Summary:
NtCreateMutant(>) | 1 | NtNotifyChangeKey(>) | 2 | NtOpenProcessToken(>) | 9 | NtOpenFile(>) | 52 |
NtDuplicateToken(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtOpenProcessTokenEx(>) | 11 | NtUnmapViewOfSection(>) | 53 |
NtEnumerateValueKey(>) | 1 | NtQueryPerformanceCounter(>) | 2 | NtOpenThreadTokenEx(>) | 11 | NtOpenSection(>) | 57 |
NtGdiCreateBitmap(>) | 1 | NtSetSecurityObject(>) | 2 | NtQueryDefaultUILanguage(>) | 12 | NtQueryVirtualMemory(>) | 58 |
NtGdiInit(>) | 1 | NtUserGetDC(>) | 2 | NtUserSystemParametersInfo(>) | 12 | NtQueryAttributesFile(>) | 59 |
NtGdiQueryFontAssocInfo(>) | 1 | NtConnectPort(>) | 3 | NtDelayExecution(>) | 13 | NtUserRegisterClassExWOW(>) | 61 |
NtGdiSelectBitmap(>) | 1 | NtDeleteValueKey(>) | 3 | NtQueryInformationFile(>) | 13 | NtCreateSection(>) | 81 |
NtOpenEvent(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtQuerySection(>) | 13 | NtFlushInstructionCache(>) | 90 |
NtOpenKeyedEvent(>) | 1 | NtReleaseSemaphore(>) | 3 | NtQueryDirectoryFile(>) | 14 | NtMapViewOfSection(>) | 114 |
NtOpenSymbolicLinkObject(>) | 1 | NtSecureConnectPort(>) | 3 | NtReadFile(>) | 14 | NtWriteVirtualMemory(>) | 116 |
NtQueryEvent(>) | 1 | NtSetInformationObject(>) | 3 | NtQueryInformationToken(>) | 16 | NtQuerySystemInformation(>) | 122 |
NtQueryInstallUILanguage(>) | 1 | NtUserRegisterWindowMessage(>) | 3 | NtWriteFile(>) | 16 | NtContinue(>) | 135 |
NtQueryObject(>) | 1 | NtWaitForMultipleObjects(>) | 3 | NtSetValueKey(>) | 19 | NtResumeThread(>) | 150 |
NtQuerySymbolicLinkObject(>) | 1 | NtAccessCheck(>) | 4 | NtCreateKey(>) | 20 | NtCreateThread(>) | 153 |
NtQuerySystemTime(>) | 1 | NtEnumerateKey(>) | 4 | NtQueryDebugFilterState(>) | 21 | NtQueryInformationThread(>) | 158 |
NtRaiseException(>) | 1 | NtOpenMutant(>) | 4 | NtSetEventBoostPriority(>) | 26 | NtTestAlert(>) | 163 |
NtSetInformationProcess(>) | 1 | NtSetEvent(>) | 4 | NtFreeVirtualMemory(>) | 29 | NtRegisterThreadTerminatePort(>) | 165 |
NtUserCallNoParam(>) | 1 | NtGdiGetStockObject(>) | 5 | NtOpenProcess(>) | 30 | NtWaitForSingleObject(>) | 171 |
NtUserCallOneParam(>) | 1 | NtCreateSemaphore(>) | 6 | NtFsControlFile(>) | 34 | NtRequestWaitReplyPort(>) | 184 |
NtUserGetThreadDesktop(>) | 1 | NtQueryDefaultLocale(>) | 6 | NtOpenThreadToken(>) | 36 | NtOpenKey(>) | 218 |
NtUserGetThreadState(>) | 1 | NtQueryVolumeInformationFile(>) | 6 | NtCreateFile(>) | 37 | NtQueryValueKey(>) | 257 |
NtAddAtom(>) | 2 | NtQueryInformationProcess(>) | 7 | NtDeviceIoControlFile(>) | 43 | NtSetInformationThread(>) | 282 |
NtCallbackReturn(>) | 2 | NtReleaseMutant(>) | 7 | NtSetInformationFile(>) | 44 | NtProtectVirtualMemory(>) | 452 |
NtCreateIoCompletion(>) | 2 | NtDuplicateObject(>) | 8 | NtCreateEvent(>) | 50 | NtClose(>) | 456 |
NtGdiCreateSolidBrush(>) | 2 | NtAdjustPrivilegesToken(>) | 9 | NtUserFindExistingCursorIcon(>) | 50 | NtAllocateVirtualMemory(>) | 467 |
Iz\212\210\13\221\224\257\377\204\333_FR\226\231\324\253j\353\350\12]\314\257b\4\331\374\357\365\362a\233\16\25\316B7\33\265\225\200|l<\274\202/\247\200\245\368\364ER\210\305\2012\224\345\202X\21\24\16\260\321\22U\270]\356\202g\341J\305\221v$\306\270Ury\221d\3425\365p\246oo{u\340\364wz\21\23 \321\316\15", ) Iz\212\210\13\221\224\257\377\204\333_FR\226\231\324\253j\353\350\12]\314\257b\4\331\374\357\365\362a\233\16\25\316B7\33\265\225\200|l<\274\202/\247\200\245\368\364ER\210\305\2012\224\345\202X\21\24\16\260\321\22U\270]\356\202g\341J\305\221v$\306\270Ury\221d\3425\365p\246oo{u\340\364wz\21\23 \321\316\15", ) == 0x0 02635 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff8e000,Pid=1252,Tid=1336,}, 0x0, ) == 0x0 02637 380 NtSetInformationThread ... ) == 0x0 02642 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81951, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\1\0\0\344\4\0\08\5\0\0" ... ... 02643 1696 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02642 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81952, 0} ... {28, 56, reply, 0, 1252, 896, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\1\0\0\344\4\0\08\5\0\0" ) ) == 0x0 02643 1696 NtCreateEvent ... 392, ) == 0x0 02644 896 NtResumeThread (388, ... 02645 1696 NtOpenThreadToken (-2, 0xc, 1, ... 02644 896 NtResumeThread ... 1, ) == 0x0 02645 1696 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02646 380 NtWaitForSingleObject (252, 0, 0x0, ... 02647 1336 NtTestAlert (... 02648 1696 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02649 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02647 1336 NtTestAlert ... ) == 0x0 02648 1696 NtCreateEvent ... 396, ) == 0x0 02649 896 NtAllocateVirtualMemory ... 49348608, 1048576, ) == 0x0 02650 1336 NtContinue (49347888, 1, ... 02651 896 NtAllocateVirtualMemory (-1, 50388992, 0, 8192, 4096, 4, ... 02652 1336 NtRegisterThreadTerminatePort (24, ... 02651 896 NtAllocateVirtualMemory ... 50388992, 8192, ) == 0x0 02652 1336 NtRegisterThreadTerminatePort ... ) == 0x0 02653 896 NtProtectVirtualMemory (-1, (0x300e000), 4096, 260, ... 02654 1696 NtOpenThreadToken (-2, 0xc, 1, ... 02653 896 NtProtectVirtualMemory ... (0x300e000), 4096, 4, ) == 0x0 02654 1696 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02655 1336 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02656 1696 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02657 1696 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 13693120, (0xc0100080, {24, 0, 0x40, 0, 13693120, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 400, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 400, {status=0x0, info=1}, ) == 0x0 02658 1696 NtSetInformationFile (400, 13693176, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02659 1696 NtSetInformationFile (400, 13693164, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02660 1696 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02661 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02655 1336 NtSetInformationThread ... ) == 0x0 02661 896 NtCreateThread ... 404, {1252, 752}, ) == 0x0 02662 1696 NtWriteFile (400, 277, 0, 0, (400, 277, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... , 72, {0, 0}, 0, ... 02663 896 NtQueryInformationThread (404, Basic, 28, ... 02662 1696 NtWriteFile ... {status=0x0, info=72}, ) == 0x0 02663 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff8d000,Pid=1252,Tid=752,}, 0x0, ) == 0x0 02664 1696 NtReadFile (400, 277, 0, 0, 1024, {0, 0}, 0, ... 02665 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81952, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\1\0\0\344\4\0\0\360\2\0\0" ... ... 02664 1696 NtReadFile ... {status=0x0, info=68}, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20v+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02666 1696 NtFsControlFile (400, 277, 0x0, 0x0, 0x11c017, (400, 277, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\210\367\320\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20v+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (400, 277, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\210\367\320\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20v+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02667 1696 NtFsControlFile (400, 277, 0x0, 0x0, 0x11c017, (400, 277, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\210\0\0\0\2\0\0\0p\0\0\0\0\0D\0\0\0\0\0\347\326\315lv\242\333N\201\354M\352\300h&\31\1\0\0\0\1\0\0\0&\0(\0\230\4\25\0\24\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0u\0t\0h\0o\0r\0i\0t\0y\0\\0s\0y\0s\0t\0e\0m\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 136, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\347\326\315lv\242\333N\201\354M\352\300h&\31\0\0\0\0", ) , 136, 1024, ... {status=0x103, info=48}, (400, 277, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\210\0\0\0\2\0\0\0p\0\0\0\0\0D\0\0\0\0\0\347\326\315lv\242\333N\201\354M\352\300h&\31\1\0\0\0\1\0\0\0&\0(\0\230\4\25\0\24\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0u\0t\0h\0o\0r\0i\0t\0y\0\\0s\0y\0s\0t\0e\0m\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 136, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\347\326\315lv\242\333N\201\354M\352\300h&\31\0\0\0\0", ) , ) == 0x103 02668 1696 NtFsControlFile (400, 277, 0x0, 0x0, 0x11c017, (400, 277, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\347\326\315lv\242\333N\201\354M\352\300h&\31", 44, 1024, ... {status=0x103, info=156}, "\5\0\2\3\20\0\0\0\234\0\0\0\2\0\0\0\204\0\0\0\0\0\0\0\320)\25\0\1\0\0\0\334)\25\0 \0\0\0\1\0\0\0\30\0\32\0\350)\25\0\4*\25\0\15\0\0\0\0\0\0\0\14\0\0\0N\0T\0 \0A\0U\0T\0H\0O\0R\0I\0T\0Y\0\0\0\0\0\1\0\0\0\0\0\0\5\1\0\0\0\250/\25\0\1\0\0\0\5\0i\0\270/\25\0\0\0\0\0\0\0\0\0\1\0\0\0\1\1\0\0\0\0\0\5\22\0\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=156}, (400, 277, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\347\326\315lv\242\333N\201\354M\352\300h&\31", 44, 1024, ... {status=0x103, info=156}, "\5\0\2\3\20\0\0\0\234\0\0\0\2\0\0\0\204\0\0\0\0\0\0\0\320)\25\0\1\0\0\0\334)\25\0 \0\0\0\1\0\0\0\30\0\32\0\350)\25\0\4*\25\0\15\0\0\0\0\0\0\0\14\0\0\0N\0T\0 \0A\0U\0T\0H\0O\0R\0I\0T\0Y\0\0\0\0\0\1\0\0\0\0\0\0\5\1\0\0\0\250/\25\0\1\0\0\0\5\0i\0\270/\25\0\0\0\0\0\0\0\0\0\1\0\0\0\1\1\0\0\0\0\0\5\22\0\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 02669 1696 NtClose (396, ... ) == 0x0 02670 1336 NtWaitForSingleObject (252, 0, 0x0, ... 02665 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81953, 0} ... {28, 56, reply, 0, 1252, 896, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\1\0\0\344\4\0\0\360\2\0\0" ) ) == 0x0 02671 1696 NtClose (400, ... 02672 896 NtResumeThread (404, ... 02671 1696 NtClose ... ) == 0x0 02672 896 NtResumeThread ... 1, ) == 0x0 02673 1696 NtSecureConnectPort ( ("\RPC Control\unimdmsvc", {12, 2, 1, 1}, 0x0, 1373088, 0x0, 13695044, 188, ... , {12, 2, 1, 1}, 0x0, 1373088, 0x0, 13695044, 188, ... 02674 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02673 1696 NtSecureConnectPort ... 400, 0x0, 0x0, 0x0, 188, ) == 0x0 02674 896 NtAllocateVirtualMemory ... 50397184, 1048576, ) == 0x0 02675 1696 NtOpenThreadToken (-2, 0xc, 1, ... 02676 896 NtAllocateVirtualMemory (-1, 51437568, 0, 8192, 4096, 4, ... 02677 752 NtTestAlert (... 02675 1696 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02677 752 NtTestAlert ... ) == 0x0 02678 1696 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02679 752 NtContinue (50396464, 1, ... 02678 1696 NtSetInformationThread ... ) == 0x0 02680 752 NtRegisterThreadTerminatePort (24, ... 02681 1696 NtRequestWaitReplyPort (400, {200, 224, new_msg, 0, 1372480, 12, 2, 1310977} (400, {200, 224, new_msg, 0, 1372480, 12, 2, 1310977} "\0\0\0\0\274\0\0\0\0\0\0\03\242t\326)X\335I\220\360`\317\234\353q)\1\0\0\0\1\0\0\0\230`\347w\26\0\0\0\2\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\320\202y(\214mzh\244\252W#\216<9b\12\0\0\0d\215\326^\325\1\73\0\0\0\0\360\5\25\0`\4s\226\370n\31\372(\0\0\0\303l\0\15\0\0\24\0\240\366\320\0\272/d\17\0\0\0\0\210#\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\320\0\372\31\221|X\376\320\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... ... 02680 752 NtRegisterThreadTerminatePort ... ) == 0x0 02681 1696 NtRequestWaitReplyPort ... {200, 224, reply, 0, 1252, 1696, 81955, 0} ... {200, 224, reply, 0, 1252, 1696, 81955, 0} "\7\0\0\0\274\0\0\0\0\0\0\03\242t\326)X\335I\220\360`\317\234\353q)\1\0\0\0\1\0\0\0\0\0\0\0\26\0\0\0\2\0\0\0\0\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\320\202y(\214mzh\244\252W#\216<9b\12\0\0\0d\215\326^\325\1\73\0\0\0\0\360\5\25\0`\4s\226\370n\31\372(\0\0\0\303l\0\15\0\0\24\0\240\366\320\0\272/d\17\0\0\0\0\210#\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\320\0\372\31\221|X\376\320\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 02676 896 NtAllocateVirtualMemory ... 51437568, 8192, ) == 0x0 02682 752 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02683 896 NtProtectVirtualMemory (-1, (0x310e000), 4096, 260, ... (0x310e000), 4096, 4, ) == 0x0 02684 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 396, {1252, 1564}, ) == 0x0 02685 896 NtQueryInformationThread (396, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff8c000,Pid=1252,Tid=1564,}, 0x0, ) == 0x0 02686 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81953, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\1\0\0\344\4\0\0\34\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\1\0\0\344\4\0\0\34\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81956, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\1\0\0\344\4\0\0\34\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\1\0\0\344\4\0\0\34\6\0\0" ) ) == 0x0 02687 896 NtResumeThread (396, ... 1, ) == 0x0 02688 1696 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02682 752 NtSetInformationThread ... ) == 0x0 02689 1564 NtTestAlert (... 02688 1696 NtSetInformationThread ... ) == 0x0 02690 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02689 1564 NtTestAlert ... ) == 0x0 02691 1696 NtRequestWaitReplyPort (400, {56, 80, new_msg, 0, 44, 3, 20, 0} (400, {56, 80, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\2\0v\242\333N\201\354M\352\300h&\31\1\0\0\0\0\0\0\0&\0(\0(\1\0\0\0\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0" ... ... 02690 896 NtAllocateVirtualMemory ... 51445760, 1048576, ) == 0x0 02692 1564 NtContinue (51445040, 1, ... 02693 896 NtAllocateVirtualMemory (-1, 52486144, 0, 8192, 4096, 4, ... 02694 1564 NtRegisterThreadTerminatePort (24, ... 02693 896 NtAllocateVirtualMemory ... 52486144, 8192, ) == 0x0 02694 1564 NtRegisterThreadTerminatePort ... ) == 0x0 02695 896 NtProtectVirtualMemory (-1, (0x320e000), 4096, 260, ... 02696 752 NtWaitForSingleObject (252, 0, 0x0, ... 02695 896 NtProtectVirtualMemory ... (0x320e000), 4096, 4, ) == 0x0 02697 1564 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... ) == 0x0 02698 1564 NtWaitForSingleObject (252, 0, 0x0, ... 02699 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 408, {1252, 1964}, ) == 0x0 02700 896 NtQueryInformationThread (408, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff8b000,Pid=1252,Tid=1964,}, 0x0, ) == 0x0 02701 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81956, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\1\0\0\344\4\0\0\254\7\0\0" ... ... 02691 1696 NtRequestWaitReplyPort ... {44, 68, reply, 0, 1252, 1696, 81957, 0} ... {44, 68, reply, 0, 1252, 1696, 81957, 0} "\4\376\255\201\0\0\0\0\200Y\274\201\356\12$\342\264\311\275\201:\332R\200X\253v\367\324\376\255\201\2\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 02702 1696 NtRaiseException (13695504, 13694764, 1, ... 02703 1696 NtQueryVirtualMemory (-1, 0x77e7a298, Basic, 28, ... {BaseAddress=0x77e7a000,AllocationBase=0x77e70000,AllocationProtect=0x80,RegionSize=0x80000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 02704 1696 NtContinue (13693732, 0, ... 02705 1696 NtDeviceIoControlFile (296, 236, 0x0, 0x0, 0x1200c, 0x0, 0, 26, ... {status=0x0, info=0}, "", ) == 0x103 02706 1696 NtWaitForSingleObject (236, 1, {-5000000, -1}, ... 02701 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81958, 0} ... {28, 56, reply, 0, 1252, 896, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\1\0\0\344\4\0\0\254\7\0\0" ) ) == 0x0 02707 896 NtResumeThread (408, ... 1, ) == 0x0 02708 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 52494336, 1048576, ) == 0x0 02709 896 NtAllocateVirtualMemory (-1, 53534720, 0, 8192, 4096, 4, ... 53534720, 8192, ) == 0x0 02710 896 NtProtectVirtualMemory (-1, (0x330e000), 4096, 260, ... (0x330e000), 4096, 4, ) == 0x0 02711 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 412, {1252, 1624}, ) == 0x0 02712 896 NtQueryInformationThread (412, Basic, 28, ... 02713 1964 NtTestAlert (... ) == 0x0 02714 1964 NtContinue (52493616, 1, ... 02715 1964 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02716 1964 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02712 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff8a000,Pid=1252,Tid=1624,}, 0x0, ) == 0x0 02717 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81958, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\1\0\0\344\4\0\0X\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\1\0\0\344\4\0\0X\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81959, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\1\0\0\344\4\0\0X\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\1\0\0\344\4\0\0X\6\0\0" ) ) == 0x0 02718 896 NtResumeThread (412, ... 1, ) == 0x0 02719 1624 NtTestAlert (... ) == 0x0 02720 1624 NtContinue (53542192, 1, ... 02721 1624 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02722 1624 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02723 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 53542912, 1048576, ) == 0x0 02724 896 NtAllocateVirtualMemory (-1, 54583296, 0, 8192, 4096, 4, ... 54583296, 8192, ) == 0x0 02725 896 NtProtectVirtualMemory (-1, (0x340e000), 4096, 260, ... (0x340e000), 4096, 4, ) == 0x0 02726 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 416, {1252, 1440}, ) == 0x0 02727 896 NtQueryInformationThread (416, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff89000,Pid=1252,Tid=1440,}, 0x0, ) == 0x0 02728 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81959, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\1\0\0\344\4\0\0\240\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\1\0\0\344\4\0\0\240\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81960, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\1\0\0\344\4\0\0\240\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\1\0\0\344\4\0\0\240\5\0\0" ) ) == 0x0 02729 896 NtResumeThread (416, ... 1, ) == 0x0 02730 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 54591488, 1048576, ) == 0x0 02731 896 NtAllocateVirtualMemory (-1, 55631872, 0, 8192, 4096, 4, ... 02732 1440 NtTestAlert (... ) == 0x0 02733 1440 NtContinue (54590768, 1, ... 02734 1440 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02735 1440 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02731 896 NtAllocateVirtualMemory ... 55631872, 8192, ) == 0x0 02736 896 NtProtectVirtualMemory (-1, (0x350e000), 4096, 260, ... (0x350e000), 4096, 4, ) == 0x0 02737 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 420, {1252, 1972}, ) == 0x0 02738 896 NtQueryInformationThread (420, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff88000,Pid=1252,Tid=1972,}, 0x0, ) == 0x0 02739 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81960, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\1\0\0\344\4\0\0\264\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\1\0\0\344\4\0\0\264\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81961, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\1\0\0\344\4\0\0\264\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\1\0\0\344\4\0\0\264\7\0\0" ) ) == 0x0 02740 896 NtResumeThread (420, ... 1, ) == 0x0 02741 1972 NtTestAlert (... ) == 0x0 02742 1972 NtContinue (55639344, 1, ... 02743 1972 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02744 1972 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02745 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 55640064, 1048576, ) == 0x0 02746 896 NtAllocateVirtualMemory (-1, 56680448, 0, 8192, 4096, 4, ... 56680448, 8192, ) == 0x0 02747 896 NtProtectVirtualMemory (-1, (0x360e000), 4096, 260, ... (0x360e000), 4096, 4, ) == 0x0 02748 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 424, {1252, 1036}, ) == 0x0 02749 896 NtQueryInformationThread (424, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff87000,Pid=1252,Tid=1036,}, 0x0, ) == 0x0 02750 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81961, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\1\0\0\344\4\0\0\14\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\1\0\0\344\4\0\0\14\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81962, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\1\0\0\344\4\0\0\14\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\1\0\0\344\4\0\0\14\4\0\0" ) ) == 0x0 02751 896 NtResumeThread (424, ... 1, ) == 0x0 02752 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 56688640, 1048576, ) == 0x0 02753 896 NtAllocateVirtualMemory (-1, 57729024, 0, 8192, 4096, 4, ... 02754 1036 NtTestAlert (... ) == 0x0 02755 1036 NtContinue (56687920, 1, ... 02756 1036 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02757 1036 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02753 896 NtAllocateVirtualMemory ... 57729024, 8192, ) == 0x0 02758 896 NtProtectVirtualMemory (-1, (0x370e000), 4096, 260, ... (0x370e000), 4096, 4, ) == 0x0 02759 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 428, {1252, 1664}, ) == 0x0 02760 896 NtQueryInformationThread (428, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff86000,Pid=1252,Tid=1664,}, 0x0, ) == 0x0 02761 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81962, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\1\0\0\344\4\0\0\200\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\1\0\0\344\4\0\0\200\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81963, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\1\0\0\344\4\0\0\200\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\1\0\0\344\4\0\0\200\6\0\0" ) ) == 0x0 02762 896 NtResumeThread (428, ... 1, ) == 0x0 02763 1664 NtTestAlert (... ) == 0x0 02764 1664 NtContinue (57736496, 1, ... 02765 1664 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02766 1664 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02767 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 57737216, 1048576, ) == 0x0 02768 896 NtAllocateVirtualMemory (-1, 58777600, 0, 8192, 4096, 4, ... 58777600, 8192, ) == 0x0 02769 896 NtProtectVirtualMemory (-1, (0x380e000), 4096, 260, ... (0x380e000), 4096, 4, ) == 0x0 02770 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 432, {1252, 1248}, ) == 0x0 02771 896 NtQueryInformationThread (432, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff85000,Pid=1252,Tid=1248,}, 0x0, ) == 0x0 02772 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81963, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0\340\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0\340\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81964, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0\340\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\1\0\0\344\4\0\0\340\4\0\0" ) ) == 0x0 02773 896 NtResumeThread (432, ... 1, ) == 0x0 02774 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 58785792, 1048576, ) == 0x0 02775 896 NtAllocateVirtualMemory (-1, 59826176, 0, 8192, 4096, 4, ... 02776 1248 NtTestAlert (... ) == 0x0 02777 1248 NtContinue (58785072, 1, ... 02778 1248 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02779 1248 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02775 896 NtAllocateVirtualMemory ... 59826176, 8192, ) == 0x0 02780 896 NtProtectVirtualMemory (-1, (0x390e000), 4096, 260, ... (0x390e000), 4096, 4, ) == 0x0 02781 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 436, {1252, 1656}, ) == 0x0 02782 896 NtQueryInformationThread (436, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff84000,Pid=1252,Tid=1656,}, 0x0, ) == 0x0 02783 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81964, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0x\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0x\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81965, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0x\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\1\0\0\344\4\0\0x\6\0\0" ) ) == 0x0 02784 896 NtResumeThread (436, ... 1, ) == 0x0 02785 1656 NtTestAlert (... ) == 0x0 02786 1656 NtContinue (59833648, 1, ... 02787 1656 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02788 1656 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02789 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 59834368, 1048576, ) == 0x0 02790 896 NtAllocateVirtualMemory (-1, 60874752, 0, 8192, 4096, 4, ... 60874752, 8192, ) == 0x0 02791 896 NtProtectVirtualMemory (-1, (0x3a0e000), 4096, 260, ... (0x3a0e000), 4096, 4, ) == 0x0 02792 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 440, {1252, 760}, ) == 0x0 02793 896 NtQueryInformationThread (440, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff83000,Pid=1252,Tid=760,}, 0x0, ) == 0x0 02794 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81965, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\370\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\370\2\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81966, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\370\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\1\0\0\344\4\0\0\370\2\0\0" ) ) == 0x0 02795 896 NtResumeThread (440, ... 1, ) == 0x0 02796 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 60882944, 1048576, ) == 0x0 02797 896 NtAllocateVirtualMemory (-1, 61923328, 0, 8192, 4096, 4, ... 02798 760 NtTestAlert (... ) == 0x0 02799 760 NtContinue (60882224, 1, ... 02800 760 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02801 760 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02797 896 NtAllocateVirtualMemory ... 61923328, 8192, ) == 0x0 02802 896 NtProtectVirtualMemory (-1, (0x3b0e000), 4096, 260, ... (0x3b0e000), 4096, 4, ) == 0x0 02803 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 444, {1252, 484}, ) == 0x0 02804 896 NtQueryInformationThread (444, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff82000,Pid=1252,Tid=484,}, 0x0, ) == 0x0 02805 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81966, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0\344\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0\344\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81967, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0\344\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\1\0\0\344\4\0\0\344\1\0\0" ) ) == 0x0 02806 896 NtResumeThread (444, ... 1, ) == 0x0 02807 484 NtTestAlert (... ) == 0x0 02808 484 NtContinue (61930800, 1, ... 02809 484 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02810 484 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02811 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 61931520, 1048576, ) == 0x0 02812 896 NtAllocateVirtualMemory (-1, 62971904, 0, 8192, 4096, 4, ... 62971904, 8192, ) == 0x0 02813 896 NtProtectVirtualMemory (-1, (0x3c0e000), 4096, 260, ... (0x3c0e000), 4096, 4, ) == 0x0 02814 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 448, {1252, 1580}, ) == 0x0 02815 896 NtQueryInformationThread (448, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff81000,Pid=1252,Tid=1580,}, 0x0, ) == 0x0 02816 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81967, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\1\0\0\344\4\0\0,\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\1\0\0\344\4\0\0,\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81968, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\1\0\0\344\4\0\0,\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\1\0\0\344\4\0\0,\6\0\0" ) ) == 0x0 02817 896 NtResumeThread (448, ... 1, ) == 0x0 02818 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 62980096, 1048576, ) == 0x0 02819 896 NtAllocateVirtualMemory (-1, 64020480, 0, 8192, 4096, 4, ... 02820 1580 NtAllocateVirtualMemory (-1, 3629056, 0, 4096, 4096, 4, ... 3629056, 4096, ) == 0x0 02821 1580 NtTestAlert (... ) == 0x0 02822 1580 NtContinue (62979376, 1, ... 02823 1580 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02824 1580 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02819 896 NtAllocateVirtualMemory ... 64020480, 8192, ) == 0x0 02825 896 NtProtectVirtualMemory (-1, (0x3d0e000), 4096, 260, ... (0x3d0e000), 4096, 4, ) == 0x0 02826 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 452, {1252, 1756}, ) == 0x0 02827 896 NtQueryInformationThread (452, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff80000,Pid=1252,Tid=1756,}, 0x0, ) == 0x0 02828 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81968, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\1\0\0\344\4\0\0\334\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\1\0\0\344\4\0\0\334\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81969, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\1\0\0\344\4\0\0\334\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\1\0\0\344\4\0\0\334\6\0\0" ) ) == 0x0 02829 896 NtResumeThread (452, ... 1, ) == 0x0 02830 1756 NtTestAlert (... ) == 0x0 02831 1756 NtContinue (64027952, 1, ... 02832 1756 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02833 1756 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02834 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 64028672, 1048576, ) == 0x0 02835 896 NtAllocateVirtualMemory (-1, 65069056, 0, 8192, 4096, 4, ... 65069056, 8192, ) == 0x0 02836 896 NtProtectVirtualMemory (-1, (0x3e0e000), 4096, 260, ... (0x3e0e000), 4096, 4, ) == 0x0 02837 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 456, {1252, 1304}, ) == 0x0 02838 896 NtQueryInformationThread (456, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7f000,Pid=1252,Tid=1304,}, 0x0, ) == 0x0 02839 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81969, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\1\0\0\344\4\0\0\30\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\1\0\0\344\4\0\0\30\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81970, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\1\0\0\344\4\0\0\30\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\1\0\0\344\4\0\0\30\5\0\0" ) ) == 0x0 02840 896 NtResumeThread (456, ... 1, ) == 0x0 02841 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 65077248, 1048576, ) == 0x0 02842 896 NtAllocateVirtualMemory (-1, 66117632, 0, 8192, 4096, 4, ... 02843 1304 NtTestAlert (... ) == 0x0 02844 1304 NtContinue (65076528, 1, ... 02845 1304 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02846 1304 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02842 896 NtAllocateVirtualMemory ... 66117632, 8192, ) == 0x0 02847 896 NtProtectVirtualMemory (-1, (0x3f0e000), 4096, 260, ... (0x3f0e000), 4096, 4, ) == 0x0 02848 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 460, {1252, 1292}, ) == 0x0 02849 896 NtQueryInformationThread (460, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7e000,Pid=1252,Tid=1292,}, 0x0, ) == 0x0 02850 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81970, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\1\0\0\344\4\0\0\14\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\1\0\0\344\4\0\0\14\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81971, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\1\0\0\344\4\0\0\14\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\1\0\0\344\4\0\0\14\5\0\0" ) ) == 0x0 02851 896 NtResumeThread (460, ... 1, ) == 0x0 02852 1292 NtTestAlert (... ) == 0x0 02853 1292 NtContinue (66125104, 1, ... 02854 1292 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02855 1292 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02856 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 66125824, 1048576, ) == 0x0 02857 896 NtAllocateVirtualMemory (-1, 67166208, 0, 8192, 4096, 4, ... 67166208, 8192, ) == 0x0 02858 896 NtProtectVirtualMemory (-1, (0x400e000), 4096, 260, ... (0x400e000), 4096, 4, ) == 0x0 02859 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 464, {1252, 1956}, ) == 0x0 02860 896 NtQueryInformationThread (464, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7d000,Pid=1252,Tid=1956,}, 0x0, ) == 0x0 02861 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81971, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\1\0\0\344\4\0\0\244\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\1\0\0\344\4\0\0\244\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81972, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\1\0\0\344\4\0\0\244\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\1\0\0\344\4\0\0\244\7\0\0" ) ) == 0x0 02862 896 NtResumeThread (464, ... 1, ) == 0x0 02863 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 67174400, 1048576, ) == 0x0 02864 896 NtAllocateVirtualMemory (-1, 68214784, 0, 8192, 4096, 4, ... 02865 1956 NtTestAlert (... ) == 0x0 02866 1956 NtContinue (67173680, 1, ... 02867 1956 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02868 1956 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02864 896 NtAllocateVirtualMemory ... 68214784, 8192, ) == 0x0 02869 896 NtProtectVirtualMemory (-1, (0x410e000), 4096, 260, ... (0x410e000), 4096, 4, ) == 0x0 02870 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 468, {1252, 1556}, ) == 0x0 02871 896 NtQueryInformationThread (468, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7c000,Pid=1252,Tid=1556,}, 0x0, ) == 0x0 02872 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81972, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\1\0\0\344\4\0\0\24\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\1\0\0\344\4\0\0\24\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81973, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\1\0\0\344\4\0\0\24\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\1\0\0\344\4\0\0\24\6\0\0" ) ) == 0x0 02873 896 NtResumeThread (468, ... 1, ) == 0x0 02874 1556 NtTestAlert (... ) == 0x0 02875 1556 NtContinue (68222256, 1, ... 02876 1556 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02877 1556 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02878 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 68222976, 1048576, ) == 0x0 02879 896 NtAllocateVirtualMemory (-1, 69263360, 0, 8192, 4096, 4, ... 69263360, 8192, ) == 0x0 02880 896 NtProtectVirtualMemory (-1, (0x420e000), 4096, 260, ... (0x420e000), 4096, 4, ) == 0x0 02881 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 472, {1252, 1480}, ) == 0x0 02882 896 NtQueryInformationThread (472, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7b000,Pid=1252,Tid=1480,}, 0x0, ) == 0x0 02883 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81973, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\1\0\0\344\4\0\0\310\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\1\0\0\344\4\0\0\310\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81974, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\1\0\0\344\4\0\0\310\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\1\0\0\344\4\0\0\310\5\0\0" ) ) == 0x0 02884 896 NtResumeThread (472, ... 1, ) == 0x0 02885 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 69271552, 1048576, ) == 0x0 02886 896 NtAllocateVirtualMemory (-1, 70311936, 0, 8192, 4096, 4, ... 02887 1480 NtTestAlert (... ) == 0x0 02888 1480 NtContinue (69270832, 1, ... 02889 1480 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02890 1480 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02886 896 NtAllocateVirtualMemory ... 70311936, 8192, ) == 0x0 02891 896 NtProtectVirtualMemory (-1, (0x430e000), 4096, 260, ... (0x430e000), 4096, 4, ) == 0x0 02892 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 476, {1252, 1784}, ) == 0x0 02893 896 NtQueryInformationThread (476, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7a000,Pid=1252,Tid=1784,}, 0x0, ) == 0x0 02894 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81974, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\1\0\0\344\4\0\0\370\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\1\0\0\344\4\0\0\370\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81975, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\1\0\0\344\4\0\0\370\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\1\0\0\344\4\0\0\370\6\0\0" ) ) == 0x0 02895 896 NtResumeThread (476, ... 1, ) == 0x0 02896 1784 NtTestAlert (... ) == 0x0 02897 1784 NtContinue (70319408, 1, ... 02898 1784 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02899 1784 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02900 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 70320128, 1048576, ) == 0x0 02901 896 NtAllocateVirtualMemory (-1, 71360512, 0, 8192, 4096, 4, ... 71360512, 8192, ) == 0x0 02902 896 NtProtectVirtualMemory (-1, (0x440e000), 4096, 260, ... (0x440e000), 4096, 4, ) == 0x0 02903 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 480, {1252, 1856}, ) == 0x0 02904 896 NtQueryInformationThread (480, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff79000,Pid=1252,Tid=1856,}, 0x0, ) == 0x0 02905 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81975, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\1\0\0\344\4\0\0@\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\1\0\0\344\4\0\0@\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81976, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\1\0\0\344\4\0\0@\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\1\0\0\344\4\0\0@\7\0\0" ) ) == 0x0 02906 896 NtResumeThread (480, ... 1, ) == 0x0 02907 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 71368704, 1048576, ) == 0x0 02908 896 NtAllocateVirtualMemory (-1, 72409088, 0, 8192, 4096, 4, ... 02909 1856 NtTestAlert (... ) == 0x0 02910 1856 NtContinue (71367984, 1, ... 02911 1856 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02912 1856 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02908 896 NtAllocateVirtualMemory ... 72409088, 8192, ) == 0x0 02913 896 NtProtectVirtualMemory (-1, (0x450e000), 4096, 260, ... (0x450e000), 4096, 4, ) == 0x0 02914 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 484, {1252, 1604}, ) == 0x0 02915 896 NtQueryInformationThread (484, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff78000,Pid=1252,Tid=1604,}, 0x0, ) == 0x0 02916 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81976, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\1\0\0\344\4\0\0D\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\1\0\0\344\4\0\0D\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81977, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\1\0\0\344\4\0\0D\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\1\0\0\344\4\0\0D\6\0\0" ) ) == 0x0 02917 896 NtResumeThread (484, ... 1, ) == 0x0 02918 1604 NtTestAlert (... ) == 0x0 02919 1604 NtContinue (72416560, 1, ... 02920 1604 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02921 1604 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02922 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 72417280, 1048576, ) == 0x0 02923 896 NtAllocateVirtualMemory (-1, 73457664, 0, 8192, 4096, 4, ... 73457664, 8192, ) == 0x0 02924 896 NtProtectVirtualMemory (-1, (0x460e000), 4096, 260, ... (0x460e000), 4096, 4, ) == 0x0 02925 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 488, {1252, 1272}, ) == 0x0 02926 896 NtQueryInformationThread (488, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff77000,Pid=1252,Tid=1272,}, 0x0, ) == 0x0 02927 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81977, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\1\0\0\344\4\0\0\370\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\1\0\0\344\4\0\0\370\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81978, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\1\0\0\344\4\0\0\370\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\1\0\0\344\4\0\0\370\4\0\0" ) ) == 0x0 02928 896 NtResumeThread (488, ... 1, ) == 0x0 02929 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 73465856, 1048576, ) == 0x0 02930 896 NtAllocateVirtualMemory (-1, 74506240, 0, 8192, 4096, 4, ... 02931 1272 NtTestAlert (... ) == 0x0 02932 1272 NtContinue (73465136, 1, ... 02933 1272 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02934 1272 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02930 896 NtAllocateVirtualMemory ... 74506240, 8192, ) == 0x0 02935 896 NtProtectVirtualMemory (-1, (0x470e000), 4096, 260, ... (0x470e000), 4096, 4, ) == 0x0 02936 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 492, {1252, 1132}, ) == 0x0 02937 896 NtQueryInformationThread (492, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff76000,Pid=1252,Tid=1132,}, 0x0, ) == 0x0 02938 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81978, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\1\0\0\344\4\0\0l\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\1\0\0\344\4\0\0l\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81979, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\1\0\0\344\4\0\0l\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\1\0\0\344\4\0\0l\4\0\0" ) ) == 0x0 02939 896 NtResumeThread (492, ... 1, ) == 0x0 02940 1132 NtTestAlert (... ) == 0x0 02941 1132 NtContinue (74513712, 1, ... 02942 1132 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02943 1132 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02944 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 74514432, 1048576, ) == 0x0 02945 896 NtAllocateVirtualMemory (-1, 75554816, 0, 8192, 4096, 4, ... 75554816, 8192, ) == 0x0 02946 896 NtProtectVirtualMemory (-1, (0x480e000), 4096, 260, ... (0x480e000), 4096, 4, ) == 0x0 02947 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 496, {1252, 184}, ) == 0x0 02948 896 NtQueryInformationThread (496, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff75000,Pid=1252,Tid=184,}, 0x0, ) == 0x0 02949 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81979, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\1\0\0\344\4\0\0\270\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\1\0\0\344\4\0\0\270\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81980, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\1\0\0\344\4\0\0\270\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\1\0\0\344\4\0\0\270\0\0\0" ) ) == 0x0 02950 896 NtResumeThread (496, ... 1, ) == 0x0 02951 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 75563008, 1048576, ) == 0x0 02952 896 NtAllocateVirtualMemory (-1, 76603392, 0, 8192, 4096, 4, ... 02953 184 NtTestAlert (... ) == 0x0 02954 184 NtContinue (75562288, 1, ... 02955 184 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02956 184 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02952 896 NtAllocateVirtualMemory ... 76603392, 8192, ) == 0x0 02957 896 NtProtectVirtualMemory (-1, (0x490e000), 4096, 260, ... (0x490e000), 4096, 4, ) == 0x0 02958 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 500, {1252, 1064}, ) == 0x0 02959 896 NtQueryInformationThread (500, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff74000,Pid=1252,Tid=1064,}, 0x0, ) == 0x0 02960 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81980, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\1\0\0\344\4\0\0(\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\1\0\0\344\4\0\0(\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81981, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\1\0\0\344\4\0\0(\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\1\0\0\344\4\0\0(\4\0\0" ) ) == 0x0 02961 896 NtResumeThread (500, ... 1, ) == 0x0 02962 1064 NtTestAlert (... ) == 0x0 02963 1064 NtContinue (76610864, 1, ... 02964 1064 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02965 1064 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02966 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 76611584, 1048576, ) == 0x0 02967 896 NtAllocateVirtualMemory (-1, 77651968, 0, 8192, 4096, 4, ... 77651968, 8192, ) == 0x0 02968 896 NtProtectVirtualMemory (-1, (0x4a0e000), 4096, 260, ... (0x4a0e000), 4096, 4, ) == 0x0 02969 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 504, {1252, 1384}, ) == 0x0 02970 896 NtQueryInformationThread (504, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff73000,Pid=1252,Tid=1384,}, 0x0, ) == 0x0 02971 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81981, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0h\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0h\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81982, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0h\5\0\0" ... {28, 56, reply, 0, 1252, 896, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\1\0\0\344\4\0\0h\5\0\0" ) ) == 0x0 02972 896 NtResumeThread (504, ... 1, ) == 0x0 02973 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 77660160, 1048576, ) == 0x0 02974 896 NtAllocateVirtualMemory (-1, 78700544, 0, 8192, 4096, 4, ... 02975 1384 NtTestAlert (... ) == 0x0 02976 1384 NtContinue (77659440, 1, ... 02977 1384 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02978 1384 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02974 896 NtAllocateVirtualMemory ... 78700544, 8192, ) == 0x0 02979 896 NtProtectVirtualMemory (-1, (0x4b0e000), 4096, 260, ... (0x4b0e000), 4096, 4, ) == 0x0 02980 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 508, {1252, 1240}, ) == 0x0 02981 896 NtQueryInformationThread (508, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff72000,Pid=1252,Tid=1240,}, 0x0, ) == 0x0 02982 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81982, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\1\0\0\344\4\0\0\330\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\1\0\0\344\4\0\0\330\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81983, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\1\0\0\344\4\0\0\330\4\0\0" ... {28, 56, reply, 0, 1252, 896, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\1\0\0\344\4\0\0\330\4\0\0" ) ) == 0x0 02983 896 NtResumeThread (508, ... 1, ) == 0x0 02984 1240 NtTestAlert (... ) == 0x0 02985 1240 NtContinue (78708016, 1, ... 02986 1240 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02987 1240 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02988 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 78708736, 1048576, ) == 0x0 02989 896 NtAllocateVirtualMemory (-1, 79749120, 0, 8192, 4096, 4, ... 79749120, 8192, ) == 0x0 02990 896 NtProtectVirtualMemory (-1, (0x4c0e000), 4096, 260, ... (0x4c0e000), 4096, 4, ) == 0x0 02991 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 512, {1252, 296}, ) == 0x0 02992 896 NtQueryInformationThread (512, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff71000,Pid=1252,Tid=296,}, 0x0, ) == 0x0 02993 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81983, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0(\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0(\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81984, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0(\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\2\0\0\344\4\0\0(\1\0\0" ) ) == 0x0 02994 896 NtResumeThread (512, ... 1, ) == 0x0 02995 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 79757312, 1048576, ) == 0x0 02996 896 NtAllocateVirtualMemory (-1, 80797696, 0, 8192, 4096, 4, ... 02997 296 NtTestAlert (... ) == 0x0 02998 296 NtContinue (79756592, 1, ... 02999 296 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03000 296 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02996 896 NtAllocateVirtualMemory ... 80797696, 8192, ) == 0x0 03001 896 NtProtectVirtualMemory (-1, (0x4d0e000), 4096, 260, ... (0x4d0e000), 4096, 4, ) == 0x0 03002 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 516, {1252, 740}, ) == 0x0 03003 896 NtQueryInformationThread (516, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff70000,Pid=1252,Tid=740,}, 0x0, ) == 0x0 03004 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81984, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\2\0\0\344\4\0\0\344\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\2\0\0\344\4\0\0\344\2\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81985, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\2\0\0\344\4\0\0\344\2\0\0" ... {28, 56, reply, 0, 1252, 896, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\2\0\0\344\4\0\0\344\2\0\0" ) ) == 0x0 03005 896 NtResumeThread (516, ... 1, ) == 0x0 03006 740 NtTestAlert (... ) == 0x0 03007 740 NtContinue (80805168, 1, ... 03008 740 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03009 740 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03010 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 80805888, 1048576, ) == 0x0 03011 896 NtAllocateVirtualMemory (-1, 81846272, 0, 8192, 4096, 4, ... 81846272, 8192, ) == 0x0 03012 896 NtProtectVirtualMemory (-1, (0x4e0e000), 4096, 260, ... (0x4e0e000), 4096, 4, ) == 0x0 03013 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 520, {1252, 120}, ) == 0x0 03014 896 NtQueryInformationThread (520, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6f000,Pid=1252,Tid=120,}, 0x0, ) == 0x0 03015 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81985, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\2\0\0\344\4\0\0x\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\2\0\0\344\4\0\0x\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81986, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\2\0\0\344\4\0\0x\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\2\0\0\344\4\0\0x\0\0\0" ) ) == 0x0 03016 896 NtResumeThread (520, ... 1, ) == 0x0 03017 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 81854464, 1048576, ) == 0x0 03018 896 NtAllocateVirtualMemory (-1, 82894848, 0, 8192, 4096, 4, ... 03019 120 NtTestAlert (... ) == 0x0 03020 120 NtContinue (81853744, 1, ... 03021 120 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03022 120 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03018 896 NtAllocateVirtualMemory ... 82894848, 8192, ) == 0x0 03023 896 NtProtectVirtualMemory (-1, (0x4f0e000), 4096, 260, ... (0x4f0e000), 4096, 4, ) == 0x0 03024 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 524, {1252, 1796}, ) == 0x0 03025 896 NtQueryInformationThread (524, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6e000,Pid=1252,Tid=1796,}, 0x0, ) == 0x0 03026 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81986, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\2\0\0\344\4\0\0\4\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\2\0\0\344\4\0\0\4\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81987, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\2\0\0\344\4\0\0\4\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\2\0\0\344\4\0\0\4\7\0\0" ) ) == 0x0 03027 896 NtResumeThread (524, ... 1, ) == 0x0 03028 1796 NtTestAlert (... ) == 0x0 03029 1796 NtContinue (82902320, 1, ... 03030 1796 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03031 1796 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03032 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 82903040, 1048576, ) == 0x0 03033 896 NtAllocateVirtualMemory (-1, 83943424, 0, 8192, 4096, 4, ... 83943424, 8192, ) == 0x0 03034 896 NtProtectVirtualMemory (-1, (0x500e000), 4096, 260, ... (0x500e000), 4096, 4, ) == 0x0 03035 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 528, {1252, 1728}, ) == 0x0 03036 896 NtQueryInformationThread (528, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6d000,Pid=1252,Tid=1728,}, 0x0, ) == 0x0 03037 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81987, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\300\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\300\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81988, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\300\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\2\0\0\344\4\0\0\300\6\0\0" ) ) == 0x0 03038 896 NtResumeThread (528, ... 1, ) == 0x0 03039 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 83951616, 1048576, ) == 0x0 03040 896 NtAllocateVirtualMemory (-1, 84992000, 0, 8192, 4096, 4, ... 03041 1728 NtTestAlert (... ) == 0x0 03042 1728 NtContinue (83950896, 1, ... 03043 1728 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03044 1728 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03040 896 NtAllocateVirtualMemory ... 84992000, 8192, ) == 0x0 03045 896 NtProtectVirtualMemory (-1, (0x510e000), 4096, 260, ... (0x510e000), 4096, 4, ) == 0x0 03046 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 532, {1252, 152}, ) == 0x0 03047 896 NtQueryInformationThread (532, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6c000,Pid=1252,Tid=152,}, 0x0, ) == 0x0 03048 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81988, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\2\0\0\344\4\0\0\230\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\2\0\0\344\4\0\0\230\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81989, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\2\0\0\344\4\0\0\230\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\2\0\0\344\4\0\0\230\0\0\0" ) ) == 0x0 03049 896 NtResumeThread (532, ... 1, ) == 0x0 03050 152 NtTestAlert (... ) == 0x0 03051 152 NtContinue (84999472, 1, ... 03052 152 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03053 152 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03054 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 85000192, 1048576, ) == 0x0 03055 896 NtAllocateVirtualMemory (-1, 86040576, 0, 8192, 4096, 4, ... 86040576, 8192, ) == 0x0 03056 896 NtProtectVirtualMemory (-1, (0x520e000), 4096, 260, ... (0x520e000), 4096, 4, ) == 0x0 03057 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 536, {1252, 180}, ) == 0x0 03058 896 NtQueryInformationThread (536, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6b000,Pid=1252,Tid=180,}, 0x0, ) == 0x0 03059 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81989, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\264\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\264\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81990, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\264\0\0\0" ... {28, 56, reply, 0, 1252, 896, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\2\0\0\344\4\0\0\264\0\0\0" ) ) == 0x0 03060 896 NtResumeThread (536, ... 1, ) == 0x0 03061 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 86048768, 1048576, ) == 0x0 03062 896 NtAllocateVirtualMemory (-1, 87089152, 0, 8192, 4096, 4, ... 03063 180 NtTestAlert (... ) == 0x0 03064 180 NtContinue (86048048, 1, ... 03065 180 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03066 180 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03062 896 NtAllocateVirtualMemory ... 87089152, 8192, ) == 0x0 03067 896 NtProtectVirtualMemory (-1, (0x530e000), 4096, 260, ... (0x530e000), 4096, 4, ) == 0x0 03068 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 540, {1252, 1904}, ) == 0x0 03069 896 NtQueryInformationThread (540, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6a000,Pid=1252,Tid=1904,}, 0x0, ) == 0x0 03070 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81990, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\2\0\0\344\4\0\0p\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\2\0\0\344\4\0\0p\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81991, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\2\0\0\344\4\0\0p\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\2\0\0\344\4\0\0p\7\0\0" ) ) == 0x0 03071 896 NtResumeThread (540, ... 1, ) == 0x0 03072 1904 NtTestAlert (... ) == 0x0 03073 1904 NtContinue (87096624, 1, ... 03074 1904 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03075 1904 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03076 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 87097344, 1048576, ) == 0x0 03077 896 NtAllocateVirtualMemory (-1, 88137728, 0, 8192, 4096, 4, ... 88137728, 8192, ) == 0x0 03078 896 NtProtectVirtualMemory (-1, (0x540e000), 4096, 260, ... (0x540e000), 4096, 4, ) == 0x0 03079 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 544, {1252, 464}, ) == 0x0 03080 896 NtQueryInformationThread (544, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff69000,Pid=1252,Tid=464,}, 0x0, ) == 0x0 03081 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81991, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \2\0\0\344\4\0\0\320\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \2\0\0\344\4\0\0\320\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81992, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \2\0\0\344\4\0\0\320\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \2\0\0\344\4\0\0\320\1\0\0" ) ) == 0x0 03082 896 NtResumeThread (544, ... 1, ) == 0x0 03083 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 88145920, 1048576, ) == 0x0 03084 896 NtAllocateVirtualMemory (-1, 89186304, 0, 8192, 4096, 4, ... 03085 464 NtTestAlert (... ) == 0x0 03086 464 NtContinue (88145200, 1, ... 03087 464 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03088 464 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03084 896 NtAllocateVirtualMemory ... 89186304, 8192, ) == 0x0 03089 896 NtProtectVirtualMemory (-1, (0x550e000), 4096, 260, ... (0x550e000), 4096, 4, ) == 0x0 03090 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 548, {1252, 1536}, ) == 0x0 03091 896 NtQueryInformationThread (548, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff68000,Pid=1252,Tid=1536,}, 0x0, ) == 0x0 03092 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81992, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\2\0\0\344\4\0\0\0\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\2\0\0\344\4\0\0\0\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81993, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\2\0\0\344\4\0\0\0\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\2\0\0\344\4\0\0\0\6\0\0" ) ) == 0x0 03093 896 NtResumeThread (548, ... 1, ) == 0x0 03094 1536 NtTestAlert (... ) == 0x0 03095 1536 NtContinue (89193776, 1, ... 03096 1536 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03097 1536 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03098 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 89194496, 1048576, ) == 0x0 03099 896 NtAllocateVirtualMemory (-1, 90234880, 0, 8192, 4096, 4, ... 90234880, 8192, ) == 0x0 03100 896 NtProtectVirtualMemory (-1, (0x560e000), 4096, 260, ... (0x560e000), 4096, 4, ) == 0x0 03101 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 552, {1252, 444}, ) == 0x0 03102 896 NtQueryInformationThread (552, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff67000,Pid=1252,Tid=444,}, 0x0, ) == 0x0 03103 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81993, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\2\0\0\344\4\0\0\274\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\2\0\0\344\4\0\0\274\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81994, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\2\0\0\344\4\0\0\274\1\0\0" ... {28, 56, reply, 0, 1252, 896, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\2\0\0\344\4\0\0\274\1\0\0" ) ) == 0x0 03104 896 NtResumeThread (552, ... 1, ) == 0x0 03105 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 90243072, 1048576, ) == 0x0 03106 896 NtAllocateVirtualMemory (-1, 91283456, 0, 8192, 4096, 4, ... 03107 444 NtTestAlert (... ) == 0x0 03108 444 NtContinue (90242352, 1, ... 03109 444 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03110 444 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03106 896 NtAllocateVirtualMemory ... 91283456, 8192, ) == 0x0 03111 896 NtProtectVirtualMemory (-1, (0x570e000), 4096, 260, ... (0x570e000), 4096, 4, ) == 0x0 03112 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 556, {1252, 1648}, ) == 0x0 03113 896 NtQueryInformationThread (556, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff66000,Pid=1252,Tid=1648,}, 0x0, ) == 0x0 03114 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81994, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\2\0\0\344\4\0\0p\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\2\0\0\344\4\0\0p\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81995, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\2\0\0\344\4\0\0p\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\2\0\0\344\4\0\0p\6\0\0" ) ) == 0x0 03115 896 NtResumeThread (556, ... 1, ) == 0x0 03116 1648 NtTestAlert (... ) == 0x0 03117 1648 NtContinue (91290928, 1, ... 03118 1648 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03119 1648 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03120 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 91291648, 1048576, ) == 0x0 03121 896 NtAllocateVirtualMemory (-1, 92332032, 0, 8192, 4096, 4, ... 92332032, 8192, ) == 0x0 03122 896 NtProtectVirtualMemory (-1, (0x580e000), 4096, 260, ... (0x580e000), 4096, 4, ) == 0x0 03123 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 560, {1252, 968}, ) == 0x0 03124 896 NtQueryInformationThread (560, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff65000,Pid=1252,Tid=968,}, 0x0, ) == 0x0 03125 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81995, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\344\4\0\0\310\3\0\0" ... {28, 56, reply, 0, 1252, 896, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\344\4\0\0\310\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81996, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\344\4\0\0\310\3\0\0" ... {28, 56, reply, 0, 1252, 896, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\344\4\0\0\310\3\0\0" ) ) == 0x0 03126 896 NtResumeThread (560, ... 1, ) == 0x0 03127 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 92340224, 1048576, ) == 0x0 03128 896 NtAllocateVirtualMemory (-1, 93380608, 0, 8192, 4096, 4, ... 03129 968 NtTestAlert (... ) == 0x0 03130 968 NtContinue (92339504, 1, ... 03131 968 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03132 968 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03128 896 NtAllocateVirtualMemory ... 93380608, 8192, ) == 0x0 03133 896 NtProtectVirtualMemory (-1, (0x590e000), 4096, 260, ... (0x590e000), 4096, 4, ) == 0x0 03134 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 564, {1252, 1688}, ) == 0x0 03135 896 NtQueryInformationThread (564, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff64000,Pid=1252,Tid=1688,}, 0x0, ) == 0x0 03136 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81996, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\2\0\0\344\4\0\0\230\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\2\0\0\344\4\0\0\230\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81997, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\2\0\0\344\4\0\0\230\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\2\0\0\344\4\0\0\230\6\0\0" ) ) == 0x0 03137 896 NtResumeThread (564, ... 1, ) == 0x0 03138 1688 NtAllocateVirtualMemory (-1, 3633152, 0, 4096, 4096, 4, ... 3633152, 4096, ) == 0x0 03139 1688 NtTestAlert (... ) == 0x0 03140 1688 NtContinue (93388080, 1, ... 03141 1688 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03142 1688 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03143 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 93388800, 1048576, ) == 0x0 03144 896 NtAllocateVirtualMemory (-1, 94429184, 0, 8192, 4096, 4, ... 94429184, 8192, ) == 0x0 03145 896 NtProtectVirtualMemory (-1, (0x5a0e000), 4096, 260, ... (0x5a0e000), 4096, 4, ) == 0x0 03146 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 568, {1252, 1584}, ) == 0x0 03147 896 NtQueryInformationThread (568, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff63000,Pid=1252,Tid=1584,}, 0x0, ) == 0x0 03148 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81997, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\344\4\0\00\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\344\4\0\00\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81998, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\344\4\0\00\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\344\4\0\00\6\0\0" ) ) == 0x0 03149 896 NtResumeThread (568, ... 1, ) == 0x0 03150 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 94437376, 1048576, ) == 0x0 03151 896 NtAllocateVirtualMemory (-1, 95477760, 0, 8192, 4096, 4, ... 03152 1584 NtTestAlert (... ) == 0x0 03153 1584 NtContinue (94436656, 1, ... 03154 1584 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03155 1584 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03151 896 NtAllocateVirtualMemory ... 95477760, 8192, ) == 0x0 03156 896 NtProtectVirtualMemory (-1, (0x5b0e000), 4096, 260, ... (0x5b0e000), 4096, 4, ) == 0x0 03157 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 572, {1252, 1944}, ) == 0x0 03158 896 NtQueryInformationThread (572, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff62000,Pid=1252,Tid=1944,}, 0x0, ) == 0x0 03159 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81998, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\2\0\0\344\4\0\0\230\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\2\0\0\344\4\0\0\230\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81999, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\2\0\0\344\4\0\0\230\7\0\0" ... {28, 56, reply, 0, 1252, 896, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\2\0\0\344\4\0\0\230\7\0\0" ) ) == 0x0 03160 896 NtResumeThread (572, ... 1, ) == 0x0 03161 1944 NtTestAlert (... ) == 0x0 03162 1944 NtContinue (95485232, 1, ... 03163 1944 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03164 1944 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03165 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 95485952, 1048576, ) == 0x0 03166 896 NtAllocateVirtualMemory (-1, 96526336, 0, 8192, 4096, 4, ... 96526336, 8192, ) == 0x0 03167 896 NtProtectVirtualMemory (-1, (0x5c0e000), 4096, 260, ... (0x5c0e000), 4096, 4, ) == 0x0 03168 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 576, {1252, 148}, ) == 0x0 03169 896 NtQueryInformationThread (576, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff61000,Pid=1252,Tid=148,}, 0x0, ) == 0x0 03170 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81999, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0\224\0\0\0" ... {28, 56, reply, 0, 1252, 896, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0\224\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82000, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0\224\0\0\0" ... {28, 56, reply, 0, 1252, 896, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\344\4\0\0\224\0\0\0" ) ) == 0x0 03171 896 NtResumeThread (576, ... 1, ) == 0x0 03172 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 96534528, 1048576, ) == 0x0 03173 896 NtAllocateVirtualMemory (-1, 97574912, 0, 8192, 4096, 4, ... 03174 148 NtTestAlert (... ) == 0x0 03175 148 NtContinue (96533808, 1, ... 03176 148 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03177 148 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03173 896 NtAllocateVirtualMemory ... 97574912, 8192, ) == 0x0 03178 896 NtProtectVirtualMemory (-1, (0x5d0e000), 4096, 260, ... (0x5d0e000), 4096, 4, ) == 0x0 03179 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 580, {1252, 1500}, ) == 0x0 03180 896 NtQueryInformationThread (580, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff60000,Pid=1252,Tid=1500,}, 0x0, ) == 0x0 03181 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82000, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\2\0\0\344\4\0\0\334\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\2\0\0\344\4\0\0\334\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82001, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\2\0\0\344\4\0\0\334\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\2\0\0\344\4\0\0\334\5\0\0" ) ) == 0x0 03182 896 NtResumeThread (580, ... 1, ) == 0x0 03183 1500 NtTestAlert (... ) == 0x0 03184 1500 NtContinue (97582384, 1, ... 03185 1500 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03186 1500 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03187 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 97583104, 1048576, ) == 0x0 03188 896 NtAllocateVirtualMemory (-1, 98623488, 0, 8192, 4096, 4, ... 98623488, 8192, ) == 0x0 03189 896 NtProtectVirtualMemory (-1, (0x5e0e000), 4096, 260, ... (0x5e0e000), 4096, 4, ) == 0x0 03190 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 584, {1252, 240}, ) == 0x0 03191 896 NtQueryInformationThread (584, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5f000,Pid=1252,Tid=240,}, 0x0, ) == 0x0 03192 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82001, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\2\0\0\344\4\0\0\360\0\0\0" ... {28, 56, reply, 0, 1252, 896, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\2\0\0\344\4\0\0\360\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82002, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\2\0\0\344\4\0\0\360\0\0\0" ... {28, 56, reply, 0, 1252, 896, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\2\0\0\344\4\0\0\360\0\0\0" ) ) == 0x0 03193 896 NtResumeThread (584, ... 1, ) == 0x0 03194 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 98631680, 1048576, ) == 0x0 03195 896 NtAllocateVirtualMemory (-1, 99672064, 0, 8192, 4096, 4, ... 03196 240 NtTestAlert (... ) == 0x0 03197 240 NtContinue (98630960, 1, ... 03198 240 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03199 240 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03195 896 NtAllocateVirtualMemory ... 99672064, 8192, ) == 0x0 03200 896 NtProtectVirtualMemory (-1, (0x5f0e000), 4096, 260, ... (0x5f0e000), 4096, 4, ) == 0x0 03201 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 588, {1252, 2032}, ) == 0x0 03202 896 NtQueryInformationThread (588, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5e000,Pid=1252,Tid=2032,}, 0x0, ) == 0x0 03203 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82002, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\2\0\0\344\4\0\0\360\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\2\0\0\344\4\0\0\360\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82003, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\2\0\0\344\4\0\0\360\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\2\0\0\344\4\0\0\360\7\0\0" ) ) == 0x0 03204 896 NtResumeThread (588, ... 1, ) == 0x0 03205 2032 NtTestAlert (... ) == 0x0 03206 2032 NtContinue (99679536, 1, ... 03207 2032 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03208 2032 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03209 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 99680256, 1048576, ) == 0x0 03210 896 NtAllocateVirtualMemory (-1, 100720640, 0, 8192, 4096, 4, ... 100720640, 8192, ) == 0x0 03211 896 NtProtectVirtualMemory (-1, (0x600e000), 4096, 260, ... (0x600e000), 4096, 4, ) == 0x0 03212 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 592, {1252, 1592}, ) == 0x0 03213 896 NtQueryInformationThread (592, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5d000,Pid=1252,Tid=1592,}, 0x0, ) == 0x0 03214 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82003, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\2\0\0\344\4\0\08\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\2\0\0\344\4\0\08\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82004, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\2\0\0\344\4\0\08\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\2\0\0\344\4\0\08\6\0\0" ) ) == 0x0 03215 896 NtResumeThread (592, ... 1, ) == 0x0 03216 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 100728832, 1048576, ) == 0x0 03217 896 NtAllocateVirtualMemory (-1, 101769216, 0, 8192, 4096, 4, ... 03218 1592 NtTestAlert (... ) == 0x0 03219 1592 NtContinue (100728112, 1, ... 03220 1592 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03221 1592 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03217 896 NtAllocateVirtualMemory ... 101769216, 8192, ) == 0x0 03222 896 NtProtectVirtualMemory (-1, (0x610e000), 4096, 260, ... (0x610e000), 4096, 4, ) == 0x0 03223 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 596, {1252, 496}, ) == 0x0 03224 896 NtQueryInformationThread (596, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5c000,Pid=1252,Tid=496,}, 0x0, ) == 0x0 03225 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82004, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\2\0\0\344\4\0\0\360\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\2\0\0\344\4\0\0\360\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82005, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\2\0\0\344\4\0\0\360\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\2\0\0\344\4\0\0\360\1\0\0" ) ) == 0x0 03226 896 NtResumeThread (596, ... 1, ) == 0x0 03227 496 NtTestAlert (... ) == 0x0 03228 496 NtContinue (101776688, 1, ... 03229 496 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03230 496 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03231 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 101777408, 1048576, ) == 0x0 03232 896 NtAllocateVirtualMemory (-1, 102817792, 0, 8192, 4096, 4, ... 102817792, 8192, ) == 0x0 03233 896 NtProtectVirtualMemory (-1, (0x620e000), 4096, 260, ... (0x620e000), 4096, 4, ) == 0x0 03234 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 600, {1252, 476}, ) == 0x0 03235 896 NtQueryInformationThread (600, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5b000,Pid=1252,Tid=476,}, 0x0, ) == 0x0 03236 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82005, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\2\0\0\344\4\0\0\334\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\2\0\0\344\4\0\0\334\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82006, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\2\0\0\344\4\0\0\334\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\2\0\0\344\4\0\0\334\1\0\0" ) ) == 0x0 03237 896 NtResumeThread (600, ... 1, ) == 0x0 03238 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 102825984, 1048576, ) == 0x0 03239 896 NtAllocateVirtualMemory (-1, 103866368, 0, 8192, 4096, 4, ... 03240 476 NtTestAlert (... ) == 0x0 03241 476 NtContinue (102825264, 1, ... 03242 476 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03243 476 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03239 896 NtAllocateVirtualMemory ... 103866368, 8192, ) == 0x0 03244 896 NtProtectVirtualMemory (-1, (0x630e000), 4096, 260, ... (0x630e000), 4096, 4, ) == 0x0 03245 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 604, {1252, 1404}, ) == 0x0 03246 896 NtQueryInformationThread (604, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5a000,Pid=1252,Tid=1404,}, 0x0, ) == 0x0 03247 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82006, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\344\4\0\0|\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\344\4\0\0|\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82007, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\344\4\0\0|\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\344\4\0\0|\5\0\0" ) ) == 0x0 03248 896 NtResumeThread (604, ... 1, ) == 0x0 03249 1404 NtTestAlert (... ) == 0x0 03250 1404 NtContinue (103873840, 1, ... 03251 1404 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03252 1404 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03253 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 103874560, 1048576, ) == 0x0 03254 896 NtAllocateVirtualMemory (-1, 104914944, 0, 8192, 4096, 4, ... 104914944, 8192, ) == 0x0 03255 896 NtProtectVirtualMemory (-1, (0x640e000), 4096, 260, ... (0x640e000), 4096, 4, ) == 0x0 03256 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 608, {1252, 1744}, ) == 0x0 03257 896 NtQueryInformationThread (608, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff59000,Pid=1252,Tid=1744,}, 0x0, ) == 0x0 03258 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82007, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\2\0\0\344\4\0\0\320\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\2\0\0\344\4\0\0\320\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82008, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\2\0\0\344\4\0\0\320\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\2\0\0\344\4\0\0\320\6\0\0" ) ) == 0x0 03259 896 NtResumeThread (608, ... 1, ) == 0x0 03260 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 104923136, 1048576, ) == 0x0 03261 896 NtAllocateVirtualMemory (-1, 105963520, 0, 8192, 4096, 4, ... 03262 1744 NtTestAlert (... ) == 0x0 03263 1744 NtContinue (104922416, 1, ... 03264 1744 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03265 1744 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03261 896 NtAllocateVirtualMemory ... 105963520, 8192, ) == 0x0 03266 896 NtProtectVirtualMemory (-1, (0x650e000), 4096, 260, ... (0x650e000), 4096, 4, ) == 0x0 03267 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 612, {1252, 336}, ) == 0x0 03268 896 NtQueryInformationThread (612, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff58000,Pid=1252,Tid=336,}, 0x0, ) == 0x0 03269 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82008, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\2\0\0\344\4\0\0P\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\2\0\0\344\4\0\0P\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82009, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\2\0\0\344\4\0\0P\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\2\0\0\344\4\0\0P\1\0\0" ) ) == 0x0 03270 896 NtResumeThread (612, ... 1, ) == 0x0 03271 336 NtTestAlert (... ) == 0x0 03272 336 NtContinue (105970992, 1, ... 03273 336 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03274 336 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03275 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 105971712, 1048576, ) == 0x0 03276 896 NtAllocateVirtualMemory (-1, 107012096, 0, 8192, 4096, 4, ... 107012096, 8192, ) == 0x0 03277 896 NtProtectVirtualMemory (-1, (0x660e000), 4096, 260, ... (0x660e000), 4096, 4, ) == 0x0 03278 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 616, {1252, 1128}, ) == 0x0 03279 896 NtQueryInformationThread (616, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff57000,Pid=1252,Tid=1128,}, 0x0, ) == 0x0 03280 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82009, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\2\0\0\344\4\0\0h\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\2\0\0\344\4\0\0h\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82010, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\2\0\0\344\4\0\0h\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\2\0\0\344\4\0\0h\4\0\0" ) ) == 0x0 03281 896 NtResumeThread (616, ... 1, ) == 0x0 03282 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 107020288, 1048576, ) == 0x0 03283 896 NtAllocateVirtualMemory (-1, 108060672, 0, 8192, 4096, 4, ... 03284 1128 NtTestAlert (... ) == 0x0 03285 1128 NtContinue (107019568, 1, ... 03286 1128 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03287 1128 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03283 896 NtAllocateVirtualMemory ... 108060672, 8192, ) == 0x0 03288 896 NtProtectVirtualMemory (-1, (0x670e000), 4096, 260, ... (0x670e000), 4096, 4, ) == 0x0 03289 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 620, {1252, 1924}, ) == 0x0 03290 896 NtQueryInformationThread (620, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff56000,Pid=1252,Tid=1924,}, 0x0, ) == 0x0 03291 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82010, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\204\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\204\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82011, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\204\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\344\4\0\0\204\7\0\0" ) ) == 0x0 03292 896 NtResumeThread (620, ... 1, ) == 0x0 03293 1924 NtTestAlert (... ) == 0x0 03294 1924 NtContinue (108068144, 1, ... 03295 1924 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03296 1924 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03297 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 108068864, 1048576, ) == 0x0 03298 896 NtAllocateVirtualMemory (-1, 109109248, 0, 8192, 4096, 4, ... 109109248, 8192, ) == 0x0 03299 896 NtProtectVirtualMemory (-1, (0x680e000), 4096, 260, ... (0x680e000), 4096, 4, ) == 0x0 03300 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 624, {1252, 2040}, ) == 0x0 03301 896 NtQueryInformationThread (624, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff55000,Pid=1252,Tid=2040,}, 0x0, ) == 0x0 03302 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82011, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\370\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\370\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82012, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\370\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\2\0\0\344\4\0\0\370\7\0\0" ) ) == 0x0 03303 896 NtResumeThread (624, ... 1, ) == 0x0 03304 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 109117440, 1048576, ) == 0x0 03305 896 NtAllocateVirtualMemory (-1, 110157824, 0, 8192, 4096, 4, ... 03306 2040 NtTestAlert (... ) == 0x0 03307 2040 NtContinue (109116720, 1, ... 03308 2040 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03309 2040 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03305 896 NtAllocateVirtualMemory ... 110157824, 8192, ) == 0x0 03310 896 NtProtectVirtualMemory (-1, (0x690e000), 4096, 260, ... (0x690e000), 4096, 4, ) == 0x0 03311 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 628, {1252, 1524}, ) == 0x0 03312 896 NtQueryInformationThread (628, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff54000,Pid=1252,Tid=1524,}, 0x0, ) == 0x0 03313 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82012, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\2\0\0\344\4\0\0\364\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\2\0\0\344\4\0\0\364\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82013, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\2\0\0\344\4\0\0\364\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\2\0\0\344\4\0\0\364\5\0\0" ) ) == 0x0 03314 896 NtResumeThread (628, ... 1, ) == 0x0 03315 1524 NtTestAlert (... ) == 0x0 03316 1524 NtContinue (110165296, 1, ... 03317 1524 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03318 1524 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03319 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 110166016, 1048576, ) == 0x0 03320 896 NtAllocateVirtualMemory (-1, 111206400, 0, 8192, 4096, 4, ... 111206400, 8192, ) == 0x0 03321 896 NtProtectVirtualMemory (-1, (0x6a0e000), 4096, 260, ... (0x6a0e000), 4096, 4, ) == 0x0 03322 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 632, {1252, 388}, ) == 0x0 03323 896 NtQueryInformationThread (632, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff53000,Pid=1252,Tid=388,}, 0x0, ) == 0x0 03324 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82013, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\344\4\0\0\204\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\344\4\0\0\204\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82014, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\344\4\0\0\204\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\344\4\0\0\204\1\0\0" ) ) == 0x0 03325 896 NtResumeThread (632, ... 1, ) == 0x0 03326 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 111214592, 1048576, ) == 0x0 03327 896 NtAllocateVirtualMemory (-1, 112254976, 0, 8192, 4096, 4, ... 03328 388 NtTestAlert (... ) == 0x0 03329 388 NtContinue (111213872, 1, ... 03330 388 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03331 388 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03327 896 NtAllocateVirtualMemory ... 112254976, 8192, ) == 0x0 03332 896 NtProtectVirtualMemory (-1, (0x6b0e000), 4096, 260, ... (0x6b0e000), 4096, 4, ) == 0x0 03333 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 636, {1252, 1020}, ) == 0x0 03334 896 NtQueryInformationThread (636, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff52000,Pid=1252,Tid=1020,}, 0x0, ) == 0x0 03335 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82014, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\2\0\0\344\4\0\0\374\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\2\0\0\344\4\0\0\374\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82015, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\2\0\0\344\4\0\0\374\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\2\0\0\344\4\0\0\374\3\0\0" ) ) == 0x0 03336 896 NtResumeThread (636, ... 1, ) == 0x0 03337 1020 NtTestAlert (... ) == 0x0 03338 1020 NtContinue (112262448, 1, ... 03339 1020 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03340 1020 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03341 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 112263168, 1048576, ) == 0x0 03342 896 NtAllocateVirtualMemory (-1, 113303552, 0, 8192, 4096, 4, ... 113303552, 8192, ) == 0x0 03343 896 NtProtectVirtualMemory (-1, (0x6c0e000), 4096, 260, ... (0x6c0e000), 4096, 4, ) == 0x0 03344 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 640, {1252, 1804}, ) == 0x0 03345 896 NtQueryInformationThread (640, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff51000,Pid=1252,Tid=1804,}, 0x0, ) == 0x0 03346 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82015, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\344\4\0\0\14\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\344\4\0\0\14\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82016, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\344\4\0\0\14\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\344\4\0\0\14\7\0\0" ) ) == 0x0 03347 896 NtResumeThread (640, ... 1, ) == 0x0 03348 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 113311744, 1048576, ) == 0x0 03349 896 NtAllocateVirtualMemory (-1, 114352128, 0, 8192, 4096, 4, ... 03350 1804 NtTestAlert (... ) == 0x0 03351 1804 NtContinue (113311024, 1, ... 03352 1804 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03353 1804 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03349 896 NtAllocateVirtualMemory ... 114352128, 8192, ) == 0x0 03354 896 NtProtectVirtualMemory (-1, (0x6d0e000), 4096, 260, ... (0x6d0e000), 4096, 4, ) == 0x0 03355 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 644, {1252, 1644}, ) == 0x0 03356 896 NtQueryInformationThread (644, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff50000,Pid=1252,Tid=1644,}, 0x0, ) == 0x0 03357 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82016, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\344\4\0\0l\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\344\4\0\0l\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82017, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\344\4\0\0l\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\344\4\0\0l\6\0\0" ) ) == 0x0 03358 896 NtResumeThread (644, ... 1, ) == 0x0 03359 1644 NtTestAlert (... ) == 0x0 03360 1644 NtContinue (114359600, 1, ... 03361 1644 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03362 1644 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03363 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 114360320, 1048576, ) == 0x0 03364 896 NtAllocateVirtualMemory (-1, 115400704, 0, 8192, 4096, 4, ... 115400704, 8192, ) == 0x0 03365 896 NtProtectVirtualMemory (-1, (0x6e0e000), 4096, 260, ... (0x6e0e000), 4096, 4, ) == 0x0 03366 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 648, {1252, 1124}, ) == 0x0 03367 896 NtQueryInformationThread (648, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4f000,Pid=1252,Tid=1124,}, 0x0, ) == 0x0 03368 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82017, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\344\4\0\0d\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\344\4\0\0d\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82018, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\344\4\0\0d\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\344\4\0\0d\4\0\0" ) ) == 0x0 03369 896 NtResumeThread (648, ... 1, ) == 0x0 03370 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 115408896, 1048576, ) == 0x0 03371 896 NtAllocateVirtualMemory (-1, 116449280, 0, 8192, 4096, 4, ... 03372 1124 NtTestAlert (... ) == 0x0 03373 1124 NtContinue (115408176, 1, ... 03374 1124 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03375 1124 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03371 896 NtAllocateVirtualMemory ... 116449280, 8192, ) == 0x0 03376 896 NtProtectVirtualMemory (-1, (0x6f0e000), 4096, 260, ... (0x6f0e000), 4096, 4, ) == 0x0 03377 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 652, {1252, 776}, ) == 0x0 03378 896 NtQueryInformationThread (652, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4e000,Pid=1252,Tid=776,}, 0x0, ) == 0x0 03379 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82018, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\344\4\0\0\10\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\344\4\0\0\10\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82019, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\344\4\0\0\10\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\344\4\0\0\10\3\0\0" ) ) == 0x0 03380 896 NtResumeThread (652, ... 1, ) == 0x0 03381 776 NtTestAlert (... ) == 0x0 03382 776 NtContinue (116456752, 1, ... 03383 776 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03384 776 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03385 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 116457472, 1048576, ) == 0x0 03386 896 NtAllocateVirtualMemory (-1, 117497856, 0, 8192, 4096, 4, ... 117497856, 8192, ) == 0x0 03387 896 NtProtectVirtualMemory (-1, (0x700e000), 4096, 260, ... (0x700e000), 4096, 4, ) == 0x0 03388 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 656, {1252, 1692}, ) == 0x0 03389 896 NtQueryInformationThread (656, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4d000,Pid=1252,Tid=1692,}, 0x0, ) == 0x0 03390 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82019, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\344\4\0\0\234\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\344\4\0\0\234\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82020, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\344\4\0\0\234\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\344\4\0\0\234\6\0\0" ) ) == 0x0 03391 896 NtResumeThread (656, ... 1, ) == 0x0 03392 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 117506048, 1048576, ) == 0x0 03393 896 NtAllocateVirtualMemory (-1, 118546432, 0, 8192, 4096, 4, ... 03394 1692 NtTestAlert (... ) == 0x0 03395 1692 NtContinue (117505328, 1, ... 03396 1692 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03397 1692 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03393 896 NtAllocateVirtualMemory ... 118546432, 8192, ) == 0x0 03398 896 NtProtectVirtualMemory (-1, (0x710e000), 4096, 260, ... (0x710e000), 4096, 4, ) == 0x0 03399 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 660, {1252, 1392}, ) == 0x0 03400 896 NtQueryInformationThread (660, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4c000,Pid=1252,Tid=1392,}, 0x0, ) == 0x0 03401 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82020, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\344\4\0\0p\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\344\4\0\0p\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82021, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\344\4\0\0p\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\344\4\0\0p\5\0\0" ) ) == 0x0 03402 896 NtResumeThread (660, ... 1, ) == 0x0 03403 1392 NtTestAlert (... ) == 0x0 03404 1392 NtContinue (118553904, 1, ... 03405 1392 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03406 1392 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03407 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 118554624, 1048576, ) == 0x0 03408 896 NtAllocateVirtualMemory (-1, 119595008, 0, 8192, 4096, 4, ... 119595008, 8192, ) == 0x0 03409 896 NtProtectVirtualMemory (-1, (0x720e000), 4096, 260, ... (0x720e000), 4096, 4, ) == 0x0 03410 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 664, {1252, 1176}, ) == 0x0 03411 896 NtQueryInformationThread (664, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4b000,Pid=1252,Tid=1176,}, 0x0, ) == 0x0 03412 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82021, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\344\4\0\0\230\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\344\4\0\0\230\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82022, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\344\4\0\0\230\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\344\4\0\0\230\4\0\0" ) ) == 0x0 03413 896 NtResumeThread (664, ... 1, ) == 0x0 03414 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 119603200, 1048576, ) == 0x0 03415 896 NtAllocateVirtualMemory (-1, 120643584, 0, 8192, 4096, 4, ... 03416 1176 NtTestAlert (... ) == 0x0 03417 1176 NtContinue (119602480, 1, ... 03418 1176 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03419 1176 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03415 896 NtAllocateVirtualMemory ... 120643584, 8192, ) == 0x0 03420 896 NtProtectVirtualMemory (-1, (0x730e000), 4096, 260, ... (0x730e000), 4096, 4, ) == 0x0 03421 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 668, {1252, 1828}, ) == 0x0 03422 896 NtQueryInformationThread (668, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4a000,Pid=1252,Tid=1828,}, 0x0, ) == 0x0 03423 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82022, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\344\4\0\0$\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\344\4\0\0$\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82023, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\344\4\0\0$\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\344\4\0\0$\7\0\0" ) ) == 0x0 03424 896 NtResumeThread (668, ... 1, ) == 0x0 03425 1828 NtTestAlert (... ) == 0x0 03426 1828 NtContinue (120651056, 1, ... 03427 1828 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03428 1828 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03429 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 120651776, 1048576, ) == 0x0 03430 896 NtAllocateVirtualMemory (-1, 121692160, 0, 8192, 4096, 4, ... 121692160, 8192, ) == 0x0 03431 896 NtProtectVirtualMemory (-1, (0x740e000), 4096, 260, ... (0x740e000), 4096, 4, ) == 0x0 03432 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 672, {1252, 1544}, ) == 0x0 03433 896 NtQueryInformationThread (672, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff49000,Pid=1252,Tid=1544,}, 0x0, ) == 0x0 03434 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82023, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\344\4\0\0\10\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\344\4\0\0\10\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82024, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\344\4\0\0\10\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\344\4\0\0\10\6\0\0" ) ) == 0x0 03435 896 NtResumeThread (672, ... 1, ) == 0x0 03436 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 121700352, 1048576, ) == 0x0 03437 896 NtAllocateVirtualMemory (-1, 122740736, 0, 8192, 4096, 4, ... 03438 1544 NtTestAlert (... ) == 0x0 03439 1544 NtContinue (121699632, 1, ... 03440 1544 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03441 1544 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03437 896 NtAllocateVirtualMemory ... 122740736, 8192, ) == 0x0 03442 896 NtProtectVirtualMemory (-1, (0x750e000), 4096, 260, ... (0x750e000), 4096, 4, ) == 0x0 03443 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 676, {1252, 1548}, ) == 0x0 03444 896 NtQueryInformationThread (676, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff48000,Pid=1252,Tid=1548,}, 0x0, ) == 0x0 03445 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82024, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\344\4\0\0\14\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\344\4\0\0\14\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82025, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\344\4\0\0\14\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\344\4\0\0\14\6\0\0" ) ) == 0x0 03446 896 NtResumeThread (676, ... 1, ) == 0x0 03447 1548 NtAllocateVirtualMemory (-1, 3637248, 0, 4096, 4096, 4, ... 3637248, 4096, ) == 0x0 03448 1548 NtTestAlert (... ) == 0x0 03449 1548 NtContinue (122748208, 1, ... 03450 1548 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03451 1548 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03452 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 122748928, 1048576, ) == 0x0 03453 896 NtAllocateVirtualMemory (-1, 123789312, 0, 8192, 4096, 4, ... 123789312, 8192, ) == 0x0 03454 896 NtProtectVirtualMemory (-1, (0x760e000), 4096, 260, ... (0x760e000), 4096, 4, ) == 0x0 03455 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 680, {1252, 1540}, ) == 0x0 03456 896 NtQueryInformationThread (680, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff47000,Pid=1252,Tid=1540,}, 0x0, ) == 0x0 03457 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82025, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\344\4\0\0\4\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\344\4\0\0\4\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82026, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\344\4\0\0\4\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\344\4\0\0\4\6\0\0" ) ) == 0x0 03458 896 NtResumeThread (680, ... 1, ) == 0x0 03459 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 123797504, 1048576, ) == 0x0 03460 896 NtAllocateVirtualMemory (-1, 124837888, 0, 8192, 4096, 4, ... 03461 1540 NtTestAlert (... ) == 0x0 03462 1540 NtContinue (123796784, 1, ... 03463 1540 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03464 1540 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03460 896 NtAllocateVirtualMemory ... 124837888, 8192, ) == 0x0 03465 896 NtProtectVirtualMemory (-1, (0x770e000), 4096, 260, ... (0x770e000), 4096, 4, ) == 0x0 03466 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 684, {1252, 420}, ) == 0x0 03467 896 NtQueryInformationThread (684, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff46000,Pid=1252,Tid=420,}, 0x0, ) == 0x0 03468 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82026, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\344\4\0\0\244\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\344\4\0\0\244\1\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82027, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\344\4\0\0\244\1\0\0" ... {28, 56, reply, 0, 1252, 896, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\344\4\0\0\244\1\0\0" ) ) == 0x0 03469 896 NtResumeThread (684, ... 1, ) == 0x0 03470 420 NtTestAlert (... ) == 0x0 03471 420 NtContinue (124845360, 1, ... 03472 420 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03473 420 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03474 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 124846080, 1048576, ) == 0x0 03475 896 NtAllocateVirtualMemory (-1, 125886464, 0, 8192, 4096, 4, ... 125886464, 8192, ) == 0x0 03476 896 NtProtectVirtualMemory (-1, (0x780e000), 4096, 260, ... (0x780e000), 4096, 4, ) == 0x0 03477 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 688, {1252, 2012}, ) == 0x0 03478 896 NtQueryInformationThread (688, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff45000,Pid=1252,Tid=2012,}, 0x0, ) == 0x0 03479 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82027, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\344\4\0\0\334\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\344\4\0\0\334\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82028, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\344\4\0\0\334\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\344\4\0\0\334\7\0\0" ) ) == 0x0 03480 896 NtResumeThread (688, ... 1, ) == 0x0 03481 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 125894656, 1048576, ) == 0x0 03482 896 NtAllocateVirtualMemory (-1, 126935040, 0, 8192, 4096, 4, ... 03483 2012 NtTestAlert (... ) == 0x0 03484 2012 NtContinue (125893936, 1, ... 03485 2012 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03486 2012 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03482 896 NtAllocateVirtualMemory ... 126935040, 8192, ) == 0x0 03487 896 NtProtectVirtualMemory (-1, (0x790e000), 4096, 260, ... (0x790e000), 4096, 4, ) == 0x0 03488 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 692, {1252, 1168}, ) == 0x0 03489 896 NtQueryInformationThread (692, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff44000,Pid=1252,Tid=1168,}, 0x0, ) == 0x0 03490 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82028, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\344\4\0\0\220\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\344\4\0\0\220\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82029, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\344\4\0\0\220\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\344\4\0\0\220\4\0\0" ) ) == 0x0 03491 896 NtResumeThread (692, ... 1, ) == 0x0 03492 1168 NtTestAlert (... ) == 0x0 03493 1168 NtContinue (126942512, 1, ... 03494 1168 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03495 1168 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03496 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 126943232, 1048576, ) == 0x0 03497 896 NtAllocateVirtualMemory (-1, 127983616, 0, 8192, 4096, 4, ... 127983616, 8192, ) == 0x0 03498 896 NtProtectVirtualMemory (-1, (0x7a0e000), 4096, 260, ... (0x7a0e000), 4096, 4, ) == 0x0 03499 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 696, {1252, 928}, ) == 0x0 03500 896 NtQueryInformationThread (696, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff43000,Pid=1252,Tid=928,}, 0x0, ) == 0x0 03501 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82029, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\240\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\240\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82030, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\240\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\344\4\0\0\240\3\0\0" ) ) == 0x0 03502 896 NtResumeThread (696, ... 1, ) == 0x0 03503 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 127991808, 1048576, ) == 0x0 03504 896 NtAllocateVirtualMemory (-1, 129032192, 0, 8192, 4096, 4, ... 03505 928 NtTestAlert (... ) == 0x0 03506 928 NtContinue (127991088, 1, ... 03507 928 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03508 928 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03504 896 NtAllocateVirtualMemory ... 129032192, 8192, ) == 0x0 03509 896 NtProtectVirtualMemory (-1, (0x7b0e000), 4096, 260, ... (0x7b0e000), 4096, 4, ) == 0x0 03510 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 700, {1252, 900}, ) == 0x0 03511 896 NtQueryInformationThread (700, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff42000,Pid=1252,Tid=900,}, 0x0, ) == 0x0 03512 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82030, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\204\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\204\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82031, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\204\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\344\4\0\0\204\3\0\0" ) ) == 0x0 03513 896 NtResumeThread (700, ... 1, ) == 0x0 03514 900 NtTestAlert (... ) == 0x0 03515 900 NtContinue (129039664, 1, ... 03516 900 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03517 900 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03518 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 129040384, 1048576, ) == 0x0 03519 896 NtAllocateVirtualMemory (-1, 130080768, 0, 8192, 4096, 4, ... 130080768, 8192, ) == 0x0 03520 896 NtProtectVirtualMemory (-1, (0x7c0e000), 4096, 260, ... (0x7c0e000), 4096, 4, ) == 0x0 03521 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 704, {1252, 1388}, ) == 0x0 03522 896 NtQueryInformationThread (704, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff41000,Pid=1252,Tid=1388,}, 0x0, ) == 0x0 03523 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82031, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0l\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0l\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82032, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0l\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\344\4\0\0l\5\0\0" ) ) == 0x0 03524 896 NtResumeThread (704, ... 1, ) == 0x0 03525 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 130088960, 1048576, ) == 0x0 03526 896 NtAllocateVirtualMemory (-1, 131129344, 0, 8192, 4096, 4, ... 03527 1388 NtTestAlert (... ) == 0x0 03528 1388 NtContinue (130088240, 1, ... 03529 1388 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03530 1388 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03526 896 NtAllocateVirtualMemory ... 131129344, 8192, ) == 0x0 03531 896 NtProtectVirtualMemory (-1, (0x7d0e000), 4096, 260, ... (0x7d0e000), 4096, 4, ) == 0x0 03532 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 708, {1252, 1948}, ) == 0x0 03533 896 NtQueryInformationThread (708, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff40000,Pid=1252,Tid=1948,}, 0x0, ) == 0x0 03534 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82032, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\234\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\234\7\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82033, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\234\7\0\0" ... {28, 56, reply, 0, 1252, 896, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\344\4\0\0\234\7\0\0" ) ) == 0x0 03535 896 NtResumeThread (708, ... 1, ) == 0x0 03536 1948 NtTestAlert (... ) == 0x0 03537 1948 NtContinue (131136816, 1, ... 03538 1948 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03539 1948 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03540 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 131137536, 1048576, ) == 0x0 03541 896 NtAllocateVirtualMemory (-1, 132177920, 0, 8192, 4096, 4, ... 132177920, 8192, ) == 0x0 03542 896 NtProtectVirtualMemory (-1, (0x7e0e000), 4096, 260, ... (0x7e0e000), 4096, 4, ) == 0x0 03543 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 712, {1252, 1708}, ) == 0x0 03544 896 NtQueryInformationThread (712, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3f000,Pid=1252,Tid=1708,}, 0x0, ) == 0x0 03545 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82033, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0\254\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0\254\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82034, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0\254\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\344\4\0\0\254\6\0\0" ) ) == 0x0 03546 896 NtResumeThread (712, ... 1, ) == 0x0 03547 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 132186112, 1048576, ) == 0x0 03548 896 NtAllocateVirtualMemory (-1, 133226496, 0, 8192, 4096, 4, ... 03549 1708 NtTestAlert (... ) == 0x0 03550 1708 NtContinue (132185392, 1, ... 03551 1708 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03552 1708 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03548 896 NtAllocateVirtualMemory ... 133226496, 8192, ) == 0x0 03553 896 NtProtectVirtualMemory (-1, (0x7f0e000), 4096, 260, ... (0x7f0e000), 4096, 4, ) == 0x0 03554 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 716, {1252, 1324}, ) == 0x0 03555 896 NtQueryInformationThread (716, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3e000,Pid=1252,Tid=1324,}, 0x0, ) == 0x0 03556 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82034, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0,\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0,\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82035, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0,\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\344\4\0\0,\5\0\0" ) ) == 0x0 03557 896 NtResumeThread (716, ... 1, ) == 0x0 03558 1324 NtTestAlert (... ) == 0x0 03559 1324 NtContinue (133233968, 1, ... 03560 1324 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03561 1324 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03562 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 133234688, 1048576, ) == 0x0 03563 896 NtAllocateVirtualMemory (-1, 134275072, 0, 8192, 4096, 4, ... 134275072, 8192, ) == 0x0 03564 896 NtProtectVirtualMemory (-1, (0x800e000), 4096, 260, ... (0x800e000), 4096, 4, ) == 0x0 03565 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 720, {1252, 248}, ) == 0x0 03566 896 NtQueryInformationThread (720, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3d000,Pid=1252,Tid=248,}, 0x0, ) == 0x0 03567 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82035, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\370\0\0\0" ... {28, 56, reply, 0, 1252, 896, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\370\0\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82036, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\370\0\0\0" ... {28, 56, reply, 0, 1252, 896, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\344\4\0\0\370\0\0\0" ) ) == 0x0 03568 896 NtResumeThread (720, ... 1, ) == 0x0 03569 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 134283264, 1048576, ) == 0x0 03570 896 NtAllocateVirtualMemory (-1, 135323648, 0, 8192, 4096, 4, ... 03571 248 NtTestAlert (... ) == 0x0 03572 248 NtContinue (134282544, 1, ... 03573 248 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03574 248 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03570 896 NtAllocateVirtualMemory ... 135323648, 8192, ) == 0x0 03575 896 NtProtectVirtualMemory (-1, (0x810e000), 4096, 260, ... (0x810e000), 4096, 4, ) == 0x0 03576 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 724, {1252, 1676}, ) == 0x0 03577 896 NtQueryInformationThread (724, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3c000,Pid=1252,Tid=1676,}, 0x0, ) == 0x0 03578 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82036, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\0\214\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\0\214\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82037, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\0\214\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\344\4\0\0\214\6\0\0" ) ) == 0x0 03579 896 NtResumeThread (724, ... 1, ) == 0x0 03580 1676 NtTestAlert (... ) == 0x0 03581 1676 NtContinue (135331120, 1, ... 03582 1676 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03583 1676 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03584 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 135331840, 1048576, ) == 0x0 03585 896 NtAllocateVirtualMemory (-1, 136372224, 0, 8192, 4096, 4, ... 136372224, 8192, ) == 0x0 03586 896 NtProtectVirtualMemory (-1, (0x820e000), 4096, 260, ... (0x820e000), 4096, 4, ) == 0x0 03587 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 728, {1252, 1588}, ) == 0x0 03588 896 NtQueryInformationThread (728, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3b000,Pid=1252,Tid=1588,}, 0x0, ) == 0x0 03589 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82037, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\04\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\04\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82038, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\04\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\344\4\0\04\6\0\0" ) ) == 0x0 03590 896 NtResumeThread (728, ... 1, ) == 0x0 03591 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 136380416, 1048576, ) == 0x0 03592 896 NtAllocateVirtualMemory (-1, 137420800, 0, 8192, 4096, 4, ... 03593 1588 NtTestAlert (... ) == 0x0 03594 1588 NtContinue (136379696, 1, ... 03595 1588 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03596 1588 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03592 896 NtAllocateVirtualMemory ... 137420800, 8192, ) == 0x0 03597 896 NtProtectVirtualMemory (-1, (0x830e000), 4096, 260, ... (0x830e000), 4096, 4, ) == 0x0 03598 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 732, {1252, 1376}, ) == 0x0 03599 896 NtQueryInformationThread (732, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3a000,Pid=1252,Tid=1376,}, 0x0, ) == 0x0 03600 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82038, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0`\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0`\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82039, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0`\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\344\4\0\0`\5\0\0" ) ) == 0x0 03601 896 NtResumeThread (732, ... 1, ) == 0x0 03602 1376 NtTestAlert (... ) == 0x0 03603 1376 NtContinue (137428272, 1, ... 03604 1376 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03605 1376 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03606 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 137428992, 1048576, ) == 0x0 03607 896 NtAllocateVirtualMemory (-1, 138469376, 0, 8192, 4096, 4, ... 138469376, 8192, ) == 0x0 03608 896 NtProtectVirtualMemory (-1, (0x840e000), 4096, 260, ... (0x840e000), 4096, 4, ) == 0x0 03609 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 736, {1252, 1436}, ) == 0x0 03610 896 NtQueryInformationThread (736, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff39000,Pid=1252,Tid=1436,}, 0x0, ) == 0x0 03611 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82039, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\344\4\0\0\234\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\344\4\0\0\234\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82040, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\344\4\0\0\234\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\344\4\0\0\234\5\0\0" ) ) == 0x0 03612 896 NtResumeThread (736, ... 1, ) == 0x0 03613 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 138477568, 1048576, ) == 0x0 03614 896 NtAllocateVirtualMemory (-1, 139517952, 0, 8192, 4096, 4, ... 03615 1436 NtTestAlert (... ) == 0x0 03616 1436 NtContinue (138476848, 1, ... 03617 1436 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03618 1436 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03614 896 NtAllocateVirtualMemory ... 139517952, 8192, ) == 0x0 03619 896 NtProtectVirtualMemory (-1, (0x850e000), 4096, 260, ... (0x850e000), 4096, 4, ) == 0x0 03620 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 740, {1252, 1276}, ) == 0x0 03621 896 NtQueryInformationThread (740, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff38000,Pid=1252,Tid=1276,}, 0x0, ) == 0x0 03622 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82040, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0\374\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0\374\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82041, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0\374\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\344\4\0\0\374\4\0\0" ) ) == 0x0 03623 896 NtResumeThread (740, ... 1, ) == 0x0 03624 1276 NtTestAlert (... ) == 0x0 03625 1276 NtContinue (139525424, 1, ... 03626 1276 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03627 1276 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03628 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 139526144, 1048576, ) == 0x0 03629 896 NtAllocateVirtualMemory (-1, 140566528, 0, 8192, 4096, 4, ... 140566528, 8192, ) == 0x0 03630 896 NtProtectVirtualMemory (-1, (0x860e000), 4096, 260, ... (0x860e000), 4096, 4, ) == 0x0 03631 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 744, {1252, 1636}, ) == 0x0 03632 896 NtQueryInformationThread (744, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff37000,Pid=1252,Tid=1636,}, 0x0, ) == 0x0 03633 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82041, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0d\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0d\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82042, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0d\6\0\0" ... {28, 56, reply, 0, 1252, 896, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\344\4\0\0d\6\0\0" ) ) == 0x0 03634 896 NtResumeThread (744, ... 1, ) == 0x0 03635 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 140574720, 1048576, ) == 0x0 03636 896 NtAllocateVirtualMemory (-1, 141615104, 0, 8192, 4096, 4, ... 03637 1636 NtTestAlert (... ) == 0x0 03638 1636 NtContinue (140574000, 1, ... 03639 1636 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03640 1636 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03636 896 NtAllocateVirtualMemory ... 141615104, 8192, ) == 0x0 03641 896 NtProtectVirtualMemory (-1, (0x870e000), 4096, 260, ... (0x870e000), 4096, 4, ) == 0x0 03642 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 748, {1252, 1152}, ) == 0x0 03643 896 NtQueryInformationThread (748, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff36000,Pid=1252,Tid=1152,}, 0x0, ) == 0x0 03644 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82042, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\200\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\200\4\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82043, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\200\4\0\0" ... {28, 56, reply, 0, 1252, 896, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\344\4\0\0\200\4\0\0" ) ) == 0x0 03645 896 NtResumeThread (748, ... 1, ) == 0x0 03646 1152 NtTestAlert (... ) == 0x0 03647 1152 NtContinue (141622576, 1, ... 03648 1152 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03649 1152 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03650 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 141623296, 1048576, ) == 0x0 03651 896 NtAllocateVirtualMemory (-1, 142663680, 0, 8192, 4096, 4, ... 142663680, 8192, ) == 0x0 03652 896 NtProtectVirtualMemory (-1, (0x880e000), 4096, 260, ... (0x880e000), 4096, 4, ) == 0x0 03653 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 752, {1252, 1484}, ) == 0x0 03654 896 NtQueryInformationThread (752, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff35000,Pid=1252,Tid=1484,}, 0x0, ) == 0x0 03655 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82043, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\314\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\314\5\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82044, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\314\5\0\0" ... {28, 56, reply, 0, 1252, 896, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\344\4\0\0\314\5\0\0" ) ) == 0x0 03656 896 NtResumeThread (752, ... 1, ) == 0x0 03657 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 142671872, 1048576, ) == 0x0 03658 896 NtAllocateVirtualMemory (-1, 143712256, 0, 8192, 4096, 4, ... 03659 1484 NtTestAlert (... ) == 0x0 03660 1484 NtContinue (142671152, 1, ... 03661 1484 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03662 1484 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03658 896 NtAllocateVirtualMemory ... 143712256, 8192, ) == 0x0 03663 896 NtProtectVirtualMemory (-1, (0x890e000), 4096, 260, ... (0x890e000), 4096, 4, ) == 0x0 03664 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 756, {1252, 888}, ) == 0x0 03665 896 NtQueryInformationThread (756, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff34000,Pid=1252,Tid=888,}, 0x0, ) == 0x0 03666 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82044, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0x\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0x\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82045, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0x\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\344\4\0\0x\3\0\0" ) ) == 0x0 03667 896 NtResumeThread (756, ... 1, ) == 0x0 03668 888 NtTestAlert (... ) == 0x0 03669 888 NtContinue (143719728, 1, ... 03670 888 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03671 888 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03672 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 143720448, 1048576, ) == 0x0 03673 896 NtAllocateVirtualMemory (-1, 144760832, 0, 8192, 4096, 4, ... 144760832, 8192, ) == 0x0 03674 896 NtProtectVirtualMemory (-1, (0x8a0e000), 4096, 260, ... (0x8a0e000), 4096, 4, ) == 0x0 03675 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 760, {1252, 840}, ) == 0x0 03676 896 NtQueryInformationThread (760, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff33000,Pid=1252,Tid=840,}, 0x0, ) == 0x0 03677 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82045, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\344\4\0\0H\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\344\4\0\0H\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82046, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\344\4\0\0H\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\344\4\0\0H\3\0\0" ) ) == 0x0 03678 896 NtResumeThread (760, ... 1, ) == 0x0 03679 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 144769024, 1048576, ) == 0x0 03680 896 NtAllocateVirtualMemory (-1, 145809408, 0, 8192, 4096, 4, ... 03681 840 NtTestAlert (... ) == 0x0 03682 840 NtContinue (144768304, 1, ... 03683 840 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03684 840 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03680 896 NtAllocateVirtualMemory ... 145809408, 8192, ) == 0x0 03685 896 NtProtectVirtualMemory (-1, (0x8b0e000), 4096, 260, ... (0x8b0e000), 4096, 4, ) == 0x0 03686 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 764, {1252, 876}, ) == 0x0 03687 896 NtQueryInformationThread (764, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff32000,Pid=1252,Tid=876,}, 0x0, ) == 0x0 03688 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82046, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\344\4\0\0l\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\344\4\0\0l\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82047, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\344\4\0\0l\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\344\4\0\0l\3\0\0" ) ) == 0x0 03689 896 NtResumeThread (764, ... 1, ) == 0x0 03690 876 NtTestAlert (... ) == 0x0 03691 876 NtContinue (145816880, 1, ... 03692 876 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03693 876 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03694 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 145817600, 1048576, ) == 0x0 03695 896 NtAllocateVirtualMemory (-1, 146857984, 0, 8192, 4096, 4, ... 146857984, 8192, ) == 0x0 03696 896 NtProtectVirtualMemory (-1, (0x8c0e000), 4096, 260, ... (0x8c0e000), 4096, 4, ) == 0x0 03697 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 768, {1252, 860}, ) == 0x0 03698 896 NtQueryInformationThread (768, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff31000,Pid=1252,Tid=860,}, 0x0, ) == 0x0 03699 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82047, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\344\4\0\0\\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\344\4\0\0\\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82048, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\344\4\0\0\\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\344\4\0\0\\3\0\0" ) ) == 0x0 03700 896 NtResumeThread (768, ... 1, ) == 0x0 03701 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 146866176, 1048576, ) == 0x0 03702 896 NtAllocateVirtualMemory (-1, 147906560, 0, 8192, 4096, 4, ... 03703 860 NtTestAlert (... ) == 0x0 03704 860 NtContinue (146865456, 1, ... 03705 860 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03706 860 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03702 896 NtAllocateVirtualMemory ... 147906560, 8192, ) == 0x0 03707 896 NtProtectVirtualMemory (-1, (0x8d0e000), 4096, 260, ... (0x8d0e000), 4096, 4, ) == 0x0 03708 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 772, {1252, 780}, ) == 0x0 03709 896 NtQueryInformationThread (772, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff30000,Pid=1252,Tid=780,}, 0x0, ) == 0x0 03710 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 82048, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\344\4\0\0\14\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82049, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\344\4\0\0\14\3\0\0" ) ... {28, 56, reply, 0, 1252, 896, 82049, 0} (24, {28, 56, new_msg, 0, 1252, 896, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\344\4\0\0\14\3\0\0" ... {28, 56, reply, 0, 1252, 896, 82049, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\344\4\0\0\14\3\0\0" ) ) == 0x0 03711 896 NtResumeThread (772, ... 1, ) == 0x0 03712 780 NtTestAlert (... ) == 0x0 03713 780 NtContinue (147914032, 1, ... 03714 780 NtRegisterThreadTerminatePort (24, ... ) == 0x0 03715 780 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 03716 896 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03717 896 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 776, ) == 0x0 03718 896 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03719 896 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03720 896 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1243192, (0xc0100080, {24, 0, 0x40, 0, 1243192, "\??\PIPE\InitShutdown"}, 0x0, 0, 3, 1, 64, 0, 0, ... 780, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 780, {status=0x0, info=1}, ) == 0x0 03721 896 NtSetInformationFile (780, 1243248, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 03722 896 NtSetInformationFile (780, 1243236, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 03723 896 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03724 896 NtWriteFile (780, 57, 0, 0, (780, 57, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\300\340M\211U\15\323\21\243"\0\300O\243!\241\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) \0\300O\243!\241\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 03725 896 NtReadFile (780, 57, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=76}, (780, 57, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=76}, "\5\0\14\3\20\0\0\0L\0\0\0\1\0\0\0\270\20\270\20\234(\0\0\23\0\PIPE\InitShutdown\0\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 03726 896 NtFsControlFile (780, 57, 0x0, 0x0, 0x11c017, (780, 57, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\36\0\0\0\1\0\0\0\6\0\0\0\0\0\1\0\330\376\22\0\210J", 30, 1024, ... {status=0x103, info=76}, "\5\0\14\3\20\0\0\0L\0\0\0\1\0\0\0\270\20\270\20\234(\0\0\23\0\PIPE\InitShutdown\0\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 30, 1024, ... {status=0x103, info=76}, (780, 57, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\36\0\0\0\1\0\0\0\6\0\0\0\0\0\1\0\330\376\22\0\210J", 30, 1024, ... {status=0x103, info=76}, "\5\0\14\3\20\0\0\0L\0\0\0\1\0\0\0\270\20\270\20\234(\0\0\23\0\PIPE\InitShutdown\0\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 03727 896 NtWaitForSingleObject (57, 0, 0x0, ... ) == 0x0 03728 896 NtClose (776, ... ) == 0x0 03729 896 NtClose (780, ... ) == 0x0 03730 896 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03731 896 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 780, ) == 0x0 03732 896 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03733 896 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03734 896 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1243188, (0xc0100080, {24, 0, 0x40, 0, 1243188, "\??\PIPE\winreg"}, 0x0, 0, 3, 1, 64, 0, 0, ... 776, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 776, {status=0x0, info=1}, ) == 0x0 03735 896 NtSetInformationFile (776, 1243244, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 03736 896 NtSetInformationFile (776, 1243232, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 03737 896 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03738 896 NtWriteFile (776, 57, 0, 0, (776, 57, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\1\320\2143D"\3611\252\252\220\08\0\20\3\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) \3611\252\252\220\08\0\20\3\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 03739 896 NtReadFile (776, 57, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (776, 57, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\2019\0\0\15\0\PIPE\winreg\0\177\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 03740 896 NtFsControlFile (776, 57, 0x0, 0x0, 0x11c017, (776, 57, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\36\0\0\0\1\0\0\0\6\0\0\0\0\0\31\0\314\376\22\0\210J", 30, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\2019\0\0\15\0\PIPE\winreg\0\177\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 30, 1024, ... {status=0x103, info=68}, (776, 57, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\36\0\0\0\1\0\0\0\6\0\0\0\0\0\31\0\314\376\22\0\210J", 30, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\2019\0\0\15\0\PIPE\winreg\0\177\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 03741 896 NtWaitForSingleObject (57, 0, 0x0, ... 02149 504 NtOpenKey ... 784, ) == 0x0 03742 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03743 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03744 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... }, ... 02196 428 NtSetInformationThread ... ) == 0x0 02197 1028 NtSetInformationThread ... ) == 0x0 02198 1700 NtSetInformationThread ... ) == 0x0 02199 1740 NtSetInformationThread ... ) == 0x0 02310 1096 NtSetInformationThread ... ) == 0x0 02314 1300 NtSetInformationThread ... ) == 0x0 02716 1964 NtSetInformationThread ... ) == 0x0 02722 1624 NtSetInformationThread ... ) == 0x0 02735 1440 NtSetInformationThread ... ) == 0x0 02744 1972 NtSetInformationThread ... ) == 0x0 02757 1036 NtSetInformationThread ... ) == 0x0 02766 1664 NtSetInformationThread ... ) == 0x0 02779 1248 NtSetInformationThread ... ) == 0x0 02788 1656 NtSetInformationThread ... ) == 0x0 02801 760 NtSetInformationThread ... ) == 0x0 02810 484 NtSetInformationThread ... ) == 0x0 03741 896 NtWaitForSingleObject ... ) == 0x0 02824 1580 NtSetInformationThread ... ) == 0x0 02833 1756 NtSetInformationThread ... ) == 0x0 02846 1304 NtSetInformationThread ... ) == 0x0 02855 1292 NtSetInformationThread ... ) == 0x0 02868 1956 NtSetInformationThread ... ) == 0x0 02877 1556 NtSetInformationThread ... ) == 0x0 02890 1480 NtSetInformationThread ... ) == 0x0 02899 1784 NtSetInformationThread ... ) == 0x0 02912 1856 NtSetInformationThread ... ) == 0x0 02921 1604 NtSetInformationThread ... ) == 0x0 02934 1272 NtSetInformationThread ... ) == 0x0 02943 1132 NtSetInformationThread ... ) == 0x0 02956 184 NtSetInformationThread ... ) == 0x0 02965 1064 NtSetInformationThread ... ) == 0x0 02978 1384 NtSetInformationThread ... ) == 0x0 02987 1240 NtSetInformationThread ... ) == 0x0 03000 296 NtSetInformationThread ... ) == 0x0 03009 740 NtSetInformationThread ... ) == 0x0 03022 120 NtSetInformationThread ... ) == 0x0 03031 1796 NtSetInformationThread ... ) == 0x0 03044 1728 NtSetInformationThread ... ) == 0x0 03053 152 NtSetInformationThread ... ) == 0x0 03066 180 NtSetInformationThread ... ) == 0x0 03075 1904 NtSetInformationThread ... ) == 0x0 03088 464 NtSetInformationThread ... ) == 0x0 03097 1536 NtSetInformationThread ... ) == 0x0 03110 444 NtSetInformationThread ... ) == 0x0 03119 1648 NtSetInformationThread ... ) == 0x0 03132 968 NtSetInformationThread ... ) == 0x0 03142 1688 NtSetInformationThread ... ) == 0x0 03155 1584 NtSetInformationThread ... ) == 0x0 03164 1944 NtSetInformationThread ... ) == 0x0 03177 148 NtSetInformationThread ... ) == 0x0 03186 1500 NtSetInformationThread ... ) == 0x0 03199 240 NtSetInformationThread ... ) == 0x0 03208 2032 NtSetInformationThread ... ) == 0x0 03221 1592 NtSetInformationThread ... ) == 0x0 03230 496 NtSetInformationThread ... ) == 0x0 03243 476 NtSetInformationThread ... ) == 0x0 03252 1404 NtSetInformationThread ... ) == 0x0 03265 1744 NtSetInformationThread ... ) == 0x0 03274 336 NtSetInformationThread ... ) == 0x0 03287 1128 NtSetInformationThread ... ) == 0x0 03296 1924 NtSetInformationThread ... ) == 0x0 03309 2040 NtSetInformationThread ... ) == 0x0 03318 1524 NtSetInformationThread ... ) == 0x0 03331 388 NtSetInformationThread ... ) == 0x0 03340 1020 NtSetInformationThread ... ) == 0x0 03353 1804 NtSetInformationThread ... ) == 0x0 03362 1644 NtSetInformationThread ... ) == 0x0 03375 1124 NtSetInformationThread ... ) == 0x0 03384 776 NtSetInformationThread ... ) == 0x0 03397 1692 NtSetInformationThread ... ) == 0x0 03406 1392 NtSetInformationThread ... ) == 0x0 03419 1176 NtSetInformationThread ... ) == 0x0 03428 1828 NtSetInformationThread ... ) == 0x0 03441 1544 NtSetInformationThread ... ) == 0x0 03451 1548 NtSetInformationThread ... ) == 0x0 03464 1540 NtSetInformationThread ... ) == 0x0 03473 420 NtSetInformationThread ... ) == 0x0 03486 2012 NtSetInformationThread ... ) == 0x0 03495 1168 NtSetInformationThread ... ) == 0x0 03508 928 NtSetInformationThread ... ) == 0x0 03517 900 NtSetInformationThread ... ) == 0x0 03530 1388 NtSetInformationThread ... ) == 0x0 03539 1948 NtSetInformationThread ... ) == 0x0 03552 1708 NtSetInformationThread ... ) == 0x0 03561 1324 NtSetInformationThread ... ) == 0x0 03574 248 NtSetInformationThread ... ) == 0x0 03583 1676 NtSetInformationThread ... ) == 0x0 03596 1588 NtSetInformationThread ... ) == 0x0 03605 1376 NtSetInformationThread ... ) == 0x0 03618 1436 NtSetInformationThread ... ) == 0x0 03627 1276 NtSetInformationThread ... ) == 0x0 03640 1636 NtSetInformationThread ... ) == 0x0 03649 1152 NtSetInformationThread ... ) == 0x0 03662 1484 NtSetInformationThread ... ) == 0x0 03671 888 NtSetInformationThread ... ) == 0x0 03684 840 NtSetInformationThread ... ) == 0x0 03693 876 NtSetInformationThread ... ) == 0x0 03706 860 NtSetInformationThread ... ) == 0x0 03715 780 NtSetInformationThread ... ) == 0x0 03745 428 NtWaitForSingleObject (252, 0, 0x0, ... 03746 1028 NtWaitForSingleObject (252, 0, 0x0, ... 03747 1700 NtWaitForSingleObject (252, 0, 0x0, ... 03748 1740 NtWaitForSingleObject (252, 0, 0x0, ... 03749 1096 NtWaitForSingleObject (252, 0, 0x0, ... 03750 1300 NtWaitForSingleObject (252, 0, 0x0, ... 03751 1964 NtWaitForSingleObject (252, 0, 0x0, ... 03752 1624 NtWaitForSingleObject (252, 0, 0x0, ... 03753 1440 NtWaitForSingleObject (252, 0, 0x0, ... 03754 1972 NtWaitForSingleObject (252, 0, 0x0, ... 03755 1036 NtWaitForSingleObject (252, 0, 0x0, ... 03756 1664 NtWaitForSingleObject (252, 0, 0x0, ... 03757 1248 NtWaitForSingleObject (252, 0, 0x0, ... 03758 1656 NtWaitForSingleObject (252, 0, 0x0, ... 03759 760 NtWaitForSingleObject (252, 0, 0x0, ... 03760 896 NtClose (780, ... 03761 484 NtWaitForSingleObject (252, 0, 0x0, ... 03762 1580 NtWaitForSingleObject (252, 0, 0x0, ... 03763 1756 NtWaitForSingleObject (252, 0, 0x0, ... 03764 1304 NtWaitForSingleObject (252, 0, 0x0, ... 03765 1292 NtWaitForSingleObject (252, 0, 0x0, ... 03766 1956 NtWaitForSingleObject (252, 0, 0x0, ... 03767 1556 NtWaitForSingleObject (252, 0, 0x0, ... 03768 1480 NtWaitForSingleObject (252, 0, 0x0, ... 03769 1784 NtWaitForSingleObject (252, 0, 0x0, ... 03770 1856 NtWaitForSingleObject (252, 0, 0x0, ... 03771 1604 NtWaitForSingleObject (252, 0, 0x0, ... 03772 1272 NtWaitForSingleObject (252, 0, 0x0, ... 03773 1132 NtWaitForSingleObject (252, 0, 0x0, ... 03774 184 NtWaitForSingleObject (252, 0, 0x0, ... 03775 1064 NtWaitForSingleObject (252, 0, 0x0, ... 03776 1384 NtWaitForSingleObject (252, 0, 0x0, ... 03777 1240 NtWaitForSingleObject (252, 0, 0x0, ... 03778 296 NtWaitForSingleObject (252, 0, 0x0, ... 03779 740 NtWaitForSingleObject (252, 0, 0x0, ... 03780 120 NtWaitForSingleObject (252, 0, 0x0, ... 03781 1796 NtWaitForSingleObject (252, 0, 0x0, ... 03782 1728 NtWaitForSingleObject (252, 0, 0x0, ... 03783 152 NtWaitForSingleObject (252, 0, 0x0, ... 03784 180 NtWaitForSingleObject (252, 0, 0x0, ... 03785 1904 NtWaitForSingleObject (252, 0, 0x0, ... 03786 464 NtWaitForSingleObject (252, 0, 0x0, ... 03787 1536 NtWaitForSingleObject (252, 0, 0x0, ... 03788 444 NtWaitForSingleObject (252, 0, 0x0, ... 03789 1648 NtWaitForSingleObject (252, 0, 0x0, ... 03790 968 NtWaitForSingleObject (252, 0, 0x0, ... 03791 1688 NtWaitForSingleObject (252, 0, 0x0, ... 03792 1584 NtWaitForSingleObject (252, 0, 0x0, ... 03793 1944 NtWaitForSingleObject (252, 0, 0x0, ... 03794 148 NtWaitForSingleObject (252, 0, 0x0, ... 03795 1500 NtWaitForSingleObject (252, 0, 0x0, ... 03796 240 NtWaitForSingleObject (252, 0, 0x0, ... 03797 2032 NtWaitForSingleObject (252, 0, 0x0, ... 03798 1592 NtWaitForSingleObject (252, 0, 0x0, ... 03799 496 NtWaitForSingleObject (252, 0, 0x0, ... 03800 476 NtWaitForSingleObject (252, 0, 0x0, ... 03801 1404 NtWaitForSingleObject (252, 0, 0x0, ... 03802 1744 NtWaitForSingleObject (252, 0, 0x0, ... 03803 336 NtWaitForSingleObject (252, 0, 0x0, ... 03804 1128 NtWaitForSingleObject (252, 0, 0x0, ... 03805 1924 NtWaitForSingleObject (252, 0, 0x0, ... 03806 2040 NtWaitForSingleObject (252, 0, 0x0, ... 03807 1524 NtWaitForSingleObject (252, 0, 0x0, ... 03808 388 NtWaitForSingleObject (252, 0, 0x0, ... 03809 1020 NtWaitForSingleObject (252, 0, 0x0, ... 03810 1804 NtWaitForSingleObject (252, 0, 0x0, ... 03811 1644 NtWaitForSingleObject (252, 0, 0x0, ... 03812 1124 NtWaitForSingleObject (252, 0, 0x0, ... 03813 776 NtWaitForSingleObject (252, 0, 0x0, ... 03814 1692 NtWaitForSingleObject (252, 0, 0x0, ... 03815 1392 NtWaitForSingleObject (252, 0, 0x0, ... 03816 1176 NtWaitForSingleObject (252, 0, 0x0, ... 03817 1828 NtWaitForSingleObject (252, 0, 0x0, ... 03818 1544 NtWaitForSingleObject (252, 0, 0x0, ... 03819 1548 NtWaitForSingleObject (252, 0, 0x0, ... 03820 1540 NtWaitForSingleObject (252, 0, 0x0, ... 03821 420 NtWaitForSingleObject (252, 0, 0x0, ... 03822 2012 NtWaitForSingleObject (252, 0, 0x0, ... 03823 1168 NtWaitForSingleObject (252, 0, 0x0, ... 03824 928 NtWaitForSingleObject (252, 0, 0x0, ... 03825 900 NtWaitForSingleObject (252, 0, 0x0, ... 03826 1388 NtWaitForSingleObject (252, 0, 0x0, ... 03827 1948 NtWaitForSingleObject (252, 0, 0x0, ... 03828 1708 NtWaitForSingleObject (252, 0, 0x0, ... 03829 1324 NtWaitForSingleObject (252, 0, 0x0, ... 03830 248 NtWaitForSingleObject (252, 0, 0x0, ... 03831 1676 NtWaitForSingleObject (252, 0, 0x0, ... 03832 1588 NtWaitForSingleObject (252, 0, 0x0, ... 03833 1376 NtWaitForSingleObject (252, 0, 0x0, ... 03834 1436 NtWaitForSingleObject (252, 0, 0x0, ... 03835 1276 NtWaitForSingleObject (252, 0, 0x0, ... 03836 1636 NtWaitForSingleObject (252, 0, 0x0, ... 03837 1152 NtWaitForSingleObject (252, 0, 0x0, ... 03838 1484 NtWaitForSingleObject (252, 0, 0x0, ... 03839 888 NtWaitForSingleObject (252, 0, 0x0, ... 03840 840 NtWaitForSingleObject (252, 0, 0x0, ... 03841 876 NtWaitForSingleObject (252, 0, 0x0, ... 03842 860 NtWaitForSingleObject (252, 0, 0x0, ... 03843 780 NtWaitForSingleObject (252, 0, 0x0, ... 03760 896 NtClose ... ) == 0x0 03844 896 NtClose (776, ... ) == 0x0 03845 896 NtDelayExecution (0, {-10000000, -1}, ... 03744 504 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03846 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 776, ) }, ... 776, ) == 0x0 03847 504 NtQueryValueKey (776, (776, "CertificateRevocation", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (776, "CertificateRevocation", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 03848 504 NtClose (776, ... ) == 0x0 03849 504 NtQueryValueKey (136, (136, "DisableKeepAlive", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03850 504 NtQueryValueKey (136, (136, "DisablePassport", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03851 504 NtQueryValueKey (136, (136, "IdnEnabled", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03852 504 NtQueryValueKey (136, (136, "CacheMode", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03853 504 NtQueryValueKey (136, (136, "EnableHttp1_1", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (136, "EnableHttp1_1", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03854 504 NtQueryValueKey (136, (136, "ProxyHttp1.1", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03855 504 NtQueryValueKey (136, (136, "EnableNegotiate", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (136, "EnableNegotiate", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03856 504 NtQueryValueKey (136, (136, "DisableBasicOverClearChannel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03857 504 NtOpenKey (0x20019, {24, 40, 0x40, 0, 0, (0x20019, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03858 504 NtOpenKey (0x20019, {24, 140, 0x40, 0, 0, (0x20019, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03859 504 NtOpenKey (0x20019, {24, 140, 0x40, 0, 0, (0x20019, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03860 504 NtOpenKey (0x20019, {24, 40, 0x40, 0, 0, (0x20019, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 776, ) }, ... 776, ) == 0x0 03861 504 NtQueryValueKey (776, (776, "Feature_ClientAuthCertFilter", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03862 504 NtClose (776, ... ) == 0x0 03863 504 NtAllocateVirtualMemory (-1, 17879040, 0, 4096, 4096, 260, ... 17879040, 4096, ) == 0x0 03864 504 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "Secur32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03865 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\Secur32.dll"}, 17886864, ... ) }, 17886864, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03866 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Secur32.dll"}, 17886864, ... ) }, 17886864, ... ) == 0x0 03867 504 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Secur32.dll"}, 5, 96, ... 776, {status=0x0, info=1}, ) }, 5, 96, ... 776, {status=0x0, info=1}, ) == 0x0 03868 504 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 776, ... 780, ) == 0x0 03869 504 NtQuerySection (780, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03870 504 NtClose (776, ... ) == 0x0 03871 504 NtMapViewOfSection (780, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77fe0000), 0x0, 69632, ) == 0x0 03872 504 NtClose (780, ... ) == 0x0 03873 504 NtProtectVirtualMemory (-1, (0x77fe1000), 388, 4, ... (0x77fe1000), 4096, 32, ) == 0x0 03874 504 NtProtectVirtualMemory (-1, (0x77fe1000), 4096, 32, ... (0x77fe1000), 4096, 4, ) == 0x0 03875 504 NtFlushInstructionCache (-1, 2013138944, 388, ... ) == 0x0 03876 504 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secur32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03877 504 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 780, ) == 0x0 03878 504 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 776, ) == 0x0 03879 504 NtOpenEvent (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\SECURITY\LSA_AUTHENTICATION_INITIALIZED"}, ... 788, ) }, ... 788, ) == 0x0 03880 504 NtQueryEvent (788, Basic, 8, ... {EventType=0,SignalState=1,}, 0x0, ) == 0x0 03881 504 NtClose (788, ... ) == 0x0 03882 504 NtConnectPort ( ("\LsaAuthenticationPort", {12, 2, 1, 0}, 0x0, 0x0, 17888436, 140, ... 788, 0x0, 0x0, 256, 140, ) , {12, 2, 1, 0}, 0x0, 0x0, 17888436, 140, ... 788, 0x0, 0x0, 256, 140, ) == 0x0 03883 504 NtRequestWaitReplyPort (788, {28, 52, new_msg, 0, 0, 0, 0, 0} (788, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\353\6\10\2\300\374\24\0" ... {188, 212, reply, 0, 1252, 504, 82051, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\34\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0" ) ... {188, 212, reply, 0, 1252, 504, 82051, 0} (788, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\353\6\10\2\300\374\24\0" ... {188, 212, reply, 0, 1252, 504, 82051, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\34\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0" ) ) == 0x0 03884 504 NtQueryValueKey (136, (136, "SyncMode5", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03885 504 NtOpenKey (0x9, {24, 40, 0x40, 0, 0, (0x9, {24, 40, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 792, ) }, ... 792, ) == 0x0 03886 504 NtQueryValueKey (792, (792, "SessionStartTimeDefaultDeltaSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03887 504 NtClose (792, ... ) == 0x0 03888 504 NtOpenKey (0xf, {24, 40, 0x40, 0, 0, (0xf, {24, 40, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 792, ) }, ... 792, ) == 0x0 03889 504 NtOpenKey (0xf, {24, 140, 0x40, 0, 0, (0xf, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 796, ) }, ... 796, ) == 0x0 03890 504 NtOpenKey (0x9, {24, 140, 0x40, 0, 0, (0x9, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 800, ) }, ... 800, ) == 0x0 03891 504 NtQueryValueKey (800, (800, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) }, 68, ) == 0x0 03892 504 NtQueryValueKey (800, (800, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) }, 68, ) == 0x0 03893 504 NtClose (800, ... ) == 0x0 03894 504 NtOpenKey (0xf, {24, 796, 0x40, 0, 0, (0xf, {24, 796, 0x40, 0, 0, "Content"}, ... 800, ) }, ... 800, ) == 0x0 03895 504 NtQueryValueKey (800, (800, "PerUserItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03896 504 NtOpenKey (0xf, {24, 792, 0x40, 0, 0, (0xf, {24, 792, 0x40, 0, 0, "Content"}, ... 804, ) }, ... 804, ) == 0x0 03897 504 NtQueryValueKey (804, (804, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (804, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03898 504 NtClose (804, ... ) == 0x0 03899 504 NtClose (800, ... ) == 0x0 03900 504 NtOpenKey (0xf, {24, 796, 0x40, 0, 0, (0xf, {24, 796, 0x40, 0, 0, "Content"}, ... 800, ) }, ... 800, ) == 0x0 03901 504 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHELL32.dll"}, ... 804, ) }, ... 804, ) == 0x0 03902 504 NtMapViewOfSection (804, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7c9c0000), 0x0, 8482816, ) == 0x0 03903 504 NtClose (804, ... ) == 0x0 03904 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03905 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03906 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03907 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03908 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03909 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03910 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03911 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03912 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03913 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03914 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03915 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03916 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03917 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03918 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03919 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03920 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03921 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03922 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03923 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03924 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03925 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 03926 504 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 03927 504 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 03928 504 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHELL32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03929 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SYSTEM\Setup"}, ... 804, ) }, ... 804, ) == 0x0 03930 504 NtQueryValueKey (804, (804, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (804, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 03931 504 NtAllocateVirtualMemory (-1, 17874944, 0, 4096, 4096, 260, ... 17874944, 4096, ) == 0x0 03932 504 NtClose (804, ... ) == 0x0 03933 504 NtQueryDefaultUILanguage (17883460, ... 03934 504 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03935 504 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482764, ) == 0x0 03936 504 NtQueryInformationToken (-2147482764, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03937 504 NtClose (-2147482764, ... ) == 0x0 03938 504 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482764, ) }, ... -2147482764, ) == 0x0 03939 504 NtOpenKey (0x80000000, {24, -2147482764, 0x240, 0, 0, (0x80000000, {24, -2147482764, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03940 504 NtOpenKey (0x80000000, {24, -2147482764, 0x640, 0, 0, (0x80000000, {24, -2147482764, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482688, ) }, ... -2147482688, ) == 0x0 03941 504 NtQueryValueKey (-2147482688, (-2147482688, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03942 504 NtClose (-2147482688, ... ) == 0x0 03943 504 NtClose (-2147482764, ... ) == 0x0 03933 504 NtQueryDefaultUILanguage ... ) == 0x0 03944 504 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1, 96, ... 804, {status=0x0, info=1}, ) }, 1, 96, ... 804, {status=0x0, info=1}, ) == 0x0 03945 504 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 804, ... 808, ) == 0x0 03946 504 NtMapViewOfSection (808, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x8d10000), 0x0, 8462336, ) == 0x0 03947 504 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03948 504 NtAllocateVirtualMemory (-1, 17870848, 0, 4096, 4096, 260, ... 17870848, 4096, ) == 0x0 03949 504 NtQueryDefaultLocale (1, 17881556, ... ) == 0x0 03950 504 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03951 504 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 17882592, 1179817, 17882316} (24, {128, 156, new_msg, 0, 2088850039, 17882592, 1179817, 17882316} "\210\6!\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6!\1$\3\0\0\377\377\377\377\0\0\0\0@ \364\10\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6!\1\0\0\0\0\0\0\0\0\324\341\20\1\0\0\0\0" ... {128, 156, reply, 0, 1252, 504, 82052, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6!\1$\3\0\0\377\377\377\377\0\0\0\0@ \364\10\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6!\1\0\0\0\0\0\0\0\0\324\341\20\1\0\0\0\0" ) ... {128, 156, reply, 0, 1252, 504, 82052, 0} (24, {128, 156, new_msg, 0, 2088850039, 17882592, 1179817, 17882316} "\210\6!\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6!\1$\3\0\0\377\377\377\377\0\0\0\0@ \364\10\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6!\1\0\0\0\0\0\0\0\0\324\341\20\1\0\0\0\0" ... {128, 156, reply, 0, 1252, 504, 82052, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6!\1$\3\0\0\377\377\377\377\0\0\0\0@ \364\10\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6!\1\0\0\0\0\0\0\0\0\324\341\20\1\0\0\0\0" ) ) == 0x0 03952 504 NtClose (804, ... ) == 0x0 03953 504 NtClose (808, ... ) == 0x0 03954 504 NtUnmapViewOfSection (-1, 0x8d10000, ... ) == 0x0 03955 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03956 504 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03957 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03958 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03959 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 17880748, ... ) }, 17880748, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03960 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03961 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03962 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03963 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 17880812, ... ) }, 17880812, ... ) == 0x0 03964 504 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 3, 33, ... 808, {status=0x0, info=1}, ) }, 3, 33, ... 808, {status=0x0, info=1}, ) == 0x0 03965 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03966 504 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll"}, 5, 96, ... 804, {status=0x0, info=1}, ) }, 5, 96, ... 804, {status=0x0, info=1}, ) == 0x0 03967 504 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 804, ... 812, ) == 0x0 03968 504 NtClose (804, ... ) == 0x0 03969 504 NtMapViewOfSection (812, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x8d10000), 0x0, 1056768, ) == 0x0 03970 504 NtClose (812, ... ) == 0x0 03971 504 NtUnmapViewOfSection (-1, 0x8d10000, ... ) == 0x0 03972 504 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll"}, 5, 96, ... 812, {status=0x0, info=1}, ) }, 5, 96, ... 812, {status=0x0, info=1}, ) == 0x0 03973 504 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 812, ... 804, ) == 0x0 03974 504 NtQuerySection (804, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03975 504 NtClose (812, ... ) == 0x0 03976 504 NtMapViewOfSection (804, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x773d0000), 0x0, 1060864, ) == 0x0 03977 504 NtClose (804, ... ) == 0x0 03978 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03979 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03980 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03981 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03982 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03983 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03984 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03985 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03986 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03987 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03988 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03989 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03990 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03991 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03992 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03993 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03994 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03995 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03996 504 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 03997 504 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 03998 504 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 03999 504 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04000 504 NtAddAtom ( ("T\0h\0e\0m\0e\0P\0r\0o\0p\0S\0c\0r\0o\0l\0l\0B\0a\0r\0C\0t\0l\0", 42, 17882292, ... ) , 42, 17882292, ... ) == 0x0 04001 504 NtQueryDefaultUILanguage (17880976, ... 04002 504 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04003 504 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482764, ) == 0x0 04004 504 NtQueryInformationToken (-2147482764, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04005 504 NtClose (-2147482764, ... ) == 0x0 04006 504 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482764, ) }, ... -2147482764, ) == 0x0 04007 504 NtOpenKey (0x80000000, {24, -2147482764, 0x240, 0, 0, (0x80000000, {24, -2147482764, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04008 504 NtOpenKey (0x80000000, {24, -2147482764, 0x640, 0, 0, (0x80000000, {24, -2147482764, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482688, ) }, ... -2147482688, ) == 0x0 04009 504 NtQueryValueKey (-2147482688, (-2147482688, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04010 504 NtClose (-2147482688, ... ) == 0x0 04011 504 NtClose (-2147482764, ... ) == 0x0 04001 504 NtQueryDefaultUILanguage ... ) == 0x0 04012 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 17879816, ... ) }, 17879816, ... ) == 0x0 04013 504 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 5, 96, ... 804, {status=0x0, info=1}, ) }, 5, 96, ... 804, {status=0x0, info=1}, ) == 0x0 04014 504 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 804, ... 812, ) == 0x0 04015 504 NtClose (804, ... ) == 0x0 04016 504 NtMapViewOfSection (812, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x3e0000), 0x0, 4096, ) == 0x0 04017 504 NtClose (812, ... ) == 0x0 04018 504 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 04019 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 17879412, ... ) }, 17879412, ... ) == 0x0 04020 504 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 17880156, (0x80100080, {24, 0, 0x40, 0, 17880156, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 0x0, 0, 5, 1, 96, 0, 0, ... 812, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 812, {status=0x0, info=1}, ) == 0x0 04021 504 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 812, ... 804, ) == 0x0 04022 504 NtClose (812, ... ) == 0x0 04023 504 NtMapViewOfSection (804, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x3e0000), {0, 0}, 4096, ) == 0x0 04024 504 NtClose (804, ... ) == 0x0 04025 504 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 04026 504 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1, 96, ... 804, {status=0x0, info=1}, ) }, 1, 96, ... 804, {status=0x0, info=1}, ) == 0x0 04027 504 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 804, ... 812, ) == 0x0 04028 504 NtMapViewOfSection (812, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x3e0000), 0x0, 4096, ) == 0x0 04029 504 NtQueryInformationFile (804, 17879808, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04030 504 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04031 504 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 17880108, 1179817, 17879832} (24, {128, 156, new_msg, 0, 2088850039, 17880108, 1179817, 17879832} "\210\6!\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6!\1$\3\0\0,\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6!\1\0\0\0\0\0\0\0\0 \330\20\1\0\0\0\0" ... {128, 156, reply, 0, 1252, 504, 82053, 0} "\260d\27\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6!\1$\3\0\0,\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6!\1\0\0\0\0\0\0\0\0 \330\20\1\0\0\0\0" ) ... {128, 156, reply, 0, 1252, 504, 82053, 0} (24, {128, 156, new_msg, 0, 2088850039, 17880108, 1179817, 17879832} "\210\6!\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6!\1$\3\0\0,\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6!\1\0\0\0\0\0\0\0\0 \330\20\1\0\0\0\0" ... {128, 156, reply, 0, 1252, 504, 82053, 0} "\260d\27\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6!\1$\3\0\0,\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6!\1\0\0\0\0\0\0\0\0 \330\20\1\0\0\0\0" ) ) == 0x0 04032 504 NtClose (804, ... ) == 0x0 04033 504 NtClose (812, ... ) == 0x0 04034 504 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 04035 504 NtQueryDebugFilterState (53, 2, ... ) == 0x0 04036 504 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 812, ) == 0x0 04037 504 NtCallbackReturn (0, 0, 0, ... 04038 504 NtUserGetThreadState (18, ... ) == 0x1 04039 504 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 04040 504 NtUserSystemParametersInfo (104, 0, 2001084812, 0, ... ) == 0x1 04041 504 NtUserGetDC (0, ... ) == 0x1010051 04042 504 NtUserCallOneParam (16842833, 57, ... ) == 0x1 04043 504 NtUserSystemParametersInfo (38, 4, 2001086940, 0, ... ) == 0x1 04044 504 NtAllocateVirtualMemory (-1, 1388544, 0, 4096, 4096, 4, ... 1388544, 4096, ) == 0x0 04045 504 NtUserSystemParametersInfo (66, 12, 17881808, 0, ... ) == 0x1 04046 504 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04047 504 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 804, ) == 0x0 04048 504 NtQueryInformationToken (804, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04049 504 NtClose (804, ... ) == 0x0 04050 504 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 804, ) }, ... 804, ) == 0x0 04051 504 NtOpenProcessToken (-1, 0x8, ... 816, ) == 0x0 04052 504 NtAccessCheck (1344040, 816, 0x1, 17881640, 17881692, 56, 17881672, ... ) == STATUS_NO_IMPERSONATION_TOKEN 04053 504 NtClose (816, ... ) == 0x0 04054 504 NtOpenKey (0x20019, {24, 804, 0x40, 0, 0, (0x20019, {24, 804, 0x40, 0, 0, "Control Panel\Desktop"}, ... 816, ) }, ... 816, ) == 0x0 04055 504 NtQueryValueKey (816, (816, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04056 504 NtClose (816, ... ) == 0x0 04057 504 NtUserSystemParametersInfo (41, 500, 17881836, 0, ... ) == 0x1 04058 504 NtOpenProcessToken (-1, 0x8, ... 816, ) == 0x0 04059 504 NtAccessCheck (1344040, 816, 0x1, 17881640, 17881692, 56, 17881672, ... ) == STATUS_NO_IMPERSONATION_TOKEN 04060 504 NtClose (816, ... ) == 0x0 04061 504 NtOpenKey (0x20019, {24, 804, 0x40, 0, 0, (0x20019, {24, 804, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 816, ) }, ... 816, ) == 0x0 04062 504 NtQueryValueKey (816, (816, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04063 504 NtClose (816, ... ) == 0x0 04064 504 NtUserSystemParametersInfo (27, 0, 2001085788, 0, ... ) == 0x1 04065 504 NtUserSystemParametersInfo (102, 0, 2001086828, 0, ... ) == 0x1 04066 504 NtClose (804, ... ) == 0x0 04067 504 NtUserSystemParametersInfo (4130, 0, 17882340, 0, ... ) == 0x1 04068 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\LanguagePack"}, ... 804, ) }, ... 804, ) == 0x0 04069 504 NtEnumerateValueKey (804, 0, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 04070 504 NtClose (804, ... ) == 0x0 04071 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04072 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc03b 04073 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc03d 04074 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04075 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc03f 04076 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04077 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc041 04078 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04079 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc043 04080 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc045 04081 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04082 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc047 04083 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04084 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc049 04085 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04086 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc04b 04087 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04088 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc04d 04089 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04090 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc04f 04091 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc051 04092 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04093 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc053 04094 504 NtUserFindExistingCursorIcon (17881584, 17881600, 17881648, ... ) == 0x10011 04095 504 NtUserRegisterClassExWOW (17881528, 17881596, 17881612, 17881628, 0, 384, 0, ... ) == 0x819fc055 04096 504 NtUserFindExistingCursorIcon (17881584, 17881600, 17881648, ... ) == 0x10011 04097 504 NtUserRegisterClassExWOW (17881528, 17881596, 17881612, 17881628, 0, 384, 0, ... ) == 0x819fc057 04098 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04099 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc059 04100 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10013 04101 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc05b 04102 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04103 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc05d 04104 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04105 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc05f 04106 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04107 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc017 04108 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04109 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc019 04110 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10013 04111 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc018 04112 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04113 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc01a 04114 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04115 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc01c 04116 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04117 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc01e 04118 504 NtUserFindExistingCursorIcon (17881580, 17881596, 17881644, ... ) == 0x10011 04119 504 NtUserRegisterClassExWOW (17881580, 17881648, 17881664, 17881680, 0, 384, 0, ... ) == 0x819fc01b 04120 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04121 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc068 04122 504 NtUserFindExistingCursorIcon (17881588, 17881604, 17881652, ... ) == 0x10011 04123 504 NtUserRegisterClassExWOW (17881532, 17881600, 17881616, 17881632, 0, 384, 0, ... ) == 0x819fc06a 04124 504 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04125 504 NtCreateSemaphore (0x1f0003, {24, 16, 0x80, 1338216, 0, (0x1f0003, {24, 16, 0x80, 1338216, 0, "shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}"}, 0, 2147483647, ... 804, ) }, 0, 2147483647, ... 804, ) == STATUS_OBJECT_NAME_EXISTS 04126 504 NtReleaseSemaphore (804, 1, ... 0, ) == 0x0 04127 504 NtWaitForSingleObject (804, 0, {0, 0}, ... ) == 0x0 04128 504 NtCreateKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 816, 2, ) }, 0, 0x0, 0, ... 816, 2, ) == 0x0 04129 504 NtQueryValueKey (816, (816, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (816, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 04130 504 NtClose (816, ... ) == 0x0 04131 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files"}, 17886532, ... ) }, 17886532, ... ) == 0x0 04132 504 NtCreateKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 816, 2, ) }, 0, 0x0, 0, ... 816, 2, ) == 0x0 04133 504 NtSetValueKey (816, (816, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 162, ... ) , 0, 1, (816, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 162, ... ) , 162, ... ) == 0x0 04134 504 NtClose (816, ... ) == 0x0 04135 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files"}, 17887224, ... ) }, 17887224, ... ) == 0x0 04136 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files"}, 17886432, ... ) }, 17886432, ... ) == 0x0 04137 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files"}, 7, 2113568, ... 816, {status=0x0, info=1}, ) }, 7, 2113568, ... 816, {status=0x0, info=1}, ) == 0x0 04138 504 NtSetInformationFile (816, 17886404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04139 504 NtClose (816, ... ) == 0x0 04140 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\desktop.ini"}, 17886428, ... ) }, 17886428, ... ) == 0x0 04141 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5"}, 17887224, ... ) }, 17887224, ... ) == 0x0 04142 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5"}, 17886432, ... ) }, 17886432, ... ) == 0x0 04143 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5"}, 7, 2113568, ... 816, {status=0x0, info=1}, ) }, 7, 2113568, ... 816, {status=0x0, info=1}, ) == 0x0 04144 504 NtSetInformationFile (816, 17886404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04145 504 NtClose (816, ... ) == 0x0 04146 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini"}, 17886428, ... ) }, 17886428, ... ) == 0x0 04147 504 NtQueryValueKey (800, (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04148 504 NtQueryValueKey (800, (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 04149 504 NtQueryValueKey (800, (800, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\260\376\3\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (800, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\260\376\3\0"}, 16, ) }, 16, ) == 0x0 04150 504 NtOpenKey (0xf, {24, 796, 0x40, 0, 0, (0xf, {24, 796, 0x40, 0, 0, "Cookies"}, ... 816, ) }, ... 816, ) == 0x0 04151 504 NtQueryValueKey (816, (816, "PerUserItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04152 504 NtOpenKey (0xf, {24, 792, 0x40, 0, 0, (0xf, {24, 792, 0x40, 0, 0, "Cookies"}, ... 820, ) }, ... 820, ) == 0x0 04153 504 NtQueryValueKey (820, (820, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (820, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04154 504 NtClose (820, ... ) == 0x0 04155 504 NtClose (816, ... ) == 0x0 04156 504 NtClose (800, ... ) == 0x0 04157 504 NtOpenKey (0xf, {24, 796, 0x40, 0, 0, (0xf, {24, 796, 0x40, 0, 0, "Cookies"}, ... 800, ) }, ... 800, ) == 0x0 04158 504 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04159 504 NtReleaseSemaphore (804, 1, ... 0, ) == 0x0 04160 504 NtWaitForSingleObject (804, 0, {0, 0}, ... ) == 0x0 04161 504 NtCreateKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 816, 2, ) }, 0, 0x0, 0, ... 816, 2, ) == 0x0 04162 504 NtQueryValueKey (816, (816, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (816, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 04163 504 NtClose (816, ... ) == 0x0 04164 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Cookies"}, 17886532, ... ) }, 17886532, ... ) == 0x0 04165 504 NtCreateKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 816, 2, ) }, 0, 0x0, 0, ... 816, 2, ) == 0x0 04166 504 NtSetValueKey (816, (816, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 98, ... ) , 0, 1, (816, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 98, ... ) , 98, ... ) == 0x0 04167 504 NtClose (816, ... ) == 0x0 04168 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Cookies"}, 17887224, ... ) }, 17887224, ... ) == 0x0 04169 504 NtQueryValueKey (800, (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) }, 28, ) == 0x0 04170 504 NtQueryValueKey (800, (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) }, 28, ) == 0x0 04171 504 NtQueryValueKey (800, (800, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (800, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04172 504 NtOpenKey (0xf, {24, 796, 0x40, 0, 0, (0xf, {24, 796, 0x40, 0, 0, "History"}, ... 816, ) }, ... 816, ) == 0x0 04173 504 NtQueryValueKey (816, (816, "PerUserItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04174 504 NtOpenKey (0xf, {24, 792, 0x40, 0, 0, (0xf, {24, 792, 0x40, 0, 0, "History"}, ... 820, ) }, ... 820, ) == 0x0 04175 504 NtQueryValueKey (820, (820, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (820, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04176 504 NtClose (820, ... ) == 0x0 04177 504 NtClose (816, ... ) == 0x0 04178 504 NtClose (800, ... ) == 0x0 04179 504 NtOpenKey (0xf, {24, 796, 0x40, 0, 0, (0xf, {24, 796, 0x40, 0, 0, "History"}, ... 800, ) }, ... 800, ) == 0x0 04180 504 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04181 504 NtReleaseSemaphore (804, 1, ... 0, ) == 0x0 04182 504 NtWaitForSingleObject (804, 0, {0, 0}, ... ) == 0x0 04183 504 NtCreateKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 816, 2, ) }, 0, 0x0, 0, ... 816, 2, ) == 0x0 04184 504 NtQueryValueKey (816, (816, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (816, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 04185 504 NtClose (816, ... ) == 0x0 04186 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History"}, 17886532, ... ) }, 17886532, ... ) == 0x0 04187 504 NtCreateKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 816, 2, ) }, 0, 0x0, 0, ... 816, 2, ) == 0x0 04188 504 NtSetValueKey (816, (816, "History", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0", 128, ... ) , 0, 1, (816, "History", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0", 128, ... ) , 128, ... ) == 0x0 04189 504 NtClose (816, ... ) == 0x0 04190 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History"}, 17887224, ... ) }, 17887224, ... ) == 0x0 04191 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History"}, 17886432, ... ) }, 17886432, ... ) == 0x0 04192 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History"}, 7, 2113568, ... 816, {status=0x0, info=1}, ) }, 7, 2113568, ... 816, {status=0x0, info=1}, ) == 0x0 04193 504 NtSetInformationFile (816, 17886404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04194 504 NtClose (816, ... ) == 0x0 04195 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\desktop.ini"}, 17886428, ... ) }, 17886428, ... ) == 0x0 04196 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5"}, 17887224, ... ) }, 17887224, ... ) == 0x0 04197 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5"}, 17886432, ... ) }, 17886432, ... ) == 0x0 04198 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5"}, 7, 2113568, ... 816, {status=0x0, info=1}, ) }, 7, 2113568, ... 816, {status=0x0, info=1}, ) == 0x0 04199 504 NtSetInformationFile (816, 17886404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04200 504 NtClose (816, ... ) == 0x0 04201 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\desktop.ini"}, 17886428, ... ) }, 17886428, ... ) == 0x0 04202 504 NtQueryValueKey (800, (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) }, 30, ) == 0x0 04203 504 NtQueryValueKey (800, (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (800, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) }, 30, ) == 0x0 04204 504 NtQueryValueKey (800, (800, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (800, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04205 504 NtClose (800, ... ) == 0x0 04206 504 NtClose (796, ... ) == 0x0 04207 504 NtClose (792, ... ) == 0x0 04208 504 NtOpenMutant (0x100000, {24, 16, 0x0, 0, 0, (0x100000, {24, 16, 0x0, 0, 0, "Local\_!MSFTHISTORY!_"}, ... 792, ) }, ... 792, ) == 0x0 04209 504 NtOpenMutant (0x100000, {24, 16, 0x0, 0, 0, (0x100000, {24, 16, 0x0, 0, 0, "Local\c:!documents and settings!martim carbone!local settings!temporary internet files!content.ie5!"}, ... 796, ) }, ... 796, ) == 0x0 04210 504 NtWaitForSingleObject (796, 0, 0x0, ... ) == 0x0 04211 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\"}, 17888532, ... ) }, 17888532, ... ) == 0x0 04212 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\"}, 7, 2113568, ... 800, {status=0x0, info=1}, ) }, 7, 2113568, ... 800, {status=0x0, info=1}, ) == 0x0 04213 504 NtSetInformationFile (800, 17888508, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04214 504 NtClose (800, ... ) == 0x0 04215 504 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 17888448, (0xc0100080, {24, 0, 0x40, 0, 17888448, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\index.dat"}, 0x0, 8198, 3, 3, 2144, 0, 0, ... 800, {status=0x0, info=1}, ) }, 0x0, 8198, 3, 3, 2144, 0, 0, ... 800, {status=0x0, info=1}, ) == 0x0 04216 504 NtSetInformationFile (800, 17888500, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04217 504 NtQueryInformationFile (800, 17888500, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04218 504 NtOpenSection (0x2, {24, 16, 0x0, 0, 0, (0x2, {24, 16, 0x0, 0, 0, "Local\C:_Documents and Settings_Martim Carbone_Local Settings_Temporary Internet Files_Content.IE5_index.dat_802816"}, ... 816, ) }, ... 816, ) == 0x0 04219 504 NtMapViewOfSection (816, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x8d10000), {0, 0}, 802816, ) == 0x0 04220 504 NtReleaseMutant (796, ... 0x0, ) == 0x0 04221 504 NtOpenMutant (0x100000, {24, 16, 0x0, 0, 0, (0x100000, {24, 16, 0x0, 0, 0, "Local\c:!documents and settings!martim carbone!cookies!"}, ... 820, ) }, ... 820, ) == 0x0 04222 504 NtWaitForSingleObject (820, 0, 0x0, ... ) == 0x0 04223 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Cookies\"}, 17888532, ... ) }, 17888532, ... ) == 0x0 04224 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Cookies\"}, 7, 2113568, ... 824, {status=0x0, info=1}, ) }, 7, 2113568, ... 824, {status=0x0, info=1}, ) == 0x0 04225 504 NtSetInformationFile (824, 17888508, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04226 504 NtClose (824, ... ) == 0x0 04227 504 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 17888448, (0xc0100080, {24, 0, 0x40, 0, 17888448, "\??\C:\Documents and Settings\Martim Carbone\Cookies\index.dat"}, 0x0, 8198, 3, 3, 2144, 0, 0, ... 824, {status=0x0, info=1}, ) }, 0x0, 8198, 3, 3, 2144, 0, 0, ... 824, {status=0x0, info=1}, ) == 0x0 04228 504 NtSetInformationFile (824, 17888500, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04229 504 NtQueryInformationFile (824, 17888500, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04230 504 NtOpenSection (0x2, {24, 16, 0x0, 0, 0, (0x2, {24, 16, 0x0, 0, 0, "Local\C:_Documents and Settings_Martim Carbone_Cookies_index.dat_32768"}, ... 828, ) }, ... 828, ) == 0x0 04231 504 NtMapViewOfSection (828, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3e0000), {0, 0}, 32768, ) == 0x0 04232 504 NtReleaseMutant (820, ... 0x0, ) == 0x0 04233 504 NtOpenMutant (0x100000, {24, 16, 0x0, 0, 0, (0x100000, {24, 16, 0x0, 0, 0, "Local\c:!documents and settings!martim carbone!local settings!history!history.ie5!"}, ... 832, ) }, ... 832, ) == 0x0 04234 504 NtWaitForSingleObject (832, 0, 0x0, ... ) == 0x0 04235 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\"}, 17888532, ... ) }, 17888532, ... ) == 0x0 04236 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\"}, 7, 2113568, ... 836, {status=0x0, info=1}, ) }, 7, 2113568, ... 836, {status=0x0, info=1}, ) == 0x0 04237 504 NtSetInformationFile (836, 17888508, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04238 504 NtClose (836, ... ) == 0x0 04239 504 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 17888448, (0xc0100080, {24, 0, 0x40, 0, 17888448, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\index.dat"}, 0x0, 8198, 3, 3, 2144, 0, 0, ... 836, {status=0x0, info=1}, ) }, 0x0, 8198, 3, 3, 2144, 0, 0, ... 836, {status=0x0, info=1}, ) == 0x0 04240 504 NtSetInformationFile (836, 17888500, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04241 504 NtQueryInformationFile (836, 17888500, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04242 504 NtOpenSection (0x2, {24, 16, 0x0, 0, 0, (0x2, {24, 16, 0x0, 0, 0, "Local\C:_Documents and Settings_Martim Carbone_Local Settings_History_History.IE5_index.dat_81920"}, ... 840, ) }, ... 840, ) == 0x0 04243 504 NtMapViewOfSection (840, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x8de0000), {0, 0}, 81920, ) == 0x0 04244 504 NtReleaseMutant (832, ... 0x0, ) == 0x0 04245 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\"}, 17888108, ... ) }, 17888108, ... ) == 0x0 04246 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\"}, 7, 2113568, ... 844, {status=0x0, info=1}, ) }, 7, 2113568, ... 844, {status=0x0, info=1}, ) == 0x0 04247 504 NtSetInformationFile (844, 17888080, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04248 504 NtClose (844, ... ) == 0x0 04249 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini"}, 17888104, ... ) }, 17888104, ... ) == 0x0 04250 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\"}, 17888108, ... ) }, 17888108, ... ) == 0x0 04251 504 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\"}, 7, 2113568, ... 844, {status=0x0, info=1}, ) }, 7, 2113568, ... 844, {status=0x0, info=1}, ) == 0x0 04252 504 NtSetInformationFile (844, 17888080, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 04253 504 NtClose (844, ... ) == 0x0 04254 504 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\History\History.IE5\desktop.ini"}, 17888104, ... ) }, 17888104, ... ) == 0x0 04255 504 NtWaitForSingleObject (796, 0, 0x0, ... ) == 0x0 04256 504 NtReleaseMutant (796, ... 0x0, ) == 0x0 04257 504 NtOpenKey (0xf, {24, 140, 0x40, 0, 0, (0xf, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 844, ) }, ... 844, ) == 0x0 04258 504 NtOpenKey (0xf, {24, 844, 0x40, 0, 0, (0xf, {24, 844, 0x40, 0, 0, "Extensible Cache"}, ... 848, ) }, ... 848, ) == 0x0 04259 504 NtClose (844, ... ) == 0x0 04260 504 NtWaitForSingleObject (792, 0, {-600000000, -1}, ... ) == 0x0 04261 504 NtEnumerateKey (848, 0, Basic, 288, ... {LastWrite={0x47401762,0x1c74db1}, TitleIdx=0, Name= (848, 0, Basic, 288, ... {LastWrite={0x47401762,0x1c74db1}, TitleIdx=0, Name="feedplat"}, 32, ) }, 32, ) == 0x0 04262 504 NtOpenKey (0xf, {24, 848, 0x40, 0, 0, (0xf, {24, 848, 0x40, 0, 0, "feedplat"}, ... 844, ) }, ... 844, ) == 0x0 04263 504 NtQueryValueKey (844, (844, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04264 504 NtQueryValueKey (844, (844, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04265 504 NtQueryValueKey (844, (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0F\0e\0e\0d\0s\0 \0C\0a\0c\0h\0e\0\0\0"}, 148, ) , Partial, 148, ... TitleIdx=0, Type=2, Data= (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0F\0e\0e\0d\0s\0 \0C\0a\0c\0h\0e\0\0\0"}, 148, ) }, 148, ) == 0x0 04266 504 NtQueryValueKey (844, (844, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04267 504 NtQueryValueKey (844, (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0F\0e\0e\0d\0s\0 \0C\0a\0c\0h\0e\0\0\0"}, 148, ) , Partial, 148, ... TitleIdx=0, Type=2, Data= (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0F\0e\0e\0d\0s\0 \0C\0a\0c\0h\0e\0\0\0"}, 148, ) }, 148, ) == 0x0 04268 504 NtQueryValueKey (844, (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="f\0e\0e\0d\0p\0l\0a\0t\0:\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="f\0e\0e\0d\0p\0l\0a\0t\0:\0\0\0"}, 32, ) }, 32, ) == 0x0 04269 504 NtQueryValueKey (844, (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="f\0e\0e\0d\0p\0l\0a\0t\0:\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="f\0e\0e\0d\0p\0l\0a\0t\0:\0\0\0"}, 32, ) }, 32, ) == 0x0 04270 504 NtQueryValueKey (844, (844, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04271 504 NtQueryValueKey (844, (844, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04272 504 NtClose (844, ... ) == 0x0 04273 504 NtEnumerateKey (848, 1, Basic, 288, ... {LastWrite={0x450668aa,0x1c8b090}, TitleIdx=0, Name= (848, 1, Basic, 288, ... {LastWrite={0x450668aa,0x1c8b090}, TitleIdx=0, Name="MSHist012008050720080508"}, 64, ) }, 64, ) == 0x0 04274 504 NtOpenKey (0xf, {24, 848, 0x40, 0, 0, (0xf, {24, 848, 0x40, 0, 0, "MSHist012008050720080508"}, ... 844, ) }, ... 844, ) == 0x0 04275 504 NtQueryValueKey (844, (844, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04276 504 NtQueryValueKey (844, (844, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04277 504 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 1392640, 4096, ) == 0x0 04278 504 NtQueryValueKey (844, (844, "CachePath", Partial, 160, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0\0\0"}, 160, ) , Partial, 160, ... TitleIdx=0, Type=2, Data= (844, "CachePath", Partial, 160, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0\0\0"}, 160, ) }, 160, ) == 0x0 04279 504 NtQueryValueKey (844, (844, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04280 504 NtQueryValueKey (844, (844, "CachePath", Partial, 160, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0\0\0"}, 160, ) , Partial, 160, ... TitleIdx=0, Type=2, Data= (844, "CachePath", Partial, 160, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0\0\0"}, 160, ) }, 160, ) == 0x0 04281 504 NtQueryValueKey (844, (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04282 504 NtQueryValueKey (844, (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\08\00\05\00\07\02\00\00\08\00\05\00\08\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 04283 504 NtQueryValueKey (844, (844, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 04284 504 NtQueryValueKey (844, (844, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 04285 504 NtClose (844, ... ) == 0x0 04286 504 NtEnumerateKey (848, 2, Basic, 288, ... {LastWrite={0x2030327f,0x1c7701e}, TitleIdx=0, Name= (848, 2, Basic, 288, ... {LastWrite={0x2030327f,0x1c7701e}, TitleIdx=0, Name="UserData"}, 32, ) }, 32, ) == 0x0 04287 504 NtOpenKey (0xf, {24, 848, 0x40, 0, 0, (0xf, {24, 848, 0x40, 0, 0, "UserData"}, ... 844, ) }, ... 844, ) == 0x0 04288 504 NtQueryValueKey (844, (844, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04289 504 NtQueryValueKey (844, (844, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04290 504 NtQueryValueKey (844, (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0I\0n\0t\0e\0r\0n\0e\0t\0 \0E\0x\0p\0l\0o\0r\0e\0r\0\\0U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 148, ) , Partial, 148, ... TitleIdx=0, Type=2, Data= (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0I\0n\0t\0e\0r\0n\0e\0t\0 \0E\0x\0p\0l\0o\0r\0e\0r\0\\0U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 148, ) }, 148, ) == 0x0 04291 504 NtQueryValueKey (844, (844, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04292 504 NtQueryValueKey (844, (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0I\0n\0t\0e\0r\0n\0e\0t\0 \0E\0x\0p\0l\0o\0r\0e\0r\0\\0U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 148, ) , Partial, 148, ... TitleIdx=0, Type=2, Data= (844, "CachePath", Partial, 148, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0I\0n\0t\0e\0r\0n\0e\0t\0 \0E\0x\0p\0l\0o\0r\0e\0r\0\\0U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 148, ) }, 148, ) == 0x0 04293 504 NtQueryValueKey (844, (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 30, ) }, 30, ) == 0x0 04294 504 NtQueryValueKey (844, (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (844, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="U\0s\0e\0r\0D\0a\0t\0a\0\0\0"}, 30, ) }, 30, ) == 0x0 04295 504 NtQueryValueKey (844, (844, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\350\3\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\350\3\0\0"}, 16, ) }, 16, ) == 0x0 04296 504 NtQueryValueKey (844, (844, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\10\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (844, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\10\0\0\0"}, 16, ) }, 16, ) == 0x0 04297 504 NtClose (844, ... ) == 0x0 04298 504 NtEnumerateKey (848, 3, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 04299 504 NtReleaseMutant (792, ... 0x0, ) == 0x0 04300 504 NtClose (848, ... ) == 0x0 04301 504 NtWaitForSingleObject (796, 0, 0x0, ... ) == 0x0 04302 504 NtReleaseMutant (796, ... 0x0, ) == 0x0 04303 504 NtWaitForSingleObject (796, 0, 0x0, ... ) == 0x0 04304 504 NtReleaseMutant (796, ... 0x0, ) == 0x0 04305 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04306 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04307 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04308 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04309 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04310 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04311 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04312 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 848, ) }, ... 848, ) == 0x0 04313 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04314 504 NtOpenKey (0x1, {24, 848, 0x40, 0, 0, (0x1, {24, 848, 0x40, 0, 0, "RETRY_HEADERONLYPOST_ONCONNECTIONRESET"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04315 504 NtClose (848, ... ) == 0x0 04316 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04317 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04318 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 848, ) }, ... 848, ) == 0x0 04319 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04320 504 NtOpenKey (0x1, {24, 848, 0x40, 0, 0, (0x1, {24, 848, 0x40, 0, 0, "FEATURE_BUFFERBREAKING_818408"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04321 504 NtClose (848, ... ) == 0x0 04322 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04323 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04324 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 848, ) }, ... 848, ) == 0x0 04325 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04326 504 NtOpenKey (0x1, {24, 848, 0x40, 0, 0, (0x1, {24, 848, 0x40, 0, 0, "FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04327 504 NtClose (848, ... ) == 0x0 04328 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04329 504 NtQueryValueKey (136, (136, "DisableWorkerThreadHibernation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04330 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 848, ) }, ... 848, ) == 0x0 04331 504 NtQueryValueKey (848, (848, "DisableWorkerThreadHibernation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04332 504 NtClose (848, ... ) == 0x0 04333 504 NtQueryValueKey (136, (136, "DisableReadRange", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04334 504 NtQueryValueKey (136, (136, "SocketSendBufferLength", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04335 504 NtQueryValueKey (136, (136, "SocketReceiveBufferLength", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04336 504 NtQueryValueKey (136, (136, "KeepAliveTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04337 504 NtQueryValueKey (136, (136, "MaxHttpRedirects", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04338 504 NtQueryValueKey (136, (136, "MaxConnectionsPerServer", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04339 504 NtQueryValueKey (136, (136, "MaxConnectionsPer1_0Server", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04340 504 NtQueryValueKey (136, (136, "ServerInfoTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04341 504 NtQueryValueKey (136, (136, "ConnectTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04342 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 848, ) }, ... 848, ) == 0x0 04343 504 NtQueryValueKey (848, (848, "ConnectTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04344 504 NtClose (848, ... ) == 0x0 04345 504 NtQueryValueKey (136, (136, "ConnectRetries", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04346 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 848, ) }, ... 848, ) == 0x0 04347 504 NtQueryValueKey (848, (848, "ConnectRetries", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04348 504 NtClose (848, ... ) == 0x0 04349 504 NtQueryValueKey (136, (136, "SendTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04350 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 848, ) }, ... 848, ) == 0x0 04351 504 NtQueryValueKey (848, (848, "SendTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04352 504 NtClose (848, ... ) == 0x0 04353 504 NtQueryValueKey (136, (136, "ReceiveTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04354 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 848, ) }, ... 848, ) == 0x0 04355 504 NtQueryValueKey (848, (848, "ReceiveTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04356 504 NtClose (848, ... ) == 0x0 04357 504 NtQueryValueKey (136, (136, "DisableNTLMPreAuth", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04358 504 NtQueryValueKey (136, (136, "ScavengeCacheLowerBound", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04359 504 NtQueryValueKey (136, (136, "CertCacheNoValidate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04360 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 848, ) }, ... 848, ) == 0x0 04361 504 NtQueryValueKey (848, (848, "ScavengeCacheFileLifeTime", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04362 504 NtClose (848, ... ) == 0x0 04363 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04364 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04365 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04366 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 848, ) }, ... 848, ) == 0x0 04367 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 844, ) }, ... 844, ) == 0x0 04368 504 NtQueryValueKey (844, (844, "ScavengeCacheFileLimit", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04369 504 NtQueryValueKey (848, (848, "ScavengeCacheFileLimit", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04370 504 NtClose (848, ... ) == 0x0 04371 504 NtClose (844, ... ) == 0x0 04372 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04373 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04374 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 844, ) }, ... 844, ) == 0x0 04375 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04376 504 NtOpenKey (0x1, {24, 844, 0x40, 0, 0, (0x1, {24, 844, 0x40, 0, 0, "FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04377 504 NtClose (844, ... ) == 0x0 04378 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04379 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04380 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 844, ) }, ... 844, ) == 0x0 04381 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04382 504 NtOpenKey (0x1, {24, 844, 0x40, 0, 0, (0x1, {24, 844, 0x40, 0, 0, "FEATURE_USE_CNAME_FOR_SPN_KB911149"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04383 504 NtClose (844, ... ) == 0x0 04384 504 NtQueryValueKey (136, (136, "HttpDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04385 504 NtQueryValueKey (136, (136, "FtpDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04386 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04387 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04388 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 844, ) }, ... 844, ) == 0x0 04389 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04390 504 NtOpenKey (0x1, {24, 844, 0x40, 0, 0, (0x1, {24, 844, 0x40, 0, 0, "FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04391 504 NtClose (844, ... ) == 0x0 04392 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04393 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04394 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 844, ) }, ... 844, ) == 0x0 04395 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04396 504 NtOpenKey (0x1, {24, 844, 0x40, 0, 0, (0x1, {24, 844, 0x40, 0, 0, "FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK"}, ... 848, ) }, ... 848, ) == 0x0 04397 504 NtQueryValueKey (848, (848, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04398 504 NtQueryValueKey (848, (848, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04399 504 NtClose (848, ... ) == 0x0 04400 504 NtClose (844, ... ) == 0x0 04401 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04402 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04403 504 NtOpenKey (0x1, {24, 40, 0x40, 0, 0, (0x1, {24, 40, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 844, ) }, ... 844, ) == 0x0 04404 504 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04405 504 NtOpenKey (0x1, {24, 844, 0x40, 0, 0, (0x1, {24, 844, 0x40, 0, 0, "FEATURE_DIGEST_NO_EXTRAS_IN_URI"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04406 504 NtClose (844, ... ) == 0x0