJCB"}, {20, 0}, 4, 134217728, 0, ... 124, ) }, {20, 0}, 4, 134217728, 0, ... 124, ) == 0x0 01576 1356 NtMapViewOfSection (124, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa30000), {0, 0}, 4096, ) == 0x0 01577 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01578 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01579 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 104, ) }, ... 104, ) == 0x0 01580 1356 NtSetEvent (104, ... 0x0, ) == 0x0 01581 1356 NtClose (128, ... ) == 0x0 01582 1356 NtClose (104, ... ) == 0x0 01583 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01584 1356 NtUserWaitMessage (... ) == 0x1 01585 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca9, 0x129c966, 0x3, 0x129c966, {0, 0}}, ) == 0x1 01586 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01587 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01588 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01589 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01590 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01591 1356 NtUserWaitMessage (... ) == 0x1 01592 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01593 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01594 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01595 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01596 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01597 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 104, ) }, ... 104, ) == 0x0 01598 1356 NtSetEvent (104, ... 0x0, ) == 0x0 01599 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01600 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01601 1356 NtOpenSection (0xf001f, {24, 52, 0x0, 0, 0, (0xf001f, {24, 52, 0x0, 0, 0, "MSCTF.MarshalInterface.FileMap.ENG.M.GGJMJCB"}, ... 128, ) }, ... 128, ) == 0x0 01602 1356 NtMapViewOfSection (128, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa40000), {0, 0}, 4096, ) == 0x0 01603 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01604 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01605 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 01606 1356 NtUserQueryWindow (65742, 1, ... ) == 0x6d4 01607 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 01608 1356 NtUserQueryWindow (65742, 1, ... ) == 0x6d4 01609 1356 NtUnmapViewOfSection (-1, 0xa40000, ... ) == 0x0 01610 1356 NtClose (128, ... ) == 0x0 01611 1356 NtOpenSection (0xf001f, {24, 52, 0x0, 0, 0, (0xf001f, {24, 52, 0x0, 0, 0, "MSCTF.MarshalInterface.FileMap.ENG.N.GGJMJCB"}, ... 128, ) }, ... 128, ) == 0x0 01612 1356 NtMapViewOfSection (128, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa40000), {0, 0}, 4096, ) == 0x0 01613 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01614 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01615 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 01616 1356 NtUserQueryWindow (65742, 1, ... ) == 0x6d4 01617 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 01618 1356 NtUserQueryWindow (65742, 1, ... ) == 0x6d4 01619 1356 NtUnmapViewOfSection (-1, 0xa40000, ... ) == 0x0 01620 1356 NtClose (128, ... ) == 0x0 01621 1356 NtOpenSection (0xf001f, {24, 52, 0x0, 0, 0, (0xf001f, {24, 52, 0x0, 0, 0, "MSCTF.MarshalInterface.FileMap.ENG.O.GGJMJCB"}, ... 128, ) }, ... 128, ) == 0x0 01622 1356 NtMapViewOfSection (128, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa40000), {0, 0}, 4096, ) == 0x0 01623 1356 NtWaitForSingleObject (84, 0, {-50000000, -1}, ... ) == 0x0 01624 1356 NtReleaseMutant (84, ... 0x0, ) == 0x0 01625 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 01626 1356 NtUserQueryWindow (65742, 1, ... ) == 0x6d4 01627 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 01628 1356 NtUserQueryWindow (65742, 1, ... ) == 0x6d4 01629 1356 NtUnmapViewOfSection (-1, 0xa40000, ... ) == 0x0 01630 1356 NtClose (128, ... ) == 0x0 01631 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01632 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01633 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01634 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01635 1356 NtClose (104, ... ) == 0x0 01636 1356 NtClose (128, ... ) == 0x0 01637 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01638 1356 NtUserWaitMessage (... ) == 0x1 01639 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01640 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01641 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01642 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01643 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01644 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01645 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01646 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01647 1356 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01648 1356 NtClose (120, ... ) == 0x0 01649 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01650 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01651 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01652 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 120, ) }, ... 120, ) == 0x0 01653 1356 NtSetEvent (120, ... 0x0, ) == 0x0 01654 1356 NtClose (128, ... ) == 0x0 01655 1356 NtClose (120, ... ) == 0x0 01656 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01657 1356 NtUserWaitMessage (... ) == 0x1 01658 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c966, {0, 0}}, ) == 0x1 01659 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01660 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01661 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01662 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01663 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 120, ) }, ... 120, ) == 0x0 01664 1356 NtSetEvent (120, ... 0x0, ) == 0x0 01665 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01666 1356 NtAllocateVirtualMemory (-1, 1363968, 0, 12288, 4096, 4, ... 1363968, 12288, ) == 0x0 01667 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01668 1356 NtQueryDefaultLocale (1, 1239964, ... ) == 0x0 01669 1356 NtQueryDefaultLocale (1, 1239984, ... ) == 0x0 01670 1356 NtUserGetDC (0, ... ) == 0x1010053 01671 1356 NtGdiCreateCompatibleBitmap (16842835, 16, 16, ... ) == 0x9f0506ac 01672 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01673 1356 NtGdiSelectBitmap (1879115345, -1627060564, ... ) == 0x185000f 01674 1356 NtGdiGetDCforBitmap (-1627060564, ... ) == 0x70010651 01675 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01676 1356 NtGdiSelectBitmap (1879115345, -1627060564, ... ) == 0x9f0506ac 01677 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01678 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01679 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 16, 0, 0, 0, 16, 1953913504, 1358040, 0, 128, 104, 1, 0, ... ) == 0x10 01680 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01681 1356 NtGdiSelectBitmap (1879115345, -1627060564, ... ) == 0x9f0506ac 01682 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01683 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x9f0506ac 01684 1356 NtUserGetDC (0, ... ) == 0x1010053 01685 1356 NtGdiCreateDIBitmapInternal (16842835, 16, 32, 2, 0, 2118583256, 0, 48, 0, 0, 0, ... ) == 0x450506e4 01686 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01687 1356 NtGdiSelectBitmap (1879115345, 1157957348, ... ) == 0x185000f 01688 1356 NtGdiGetDCforBitmap (1157957348, ... ) == 0x70010651 01689 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01690 1356 NtGdiSelectBitmap (1879115345, 1157957348, ... ) == 0x450506e4 01691 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01692 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01693 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 32, 0, 0, 0, 32, 1953913568, 1358040, 0, 128, 48, 1, 0, ... ) == 0x20 01694 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01695 1356 NtGdiSelectBitmap (1879115345, 1157957348, ... ) == 0x450506e4 01696 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01697 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x450506e4 01698 1356 NtGdiCreateCompatibleDC (1879115345, ... ) == 0xba0107bb 01699 1356 NtGdiExtGetObjectW (1157957348, 24, 1239416, ... ) == 0x18 01700 1356 NtGdiCreateBitmap (16, 32, 1, 1, 0, ... ) == 0xe70503d2 01701 1356 NtGdiSelectBitmap (1879115345, 1157957348, ... ) == 0x185000f 01702 1356 NtGdiSelectBitmap (-1174337605, -419101742, ... ) == 0x185000f 01703 1356 NtGdiBitBlt (-1174337605, 0, 0, 16, 32, 1879115345, 0, 0, 13369376, -1, 0, ... ) == 0x1 01704 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x450506e4 01705 1356 NtGdiSelectBitmap (-1174337605, 25493519, ... ) == 0xe70503d2 01706 1356 NtGdiDeleteObjectApp (1157957348, ... ) == 0x1 01707 1356 NtGdiDeleteObjectApp (-1174337605, ... ) == 0x1 01708 1356 NtUserCallOneParam (0, 33, ... ) == 0x5801d7 01709 1356 NtUserSetCursorIconData (5767639, 1239464, 1239480, 1239544, ... ) == 0x1 01710 1356 NtUserGetIconInfo (5767639, 1240816, 0, 0, 0, 0, ... ) == 0x1 01711 1356 NtGdiExtGetObjectW (-200997158, 24, 1240740, ... ) == 0x18 01712 1356 NtGdiExtGetObjectW (-1140521029, 24, 1240716, ... ) == 0x18 01713 1356 NtGdiDeleteObjectApp (-200997158, ... ) == 0x1 01714 1356 NtGdiDeleteObjectApp (-1140521029, ... ) == 0x1 01715 1356 NtUserGetIconInfo (5767639, 1240812, 0, 0, 0, 0, ... ) == 0x1 01716 1356 NtGdiExtGetObjectW (-184219942, 24, 1240728, ... ) == 0x18 01717 1356 NtGdiExtGetObjectW (-1123743813, 24, 1240704, ... ) == 0x18 01718 1356 NtGdiGetBitmapBits (-184219942, 1024, 1358288, ... ) == 0x400 01719 1356 NtGdiGetBitmapBits (-1123743813, 32, 1359312, ... ) == 0x20 01720 1356 NtGdiDeleteObjectApp (-184219942, ... ) == 0x1 01721 1356 NtGdiDeleteObjectApp (-1123743813, ... ) == 0x1 01722 1356 NtUserDestroyCursor (5767639, 1, ... ) == 0x1 01723 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01724 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01725 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01726 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01727 1356 NtClose (120, ... ) == 0x0 01728 1356 NtClose (128, ... ) == 0x0 01729 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01730 1356 NtUserWaitMessage (... ) == 0x1 01731 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x6012e, WM_TIMER, 0x1, 0x0, 0x129c9c3, {0, 0}}, ) == 0x1 01732 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01733 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01734 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 01735 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 01736 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 01737 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 01738 1356 NtUserKillTimer (393518, 1, ... ) == 0x1 01739 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 01740 1356 NtUserWaitMessage (... ) == 0x1 01741 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c9c3, {0, 0}}, ) == 0x1 01742 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01743 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01744 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01745 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01746 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 128, ) }, ... 128, ) == 0x0 01747 1356 NtSetEvent (128, ... 0x0, ) == 0x0 01748 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01749 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01750 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01751 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01752 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 120, ) }, ... 120, ) == 0x0 01753 1356 NtSetEvent (120, ... 0x0, ) == 0x0 01754 1356 NtClose (128, ... ) == 0x0 01755 1356 NtClose (120, ... ) == 0x0 01756 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01757 1356 NtUserWaitMessage (... ) == 0x1 01758 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c9d3, {0, 0}}, ) == 0x1 01759 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01760 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01761 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01762 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01763 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 120, ) }, ... 120, ) == 0x0 01764 1356 NtSetEvent (120, ... 0x0, ) == 0x0 01765 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01766 1356 NtUnmapViewOfSection (-1, 0x990000, ... ) == 0x0 01767 1356 NtClose (112, ... ) == 0x0 01768 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01769 1356 NtUserGetIconInfo (2228887, 1240892, 0, 0, 0, 0, ... ) == 0x1 01770 1356 NtGdiExtGetObjectW (100991998, 24, 1240748, ... ) == 0x18 01771 1356 NtGdiExtGetObjectW (100992000, 24, 1240724, ... ) == 0x18 01772 1356 NtUserCallOneParam (0, 33, ... ) == 0x400c9 01773 1356 NtGdiExtGetObjectW (100992000, 24, 1240620, ... ) == 0x18 01774 1356 NtGdiGetDIBitsInternal (1879115345, 100992000, 0, 16, 1358444, 1358392, 0, 1024, 0, ... ) == 0x10 01775 1356 NtGdiCreateDIBitmapInternal (1879115345, 16, 16, 2, 0, 1362232, 0, 40, 0, 0, 0, ... ) == 0xb30506b1 01776 1356 NtGdiSelectBitmap (1879115345, -1291516239, ... ) == 0x185000f 01777 1356 NtGdiGetDCforBitmap (-1291516239, ... ) == 0x70010651 01778 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01779 1356 NtGdiSelectBitmap (1879115345, -1291516239, ... ) == 0xb30506b1 01780 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01781 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01782 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 16, 0, 0, 0, 16, 1358444, 1362232, 0, 1024, 40, 1, 0, ... ) == 0x10 01783 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01784 1356 NtGdiSelectBitmap (1879115345, -1291516239, ... ) == 0xb30506b1 01785 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01786 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0xb30506b1 01787 1356 NtGdiCreateBitmap (16, 32, 1, 1, 0, ... ) == 0xf505060c 01788 1356 NtGdiCreateCompatibleDC (1879115345, ... ) == 0x2f0106a7 01789 1356 NtGdiSelectBitmap (788596391, -184220148, ... ) == 0x185000f 01790 1356 NtGdiSelectBitmap (1879115345, 100991998, ... ) == 0x185000f 01791 1356 NtGdiBitBlt (788596391, 0, 0, 16, 16, 1879115345, 0, 0, 13369376, -1, 0, ... ) == 0x1 01792 1356 NtGdiSelectBitmap (788596391, 25493519, ... ) == 0xf505060c 01793 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x60503fe 01794 1356 NtGdiDeleteObjectApp (788596391, ... ) == 0x1 01795 1356 NtUserSetCursorIconData (262345, 1240664, 1240680, 1240772, ... ) == 0x1 01796 1356 NtGdiDeleteObjectApp (100991998, ... ) == 0x1 01797 1356 NtGdiDeleteObjectApp (100992000, ... ) == 0x1 01798 1356 NtUserGetIconInfo (262345, 1240816, 0, 0, 0, 0, ... ) == 0x1 01799 1356 NtGdiExtGetObjectW (117769214, 24, 1240740, ... ) == 0x18 01800 1356 NtGdiExtGetObjectW (134546429, 24, 1240716, ... ) == 0x18 01801 1356 NtGdiDeleteObjectApp (117769214, ... ) == 0x1 01802 1356 NtGdiDeleteObjectApp (134546429, ... ) == 0x1 01803 1356 NtUserGetIconInfo (262345, 1240812, 0, 0, 0, 0, ... ) == 0x1 01804 1356 NtGdiExtGetObjectW (134546430, 24, 1240728, ... ) == 0x18 01805 1356 NtGdiExtGetObjectW (151323645, 24, 1240704, ... ) == 0x18 01806 1356 NtGdiGetBitmapBits (134546430, 1024, 1358520, ... ) == 0x400 01807 1356 NtGdiGetBitmapBits (151323645, 32, 1359544, ... ) == 0x20 01808 1356 NtGdiDeleteObjectApp (134546430, ... ) == 0x1 01809 1356 NtGdiDeleteObjectApp (151323645, ... ) == 0x1 01810 1356 NtUserDestroyCursor (262345, 1, ... ) == 0x1 01811 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01812 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01813 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 112, ) }, ... 112, ) == 0x0 01814 1356 NtSetEvent (112, ... 0x0, ) == 0x0 01815 1356 NtClose (120, ... ) == 0x0 01816 1356 NtClose (112, ... ) == 0x0 01817 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01818 1356 NtUserWaitMessage (... ) == 0x1 01819 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c9d3, {0, 0}}, ) == 0x1 01820 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01821 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01822 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01823 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01824 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 112, ) }, ... 112, ) == 0x0 01825 1356 NtSetEvent (112, ... 0x0, ) == 0x0 01826 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01827 1356 NtUnmapViewOfSection (-1, 0xa30000, ... ) == 0x0 01828 1356 NtClose (124, ... ) == 0x0 01829 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01830 1356 NtQueryDefaultLocale (1, 1239944, ... ) == 0x0 01831 1356 NtQueryDefaultLocale (1, 1239964, ... ) == 0x0 01832 1356 NtUserGetDC (0, ... ) == 0x1010053 01833 1356 NtGdiCreateCompatibleBitmap (16842835, 16, 16, ... ) == 0xc0503fd 01834 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01835 1356 NtGdiSelectBitmap (1879115345, 201655293, ... ) == 0x185000f 01836 1356 NtGdiGetDCforBitmap (201655293, ... ) == 0x70010651 01837 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01838 1356 NtGdiSelectBitmap (1879115345, 201655293, ... ) == 0xc0503fd 01839 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01840 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01841 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 16, 0, 0, 0, 16, 1953912544, 1358040, 0, 128, 104, 1, 0, ... ) == 0x10 01842 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01843 1356 NtGdiSelectBitmap (1879115345, 201655293, ... ) == 0xc0503fd 01844 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01845 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0xc0503fd 01846 1356 NtUserGetDC (0, ... ) == 0x1010053 01847 1356 NtGdiCreateDIBitmapInternal (16842835, 16, 32, 2, 0, 2118583256, 0, 48, 0, 0, 0, ... ) == 0xc0503fe 01848 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01849 1356 NtGdiSelectBitmap (1879115345, 201655294, ... ) == 0x185000f 01850 1356 NtGdiGetDCforBitmap (201655294, ... ) == 0x70010651 01851 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01852 1356 NtGdiSelectBitmap (1879115345, 201655294, ... ) == 0xc0503fe 01853 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01854 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01855 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 32, 0, 0, 0, 32, 1953912608, 1358040, 0, 128, 48, 1, 0, ... ) == 0x20 01856 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01857 1356 NtGdiSelectBitmap (1879115345, 201655294, ... ) == 0xc0503fe 01858 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01859 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0xc0503fe 01860 1356 NtGdiCreateCompatibleDC (1879115345, ... ) == 0xb90106b1 01861 1356 NtGdiExtGetObjectW (201655294, 24, 1239396, ... ) == 0x18 01862 1356 NtGdiCreateBitmap (16, 32, 1, 1, 0, ... ) == 0xfa05060c 01863 1356 NtGdiSelectBitmap (1879115345, 201655294, ... ) == 0x185000f 01864 1356 NtGdiSelectBitmap (-1191115087, -100334068, ... ) == 0x185000f 01865 1356 NtGdiBitBlt (-1191115087, 0, 0, 16, 32, 1879115345, 0, 0, 13369376, -1, 0, ... ) == 0x1 01866 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0xc0503fe 01867 1356 NtGdiSelectBitmap (-1191115087, 25493519, ... ) == 0xfa05060c 01868 1356 NtGdiDeleteObjectApp (201655294, ... ) == 0x1 01869 1356 NtGdiDeleteObjectApp (-1191115087, ... ) == 0x1 01870 1356 NtUserCallOneParam (0, 33, ... ) == 0x600c9 01871 1356 NtUserSetCursorIconData (393417, 1239444, 1239460, 1239524, ... ) == 0x1 01872 1356 NtUserGetIconInfo (393417, 1240816, 0, 0, 0, 0, ... ) == 0x1 01873 1356 NtGdiExtGetObjectW (218432512, 24, 1240740, ... ) == 0x18 01874 1356 NtGdiExtGetObjectW (-1157298511, 24, 1240716, ... ) == 0x18 01875 1356 NtGdiDeleteObjectApp (218432512, ... ) == 0x1 01876 1356 NtGdiDeleteObjectApp (-1157298511, ... ) == 0x1 01877 1356 NtUserGetIconInfo (393417, 1240812, 0, 0, 0, 0, ... ) == 0x1 01878 1356 NtGdiExtGetObjectW (235209728, 24, 1240728, ... ) == 0x18 01879 1356 NtGdiExtGetObjectW (-1140521295, 24, 1240704, ... ) == 0x18 01880 1356 NtGdiGetBitmapBits (235209728, 1024, 1358520, ... ) == 0x400 01881 1356 NtGdiGetBitmapBits (-1140521295, 32, 1359544, ... ) == 0x20 01882 1356 NtGdiDeleteObjectApp (235209728, ... ) == 0x1 01883 1356 NtGdiDeleteObjectApp (-1140521295, ... ) == 0x1 01884 1356 NtUserDestroyCursor (393417, 1, ... ) == 0x1 01885 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01886 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01887 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 124, ) }, ... 124, ) == 0x0 01888 1356 NtSetEvent (124, ... 0x0, ) == 0x0 01889 1356 NtClose (112, ... ) == 0x0 01890 1356 NtClose (124, ... ) == 0x0 01891 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01892 1356 NtUserWaitMessage (... ) == 0x1 01893 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x12010a, WM_USER+0xbca6, 0x6d4, 0x28, 0x129c9d3, {0, 0}}, ) == 0x1 01894 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01895 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01896 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01897 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01898 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceiveConection.Event.ENG.IC"}, ... 124, ) }, ... 124, ) == 0x0 01899 1356 NtSetEvent (124, ... 0x0, ) == 0x0 01900 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01901 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01902 1356 NtQueryDefaultLocale (1, 1239964, ... ) == 0x0 01903 1356 NtQueryDefaultLocale (1, 1239984, ... ) == 0x0 01904 1356 NtUserGetDC (0, ... ) == 0x1010053 01905 1356 NtGdiCreateCompatibleBitmap (16842835, 16, 16, ... ) == 0x11050400 01906 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01907 1356 NtGdiSelectBitmap (1879115345, 285541376, ... ) == 0x185000f 01908 1356 NtGdiGetDCforBitmap (285541376, ... ) == 0x70010651 01909 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01910 1356 NtGdiSelectBitmap (1879115345, 285541376, ... ) == 0x11050400 01911 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01912 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01913 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 16, 0, 0, 0, 16, 1953913504, 1358040, 0, 128, 104, 1, 0, ... ) == 0x10 01914 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01915 1356 NtGdiSelectBitmap (1879115345, 285541376, ... ) == 0x11050400 01916 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01917 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x11050400 01918 1356 NtUserGetDC (0, ... ) == 0x1010053 01919 1356 NtGdiCreateDIBitmapInternal (16842835, 16, 32, 2, 0, 2118583256, 0, 48, 0, 0, 0, ... ) == 0x100503fb 01920 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 01921 1356 NtGdiSelectBitmap (1879115345, 268764155, ... ) == 0x185000f 01922 1356 NtGdiGetDCforBitmap (268764155, ... ) == 0x70010651 01923 1356 NtGdiSaveDC (1879115345, ... ) == 0x1 01924 1356 NtGdiSelectBitmap (1879115345, 268764155, ... ) == 0x100503fb 01925 1356 NtGdiGetDCObject (1879115345, 524288, ... ) == 0x188000b 01926 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01927 1356 NtGdiSetDIBitsToDeviceInternal (1879115345, 0, 0, 16, 32, 0, 0, 0, 32, 1953913568, 1358040, 0, 128, 48, 1, 0, ... ) == 0x20 01928 1356 NtUserSelectPalette (1879115345, 25690123, 0, ... ) == 0x188000b 01929 1356 NtGdiSelectBitmap (1879115345, 268764155, ... ) == 0x100503fb 01930 1356 NtGdiRestoreDC (1879115345, -1, ... ) == 0x1 01931 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x100503fb 01932 1356 NtGdiCreateCompatibleDC (1879115345, ... ) == 0x1060c 01933 1356 NtGdiExtGetObjectW (268764155, 24, 1239416, ... ) == 0x18 01934 1356 NtGdiCreateBitmap (16, 32, 1, 1, 0, ... ) == 0xc10506b1 01935 1356 NtGdiSelectBitmap (1879115345, 268764155, ... ) == 0x185000f 01936 1356 NtGdiSelectBitmap (67084, -1056635215, ... ) == 0x185000f 01937 1356 NtGdiBitBlt (67084, 0, 0, 16, 32, 1879115345, 0, 0, 13369376, -1, 0, ... ) == 0x1 01938 1356 NtGdiSelectBitmap (1879115345, 25493519, ... ) == 0x100503fb 01939 1356 NtGdiSelectBitmap (67084, 25493519, ... ) == 0xc10506b1 01940 1356 NtGdiDeleteObjectApp (268764155, ... ) == 0x1 01941 1356 NtGdiDeleteObjectApp (67084, ... ) == 0x1 01942 1356 NtUserCallOneParam (0, 33, ... ) == 0x800c9 01943 1356 NtUserSetCursorIconData (524489, 1239464, 1239480, 1239544, ... ) == 0x1 01944 1356 NtUserGetIconInfo (524489, 1240816, 0, 0, 0, 0, ... ) == 0x1 01945 1356 NtGdiExtGetObjectW (302318590, 24, 1240740, ... ) == 0x18 01946 1356 NtGdiExtGetObjectW (33883660, 24, 1240716, ... ) == 0x18 01947 1356 NtGdiDeleteObjectApp (302318590, ... ) == 0x1 01948 1356 NtGdiDeleteObjectApp (33883660, ... ) == 0x1 01949 1356 NtUserGetIconInfo (524489, 1240812, 0, 0, 0, 0, ... ) == 0x1 01950 1356 NtGdiExtGetObjectW (319095806, 24, 1240728, ... ) == 0x18 01951 1356 NtGdiExtGetObjectW (50660876, 24, 1240704, ... ) == 0x18 01952 1356 NtGdiGetBitmapBits (319095806, 1024, 1358520, ... ) == 0x400 01953 1356 NtGdiGetBitmapBits (50660876, 32, 1359544, ... ) == 0x20 01954 1356 NtGdiDeleteObjectApp (319095806, ... ) == 0x1 01955 1356 NtGdiDeleteObjectApp (50660876, ... ) == 0x1 01956 1356 NtUserDestroyCursor (524489, 1, ... ) == 0x1 01957 1356 NtWaitForSingleObject (108, 0, {-50000000, -1}, ... ) == 0x0 01958 1356 NtReleaseMutant (108, ... 0x0, ) == 0x0 01959 1356 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "MSCTF.SendReceive.Event.ENG.IC"}, ... 112, ) }, ... 112, ) == 0x0 01960 1356 NtSetEvent (112, ... 0x0, ) == 0x0 01961 1356 NtClose (124, ... ) == 0x0 01962 1356 NtClose (112, ... ) == 0x0 01963 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 01964 1356 NtUserWaitMessage (... ) == 0x1 01965 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x60128, WM_KEYFIRST, 0x20, 0x0, 0x129cd1f, {0, 0}}, ) == 0x1 01966 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01967 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01968 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01969 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01970 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01971 1356 NtUserTranslateMessage (1242200, 0, ... ) == 0x1 01972 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01973 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01974 1356 NtUserSetCapture (393512, ... ) == 0x0 01975 1356 NtUserSetFocus (393512, ... ) == 0x60128 01976 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01977 1356 NtUserGetDC (393512, ... ) == 0x1010052 01978 1356 NtUserGetControlBrush (0x60128, 16842834, 309, ... ) == 0x1100056 01979 1356 NtGdiIntersectClipRect (16842834, 0, 0, 75, 23, ... ) == 0x3 01980 1356 NtGdiIntersectClipRect (16842834, 3, 3, 72, 20, ... ) == 0x3 01981 1356 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01982 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x60128, WM_CHAR, 0x20, 0x0, 0x129cd1f, {0, 0}}, ) == 0x1 01983 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01984 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01985 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01986 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01987 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01988 1356 NtUserPeekMessage (0, 0, 0, 1, ... {0x60128, WM_KEYFIRST, 0xd, 0x0, 0x129cd1f, {0, 0}}, ) == 0x1 01989 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 01990 1356 NtUserCallMsgFilter (1242108, 0, ... ) == 0x0 01991 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01992 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01993 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01994 1356 NtUserGetThreadState (0, ... ) == 0x60128 01995 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01996 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01997 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01998 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 01999 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02000 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02001 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02002 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02003 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02004 1356 NtUserGetThreadState (1, ... ) == 0x80144 02005 1356 NtUserGetThreadState (0, ... ) == 0x60128 02006 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02007 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02008 1356 NtUserSetFocus (524612, ... 02009 1356 NtUserPostThreadMessage (1356, 49313, 17, 524612, ... ) == 0x1 02010 1356 NtUserGetDC (393512, ... ) == 0x1010052 02011 1356 NtUserGetControlBrush (0x60128, 16842834, 309, ... ) == 0x1100056 02012 1356 NtGdiIntersectClipRect (16842834, 0, 0, 75, 23, ... ) == 0x3 02013 1356 NtGdiIntersectClipRect (16842834, 3, 3, 72, 20, ... ) == 0x3 02014 1356 NtUserCallOneParam (16842834, 57, ... ) == 0x1 02015 1356 NtUserCallNoParam (13, ... ) == 0x1 02016 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02017 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02018 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02019 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02020 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02021 1356 NtUserGetThreadState (1, ... ) == 0x80144 02022 1356 NtUserGetThreadState (0, ... ) == 0x80144 02023 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02024 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02025 1356 NtUserSetWindowPos (524612, 0, 0, 0, 0, 0, 151, ... 02026 1356 NtUserInternalGetWindowText (0x80144, 260, ... (0x80144, 260, ... "Error", ) , ) == 0x5 02027 1356 NtUserGetWindowDC (524612, ... ) == 0x1010053 02028 1356 NtGdiGetRandomRgn (16842835, -1190918219, 1, ... ) == 0x0 02029 1356 NtGdiIntersectClipRect (16842835, 0, 0, 0, 0, ... ) == 0x3 02030 1356 NtGdiGetCharSet (16842835, ... ) == 0x4e4 02031 1356 NtGdiExtSelectClipRgn (16842835, 0, 5, ... ) == 0x1 02032 1356 NtUserCallOneParam (16842835, 57, ... ) == 0x1 02033 1356 NtUserCalcMenuBar (524612, 3, 3, 29, 8661352, ... ) == 0x0 02034 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 1239032, 690, 0, ... 02035 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x2, 0x0, 0, 670, 0, ... ) == 0x0 02034 1356 NtUserMessageCall ... ) == 0x0 02036 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 1239032, 690, 0, ... 02037 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x0, 0x0, 0, 670, 0, ... ) == 0x0 02036 1356 NtUserMessageCall ... ) == 0x0 02038 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 1239032, 690, 0, ... 02039 1356 NtUserMessageCall (0x80144, WM_GETICON, 0x1, 0x0, 0, 670, 0, ... ) == 0x0 02038 1356 NtUserMessageCall ... ) == 0x0 02040 1356 NtUserGetTitleBarInfo (524612, 1239664, ... ) == 0x1 02041 1356 NtUserBuildHwndList (0, 524612, 1, 0, 64, ... (0x60128, 0x1100f0, 0x60130, 0x1, ), 4, ) == 0x0 02042 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02043 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02044 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02045 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 02046 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 02047 1356 NtUserValidateHandleSecure (1114352, ... ) == 0x1 02048 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 02049 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 02050 1356 NtUserValidateHandleSecure (393520, ... ) == 0x1 02025 1356 NtUserSetWindowPos ... ) == 0x1 02051 1356 NtUserGetThreadState (1, ... ) == 0x80144 02052 1356 NtUserCallNoParam (15, ... ) == 0xbc660168 02053 1356 NtUserPostMessage (524612, 0, 0, 0, ... ) == 0x1 02054 1356 NtUserInvalidateRect (393512, 0, 0, ... ) == 0x1 02055 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02056 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02057 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 02058 1356 NtUserCallOneParam (0, 40, ... ) == 0x4090409 02059 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02060 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02061 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02062 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02063 1356 NtUserQueryWindow (393512, 7, ... ) == 0x1000a4 02064 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02065 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02066 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02067 1356 NtUserKillTimer (393518, 1, ... ) == 0x0 02068 1356 NtUserSetTimer (393518, 1, 300, 0, ... ) == 0x1 02069 1356 NtUserCallNoParam (7, ... ) == 0x1 02070 1356 NtUserQueryWindow (1048740, 3, ... ) == 0x0 02071 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02072 1356 NtUserQueryWindow (1048740, 2, ... ) == 0x0 02073 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02074 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02075 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02076 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02077 1356 NtUserQueryWindow (393512, 7, ... ) == 0x1000a4 02078 1356 NtUserValidateHandleSecure (393512, ... ) == 0x1 02079 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02080 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02008 1356 NtUserSetFocus ... ) == 0x60128 02081 1356 NtUserSetWindowPos (524612, 0, 0, 0, 0, 0, 151, ... ) == 0x1 02082 1356 NtUserGetThreadState (1, ... ) == 0x0 02083 1356 NtUserPostMessage (524612, 0, 0, 0, ... ) == 0x1 02084 1356 NtUserDestroyWindow (524612, ... 02085 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02086 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02087 1356 NtUserGetThreadState (0, ... ) == 0x0 02088 1356 NtUserBuildHwndList (0, 0, 0, 1356, 64, ... (0x80144, 0x6012e, 0x1000a4, 0x1, ), 4, ) == 0x0 02089 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02090 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02091 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02092 1356 NtUserValidateHandleSecure (1048740, ... ) == 0x1 02093 1356 NtUserValidateHandleSecure (1048740, ... ) == 0x1 02094 1356 NtUserValidateHandleSecure (1048740, ... ) == 0x1 02095 1356 NtUserCallOneParam (8, 43, ... ) == 0x80008 02096 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02097 1356 NtUserPeekMessage (1179914, 0, 0, 9961475, ... {0x7e470254, WM_USER+0x148588, 0x145540, 0x80144, 0x0, {2118223026, 2118313942}}, ) == 0x0 02098 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02099 1356 NtUserPeekMessage (0, 49313, 49313, 9961475, ... {0x0, WM_USER+0xbca1, 0x11, 0x80144, 0x129cd1f, {0, 0}}, ) == 0x1 02100 1356 NtUserPeekMessage (0, 49313, 49313, 9961475, ... {0x0, WM_USER+0xbca1, 0x11, 0x80144, 0x129cd1f, {0, 0}}, ) == 0x0 02101 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02102 1356 NtUserPeekMessage (0, 49318, 49318, 9961475, ... {0x0, WM_USER+0xbca1, 0x11, 0x80144, 0x129cd1f, {0, 0}}, ) == 0x0 02103 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02104 1356 NtUserPeekMessage (0, 49319, 49319, 9961475, ... {0x0, WM_USER+0xbca1, 0x11, 0x80144, 0x129cd1f, {0, 0}}, ) == 0x0 02105 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02106 1356 NtUserPeekMessage (0, 49321, 49321, 9961475, ... {0x0, WM_USER+0xbca1, 0x11, 0x80144, 0x129cd1f, {0, 0}}, ) == 0x0 02107 1356 NtUserBuildHwndList (0, 0, 0, 1356, 64, ... (0x80144, 0x6012e, 0x1000a4, 0x1, ), 4, ) == 0x0 02108 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02109 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02110 1356 NtUserDestroyCursor (65545, 1, ... ) == 0x1 02111 1356 NtUserValidateHandleSecure (1048740, ... ) == 0x1 02112 1356 NtUserValidateHandleSecure (1048740, ... ) == 0x1 02113 1356 NtUserGetThreadState (0, ... ) == 0x0 02114 1356 NtUserBuildHwndList (0, 0, 0, 1356, 64, ... (0x80144, 0x6012e, 0x1000a4, 0x1, ), 4, ) == 0x0 02115 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02116 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02117 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02118 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02119 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02120 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02121 1356 NtUserValidateHandleSecure (1048740, ... ) == 0x1 02122 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02123 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02124 1356 NtUserPeekMessage (1179914, 0, 0, 9961475, ... {0x7e470254, WM_USER+0x148588, 0x145540, 0x1000a4, 0x0, {2118223026, 2118313942}}, ) == 0x0 02125 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02126 1356 NtUserPeekMessage (0, 49313, 49313, 9961475, ... {0x7e470254, WM_USER+0x148588, 0x145540, 0x1000a4, 0x0, {2118223026, 2118313942}}, ) == 0x0 02127 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02128 1356 NtUserPeekMessage (0, 49318, 49318, 9961475, ... {0x7e470254, WM_USER+0x148588, 0x145540, 0x1000a4, 0x0, {2118223026, 2118313942}}, ) == 0x0 02129 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02130 1356 NtUserPeekMessage (0, 49319, 49319, 9961475, ... {0x7e470254, WM_USER+0x148588, 0x145540, 0x1000a4, 0x0, {2118223026, 2118313942}}, ) == 0x0 02131 1356 NtUserCallOneParam (8, 43, ... ) == 0x80000 02132 1356 NtUserPeekMessage (0, 49321, 49321, 9961475, ... {0x7e470254, WM_USER+0x148588, 0x145540, 0x1000a4, 0x0, {2118223026, 2118313942}}, ) == 0x0 02133 1356 NtUserBuildHwndList (0, 0, 0, 1356, 64, ... (0x80144, 0x6012e, 0x1000a4, 0x1, ), 4, ) == 0x0 02134 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02135 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02136 1356 NtUserValidateHandleSecure (393518, ... ) == 0x1 02137 1356 NtUserBuildHwndList (0, 0, 0, 1356, 64, ... (0x80144, 0x6012e, 0x1000a4, 0x1, ), 4, ) == 0x0 02138 1356 NtUserValidateHandleSecure (524612, ... ) == 0x1 02139 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02140 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02141 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02142 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02143 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02144 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02145 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02146 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02147 1356 NtUserSetWindowLong (393518, 4, 0, 1, ... ) == 0x147680 02148 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02149 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02150 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02151 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02152 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02153 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02154 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02155 1356 NtUserValidateHandleSecure (0, ... ) == 0x0 02156 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02157 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02158 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02159 1356 NtUserKillTimer (0, 0, ... ) == 0x0 02160 1356 NtUserRemoveProp (393518, 43288, ... ) == 0xffffffff 02161 1356 NtUserRemoveProp (393518, 43282, ... ) == 0x0 02162 1356 NtUserRemoveProp (393518, 43287, ... ) == 0x0 02163 1356 NtUserBuildHwndList (0, 0, 0, 1356, 64, ... (0x80144, 0x1000a4, 0x1, ), 3, ) == 0x0 02164 1356 NtUserValidateHandleSecure (393518, ... ) == 0x0 02165 1356 NtUserSetWindowFNID (1048740, 16384, ... ) == 0x1 02166 1356 NtUserRemoveProp (1048740, 43288, ... ) == 0xffffffff 02167 1356 NtUserRemoveProp (1048740, 43282, ... ) == 0x0 02168 1356 NtUserRemoveProp (1048740, 43287, ... ) == 0x0 02169 1356 NtUserSetWindowFNID (393512, 16384, ... ) == 0x1 02170 1356 NtUserRemoveProp (393512, 43288, ... ) == 0xffffffff 02171 1356 NtUserRemoveProp (393512, 43282, ... ) == 0x0 02172 1356 NtUserRemoveProp (393512, 43287, ... ) == 0x0 02173 1356 NtUserSetWindowFNID (1114352, 16384, ... ) == 0x1 02174 1356 NtUserRemoveProp (1114352, 43288, ... ) == 0xffffffff 02175 1356 NtUserRemoveProp (1114352, 43282, ... ) == 0x0 02176 1356 NtUserRemoveProp (1114352, 43287, ... ) == 0x0 02177 1356 NtUserSetWindowFNID (393520, 16384, ... ) == 0x1 02178 1356 NtUserRemoveProp (393520, 43288, ... ) == 0xffffffff 02179 1356 NtUserRemoveProp (393520, 43282, ... ) == 0x0 02180 1356 NtUserRemoveProp (393520, 43287, ... ) == 0x0 02181 1356 NtUserSetThreadState (0, 16384, ... ) == 0x81734078 02182 1356 NtGdiDeleteObjectApp (856295068, ... ) == 0x1 02183 1356 NtUserCallHwndParam (524612, 0, 79, ... ) == 0x0 02184 1356 NtUserRemoveProp (524612, 43285, ... ) == 0x0 02185 1356 NtUserRemoveProp (524612, 43288, ... ) == 0x8428b0 02186 1356 NtGdiDeleteObjectApp (1996752234, ... ) == 0x1 02187 1356 NtUserRemoveProp (524612, 43282, ... ) == 0x0 02188 1356 NtUserRemoveProp (524612, 43287, ... ) == 0x0 02084 1356 NtUserDestroyWindow ... ) == 0x1 02189 1356 NtUserSetCursor (65557, ... ) == 0x10015 02190 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1242580, (0x80100080, {24, 0, 0x40, 0, 1242580, "\??\u:\work\packed.exe"}, 0x0, 0, 1, 1, 2097252, 0, 0, ... 112, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 2097252, 0, 0, ... 112, {status=0x0, info=1}, ) == 0x0 02191 1356 NtQueryInformationFile (112, 1243016, 8, AttributeFlag, ... {status=0x0, info=8}, ) == 0x0 02192 1356 NtQueryInformationFile (112, 1242932, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02193 1356 NtQueryInformationFile (112, 1242748, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02194 1356 NtQueryInformationFile (112, 1353208, 4094, Stream, ... {status=0x0, info=38}, ) == 0x0 02195 1356 NtQueryInformationFile (112, 1241196, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02196 1356 NtQueryInformationFile (112, 1241472, 4, Ea, ... {status=0x0, info=4}, ) == 0x0 02197 1356 NtCreateFile (0x40110080, {24, 0, 0x40, 0, 1241348, (0x40110080, {24, 0, 0x40, 0, 1241348, "\??\C:\WINDOWS\system32\upu.exe"}, 0x0, 32, 0, 5, 100, 0, 0, ... }, 0x0, 32, 0, 5, 100, 0, 0, ... 02198 1356 NtClose (-2147482644, ... ) == 0x0 02197 1356 NtCreateFile ... 124, {status=0x0, info=2}, ) == 0x0 02199 1356 NtQueryVolumeInformationFile (124, 1241500, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 02200 1356 NtQueryInformationFile (124, 1241084, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02201 1356 NtQueryVolumeInformationFile (112, 1241500, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 02202 1356 NtSetInformationFile (124, 1241400, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 02203 1356 NtCreateSection (0xf001f, 0x0, 0x0, 2, 134217728, 112, ... 120, ) == 0x0 02204 1356 NtMapViewOfSection (120, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x990000), {0, 0}, 40960, ) == 0x0 02205 1356 NtClose (120, ... ) == 0x0 02206 1356 NtWriteFile (124, 0, 0, 0, (124, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0PE\0\0L\1\2\0FSG!\0\0\0\0\0\0\0\0\340\0\17\1\13\1\0\0\0\12\0\0\0\232\0\0\0\0\0\0]l\1\0\0\20\0\0\14\0\0\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0p\1\0\0\2\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0"m\1\04\0\0\0\0\320\0\0H\227\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0t\0\0\0\0\300\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300\0\0\0\0a\0\0\0\0\240\0\0\0\320\0\0V\235\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300KERNEL32.dll\0\0\0LoadLibraryA\0\0GetProcAddress\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30mA\0\14mA\0\16mA\0\230\1@\0\0\20@\0\14fA\0\1 @\0\10@\0\0\0\0\0\316\26@\0\1\0\0\0JmA\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 40800, 0x0, 0, ... {status=0x0, info=40800}, ) m\1\04\0\0\0\0\320\0\0H\227\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0t\0\0\0\0\300\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300\0\0\0\0a\0\0\0\0\240\0\0\0\320\0\0V\235\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300KERNEL32.dll\0\0\0LoadLibraryA\0\0GetProcAddress\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30mA\0\14mA\0\16mA\0\230\1@\0\0\20@\0\14fA\0\1 @\0\10@\0\0\0\0\0\316\26@\0\1\0\0\0JmA\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 40800, 0x0, 0, ... {status=0x0, info=40800}, ) == 0x0 02207 1356 NtUnmapViewOfSection (-1, 0x990000, ... ) == 0x0 02208 1356 NtSetInformationFile (124, 1242748, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02209 1356 NtClose (112, ... ) == 0x0 02210 1356 NtClose (124, ... ) == 0x0 02211 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1243640, ... ) }, 1243640, ... ) == 0x0 02212 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1242608, ... ) }, 1242608, ... ) == 0x0 02213 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1241380, ... ) }, 1241380, ... ) == 0x0 02214 1356 NtAllocateVirtualMemory (-1, 1376256, 0, 16384, 4096, 4, ... 1376256, 16384, ) == 0x0 02215 1356 NtAllocateVirtualMemory (-1, 1392640, 0, 24576, 4096, 4, ... 1392640, 24576, ) == 0x0 02216 1356 NtQueryDefaultLocale (1, 1243632, ... ) == 0x0 02217 1356 NtQueryDefaultLocale (1, 1243632, ... ) == 0x0 02218 1356 NtQueryDefaultLocale (0, 1243628, ... ) == 0x0 02219 1356 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1243676, (0xc0100080, {24, 0, 0x40, 0, 1243676, "\??\C:\WINDOWS\system32\setupex.exe"}, 0x0, 128, 0, 5, 96, 0, 0, ... }, 0x0, 128, 0, 5, 96, 0, 0, ... 02220 1356 NtClose (-2147482644, ... ) == 0x0 02219 1356 NtCreateFile ... 124, {status=0x0, info=2}, ) == 0x0 02221 1356 NtWriteFile (124, 0, 0, 0, (124, 0, 0, 0, "MZP\0\2\0\0\0\4\0\17\0PE\0\0L\1\2\0FSG!\0\0\0\0\0\0\0\0\340\0\216\201\13\1\0\0\0B\0\0\0n\0\0\0\0\0\0Z/\1\0\0\20\0\0\14\0\0\0\0\0@\0\0\20\0\0\0\2\0\0\1\0\0\0\0\0\0\0\3\0\12\0\0\0\0\0\0@\1\0\0\2\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0 \0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\370\1\04\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\320\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300\0\0\0\0\0\0\0\0\0`\0\0\0\340\0\0SP\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300KERNEL32.dll\0\0\0LoadLibraryA\0\0GetProcAddress\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\250A\0\110A\0\130A\0\230\1@\0\0\20@\0\0\340@\0\1`@\0\1\320@\0\0\0\0\0\4\304@\0\1\0\0\0G0A\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 21088, 0x0, 0, ... , 21088, 0x0, 0, ... 02222 1356 NtContinue (-140694060, 0, ... 02221 1356 NtWriteFile ... {status=0x0, info=21088}, ) == 0x0 02223 1356 NtClose (124, ... ) == 0x0 02224 1356 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 02225 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe"}, 1239968, ... ) }, 1239968, ... ) == 0x0 02226 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe"}, 1240704, ... ) }, 1240704, ... ) == 0x0 02227 1356 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe"}, 5, 96, ... 124, {status=0x0, info=1}, ) }, 5, 96, ... 124, {status=0x0, info=1}, ) == 0x0 02228 1356 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 124, ... 112, ) == 0x0 02229 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02230 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 120, ) }, ... 120, ) == 0x0 02231 1356 NtQueryValueKey (120, (120, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02232 1356 NtClose (120, ... ) == 0x0 02233 1356 NtQueryVolumeInformationFile (124, 1239980, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02234 1356 NtWaitForSingleObject (92, 0, {-1000000, -1}, ... ) == 0x0 02235 1356 NtReleaseMutant (92, ... 0x0, ) == 0x0 02236 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1237912, ... ) }, 1237912, ... ) == 0x0 02237 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 120, {status=0x0, info=1}, ) }, 5, 96, ... 120, {status=0x0, info=1}, ) == 0x0 02238 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 120, ... 128, ) == 0x0 02239 1356 NtClose (120, ... ) == 0x0 02240 1356 NtMapViewOfSection (128, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa20000), 0x0, 126976, ) == 0x0 02241 1356 NtClose (128, ... ) == 0x0 02242 1356 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 02243 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1238220, ... ) }, 1238220, ... ) == 0x0 02244 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 128, {status=0x0, info=1}, ) }, 5, 96, ... 128, {status=0x0, info=1}, ) == 0x0 02245 1356 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 128, ... 120, ) == 0x0 02246 1356 NtQuerySection (120, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02247 1356 NtClose (128, ... ) == 0x0 02248 1356 NtMapViewOfSection (120, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 02249 1356 NtClose (120, ... ) == 0x0 02250 1356 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 02251 1356 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 02252 1356 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 02253 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02254 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 120, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 120, {status=0x0, info=1}, ) == 0x0 02255 1356 NtQueryInformationFile (120, 1238236, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02256 1356 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 120, ... 128, ) == 0x0 02257 1356 NtMapViewOfSection (128, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa20000), 0x0, 1191936, ) == 0x0 02258 1356 NtQueryInformationFile (120, 1238336, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02259 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02260 1356 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02261 1356 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 02262 1356 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02263 1356 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 104, ) }, ... 104, ) == 0x0 02264 1356 NtQueryValueKey (104, (104, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (104, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02265 1356 NtClose (104, ... ) == 0x0 02266 1356 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02267 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02268 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235932, 616, BothDirectory, 1, (104, 0, 0, 0, 1235932, 616, BothDirectory, 1, "setupex.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02269 1356 NtClose (104, ... ) == 0x0 02270 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02271 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02272 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe"}, 1236308, ... ) }, 1236308, ... ) == 0x0 02273 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02274 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02275 1356 NtClose (104, ... ) == 0x0 02276 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02277 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02278 1356 NtClose (104, ... ) == 0x0 02279 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02280 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, "setupex.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02281 1356 NtClose (104, ... ) == 0x0 02282 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02283 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02284 1356 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02285 1356 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02286 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02287 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 104, ) == 0x0 02288 1356 NtQueryInformationToken (104, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02289 1356 NtClose (104, ... ) == 0x0 02290 1356 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02291 1356 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\setupex.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02292 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02293 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02294 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe"}, 1237560, ... ) }, 1237560, ... ) == 0x0 02295 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02296 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02297 1356 NtClose (104, ... ) == 0x0 02298 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02299 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02300 1356 NtClose (104, ... ) == 0x0 02301 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02302 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, "setupex.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02303 1356 NtClose (104, ... ) == 0x0 02304 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02305 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02306 1356 NtWaitForSingleObject (92, 0, {-1000000, -1}, ... ) == 0x0 02307 1356 NtQueryVolumeInformationFile (124, 1238216, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02308 1356 NtQueryInformationFile (124, 1238196, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02309 1356 NtQueryInformationFile (124, 1238236, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02310 1356 NtReleaseMutant (92, ... 0x0, ) == 0x0 02311 1356 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 02312 1356 NtClose (128, ... ) == 0x0 02313 1356 NtClose (120, ... ) == 0x0 02314 1356 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 02315 1356 NtOpenProcessToken (-1, 0xa, ... 120, ) == 0x0 02316 1356 NtQueryInformationToken (120, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 02317 1356 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02318 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 128, ) }, ... 128, ) == 0x0 02319 1356 NtQueryValueKey (128, (128, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (128, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02320 1356 NtQueryValueKey (128, (128, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (128, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02321 1356 NtClose (128, ... ) == 0x0 02322 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02323 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 128, ) }, ... 128, ) == 0x0 02324 1356 NtQueryValueKey (128, (128, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02325 1356 NtClose (128, ... ) == 0x0 02326 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02327 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02328 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02329 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02330 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02331 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02332 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02333 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02334 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02335 1356 NtQueryDefaultLocale (1, 1239408, ... ) == 0x0 02336 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 128, ) }, ... 128, ) == 0x0 02337 1356 NtEnumerateKey (128, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (128, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 02338 1356 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 104, ) }, ... 104, ) == 0x0 02339 1356 NtQueryValueKey (104, (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 02340 1356 NtQueryValueKey (104, (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02341 1356 NtClose (104, ... ) == 0x0 02342 1356 NtEnumerateKey (128, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02343 1356 NtClose (128, ... ) == 0x0 02344 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... 128, ) }, ... 128, ) == 0x0 02345 1356 NtEnumerateKey (128, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (128, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, 92, ) }, 92, ) == 0x0 02346 1356 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, ... 104, ) }, ... 104, ) == 0x0 02347 1356 NtQueryValueKey (104, (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) }, 28, ) == 0x0 02348 1356 NtQueryValueKey (104, (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02349 1356 NtQueryValueKey (104, (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02350 1356 NtQueryValueKey (104, (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02351 1356 NtClose (104, ... ) == 0x0 02352 1356 NtEnumerateKey (128, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (128, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, 92, ) }, 92, ) == 0x0 02353 1356 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, ... 104, ) }, ... 104, ) == 0x0 02354 1356 NtQueryValueKey (104, (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) }, 28, ) == 0x0 02355 1356 NtQueryValueKey (104, (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02356 1356 NtQueryValueKey (104, (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02357 1356 NtQueryValueKey (104, (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02358 1356 NtClose (104, ... ) == 0x0 02359 1356 NtEnumerateKey (128, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (128, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, 92, ) }, 92, ) == 0x0 02360 1356 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, ... 104, ) }, ... 104, ) == 0x0 02361 1356 NtQueryValueKey (104, (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) }, 28, ) == 0x0 02362 1356 NtQueryValueKey (104, (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02363 1356 NtQueryValueKey (104, (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02364 1356 NtQueryValueKey (104, (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02365 1356 NtClose (104, ... ) == 0x0 02366 1356 NtEnumerateKey (128, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (128, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, 92, ) }, 92, ) == 0x0 02367 1356 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, ... 104, ) }, ... 104, ) == 0x0 02368 1356 NtQueryValueKey (104, (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) }, 28, ) == 0x0 02369 1356 NtQueryValueKey (104, (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02370 1356 NtQueryValueKey (104, (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02371 1356 NtQueryValueKey (104, (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02372 1356 NtClose (104, ... ) == 0x0 02373 1356 NtEnumerateKey (128, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (128, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, 92, ) }, 92, ) == 0x0 02374 1356 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, ... 104, ) }, ... 104, ) == 0x0 02375 1356 NtQueryValueKey (104, (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (104, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) \300\36\200"}, 28, ) == 0x0 02376 1356 NtQueryValueKey (104, (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02377 1356 NtQueryValueKey (104, (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (104, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02378 1356 NtQueryValueKey (104, (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (104, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02379 1356 NtClose (104, ... ) == 0x0 02380 1356 NtEnumerateKey (128, 5, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02381 1356 NtClose (128, ... ) == 0x0 02382 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02383 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02384 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02385 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02386 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02387 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02388 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02389 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02390 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02391 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02392 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02393 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02394 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02395 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02396 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02397 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02398 1356 NtClose (128, ... ) == 0x0 02399 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02400 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02401 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02402 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02403 1356 NtClose (128, ... ) == 0x0 02404 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02405 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02406 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02407 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02408 1356 NtClose (128, ... ) == 0x0 02409 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02410 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02411 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02412 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02413 1356 NtClose (128, ... ) == 0x0 02414 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02415 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02416 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02417 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02418 1356 NtClose (128, ... ) == 0x0 02419 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02420 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02421 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02422 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02423 1356 NtClose (128, ... ) == 0x0 02424 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02425 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02426 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02427 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02428 1356 NtClose (128, ... ) == 0x0 02429 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02430 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02431 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02432 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02433 1356 NtClose (128, ... ) == 0x0 02434 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02435 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02436 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02437 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02438 1356 NtClose (128, ... ) == 0x0 02439 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02440 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02441 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02442 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02443 1356 NtClose (128, ... ) == 0x0 02444 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02445 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02446 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02447 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02448 1356 NtClose (128, ... ) == 0x0 02449 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02450 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02451 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02452 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02453 1356 NtClose (128, ... ) == 0x0 02454 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02455 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02456 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02457 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02458 1356 NtClose (128, ... ) == 0x0 02459 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02460 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02461 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02462 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02463 1356 NtClose (128, ... ) == 0x0 02464 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02465 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02466 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02467 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02468 1356 NtClose (128, ... ) == 0x0 02469 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02470 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 128, ) }, ... 128, ) == 0x0 02471 1356 NtQueryValueKey (128, (128, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (128, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (128, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 02472 1356 NtClose (128, ... ) == 0x0 02473 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02474 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 02475 1356 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02476 1356 NtClose (128, ... ) == 0x0 02477 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02478 1356 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 02479 1356 NtOpenProcessToken (-1, 0xa, ... 128, ) == 0x0 02480 1356 NtDuplicateToken (128, 0xc, {24, 0, 0x0, 0, 1239840, 0x0}, 0, 2, ... 104, ) == 0x0 02481 1356 NtClose (128, ... ) == 0x0 02482 1356 NtAccessCheck (1363240, 104, 0x1, 1239916, 1239968, 56, 1239948, ... (0x1), ) == 0x0 02483 1356 NtClose (104, ... ) == 0x0 02484 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 104, ) }, ... 104, ) == 0x0 02485 1356 NtQueryValueKey (104, (104, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (104, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02486 1356 NtClose (104, ... ) == 0x0 02487 1356 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 104, ) }, ... 104, ) == 0x0 02488 1356 NtQuerySymbolicLinkObject (104, ... (104, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 02489 1356 NtClose (104, ... ) == 0x0 02490 1356 NtQueryVolumeInformationFile (124, 1237672, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02491 1356 NtQueryInformationFile (124, 1237788, 528, Name, ... {status=0x0, info=62}, ) == 0x0 02492 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02493 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02494 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe"}, 1236960, ... ) }, 1236960, ... ) == 0x0 02495 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02496 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236388, 616, BothDirectory, 1, (104, 0, 0, 0, 1236388, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02497 1356 NtClose (104, ... ) == 0x0 02498 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02499 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236388, 616, BothDirectory, 1, (104, 0, 0, 0, 1236388, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02500 1356 NtClose (104, ... ) == 0x0 02501 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02502 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236388, 616, BothDirectory, 1, (104, 0, 0, 0, 1236388, 616, BothDirectory, 1, "setupex.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02503 1356 NtClose (104, ... ) == 0x0 02504 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02505 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02506 1356 NtQueryInformationFile (124, 1239828, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02507 1356 NtCreateSection (0xf0005, 0x0, {21088, 0}, 2, 134217728, 124, ... 104, ) == 0x0 02508 1356 NtMapViewOfSection (104, -1, (0x0), 0, 0, {0, 0}, 21088, 1, 0, 2, ... (0x990000), {0, 0}, 24576, ) == 0x0 02509 1356 NtClose (104, ... ) == 0x0 02510 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02511 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 104, ) == 0x0 02512 1356 NtQueryInformationToken (104, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02513 1356 NtClose (104, ... ) == 0x0 02514 1356 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 104, ) }, ... 104, ) == 0x0 02515 1356 NtOpenKey (0x20019, {24, 104, 0x40, 0, 0, (0x20019, {24, 104, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 128, ) }, ... 128, ) == 0x0 02516 1356 NtClose (104, ... ) == 0x0 02517 1356 NtQueryValueKey (128, (128, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02518 1356 NtQueryValueKey (128, (128, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) , Partial, 174, ... TitleIdx=0, Type=1, Data= (128, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) }, 174, ) == 0x0 02519 1356 NtClose (128, ... ) == 0x0 02520 1356 NtUnmapViewOfSection (-1, 0x990000, ... ) == 0x0 02521 1356 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 10027008, 4096, ) == 0x0 02522 1356 NtAllocateVirtualMemory (-1, 10027008, 0, 4096, 4096, 4, ... 10027008, 4096, ) == 0x0 02523 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 128, ) }, ... 128, ) == 0x0 02524 1356 NtQueryValueKey (128, (128, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02525 1356 NtClose (128, ... ) == 0x0 02526 1356 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02527 1356 NtQueryInformationToken (120, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 02528 1356 NtQueryInformationToken (120, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 02529 1356 NtClose (120, ... ) == 0x0 02530 1356 NtQuerySection (112, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02531 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setupex.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02532 1356 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0 02533 1356 NtCreateProcessEx (1241752, 2035711, 0, -1, 0, 112, 0, 0, 0, ... ) == 0x0 02534 1356 NtQueryInformationProcess (120, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffde000,AffinityMask=0x1,BasePriority=8,Pid=336,ParentPid=220,}, 0x0, ) == 0x0 02535 1356 NtReadVirtualMemory (120, 0x7ffde008, 4, ... (120, 0x7ffde008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 02536 1356 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\setupex.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02537 1356 NtReadVirtualMemory (120, 0x400000, 4096, ... (120, 0x400000, 4096, ... "MZP\0\2\0\0\0\4\0\17\0PE\0\0L\1\2\0FSG!\0\0\0\0\0\0\0\0\340\0\216\201\13\1\0\0\0B\0\0\0n\0\0\0\0\0\0Z/\1\0\0\20\0\0\14\0\0\0\0\0@\0\0\20\0\0\0\2\0\0\1\0\0\0\0\0\0\0\3\0\12\0\0\0\0\0\0@\1\0\0\2\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0 \0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\370\1\04\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\320\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300\0\0\0\0\0\0\0\0\0`\0\0\0\340\0\0SP\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300KERNEL32.dll\0\0\0LoadLibraryA\0\0GetProcAddress\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\250A\0\110A\0\130A\0\230\1@\0\0\20@\0\0\340@\0\1`@\0\1\320@\0\0\0\0\0\4\304@\0\1\0\0\0G0A\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 4096, ) , 4096, ) == 0x0 02538 1356 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02539 1356 NtQueryInformationProcess (120, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffde000,AffinityMask=0x1,BasePriority=8,Pid=336,ParentPid=220,}, 0x0, ) == 0x0 02540 1356 NtAllocateVirtualMemory (-1, 0, 0, 2420, 4096, 4, ... 10616832, 4096, ) == 0x0 02541 1356 NtAllocateVirtualMemory (120, 0, 0, 6432, 4096, 4, ... 65536, 8192, ) == 0x0 02542 1356 NtWriteVirtualMemory (120, 0x10000, (120, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6432, ... 0x0, ) , 6432, ... 0x0, ) == 0x0 02543 1356 NtAllocateVirtualMemory (120, 0, 0, 2420, 4096, 4, ... 131072, 4096, ) == 0x0 02544 1356 NtWriteVirtualMemory (120, 0x20000, (120, 0x20000, "\0\20\0\0t\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\0\0\0\0\13\0\0\0\26\0\10\2\220\2\0\0\0\0\0\0\364\3\366\3\230\4\0\0>\0@\0\220\10\0\0>\0@\0\320\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0>\0@\0\20\11\0\0\36\0 \0P\11\0\0\0\0\2\0p\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2420, ... 0x0, ) , 2420, ... 0x0, ) == 0x0 02545 1356 NtWriteVirtualMemory (120, 0x7ffde010, (120, 0x7ffde010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02546 1356 NtWriteVirtualMemory (120, 0x7ffde1e8, (120, 0x7ffde1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02547 1356 NtFreeVirtualMemory (-1, (0xa20000), 0, 32768, ... (0xa20000), 4096, ) == 0x0 02548 1356 NtAllocateVirtualMemory (120, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 02549 1356 NtAllocateVirtualMemory (120, 1232896, 0, 12288, 4096, 4, ... 1232896, 12288, ) == 0x0 02550 1356 NtProtectVirtualMemory (120, (0x12d000), 4096, 260, ... (0x12d000), 4096, 4, ) == 0x0 02551 1356 NtCreateThread (0x1f03ff, 0x0, 120, 1241760, 1241424, 1, ... 128, {336, 800}, ) == 0x0 02552 1356 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 2089883030, 2089879275, 1329928, 2147348480} (24, {168, 196, new_msg, 0, 2089883030, 2089879275, 1329928, 2147348480} "\0\0\0\0\0\0\1\0\10\366\22\0\0\0\0\0{\0\0\0\200\0\0\0P\1\0\0 \3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\221|\224\371\22\0" ... {168, 196, reply, 0, 220, 1356, 75693, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0x\0\0\0\200\0\0\0P\1\0\0 \3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\221|\224\371\22\0" ) ... {168, 196, reply, 0, 220, 1356, 75693, 0} (24, {168, 196, new_msg, 0, 2089883030, 2089879275, 1329928, 2147348480} "\0\0\0\0\0\0\1\0\10\366\22\0\0\0\0\0{\0\0\0\200\0\0\0P\1\0\0 \3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\221|\224\371\22\0" ... {168, 196, reply, 0, 220, 1356, 75693, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0x\0\0\0\200\0\0\0P\1\0\0 \3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\221|\224\371\22\0" ) ) == 0x0 02553 1356 NtResumeThread (128, ... 1, ) == 0x0 02554 1356 NtClose (124, ... ) == 0x0 02555 1356 NtClose (112, ... ) == 0x0 02556 1356 NtQueryInformationProcess (120, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffde000,AffinityMask=0x1,BasePriority=8,Pid=336,ParentPid=220,}, 0x0, ) == 0x0 02557 1356 NtUserWaitForInputIdle (336, 30000, 0, ... 02558 1356 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 112, ) == 0x0 02559 1356 NtClose (112, ... ) == 0x0 02557 1356 NtUserWaitForInputIdle ... ) == 0x0 02560 1356 NtClose (120, ... ) == 0x0 02561 1356 NtClose (128, ... ) == 0x0 02562 1356 NtQueryDefaultLocale (1, 1243632, ... ) == 0x0 02563 1356 NtQueryDefaultLocale (1, 1243632, ... ) == 0x0 02564 1356 NtQueryDefaultLocale (0, 1243628, ... ) == 0x0 02565 1356 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1243676, (0xc0100080, {24, 0, 0x40, 0, 1243676, "\??\C:\WINDOWS\svchost.exe"}, 0x0, 128, 0, 5, 96, 0, 0, ... }, 0x0, 128, 0, 5, 96, 0, 0, ... 02566 1356 NtClose (-2147482644, ... ) == 0x0 02565 1356 NtCreateFile ... 128, {status=0x0, info=2}, ) == 0x0 02567 1356 NtWriteFile (128, 0, 0, 0, (128, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0PE\0\0L\1\2\0FSG!\0\0\0\0\0\0\0\0\340\0\17\1\13\1\0\0\0N\0\0\0\220\0\0\0\0\0\0N,\1\0\0\20\0\0\14\0\0\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\00\1\0\0\2\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\23-\1\04\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0t\0\0\0\0\340\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300\0\0\0\0a\0\0\0\0@\0\0\0\360\0\0G=\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300KERNEL32.dll\0\0\0LoadLibraryA\0\0GetProcAddress\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\11-A\0\375,A\0\377,A\0\230\1@\0\0\20@\0\0\360@\0\1`@\0\0\0\0\0\334Y@\0\1\0\0\0;-A\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 16208, 0x0, 0, ... , 16208, 0x0, 0, ... 02568 1356 NtContinue (-140694060, 0, ... 02567 1356 NtWriteFile ... {status=0x0, info=16208}, ) == 0x0 02569 1356 NtClose (128, ... ) == 0x0 02570 1356 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 7, 2113568, ... 128, {status=0x0, info=1}, ) }, 7, 2113568, ... 128, {status=0x0, info=1}, ) == 0x0 02571 1356 NtSetInformationFile (128, 1243668, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02572 1356 NtClose (128, ... ) == 0x0 02573 1356 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 02574 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1239968, ... ) }, 1239968, ... ) == 0x0 02575 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1240704, ... ) }, 1240704, ... ) == 0x0 02576 1356 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 5, 96, ... 128, {status=0x0, info=1}, ) }, 5, 96, ... 128, {status=0x0, info=1}, ) == 0x0 02577 1356 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 128, ... 120, ) == 0x0 02578 1356 NtQueryVolumeInformationFile (128, 1239980, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02579 1356 NtWaitForSingleObject (92, 0, {-1000000, -1}, ... ) == 0x0 02580 1356 NtReleaseMutant (92, ... 0x0, ) == 0x0 02581 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 112, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 112, {status=0x0, info=1}, ) == 0x0 02582 1356 NtQueryInformationFile (112, 1238236, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02583 1356 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 112, ... 124, ) == 0x0 02584 1356 NtMapViewOfSection (124, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa20000), 0x0, 1191936, ) == 0x0 02585 1356 NtQueryInformationFile (112, 1238336, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02586 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02587 1356 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02588 1356 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 104, ) }, ... 104, ) == 0x0 02589 1356 NtQueryValueKey (104, (104, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (104, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02590 1356 NtClose (104, ... ) == 0x0 02591 1356 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02592 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02593 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235932, 616, BothDirectory, 1, (104, 0, 0, 0, 1235932, 616, BothDirectory, 1, "svchost.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02594 1356 NtClose (104, ... ) == 0x0 02595 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02596 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02597 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1236308, ... ) }, 1236308, ... ) == 0x0 02598 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02599 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02600 1356 NtClose (104, ... ) == 0x0 02601 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02602 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, (104, 0, 0, 0, 1235736, 616, BothDirectory, 1, "svchost.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02603 1356 NtClose (104, ... ) == 0x0 02604 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02605 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02606 1356 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02607 1356 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02608 1356 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02609 1356 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 104, ) == 0x0 02610 1356 NtQueryInformationToken (104, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02611 1356 NtClose (104, ... ) == 0x0 02612 1356 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02613 1356 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\svchost.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02614 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1237156, ... ) }, 1237156, ... ) == 0x0 02615 1356 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "VERSION.dll"}, ... 104, ) }, ... 104, ) == 0x0 02616 1356 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c00000), 0x0, 32768, ) == 0x0 02617 1356 NtClose (104, ... ) == 0x0 02618 1356 NtProtectVirtualMemory (-1, (0x77c01000), 304, 4, ... (0x77c01000), 4096, 32, ) == 0x0 02619 1356 NtProtectVirtualMemory (-1, (0x77c01000), 4096, 32, ... (0x77c01000), 4096, 4, ) == 0x0 02620 1356 NtFlushInstructionCache (-1, 2009075712, 304, ... ) == 0x0 02621 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VERSION.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02622 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02623 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02624 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1236008, ... ) }, 1236008, ... ) == 0x0 02625 1356 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 02626 1356 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 104, ... 132, ) == 0x0 02627 1356 NtClose (104, ... ) == 0x0 02628 1356 NtMapViewOfSection (132, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xb50000), 0x0, 16384, ) == 0x0 02629 1356 NtClose (132, ... ) == 0x0 02630 1356 NtUnmapViewOfSection (-1, 0xb50000, ... ) == 0x0 02631 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1235604, ... ) }, 1235604, ... ) == 0x0 02632 1356 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1236348, (0x80100080, {24, 0, 0x40, 0, 1236348, "\??\C:\WINDOWS\svchost.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 132, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 132, {status=0x0, info=1}, ) == 0x0 02633 1356 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 132, ... 104, ) == 0x0 02634 1356 NtClose (132, ... ) == 0x0 02635 1356 NtMapViewOfSection (104, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xb50000), {0, 0}, 16384, ) == 0x0 02636 1356 NtClose (104, ... ) == 0x0 02637 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02638 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02639 1356 NtUnmapViewOfSection (-1, 0xb50000, ... ) == 0x0 02640 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02641 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02642 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1237560, ... ) }, 1237560, ... ) == 0x0 02643 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02644 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02645 1356 NtClose (104, ... ) == 0x0 02646 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 104, {status=0x0, info=1}, ) }, 3, 16417, ... 104, {status=0x0, info=1}, ) == 0x0 02647 1356 NtQueryDirectoryFile (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, (104, 0, 0, 0, 1236988, 616, BothDirectory, 1, "svchost.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02648 1356 NtClose (104, ... ) == 0x0 02649 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02650 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02651 1356 NtWaitForSingleObject (92, 0, {-1000000, -1}, ... ) == 0x0 02652 1356 NtQueryVolumeInformationFile (128, 1238216, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02653 1356 NtQueryInformationFile (128, 1238196, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02654 1356 NtQueryInformationFile (128, 1238236, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02655 1356 NtReleaseMutant (92, ... 0x0, ) == 0x0 02656 1356 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 02657 1356 NtClose (124, ... ) == 0x0 02658 1356 NtClose (112, ... ) == 0x0 02659 1356 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 02660 1356 NtOpenProcessToken (-1, 0xa, ... 112, ) == 0x0 02661 1356 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 02662 1356 NtQueryKey (124, Basic, 520, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (124, Basic, 520, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="CodeIdentifierso"}, 46, ) }, 46, ) == 0x0 02663 1356 NtClose (124, ... ) == 0x0 02664 1356 NtOpenKey (0x2000000, {24, 80, 0x40, 0, 0, (0x2000000, {24, 80, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02665 1356 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 124, ) }, ... 124, ) == 0x0 02666 1356 NtQuerySymbolicLinkObject (124, ... (124, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 02667 1356 NtClose (124, ... ) == 0x0 02668 1356 NtQueryVolumeInformationFile (128, 1237672, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02669 1356 NtQueryInformationFile (128, 1237788, 528, Name, ... {status=0x0, info=44}, ) == 0x0 02670 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02671 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02672 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe"}, 1236960, ... ) }, 1236960, ... ) == 0x0 02673 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 124, {status=0x0, info=1}, ) }, 3, 16417, ... 124, {status=0x0, info=1}, ) == 0x0 02674 1356 NtQueryDirectoryFile (124, 0, 0, 0, 1236388, 616, BothDirectory, 1, (124, 0, 0, 0, 1236388, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02675 1356 NtClose (124, ... ) == 0x0 02676 1356 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 124, {status=0x0, info=1}, ) }, 3, 16417, ... 124, {status=0x0, info=1}, ) == 0x0 02677 1356 NtQueryDirectoryFile (124, 0, 0, 0, 1236388, 616, BothDirectory, 1, (124, 0, 0, 0, 1236388, 616, BothDirectory, 1, "svchost.exe", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02678 1356 NtClose (124, ... ) == 0x0 02679 1356 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02680 1356 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02681 1356 NtQueryInformationFile (128, 1239828, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02682 1356 NtCreateSection (0xf0005, 0x0, {16208, 0}, 2, 134217728, 128, ... 124, ) == 0x0 02683 1356 NtMapViewOfSection (124, -1, (0x0), 0, 0, {0, 0}, 16208, 1, 0, 2, ... (0xa20000), {0, 0}, 16384, ) == 0x0 02684 1356 NtClose (124, ... ) == 0x0 02685 1356 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 02686 1356 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 02687 1356 NtQueryValueKey (124, (124, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02688 1356 NtClose (124, ... ) == 0x0 02689 1356 NtQueryInformationToken (112, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 02690 1356 NtQueryInformationToken (112, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 02691 1356 NtClose (112, ... ) == 0x0 02692 1356 NtQuerySection (120, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02693 1356 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02694 1356 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0 02695 1356 NtCreateProcessEx (1241752, 2035711, 0, -1, 0, 120, 0, 0, 0, ... ) == 0x0 02696 1356 NtQueryInformationProcess (112, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdb000,AffinityMask=0x1,BasePriority=8,Pid=1588,ParentPid=220,}, 0x0, ) == 0x0 02697 1356 NtReadVirtualMemory (112, 0x7ffdb008, 4, ... (112, 0x7ffdb008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 02698 1356 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\svchost.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02699 1356 NtReadVirtualMemory (112, 0x400000, 4096, ... (112, 0x400000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0PE\0\0L\1\2\0FSG!\0\0\0\0\0\0\0\0\340\0\17\1\13\1\0\0\0N\0\0\0\220\0\0\0\0\0\0N,\1\0\0\20\0\0\14\0\0\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\00\1\0\0\2\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\23-\1\04\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0t\0\0\0\0\340\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300\0\0\0\0a\0\0\0\0@\0\0\0\360\0\0G=\0\0\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\300KERNEL32.dll\0\0\0LoadLibraryA\0\0GetProcAddress\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\11-A\0\375,A\0\377,A\0\230\1@\0\0\20@\0\0\360@\0\1`@\0\0\0\0\0\334Y@\0\1\0\0\0;-A\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 4096, ) , 4096, ) == 0x0 02700 1356 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02701 1356 NtQueryInformationProcess (112, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdb000,AffinityMask=0x1,BasePriority=8,Pid=1588,ParentPid=220,}, 0x0, ) == 0x0 02702 1356 NtAllocateVirtualMemory (-1, 0, 0, 2352, 4096, 4, ... 10616832, 4096, ) == 0x0 02703 1356 NtAllocateVirtualMemory (112, 0, 0, 6432, 4096, 4, ... 65536, 8192, ) == 0x0 02704 1356 NtWriteVirtualMemory (112, 0x10000, (112, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6432, ... 0x0, ) , 6432, ... 0x0, ) == 0x0 02705 1356 NtAllocateVirtualMemory (112, 0, 0, 2352, 4096, 4, ... 131072, 4096, ) == 0x0 02706 1356 NtWriteVirtualMemory (112, 0x20000, (112, 0x20000, "\0\20\0\00\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\0\0\0\0\13\0\0\0\26\0\10\2\220\2\0\0\0\0\0\0\342\3\344\3\230\4\0\0,\0.\0|\10\0\0,\0.\0\254\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0,\0.\0\334\10\0\0\36\0 \0\14\11\0\0\0\0\2\0,\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2352, ... 0x0, ) , 2352, ... 0x0, ) == 0x0 02707 1356 NtWriteVirtualMemory (112, 0x7ffdb010, (112, 0x7ffdb010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02708 1356 NtWriteVirtualMemory (112, 0x7ffdb1e8, (112, 0x7ffdb1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02709 1356 NtFreeVirtualMemory (-1, (0xa20000), 0, 32768, ... (0xa20000), 4096, ) == 0x0 02710 1356 NtAllocateVirtualMemory (112, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 02711 1356 NtAllocateVirtualMemory (112, 1236992, 0, 8192, 4096, 4, ... 1236992, 8192, ) == 0x0 02712 1356 NtProtectVirtualMemory (112, (0x12e000), 4096, 260, ... (0x12e000), 4096, 4, ) == 0x0 02713 1356 NtCreateThread (0x1f03ff, 0x0, 112, 1241760, 1241424, 1, ... 124, {1588, 2044}, ) == 0x0 02714 1356 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 220, 1356, 75693, 0} (24, {168, 196, new_msg, 0, 220, 1356, 75693, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0s\0\0\0|\0\0\04\6\0\0\374\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\260\375\177\0\0\0\0\0\0\221|\224\371\22\0" ... {168, 196, reply, 0, 220, 1356, 75789, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0p\0\0\0|\0\0\04\6\0\0\374\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\260\375\177\0\0\0\0\0\0\221|\224\371\22\0" ) ... {168, 196, reply, 0, 220, 1356, 75789, 0} (24, {168, 196, new_msg, 0, 220, 1356, 75693, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0s\0\0\0|\0\0\04\6\0\0\374\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\260\375\177\0\0\0\0\0\0\221|\224\371\22\0" ... {168, 196, reply, 0, 220, 1356, 75789, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0p\0\0\0|\0\0\04\6\0\0\374\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\244\365\22\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\260\375\177\0\0\0\0\0\0\221|\224\371\22\0" ) ) == 0x0 02715 1356 NtResumeThread (124, ... 1, ) == 0x0 02716 1356 NtClose (128, ... ) == 0x0 02717 1356 NtClose (120, ... ) == 0x0 02718 1356 NtQueryInformationProcess (112, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdb000,AffinityMask=0x1,BasePriority=8,Pid=1588,ParentPid=220,}, 0x0, ) == 0x0 02719 1356 NtUserWaitForInputIdle (1588, 30000, 0, ... 02720 1356 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 120, ) == 0x0 02721 1356 NtClose (120, ... ) == 0x0 02719 1356 NtUserWaitForInputIdle ... ) == 0x0 02722 1356 NtClose (112, ... ) == 0x0 02723 1356 NtClose (124, ... ) == 0x0 02724 1356 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 02725 1356 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 02726 1356 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 02727 1356 NtTerminateProcess (0, 0, ... ) == 0x0 02728 1356 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 02729 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Msctf.dll"}, 1241600, ... ) }, 1241600, ... ) == 0x0 02730 1356 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Msctf.dll"}, 1241508, ... ) }, 1241508, ... ) == 0x0 02731 1356 NtUserGetClassInfo (1968963584, 1243836, 1244400, 1243832, 0, ... ) == 0xc079 02732 1356 NtUserUnregisterClass (1243840, 1968963584, 1243828, ... ) == 0x1 02733 1356 NtUserDestroyCursor (65539, 1, ... ) == 0x1 02734 1356 NtUserDestroyCursor (3867137, 1, ... ) == 0x0 02735 1356 NtUserGetClassInfo (1968963584, 1243836, 1244400, 1243832, 0, ... ) == 0xc07a 02736 1356 NtUserUnregisterClass (1243840, 1968963584, 1243828, ... ) == 0x1 02737 1356 NtUserDestroyCursor (0, 1, ... ) == 0x0 02738 1356 NtUserDestroyCursor (0, 1, ... ) == 0x0 02739 1356 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 02740 1356 NtGdiDeleteObjectApp (-1895758623, ... ) == 0x1 02741 1356 NtGdiDeleteObjectApp (2097219254, ... ) == 0x1 02742 1356 NtGdiDeleteObjectApp (1812006132, ... ) == 0x1 02743 1356 NtUserPostThreadMessage (1748, 49315, 0, 1356, ... ) == 0x1 02744 1356 NtUserPostThreadMessage (416, 49315, 0, 1356, ... ) == 0x1 02745 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 02746 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 02747 1356 NtUserValidateHandleSecure (1179914, ... ) == 0x1 02748 1356 NtUserSetWindowLong (1179914, -4, 2118243566, 1, ... ) == 0x7473f99e 02749 1356 NtUserUnhookWindowsHookEx (3735967, ... ) == 0x1 02750 1356 NtUserUnhookWindowsHookEx (1311203, ... ) == 0x1 02751 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 02752 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 02753 1356 NtUserDestroyCursor (2228887, 1, ... ) == 0x1 02754 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 02755 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 02756 1356 NtUserPostThreadMessage (1748, 49316, 0, 1356, ... ) == 0x1 02757 1356 NtUserPostThreadMessage (416, 49316, 0, 1356, ... ) == 0x1 02758 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 02759 1356 NtUserPostMessage (65742, 49321, 19515750, 12, ... ) == 0x1 02760 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 02761 1356 NtUserPostMessage (65742, 49321, 19515750, 13, ... ) == 0x1 02762 1356 NtUserValidateHandleSecure (65742, ... ) == 0x1 02763 1356 NtUserPostMessage (65742, 49321, 19515750, 14, ... ) == 0x1 02764 1356 NtUnmapViewOfSection (-1, 0x9a0000, ... ) == 0x0 02765 1356 NtClose (116, ... ) == 0x0 02766 1356 NtClose (108, ... ) == 0x0 02767 1356 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 02768 1356 NtUnmapViewOfSection (-1, 0x8c0000, ... ) == 0x0 02769 1356 NtClose (88, ... ) == 0x0 02770 1356 NtClose (84, ... ) == 0x0 02771 1356 NtClose (60, ... ) == 0x0 02772 1356 NtClose (64, ... ) == 0x0 02773 1356 NtClose (68, ... ) == 0x0 02774 1356 NtClose (72, ... ) == 0x0 02775 1356 NtClose (76, ... ) == 0x0 02776 1356 NtUnmapViewOfSection (-1, 0x8b0000, ... ) == 0x0 02777 1356 NtClose (56, ... ) == 0x0 02778 1356 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 02779 1356 NtUnmapViewOfSection (-1, 0x860000, ... ) == 0x0 02780 1356 NtClose (48, ... ) == 0x0 02781 1356 NtGdiDeleteObjectApp (1175455340, ... ) == 0x1 02782 1356 NtUserGetProcessWindowStation (... ) == 0x20 02783 1356 NtUserBuildNameList (32, 522, 1334440, 1244040, ... ) == 0x0 02784 1356 NtUserGetProcessWindowStation (... ) == 0x20 02785 1356 NtUserOpenDesktop ({24, 32, 0x40, 0, 0, ({24, 32, 0x40, 0, 0, "Default"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x30 02786 1356 NtUserBuildHwndList (48, 0, 0, 0, 64, ... (0x1a00f4, 0x5009e, 0x400fa, 0x10074, 0x10070, 0x10080, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x1401b6, 0xc01d2, 0xd0102, 0x500a2, 0xd011a, 0x10090, 0x100d0, 0x200b0, 0x100cc, 0x90144, 0x13010c, 0x16012c, 0x7015a, 0xd01c8, 0xe01ac, 0xc01d0, 0xa01cc, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x70130, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 63, ) == 0x0 02787 1356 NtUserValidateHandleSecure (1704180, ... ) == 0x1 02788 1356 NtUserQueryWindow (1704180, 0, ... ) == 0x6b8 02789 1356 NtUserQueryWindow (1704180, 1, ... ) == 0x6d4 02790 1356 NtUserValidateHandleSecure (1704180, ... ) == 0x1 02791 1356 NtUserValidateHandleSecure (327838, ... ) == 0x1 02792 1356 NtUserQueryWindow (327838, 0, ... ) == 0x6b8 02793 1356 NtUserQueryWindow (327838, 1, ... ) == 0x6d4 02794 1356 NtUserValidateHandleSecure (327838, ... ) == 0x1 02795 1356 NtUserValidateHandleSecure (262394, ... ) == 0x1 02796 1356 NtUserQueryWindow (262394, 0, ... ) == 0x6b8 02797 1356 NtUserQueryWindow (262394, 1, ... ) == 0x6d4 02798 1356 NtUserValidateHandleSecure (262394, ... ) == 0x1 02799 1356 NtUserBuildHwndList (0, 262394, 1, 0, 64, ... (0x80064, 0x60068, 0x6006c, 0x50094, 0x50096, 0x60066, 0x7006a, 0x90058, 0x6006e, 0x5008a, 0x50088, 0x500a0, 0x1, ), 13, ) == 0x0 02800 1356 NtUserValidateHandleSecure (524388, ... ) == 0x1 02801 1356 NtUserQueryWindow (524388, 0, ... ) == 0x6b8 02802 1356 NtUserQueryWindow (524388, 1, ... ) == 0x6d4 02803 1356 NtUserValidateHandleSecure (393320, ... ) == 0x1 02804 1356 NtUserQueryWindow (393320, 0, ... ) == 0x6b8 02805 1356 NtUserQueryWindow (393320, 1, ... ) == 0x6d4 02806 1356 NtUserValidateHandleSecure (393324, ... ) == 0x1 02807 1356 NtUserQueryWindow (393324, 0, ... ) == 0x6b8 02808 1356 NtUserQueryWindow (393324, 1, ... ) == 0x6d4 02809 1356 NtUserValidateHandleSecure (327828, ... ) == 0x1 02810 1356 NtUserQueryWindow (327828, 0, ... ) == 0x6b8 02811 1356 NtUserQueryWindow (327828, 1, ... ) == 0x6d4 02812 1356 NtUserValidateHandleSecure (327830, ... ) == 0x1 02813 1356 NtUserQueryWindow (327830, 0, ... ) == 0x6b8 02814 1356 NtUserQueryWindow (327830, 1, ... ) == 0x6d4 02815 1356 NtUserValidateHandleSecure (393318, ... ) == 0x1 02816 1356 NtUserQueryWindow (393318, 0, ... ) == 0x6b8 02817 1356 NtUserQueryWindow (393318, 1, ... ) == 0x6d4 02818 1356 NtUserValidateHandleSecure (458858, ... ) == 0x1 02819 1356 NtUserQueryWindow (458858, 0, ... ) == 0x6b8 02820 1356 NtUserQueryWindow (458858, 1, ... ) == 0x6d4 02821 1356 NtUserValidateHandleSecure (589912, ... ) == 0x1 02822 1356 NtUserQueryWindow (589912, 0, ... ) == 0x6b8 02823 1356 NtUserQueryWindow (589912, 1, ... ) == 0x6d4 02824 1356 NtUserValidateHandleSecure (393326, ... ) == 0x1 02825 1356 NtUserQueryWindow (393326, 0, ... ) == 0x6b8 02826 1356 NtUserQueryWindow (393326, 1, ... ) == 0x6d4 02827 1356 NtUserValidateHandleSecure (327818, ... ) == 0x1 02828 1356 NtUserQueryWindow (327818, 0, ... ) == 0x6b8 02829 1356 NtUserQueryWindow (327818, 1, ... ) == 0x6d4 02830 1356 NtUserValidateHandleSecure (327816, ... ) == 0x1 02831 1356 NtUserQueryWindow (327816, 0, ... ) == 0x6b8 02832 1356 NtUserQueryWindow (327816, 1, ... ) == 0x6d4 02833 1356 NtUserValidateHandleSecure (327840, ... ) == 0x1 02834 1356 NtUserQueryWindow (327840, 0, ... ) == 0x6b8 02835 1356 NtUserQueryWindow (327840, 1, ... ) == 0x6d4 02836 1356 NtUserValidateHandleSecure (65652, ... ) == 0x1 02837 1356 NtUserQueryWindow (65652, 0, ... ) == 0x6b8 02838 1356 NtUserQueryWindow (65652, 1, ... ) == 0x6d4 02839 1356 NtUserValidateHandleSecure (65652, ... ) == 0x1 02840 1356 NtUserValidateHandleSecure (65648, ... ) == 0x1 02841 1356 NtUserQueryWindow (65648, 0, ... ) == 0x6b8 02842 1356 NtUserQueryWindow (65648, 1, ... ) == 0x6d4 02843 1356 NtUserValidateHandleSecure (65648, ... ) == 0x1 02844 1356 NtUserValidateHandleSecure (65664, ... ) == 0x1 02845 1356 NtUserQueryWindow (65664, 0, ... ) == 0x6b8 02846 1356 NtUserQueryWindow (65664, 1, ... ) == 0x6d4 02847 1356 NtUserValidateHandleSecure (65664, ... ) == 0x1 02848 1356 NtUserValidateHandleSecure (65668, ... ) == 0x1 02849 1356 NtUserQueryWindow (65668, 0, ... ) == 0x6b8 02850 1356 NtUserQueryWindow (65668, 1, ... ) == 0x6d4 02851 1356 NtUserValidateHandleSecure (65668, ... ) == 0x1 02852 1356 NtUserValidateHandleSecure (196680, ... ) == 0x1 02853 1356 NtUserQueryWindow (196680, 0, ... ) == 0x6b8 02854 1356 NtUserQueryWindow (196680, 1, ... ) == 0x6d4 02855 1356 NtUserValidateHandleSecure (196680, ... ) == 0x1 02856 1356 NtUserValidateHandleSecure (65650, ... ) == 0x1 02857 1356 NtUserQueryWindow (65650, 0, ... ) == 0x6b8 02858 1356 NtUserQueryWindow (65650, 1, ... ) == 0x6d4 02859 1356 NtUserValidateHandleSecure (65650, ... ) == 0x1 02860 1356 NtUserValidateHandleSecure (131154, ... ) == 0x1 02861 1356 NtUserQueryWindow (131154, 0, ... ) == 0x6b8 02862 1356 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 02863 1356 NtUserValidateHandleSecure (131154, ... ) == 0x1 02864 1356 NtUserBuildHwndList (0, 131154, 1, 0, 64, ... (0x3003e, 0x3003c, 0x30040, 0x30042, 0x30044, 0x30046, 0x10076, 0x10082, 0x1007a, 0x1007e, 0x1, ), 11, ) == 0x0 02865 1356 NtUserValidateHandleSecure (196670, ... ) == 0x1 02866 1356 NtUserQueryWindow (196670, 0, ... ) == 0x6b8 02867 1356 NtUserQueryWindow (196670, 1, ... ) == 0x6d4 02868 1356 NtUserValidateHandleSecure (196668, ... ) == 0x1 02869 1356 NtUserQueryWindow (196668, 0, ... ) == 0x6b8 02870 1356 NtUserQueryWindow (196668, 1, ... ) == 0x6d4 02871 1356 NtUserValidateHandleSecure (196672, ... ) == 0x1 02872 1356 NtUserQueryWindow (196672, 0, ... ) == 0x6b8 02873 1356 NtUserQueryWindow (196672, 1, ... ) == 0x6d4 02874 1356 NtUserValidateHandleSecure (196674, ... ) == 0x1 02875 1356 NtUserQueryWindow (196674, 0, ... ) == 0x6b8 02876 1356 NtUserQueryWindow (196674, 1, ... ) == 0x6d4 02877 1356 NtUserValidateHandleSecure (196676, ... ) == 0x1 02878 1356 NtUserQueryWindow (196676, 0, ... ) == 0x6b8 02879 1356 NtUserQueryWindow (196676, 1, ... ) == 0x6d4 02880 1356 NtUserValidateHandleSecure (196678, ... ) == 0x1 02881 1356 NtUserQueryWindow (196678, 0, ... ) == 0x6b8 02882 1356 NtUserQueryWindow (196678, 1, ... ) == 0x6d4 02883 1356 NtUserValidateHandleSecure (65654, ... ) == 0x1 02884 1356 NtUserQueryWindow (65654, 0, ... ) == 0x6b8 02885 1356 NtUserQueryWindow (65654, 1, ... ) == 0x6d4 02886 1356 NtUserValidateHandleSecure (65666, ... ) == 0x1 02887 1356 NtUserQueryWindow (65666, 0, ... ) == 0x6b8 02888 1356 NtUserQueryWindow (65666, 1, ... ) == 0x6d4 02889 1356 NtUserValidateHandleSecure (65658, ... ) == 0x1 02890 1356 NtUserQueryWindow (65658, 0, ... ) == 0x6b8 02891 1356 NtUserQueryWindow (65658, 1, ... ) == 0x6d4 02892 1356 NtUserValidateHandleSecure (65662, ... ) == 0x1 02893 1356 NtUserQueryWindow (65662, 0, ... ) == 0x6b8 02894 1356 NtUserQueryWindow (65662, 1, ... ) == 0x6d4 02895 1356 NtUserValidateHandleSecure (327836, ... ) == 0x1 02896 1356 NtUserQueryWindow (327836, 0, ... ) == 0x6b8 02897 1356 NtUserQueryWindow (327836, 1, ... ) == 0x6d4 02898 1356 NtUserValidateHandleSecure (327836, ... ) == 0x1 02899 1356 NtUserValidateHandleSecure (1311158, ... ) == 0x1 02900 1356 NtUserQueryWindow (1311158, 0, ... ) == 0x6b8 02901 1356 NtUserQueryWindow (1311158, 1, ... ) == 0x6d4 02902 1356 NtUserValidateHandleSecure (1311158, ... ) == 0x1 02903 1356 NtUserBuildHwndList (0, 1311158, 1, 0, 64, ... (0xf0192, 0x80198, 0x1, ), 3, ) == 0x0 02904 1356 NtUserValidateHandleSecure (983442, ... ) == 0x1 02905 1356 NtUserQueryWindow (983442, 0, ... ) == 0x6b8 02906 1356 NtUserQueryWindow (983442, 1, ... ) == 0x6d4 02907 1356 NtUserValidateHandleSecure (524696, ... ) == 0x1 02908 1356 NtUserQueryWindow (524696, 0, ... ) == 0x6b8 02909 1356 NtUserQueryWindow (524696, 1, ... ) == 0x6d4 02910 1356 NtUserValidateHandleSecure (786898, ... ) == 0x1 02911 1356 NtUserQueryWindow (786898, 0, ... ) == 0x6b8 02912 1356 NtUserQueryWindow (786898, 1, ... ) == 0x6d4 02913 1356 NtUserValidateHandleSecure (786898, ... ) == 0x1 02914 1356 NtUserValidateHandleSecure (852226, ... ) == 0x1 02915 1356 NtUserQueryWindow (852226, 0, ... ) == 0x6b8 02916 1356 NtUserQueryWindow (852226, 1, ... ) == 0x6d4 02917 1356 NtUserValidateHandleSecure (852226, ... ) == 0x1 02918 1356 NtUserBuildHwndList (0, 852226, 1, 0, 64, ... (0x700fc, 0xc0114, 0x1, ), 3, ) == 0x0 02919 1356 NtUserValidateHandleSecure (459004, ... ) == 0x1 02920 1356 NtUserQueryWindow (459004, 0, ... ) == 0x6b8 02921 1356 NtUserQueryWindow (459004, 1, ... ) == 0x6d4 02922 1356 NtUserValidateHandleSecure (786708, ... ) == 0x1 02923 1356 NtUserQueryWindow (786708, 0, ... ) == 0x6b8 02924 1356 NtUserQueryWindow (786708, 1, ... ) == 0x6d4 02925 1356 NtUserValidateHandleSecure (327842, ... ) == 0x1 02926 1356 NtUserQueryWindow (327842, 0, ... ) == 0x6b8 02927 1356 NtUserQueryWindow (327842, 1, ... ) == 0x6d4 02928 1356 NtUserValidateHandleSecure (327842, ... ) == 0x1 02929 1356 NtUserValidateHandleSecure (852250, ... ) == 0x1 02930 1356 NtUserQueryWindow (852250, 0, ... ) == 0x6b8 02931 1356 NtUserQueryWindow (852250, 1, ... ) == 0x6d4 02932 1356 NtUserValidateHandleSecure (852250, ... ) == 0x1 02933 1356 NtUserValidateHandleSecure (65680, ... ) == 0x1 02934 1356 NtUserQueryWindow (65680, 0, ... ) == 0x6b8 02935 1356 NtUserQueryWindow (65680, 1, ... ) == 0x6bc 02936 1356 NtUserValidateHandleSecure (65680, ... ) == 0x1 02937 1356 NtUserValidateHandleSecure (65744, ... ) == 0x1 02938 1356 NtUserQueryWindow (65744, 0, ... ) == 0x19c 02939 1356 NtUserQueryWindow (65744, 1, ... ) == 0x1a0 02940 1356 NtUserValidateHandleSecure (65744, ... ) == 0x1 02941 1356 NtUserValidateHandleSecure (131248, ... ) == 0x1 02942 1356 NtUserQueryWindow (131248, 0, ... ) == 0xa0 02943 1356 NtUserQueryWindow (131248, 1, ... ) == 0xe4 02944 1356 NtUserValidateHandleSecure (131248, ... ) == 0x1 02945 1356 NtUserValidateHandleSecure (65740, ... ) == 0x1 02946 1356 NtUserQueryWindow (65740, 0, ... ) == 0x19c 02947 1356 NtUserQueryWindow (65740, 1, ... ) == 0x1a0 02948 1356 NtUserValidateHandleSecure (65740, ... ) == 0x1 02949 1356 NtUserValidateHandleSecure (590148, ... ) == 0x1 02950 1356 NtUserQueryWindow (590148, 0, ... ) == 0x150 02951 1356 NtUserQueryWindow (590148, 1, ... ) == 0x1e8 02952 1356 NtUserValidateHandleSecure (590148, ... ) == 0x1 02953 1356 NtUserValidateHandleSecure (1245452, ... ) == 0x1 02954 1356 NtUserQueryWindow (1245452, 0, ... ) == 0x5e8 02955 1356 NtUserQueryWindow (1245452, 1, ... ) == 0x534 02956 1356 NtUserValidateHandleSecure (1245452, ... ) == 0x1 02957 1356 NtUserValidateHandleSecure (1442092, ... ) == 0x1 02958 1356 NtUserQueryWindow (1442092, 0, ... ) == 0xa4 02959 1356 NtUserQueryWindow (1442092, 1, ... ) == 0x61c 02960 1356 NtUserValidateHandleSecure (1442092, ... ) == 0x1 02961 1356 NtUserValidateHandleSecure (459098, ... ) == 0x1 02962 1356 NtUserQueryWindow (459098, 0, ... ) == 0x4b0 02963 1356 NtUserQueryWindow (459098, 1, ... ) == 0x780 02964 1356 NtUserValidateHandleSecure (459098, ... ) == 0x1 02965 1356 NtUserValidateHandleSecure (852424, ... ) == 0x1 02966 1356 NtUserQueryWindow (852424, 0, ... ) == 0x6b8 02967 1356 NtUserQueryWindow (852424, 1, ... ) == 0x6d4 02968 1356 NtUserValidateHandleSecure (852424, ... ) == 0x1 02969 1356 NtUserValidateHandleSecure (917932, ... ) == 0x1 02970 1356 NtUserQueryWindow (917932, 0, ... ) == 0x6b8 02971 1356 NtUserQueryWindow (917932, 1, ... ) == 0x6d4 02972 1356 NtUserValidateHandleSecure (917932, ... ) == 0x1 02973 1356 NtUserValidateHandleSecure (786896, ... ) == 0x1 02974 1356 NtUserQueryWindow (786896, 0, ... ) == 0x6b8 02975 1356 NtUserQueryWindow (786896, 1, ... ) == 0x6d4 02976 1356 NtUserValidateHandleSecure (786896, ... ) == 0x1 02977 1356 NtUserValidateHandleSecure (655820, ... ) == 0x1 02978 1356 NtUserQueryWindow (655820, 0, ... ) == 0x6b8 02979 1356 NtUserQueryWindow (655820, 1, ... ) == 0x6d4 02980 1356 NtUserValidateHandleSecure (655820, ... ) == 0x1 02981 1356 NtUserValidateHandleSecure (196940, ... ) == 0x1 02982 1356 NtUserQueryWindow (196940, 0, ... ) == 0x4b4 02983 1356 NtUserQueryWindow (196940, 1, ... ) == 0x474 02984 1356 NtUserValidateHandleSecure (196940, ... ) == 0x1 02985 1356 NtUserValidateHandleSecure (65820, ... ) == 0x1 02986 1356 NtUserQueryWindow (65820, 0, ... ) == 0x22c 02987 1356 NtUserQueryWindow (65820, 1, ... ) == 0x220 02988 1356 NtUserValidateHandleSecure (65820, ... ) == 0x1 02989 1356 NtUserValidateHandleSecure (65766, ... ) == 0x1 02990 1356 NtUserQueryWindow (65766, 0, ... ) == 0x6b8 02991 1356 NtUserQueryWindow (65766, 1, ... ) == 0x13c 02992 1356 NtUserValidateHandleSecure (65766, ... ) == 0x1 02993 1356 NtUserValidateHandleSecure (65750, ... ) == 0x1 02994 1356 NtUserQueryWindow (65750, 0, ... ) == 0x6b8 02995 1356 NtUserQueryWindow (65750, 1, ... ) == 0x13c 02996 1356 NtUserValidateHandleSecure (65750, ... ) == 0x1 02997 1356 NtUserBuildHwndList (0, 65750, 1, 0, 64, ... (0x100da, 0x100dc, 0x100de, 0x100e0, 0x1, ), 5, ) == 0x0 02998 1356 NtUserValidateHandleSecure (65754, ... ) == 0x1 02999 1356 NtUserQueryWindow (65754, 0, ... ) == 0x6b8 03000 1356 NtUserQueryWindow (65754, 1, ... ) == 0x13c 03001 1356 NtUserValidateHandleSecure (65756, ... ) == 0x1 03002 1356 NtUserQueryWindow (65756, 0, ... ) == 0x6b8 03003 1356 NtUserQueryWindow (65756, 1, ... ) == 0x13c 03004 1356 NtUserValidateHandleSecure (65758, ... ) == 0x1 03005 1356 NtUserQueryWindow (65758, 0, ... ) == 0x6b8 03006 1356 NtUserQueryWindow (65758, 1, ... ) == 0x13c 03007 1356 NtUserValidateHandleSecure (65760, ... ) == 0x1 03008 1356 NtUserQueryWindow (65760, 0, ... ) == 0x6b8 03009 1356 NtUserQueryWindow (65760, 1, ... ) == 0x13c 03010 1356 NtUserValidateHandleSecure (65746, ... ) == 0x1 03011 1356 NtUserQueryWindow (65746, 0, ... ) == 0x6b8 03012 1356 NtUserQueryWindow (65746, 1, ... ) == 0x6d4 03013 1356 NtUserValidateHandleSecure (65746, ... ) == 0x1 03014 1356 NtUserValidateHandleSecure (65738, ... ) == 0x1 03015 1356 NtUserQueryWindow (65738, 0, ... ) == 0x19c 03016 1356 NtUserQueryWindow (65738, 1, ... ) == 0x1a0 03017 1356 NtUserValidateHandleSecure (65738, ... ) == 0x1 03018 1356 NtUserValidateHandleSecure (65736, ... ) == 0x1 03019 1356 NtUserQueryWindow (65736, 0, ... ) == 0xa0 03020 1356 NtUserQueryWindow (65736, 1, ... ) == 0xe4 03021 1356 NtUserValidateHandleSecure (65736, ... ) == 0x1 03022 1356 NtUserValidateHandleSecure (65722, ... ) == 0x1 03023 1356 NtUserQueryWindow (65722, 0, ... ) == 0x104 03024 1356 NtUserQueryWindow (65722, 1, ... ) == 0x108 03025 1356 NtUserValidateHandleSecure (65722, ... ) == 0x1 03026 1356 NtUserValidateHandleSecure (65710, ... ) == 0x1 03027 1356 NtUserQueryWindow (65710, 0, ... ) == 0x104 03028 1356 NtUserQueryWindow (65710, 1, ... ) == 0x108 03029 1356 NtUserValidateHandleSecure (65710, ... ) == 0x1 03030 1356 NtUserValidateHandleSecure (65708, ... ) == 0x1 03031 1356 NtUserQueryWindow (65708, 0, ... ) == 0x120 03032 1356 NtUserQueryWindow (65708, 1, ... ) == 0x124 03033 1356 NtUserValidateHandleSecure (65708, ... ) == 0x1 03034 1356 NtUserValidateHandleSecure (196774, ... ) == 0x1 03035 1356 NtUserQueryWindow (196774, 0, ... ) == 0xc4 03036 1356 NtUserQueryWindow (196774, 1, ... ) == 0xc8 03037 1356 NtUserValidateHandleSecure (196774, ... ) == 0x1 03038 1356 NtUserValidateHandleSecure (65656, ... ) == 0x1 03039 1356 NtUserQueryWindow (65656, 0, ... ) == 0x6b8 03040 1356 NtUserQueryWindow (65656, 1, ... ) == 0x6ec 03041 1356 NtUserValidateHandleSecure (65656, ... ) == 0x1 03042 1356 NtUserValidateHandleSecure (196706, ... ) == 0x1 03043 1356 NtUserQueryWindow (196706, 0, ... ) == 0x6b8 03044 1356 NtUserQueryWindow (196706, 1, ... ) == 0x6bc 03045 1356 NtUserValidateHandleSecure (196706, ... ) == 0x1 03046 1356 NtUserValidateHandleSecure (327734, ... ) == 0x1 03047 1356 NtUserQueryWindow (327734, 0, ... ) == 0x6b8 03048 1356 NtUserQueryWindow (327734, 1, ... ) == 0x6bc 03049 1356 NtUserValidateHandleSecure (327734, ... ) == 0x1 03050 1356 NtUserValidateHandleSecure (327772, ... ) == 0x1 03051 1356 NtUserQueryWindow (327772, 0, ... ) == 0x6b8 03052 1356 NtUserQueryWindow (327772, 1, ... ) == 0x6bc 03053 1356 NtUserValidateHandleSecure (327772, ... ) == 0x1 03054 1356 NtUserValidateHandleSecure (65726, ... ) == 0x1 03055 1356 NtUserQueryWindow (65726, 0, ... ) == 0x19c 03056 1356 NtUserQueryWindow (65726, 1, ... ) == 0x1a0 03057 1356 NtUserValidateHandleSecure (65726, ... ) == 0x1 03058 1356 NtUserValidateHandleSecure (262398, ... ) == 0x1 03059 1356 NtUserQueryWindow (262398, 0, ... ) == 0x6b8 03060 1356 NtUserQueryWindow (262398, 1, ... ) == 0x6d4 03061 1356 NtUserValidateHandleSecure (262398, ... ) == 0x1 03062 1356 NtUserValidateHandleSecure (65682, ... ) == 0x1 03063 1356 NtUserQueryWindow (65682, 0, ... ) == 0x6b8 03064 1356 NtUserQueryWindow (65682, 1, ... ) == 0x6bc 03065 1356 NtUserValidateHandleSecure (65682, ... ) == 0x1 03066 1356 NtUserValidateHandleSecure (65670, ... ) == 0x1 03067 1356 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 03068 1356 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 03069 1356 NtUserValidateHandleSecure (65670, ... ) == 0x1 03070 1356 NtUserBuildHwndList (0, 65670, 1, 0, 64, ... (0x1008c, 0x1008e, 0x1, ), 3, ) == 0x0 03071 1356 NtUserValidateHandleSecure (65676, ... ) == 0x1 03072 1356 NtUserQueryWindow (65676, 0, ... ) == 0x6b8 03073 1356 NtUserQueryWindow (65676, 1, ... ) == 0x6bc 03074 1356 NtUserValidateHandleSecure (65678, ... ) == 0x1 03075 1356 NtUserQueryWindow (65678, 0, ... ) == 0x6b8 03076 1356 NtUserQueryWindow (65678, 1, ... ) == 0x6bc 03077 1356 NtUserValidateHandleSecure (262196, ... ) == 0x1 03078 1356 NtUserQueryWindow (262196, 0, ... ) == 0x6b8 03079 1356 NtUserQueryWindow (262196, 1, ... ) == 0x6d4 03080 1356 NtUserValidateHandleSecure (262196, ... ) == 0x1 03081 1356 NtUserValidateHandleSecure (327760, ... ) == 0x1 03082 1356 NtUserQueryWindow (327760, 0, ... ) == 0x6b8 03083 1356 NtUserQueryWindow (327760, 1, ... ) == 0x6d4 03084 1356 NtUserValidateHandleSecure (327760, ... ) == 0x1 03085 1356 NtUserValidateHandleSecure (65852, ... ) == 0x1 03086 1356 NtUserQueryWindow (65852, 0, ... ) == 0x22c 03087 1356 NtUserQueryWindow (65852, 1, ... ) == 0x220 03088 1356 NtUserValidateHandleSecure (65852, ... ) == 0x1 03089 1356 NtUserValidateHandleSecure (65824, ... ) == 0x1 03090 1356 NtUserQueryWindow (65824, 0, ... ) == 0x22c 03091 1356 NtUserQueryWindow (65824, 1, ... ) == 0x220 03092 1356 NtUserValidateHandleSecure (65824, ... ) == 0x1 03093 1356 NtUserValidateHandleSecure (65730, ... ) == 0x1 03094 1356 NtUserQueryWindow (65730, 0, ... ) == 0xa0 03095 1356 NtUserQueryWindow (65730, 1, ... ) == 0xe4 03096 1356 NtUserValidateHandleSecure (65730, ... ) == 0x1 03097 1356 NtUserValidateHandleSecure (65724, ... ) == 0x1 03098 1356 NtUserQueryWindow (65724, 0, ... ) == 0xa0 03099 1356 NtUserQueryWindow (65724, 1, ... ) == 0xe4 03100 1356 NtUserValidateHandleSecure (65724, ... ) == 0x1 03101 1356 NtUserValidateHandleSecure (459056, ... ) == 0x1 03102 1356 NtUserQueryWindow (459056, 0, ... ) == 0x150 03103 1356 NtUserQueryWindow (459056, 1, ... ) == 0x1e8 03104 1356 NtUserValidateHandleSecure (459056, ... ) == 0x1 03105 1356 NtUserValidateHandleSecure (131406, ... ) == 0x1 03106 1356 NtUserQueryWindow (131406, 0, ... ) == 0x4b4 03107 1356 NtUserQueryWindow (131406, 1, ... ) == 0x474 03108 1356 NtUserValidateHandleSecure (131406, ... ) == 0x1 03109 1356 NtUserValidateHandleSecure (65752, ... ) == 0x1 03110 1356 NtUserQueryWindow (65752, 0, ... ) == 0x6b8 03111 1356 NtUserQueryWindow (65752, 1, ... ) == 0x13c 03112 1356 NtUserValidateHandleSecure (65752, ... ) == 0x1 03113 1356 NtUserValidateHandleSecure (65718, ... ) == 0x1 03114 1356 NtUserQueryWindow (65718, 0, ... ) == 0x104 03115 1356 NtUserQueryWindow (65718, 1, ... ) == 0x108 03116 1356 NtUserValidateHandleSecure (65718, ... ) == 0x1 03117 1356 NtUserValidateHandleSecure (65720, ... ) == 0x1 03118 1356 NtUserQueryWindow (65720, 0, ... ) == 0x120 03119 1356 NtUserQueryWindow (65720, 1, ... ) == 0x124 03120 1356 NtUserValidateHandleSecure (65720, ... ) == 0x1 03121 1356 NtUserValidateHandleSecure (65716, ... ) == 0x1 03122 1356 NtUserQueryWindow (65716, 0, ... ) == 0xc4 03123 1356 NtUserQueryWindow (65716, 1, ... ) == 0xc8 03124 1356 NtUserValidateHandleSecure (65716, ... ) == 0x1 03125 1356 NtUserValidateHandleSecure (65728, ... ) == 0x1 03126 1356 NtUserQueryWindow (65728, 0, ... ) == 0x19c 03127 1356 NtUserQueryWindow (65728, 1, ... ) == 0x1a0 03128 1356 NtUserValidateHandleSecure (65728, ... ) == 0x1 03129 1356 NtUserValidateHandleSecure (65690, ... ) == 0x1 03130 1356 NtUserQueryWindow (65690, 0, ... ) == 0x6b8 03131 1356 NtUserQueryWindow (65690, 1, ... ) == 0x6bc 03132 1356 NtUserValidateHandleSecure (65690, ... ) == 0x1 03133 1356 NtUserValidateHandleSecure (327774, ... ) == 0x1 03134 1356 NtUserQueryWindow (327774, 0, ... ) == 0x6b8 03135 1356 NtUserQueryWindow (327774, 1, ... ) == 0x6bc 03136 1356 NtUserValidateHandleSecure (327774, ... ) == 0x1 03137 1356 NtUserCloseDesktop (48, ... ) == 0x1 03138 1356 NtUserGetProcessWindowStation (... ) == 0x20 03139 1356 NtUserOpenDesktop ({24, 32, 0x40, 0, 0, ({24, 32, 0x40, 0, 0, "Disconnect"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 03140 1356 NtUserGetProcessWindowStation (... ) == 0x20 03141 1356 NtUserOpenDesktop ({24, 32, 0x40, 0, 0, ({24, 32, 0x40, 0, 0, "Winlogon"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 03142 1356 NtGdiDeleteObjectApp (-368442200, ... ) == 0x1 03143 1356 NtGdiDeleteObjectApp (1812596649, ... ) == 0x1 03144 1356 NtClose (44, ... ) == 0x0 03145 1356 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 03146 1356 NtClose (100, ... ) == 0x0 03147 1356 NtFreeVirtualMemory (-1, (0x990000), 4096, 32768, ... (0x990000), 4096, ) == 0x0 03148 1356 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 100, ) }, ... 100, ) == 0x0 03149 1356 NtQueryValueKey (100, (100, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03150 1356 NtClose (100, ... ) == 0x0 03151 1356 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 2089879920, 2090329280, 1329896, 2089305592} (24, {20, 48, new_msg, 0, 2089879920, 2090329280, 1329896, 2089305592} "\0\0\0\0\3\0\1\0\0@\0\0\2012\221|\0\0\0\0" ... {20, 48, reply, 0, 220, 1356, 75818, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\2012\221|\0\0\0\0" ) ... {20, 48, reply, 0, 220, 1356, 75818, 0} (24, {20, 48, new_msg, 0, 2089879920, 2090329280, 1329896, 2089305592} "\0\0\0\0\3\0\1\0\0@\0\0\2012\221|\0\0\0\0" ... {20, 48, reply, 0, 220, 1356, 75818, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\2012\221|\0\0\0\0" ) ) == 0x0 03152 1356 NtTerminateProcess (-1, 0, ...