Summary:
NtAddAtom(>) | 1 | NtFsControlFile(>) | 2 | NtGdiGetStockObject(>) | 5 | NtQueryInformationFile(>) | 21 |
NtCallbackReturn(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtUserGetProcessWindowStation(>) | 5 | NtCreateEvent(>) | 23 |
NtCreateMutant(>) | 1 | NtGdiHfontCreate(>) | 2 | NtOpenThreadToken(>) | 6 | NtQueryInformationProcess(>) | 23 |
NtCreateProcessEx(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtSetEvent(>) | 7 | NtQueryDirectoryFile(>) | 24 |
NtDelayExecution(>) | 1 | NtOpenEvent(>) | 2 | NtSetValueKey(>) | 7 | NtCreateFile(>) | 28 |
NtEnumerateValueKey(>) | 1 | NtOpenProcess(>) | 2 | NtUserBuildHwndList(>) | 7 | NtOpenProcessTokenEx(>) | 33 |
NtGdiCreateBitmap(>) | 1 | NtOpenSymbolicLinkObject(>) | 2 | NtOpenMutant(>) | 8 | NtOpenThreadTokenEx(>) | 33 |
NtGdiCreatePatternBrushInternal(>) | 1 | NtQuerySymbolicLinkObject(>) | 2 | NtOpenProcessToken(>) | 9 | NtOpenSection(>) | 40 |
NtGdiInit(>) | 1 | NtReadVirtualMemory(>) | 2 | NtSetInformationProcess(>) | 9 | NtQueryInformationToken(>) | 40 |
NtGdiQueryFontAssocInfo(>) | 1 | NtRegisterThreadTerminatePort(>) | 2 | NtUserCallNoParam(>) | 9 | NtQuerySystemInformation(>) | 41 |
NtGdiSelectBitmap(>) | 1 | NtResumeThread(>) | 2 | NtCreateKey(>) | 10 | NtUserGetAtomName(>) | 47 |
NtOpenKeyedEvent(>) | 1 | NtSetEventBoostPriority(>) | 2 | NtQueryDefaultUILanguage(>) | 10 | NtUserUnregisterClass(>) | 47 |
NtQueryEvent(>) | 1 | NtTestAlert(>) | 2 | NtReleaseMutant(>) | 10 | NtUserFindExistingCursorIcon(>) | 50 |
NtQueryInformationJobObject(>) | 1 | NtClearEvent(>) | 3 | NtUserGetWindowDC(>) | 10 | NtFreeVirtualMemory(>) | 56 |
NtQueryInformationThread(>) | 1 | NtContinue(>) | 3 | NtCreateSemaphore(>) | 11 | NtQueryVirtualMemory(>) | 57 |
NtQueryInstallUILanguage(>) | 1 | NtDuplicateObject(>) | 3 | NtEnumerateKey(>) | 12 | NtMapViewOfSection(>) | 60 |
NtQueryObject(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtUserCallOneParam(>) | 12 | NtUserRegisterClassExWOW(>) | 61 |
NtQueryTimerResolution(>) | 1 | NtGdiDeleteObjectApp(>) | 3 | NtUserSystemParametersInfo(>) | 12 | NtOpenFile(>) | 64 |
NtReadFile(>) | 1 | NtNotifyChangeKey(>) | 3 | NtSetInformationThread(>) | 13 | NtQueryAttributesFile(>) | 76 |
NtSecureConnectPort(>) | 1 | NtQueryPerformanceCounter(>) | 3 | NtQueryVolumeInformationFile(>) | 15 | NtCreateSection(>) | 82 |
NtUserBuildNameList(>) | 1 | NtReleaseSemaphore(>) | 3 | NtRequestWaitReplyPort(>) | 15 | NtFlushInstructionCache(>) | 136 |
NtUserCloseDesktop(>) | 1 | NtTerminateProcess(>) | 3 | NtQueryDebugFilterState(>) | 17 | NtUserValidateHandleSecure(>) | 144 |
NtUserGetDC(>) | 1 | NtUserOpenDesktop(>) | 3 | NtSetInformationFile(>) | 17 | NtUserQueryWindow(>) | 178 |
NtUserGetGUIThreadInfo(>) | 1 | NtWaitForMultipleObjects(>) | 3 | NtQuerySection(>) | 18 | NtAllocateVirtualMemory(>) | 203 |
NtUserGetObjectInformation(>) | 1 | NtQueryKey(>) | 4 | NtUnmapViewOfSection(>) | 18 | NtProtectVirtualMemory(>) | 278 |
NtUserGetThreadDesktop(>) | 1 | NtSetInformationObject(>) | 4 | NtDeviceIoControlFile(>) | 19 | NtOpenKey(>) | 311 |
NtConnectPort(>) | 2 | NtWriteFile(>) | 4 | NtQueryDefaultLocale(>) | 19 | NtQueryValueKey(>) | 423 |
NtCreateThread(>) | 2 | NtWriteVirtualMemory(>) | 4 | NtUserRegisterWindowMessage(>) | 20 | NtClose(>) | 466 |
NtDuplicateToken(>) | 2 | NtAccessCheck(>) | 5 | NtWaitForSingleObject(>) | 20 |
\177\15d\212}'\224\315V)F}F\335\307Dr\2240\343\341\227\34\332]\366\2177\312\310\306\236\263\260\254\27\337\303\270}=\233\227\250\222\301\304Z\318\275\232\232\232HLt|N\362\212\341\355\341\306\305SX\265\240\376\377\264G\14U\6 Y\313\305G\252\5P\26P\336\347B\354\35a\3258K\31\344\200V\355\30\245\342\352\261\334\13D\261T\17\5z\2\365\344\317\250\253\313\232\302\217_\35\247\337\3016\271\3003\14\226f\306\305\343\341\12\254\371\317\334\347q\246\331\272\267!\217\302#[\270\372\32J\237:%\250>tY\266\356\27\225\3\355#!\276l.~\11O\354W\263\353qE\347\332\272\13\320i\212w\372&\360a\313\351\373\345wO\27\262\270\25\252", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) 3pO\314$\2474\307\216\356\230\304\22\232\252\26550\335\0\331\270\362\13\337\352\21m\275x\205\253!\30 (332, 0, 0, 0, "\352\336\204\274\247\210\26\6U\344\222O\270f\275R\221(\271\337\2\335\344\13\261\22P\311\212!\31o\346\20#H\260\272\223\223\276\340[S\374*=\254\300g\335\210u\305\267\354\201\357\340\317\275\255\352SUu\351\13A\205\216x\347\367"3pO\314$\2474\307\216\356\230\304\22\232\252\26550\335\0\331\270\362\13\337\352\21m\275x\205\253!\30"\265Y\306\323\14\321\314\237,\202_\7RV\210G\256x\271\334\244\223\326+\345\323\360\323\333\246\375\322\372n\34\341`n\223X!q\244\225\354\205\302\213?9\255\35\340K\301tC%\342p\22\202\230\340\231\23\0#\376\265%\234L\47\253\224\255Gf\244\31\270]\267\220\306\224\31\\256\207\251\304[\336X\34\367\367R\31`\2\217\303\307\275\377\3123x*<\235\2641&:\177]/W>\202v\364m\35\276\177\374\263\324
\177\15d\212}'\224\315V)F}F\335\307Dr\2240\343\341\227\34\332]\366\2177\312\310\306\236\263\260\254\27\337\303\270}=\233\227\250\222\301\304Z\318\275\232\232\232HLt|N\362\212\341\355\341\306\305SX\265\240\376\377\264G\14U\6 Y\313\305G\252\5P\26P\336\347B\354\35a\3258K\31\344\200V\355\30\245\342\352\261\334\13D\261T\17\5z\2\365\344\317\250\253\313\232\302\217_\35\247\337\3016\271\3003\14\226f\306\305\343\341\12\254\371\317\334\347q\246\331\272\267!\217\302#[\270\372\32J\237:%\250>tY\266\356\27\225\3\355#!\276l.~\11O\354W\263\353qE\347\332\272\13\320i\212w\372&\360a\313\351\373\345wO\27\262\270\25\252", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 02619 896 NtWriteFile (332, 0, 0, 0, (332, 0, 0, 0, "3\4\203\3408\263\357\3630\216bRVe\306e\270\212\2\357\68:\371\354\352\327r\333;\301M\341\264\37\330\23$E*\260\275\350\376|\307\241\262\266\254&r\240P\317\306\14\347V\260pX\303k\6\370\256\251\354\263\220\2\31v\343\331\247zC_\2\361\200\376\3661\371w.\224H\355\222\256\356\310\225J\5\246\15\21fN\224\250\222\342\362\27\1772\30\342"v\36$s8\10wO\240\23\23\222\177\334\204\325P\15H\301n\201\30j^\216%\300!gf\26\203\300\262\366L\303\305*\304[2\6\374s\300\17\370\203\340F\274c.\225\203\331\0\210 \222y\334'\367\346\35\266\205a\333F\273*3[Kq\274A\314\201\315t\224c\251xn\361S"L\275\347\23\373\2\343\323M!\224\363\364\34{\317\32\333\343\363\203\305\248\333V\330\226n!\353\7\262zH+\26|\232\31\30\6\242P)\300\353\337yq\5&c.6V\315\230\316\227z\326\352r\336?\25\277\274\205mv(~\301+I\360A\242i\302Z\360=\225\260\214\241\355\303\337J\0a\275\264>\347Q\341\24>\265Im\6f\10@\3311\253\1\236\34\270\31\157\327\365\327\373f\251\34E\201\13Ok\245\210\13\234\242;\301_\213\33\204D\201\366\302)k%\272\211\226\275\22\246(_\342\204\177Z\316\347\230\4\25\203alA/L\263{?\354w+\230}\356\325\375\266\370NG\362\256\301\354\370Y\325\15v$6\210\320Z\361\342\203\221A*hN\271t\220\326\32\250H,\300\227r?W\234\340F\340\201\214\371\375q?\212i\211\243\360s\312.\260\207\311\372\14\341\244<\24\357\373\6\212wdtP\365\177\360t\275\334t\340\202gXY\15\5\271\365\311B\271`}\363h\364\201\242\222\177\16\230Sg\356", 51200, 0x0, 0, ... {status=0x0, info=51200}, ) v\36$s8\10wO\240\23\23\222\177\334\204\325P\15H\301n\201\30j^\216%\300!gf\26\203\300\262\366L\303\305*\304[2\6\374s\300\17\370\203\340F\274c.\225\203\331\0\210 \222y\334'\367\346\35\266\205a\333F\273*3[Kq\274A\314\201\315t\224c\251xn\361S (332, 0, 0, 0, "3\4\203\3408\263\357\3630\216bRVe\306e\270\212\2\357\68:\371\354\352\327r\333;\301M\341\264\37\330\23$E*\260\275\350\376|\307\241\262\266\254&r\240P\317\306\14\347V\260pX\303k\6\370\256\251\354\263\220\2\31v\343\331\247zC_\2\361\200\376\3661\371w.\224H\355\222\256\356\310\225J\5\246\15\21fN\224\250\222\342\362\27\1772\30\342"v\36$s8\10wO\240\23\23\222\177\334\204\325P\15H\301n\201\30j^\216%\300!gf\26\203\300\262\366L\303\305*\304[2\6\374s\300\17\370\203\340F\274c.\225\203\331\0\210 \222y\334'\367\346\35\266\205a\333F\273*3[Kq\274A\314\201\315t\224c\251xn\361S"L\275\347\23\373\2\343\323M!\224\363\364\34{\317\32\333\343\363\203\305\248\333V\330\226n!\353\7\262zH+\26|\232\31\30\6\242P)\300\353\337yq\5&c.6V\315\230\316\227z\326\352r\336?\25\277\274\205mv(~\301+I\360A\242i\302Z\360=\225\260\214\241\355\303\337J\0a\275\264>\347Q\341\24>\265Im\6f\10@\3311\253\1\236\34\270\31\157\327\365\327\373f\251\34E\201\13Ok\245\210\13\234\242;\301_\213\33\204D\201\366\302)k%\272\211\226\275\22\246(_\342\204\177Z\316\347\230\4\25\203alA/L\263{?\354w+\230}\356\325\375\266\370NG\362\256\301\354\370Y\325\15v$6\210\320Z\361\342\203\221A*hN\271t\220\326\32\250H,\300\227r?W\234\340F\340\201\214\371\375q?\212i\211\243\360s\312.\260\207\311\372\14\341\244<\24\357\373\6\212wdtP\365\177\360t\275\334t\340\202gXY\15\5\271\365\311B\271`}\363h\364\201\242\222\177\16\230Sg\356", 51200, 0x0, 0, ... {status=0x0, info=51200}, ) , 51200, 0x0, 0, ... {status=0x0, info=51200}, ) == 0x0 02620 896 NtUnmapViewOfSection (-1, 0x13a0000, ... ) == 0x0 02621 896 NtSetInformationFile (332, 1241392, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02622 896 NtClose (328, ... ) == 0x0 02623 896 NtClose (332, ... ) == 0x0 02624 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\explorer.exe"}, 1241212, ... ) }, 1241212, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02625 896 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "explorer.exe"}, 1241212, ... ) }, 1241212, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02626 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\explorer.exe"}, 1241212, ... ) }, 1241212, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02627 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\explorer.exe"}, 1241212, ... ) }, 1241212, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02628 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\explorer.exe"}, 1241212, ... ) }, 1241212, ... ) == 0x0 02629 896 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1242012, (0x80100080, {24, 0, 0x40, 0, 1242012, "\??\C:\WINDOWS\explorer.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... 332, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 332, {status=0x0, info=1}, ) == 0x0 02630 896 NtAllocateVirtualMemory (-1, 0, 0, 29, 4096, 64, ... 20578304, 4096, ) == 0x0 02631 896 NtAllocateVirtualMemory (-1, 0, 0, 512, 4096, 64, ... 20643840, 4096, ) == 0x0 02632 896 NtQueryInformationFile (332, 1242064, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02633 896 NtClose (332, ... ) == 0x0 02634 896 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1242012, (0x40100080, {24, 0, 0x40, 0, 1242012, "\??\C:\WINDOWS\system32\spools.exe"}, 0x0, 128, 2, 1, 96, 0, 0, ... 332, {status=0x0, info=1}, ) }, 0x0, 128, 2, 1, 96, 0, 0, ... 332, {status=0x0, info=1}, ) == 0x0 02635 896 NtAllocateVirtualMemory (-1, 0, 0, 29, 4096, 64, ... 20709376, 4096, ) == 0x0 02636 896 NtAllocateVirtualMemory (-1, 0, 0, 512, 4096, 64, ... 20774912, 4096, ) == 0x0 02637 896 NtSetInformationFile (332, 1242064, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02638 896 NtClose (332, ... ) == 0x0 02639 896 NtAllocateVirtualMemory (-1, 0, 0, 23, 4096, 64, ... 20840448, 4096, ) == 0x0 02640 896 NtAllocateVirtualMemory (-1, 0, 0, 512, 4096, 64, ... 20905984, 4096, ) == 0x0 02641 896 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\spools.exe"}, 7, 2113568, ... 332, {status=0x0, info=1}, ) }, 7, 2113568, ... 332, {status=0x0, info=1}, ) == 0x0 02642 896 NtSetInformationFile (332, 1242312, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02643 896 NtClose (332, ... ) == 0x0 02644 896 NtAllocateVirtualMemory (-1, 0, 0, 17, 4096, 64, ... 20971520, 4096, ) == 0x0 02645 896 NtAllocateVirtualMemory (-1, 0, 0, 512, 4096, 64, ... 21037056, 4096, ) == 0x0 02646 896 NtAllocateVirtualMemory (-1, 0, 0, 86, 4096, 64, ... 21102592, 4096, ) == 0x0 02647 896 NtAllocateVirtualMemory (-1, 0, 0, 512, 4096, 64, ... 21168128, 4096, ) == 0x0 02648 896 NtOpenProcess (0x100000, {24, 0, 0x2, 0, 0, 0x0}, {1252, 0}, ... 332, ) == 0x0 02649 896 NtAllocateVirtualMemory (-1, 0, 0, 54, 4096, 64, ... 21233664, 4096, ) == 0x0 02650 896 NtAllocateVirtualMemory (-1, 0, 0, 512, 4096, 64, ... 21299200, 4096, ) == 0x0 02651 896 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 02652 896 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\spools.exe"}, 5, 96, ... 328, {status=0x0, info=1}, ) }, 5, 96, ... 328, {status=0x0, info=1}, ) == 0x0 02653 896 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 328, ... 336, ) == 0x0 02654 896 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02655 896 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 340, ) }, ... 340, ) == 0x0 02656 896 NtQueryValueKey (340, (340, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02657 896 NtClose (340, ... ) == 0x0 02658 896 NtQueryVolumeInformationFile (328, 1238688, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02659 896 NtOpenMutant (0x120001, {24, 68, 0x0, 0, 0, (0x120001, {24, 68, 0x0, 0, 0, "ShimCacheMutex"}, ... 340, ) }, ... 340, ) == 0x0 02660 896 NtWaitForSingleObject (340, 0, {-1000000, -1}, ... ) == 0x0 02661 896 NtOpenSection (0x2, {24, 68, 0x0, 0, 0, (0x2, {24, 68, 0x0, 0, 0, "ShimSharedMemory"}, ... 344, ) }, ... 344, ) == 0x0 02662 896 NtMapViewOfSection (344, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x1460000), {0, 0}, 57344, ) == 0x0 02663 896 NtReleaseMutant (340, ... 0x0, ) == 0x0 02664 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1236620, ... ) }, 1236620, ... ) == 0x0 02665 896 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 348, {status=0x0, info=1}, ) }, 5, 96, ... 348, {status=0x0, info=1}, ) == 0x0 02666 896 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 348, ... 352, ) == 0x0 02667 896 NtClose (348, ... ) == 0x0 02668 896 NtMapViewOfSection (352, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x1470000), 0x0, 126976, ) == 0x0 02669 896 NtClose (352, ... ) == 0x0 02670 896 NtUnmapViewOfSection (-1, 0x1470000, ... ) == 0x0 02671 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1236928, ... ) }, 1236928, ... ) == 0x0 02672 896 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 352, {status=0x0, info=1}, ) }, 5, 96, ... 352, {status=0x0, info=1}, ) == 0x0 02673 896 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 352, ... 348, ) == 0x0 02674 896 NtQuerySection (348, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02675 896 NtClose (352, ... ) == 0x0 02676 896 NtMapViewOfSection (348, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 02677 896 NtClose (348, ... ) == 0x0 02678 896 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 02679 896 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 02680 896 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 02681 896 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02682 896 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 348, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 348, {status=0x0, info=1}, ) == 0x0 02683 896 NtQueryInformationFile (348, 1236944, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02684 896 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 348, ... 352, ) == 0x0 02685 896 NtMapViewOfSection (352, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x1470000), 0x0, 1191936, ) == 0x0 02686 896 NtQueryInformationFile (348, 1237044, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02687 896 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02688 896 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02689 896 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 02690 896 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02691 896 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 356, ) }, ... 356, ) == 0x0 02692 896 NtQueryValueKey (356, (356, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (356, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02693 896 NtClose (356, ... ) == 0x0 02694 896 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02695 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02696 896 NtQueryDirectoryFile (356, 0, 0, 0, 1234640, 616, BothDirectory, 1, (356, 0, 0, 0, 1234640, 616, BothDirectory, 1, "spools.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 02697 896 NtClose (356, ... ) == 0x0 02698 896 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02699 896 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02700 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\spools.exe"}, 1235016, ... ) }, 1235016, ... ) == 0x0 02701 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02702 896 NtQueryDirectoryFile (356, 0, 0, 0, 1234444, 616, BothDirectory, 1, (356, 0, 0, 0, 1234444, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02703 896 NtClose (356, ... ) == 0x0 02704 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02705 896 NtQueryDirectoryFile (356, 0, 0, 0, 1234444, 616, BothDirectory, 1, (356, 0, 0, 0, 1234444, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02706 896 NtClose (356, ... ) == 0x0 02707 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02708 896 NtQueryDirectoryFile (356, 0, 0, 0, 1234444, 616, BothDirectory, 1, (356, 0, 0, 0, 1234444, 616, BothDirectory, 1, "spools.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 02709 896 NtClose (356, ... ) == 0x0 02710 896 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02711 896 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02712 896 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02713 896 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02714 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02715 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02716 896 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02717 896 NtClose (356, ... ) == 0x0 02718 896 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02719 896 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\spools.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02720 896 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02721 896 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02722 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\spools.exe"}, 1236268, ... ) }, 1236268, ... ) == 0x0 02723 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02724 896 NtQueryDirectoryFile (356, 0, 0, 0, 1235696, 616, BothDirectory, 1, (356, 0, 0, 0, 1235696, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02725 896 NtClose (356, ... ) == 0x0 02726 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02727 896 NtQueryDirectoryFile (356, 0, 0, 0, 1235696, 616, BothDirectory, 1, (356, 0, 0, 0, 1235696, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02728 896 NtClose (356, ... ) == 0x0 02729 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02730 896 NtQueryDirectoryFile (356, 0, 0, 0, 1235696, 616, BothDirectory, 1, (356, 0, 0, 0, 1235696, 616, BothDirectory, 1, "spools.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 02731 896 NtClose (356, ... ) == 0x0 02732 896 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02733 896 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02734 896 NtWaitForSingleObject (340, 0, {-1000000, -1}, ... ) == 0x0 02735 896 NtQueryVolumeInformationFile (328, 1236924, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02736 896 NtQueryInformationFile (328, 1236904, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02737 896 NtQueryInformationFile (328, 1236944, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02738 896 NtReleaseMutant (340, ... 0x0, ) == 0x0 02739 896 NtUnmapViewOfSection (-1, 0x1470000, ... ) == 0x0 02740 896 NtClose (352, ... ) == 0x0 02741 896 NtClose (348, ... ) == 0x0 02742 896 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 02743 896 NtOpenProcessToken (-1, 0xa, ... 348, ) == 0x0 02744 896 NtQueryInformationToken (348, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 02745 896 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02746 896 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 352, ) }, ... 352, ) == 0x0 02747 896 NtQueryValueKey (352, (352, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (352, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02748 896 NtQueryValueKey (352, (352, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (352, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02749 896 NtClose (352, ... ) == 0x0 02750 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02751 896 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 352, ) }, ... 352, ) == 0x0 02752 896 NtQueryValueKey (352, (352, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02753 896 NtClose (352, ... ) == 0x0 02754 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02755 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02756 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02757 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02758 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02759 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02760 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02761 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02762 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02763 896 NtQueryDefaultLocale (1, 1238116, ... ) == 0x0 02764 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 352, ) }, ... 352, ) == 0x0 02765 896 NtEnumerateKey (352, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (352, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 02766 896 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 356, ) }, ... 356, ) == 0x0 02767 896 NtQueryValueKey (356, (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 02768 896 NtQueryValueKey (356, (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02769 896 NtClose (356, ... ) == 0x0 02770 896 NtEnumerateKey (352, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02771 896 NtClose (352, ... ) == 0x0 02772 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... 352, ) }, ... 352, ) == 0x0 02773 896 NtEnumerateKey (352, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (352, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, 92, ) }, 92, ) == 0x0 02774 896 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, ... 356, ) }, ... 356, ) == 0x0 02775 896 NtQueryValueKey (356, (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) }, 28, ) == 0x0 02776 896 NtQueryValueKey (356, (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02777 896 NtQueryValueKey (356, (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02778 896 NtQueryValueKey (356, (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02779 896 NtClose (356, ... ) == 0x0 02780 896 NtEnumerateKey (352, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (352, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, 92, ) }, 92, ) == 0x0 02781 896 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, ... 356, ) }, ... 356, ) == 0x0 02782 896 NtQueryValueKey (356, (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) }, 28, ) == 0x0 02783 896 NtQueryValueKey (356, (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02784 896 NtQueryValueKey (356, (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02785 896 NtQueryValueKey (356, (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02786 896 NtClose (356, ... ) == 0x0 02787 896 NtEnumerateKey (352, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (352, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, 92, ) }, 92, ) == 0x0 02788 896 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, ... 356, ) }, ... 356, ) == 0x0 02789 896 NtQueryValueKey (356, (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) }, 28, ) == 0x0 02790 896 NtQueryValueKey (356, (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02791 896 NtQueryValueKey (356, (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02792 896 NtQueryValueKey (356, (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02793 896 NtClose (356, ... ) == 0x0 02794 896 NtEnumerateKey (352, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (352, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, 92, ) }, 92, ) == 0x0 02795 896 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, ... 356, ) }, ... 356, ) == 0x0 02796 896 NtQueryValueKey (356, (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) }, 28, ) == 0x0 02797 896 NtQueryValueKey (356, (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02798 896 NtQueryValueKey (356, (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02799 896 NtQueryValueKey (356, (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02800 896 NtClose (356, ... ) == 0x0 02801 896 NtEnumerateKey (352, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (352, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, 92, ) }, 92, ) == 0x0 02802 896 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, ... 356, ) }, ... 356, ) == 0x0 02803 896 NtQueryValueKey (356, (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (356, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) \300\36\200"}, 28, ) == 0x0 02804 896 NtQueryValueKey (356, (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02805 896 NtQueryValueKey (356, (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (356, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02806 896 NtQueryValueKey (356, (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (356, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02807 896 NtClose (356, ... ) == 0x0 02808 896 NtEnumerateKey (352, 5, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02809 896 NtClose (352, ... ) == 0x0 02810 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02811 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02812 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02813 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02814 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02815 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02816 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02817 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02818 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02819 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02820 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02821 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02822 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02823 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02824 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02825 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02826 896 NtClose (352, ... ) == 0x0 02827 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02828 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02829 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02830 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02831 896 NtClose (352, ... ) == 0x0 02832 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02833 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02834 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02835 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02836 896 NtClose (352, ... ) == 0x0 02837 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02838 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02839 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02840 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02841 896 NtClose (352, ... ) == 0x0 02842 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02843 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02844 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02845 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02846 896 NtClose (352, ... ) == 0x0 02847 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02848 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02849 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02850 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02851 896 NtClose (352, ... ) == 0x0 02852 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02853 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02854 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02855 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02856 896 NtClose (352, ... ) == 0x0 02857 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02858 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02859 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02860 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02861 896 NtClose (352, ... ) == 0x0 02862 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02863 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02864 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02865 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02866 896 NtClose (352, ... ) == 0x0 02867 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02868 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02869 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02870 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02871 896 NtClose (352, ... ) == 0x0 02872 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02873 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02874 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02875 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02876 896 NtClose (352, ... ) == 0x0 02877 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02878 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02879 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02880 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02881 896 NtClose (352, ... ) == 0x0 02882 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02883 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02884 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02885 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02886 896 NtClose (352, ... ) == 0x0 02887 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02888 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02889 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02890 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02891 896 NtClose (352, ... ) == 0x0 02892 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02893 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02894 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02895 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02896 896 NtClose (352, ... ) == 0x0 02897 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02898 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 352, ) }, ... 352, ) == 0x0 02899 896 NtQueryValueKey (352, (352, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (352, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (352, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 02900 896 NtClose (352, ... ) == 0x0 02901 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02902 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02903 896 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02904 896 NtClose (352, ... ) == 0x0 02905 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02906 896 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 02907 896 NtOpenProcessToken (-1, 0xa, ... 352, ) == 0x0 02908 896 NtDuplicateToken (352, 0xc, {24, 0, 0x0, 0, 1238548, 0x0}, 0, 2, ... 356, ) == 0x0 02909 896 NtClose (352, ... ) == 0x0 02910 896 NtAccessCheck (1400016, 356, 0x1, 1238624, 1238676, 56, 1238656, ... (0x1), ) == 0x0 02911 896 NtClose (356, ... ) == 0x0 02912 896 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 356, ) }, ... 356, ) == 0x0 02913 896 NtQueryValueKey (356, (356, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (356, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02914 896 NtClose (356, ... ) == 0x0 02915 896 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 356, ) }, ... 356, ) == 0x0 02916 896 NtQuerySymbolicLinkObject (356, ... (356, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 02917 896 NtClose (356, ... ) == 0x0 02918 896 NtQueryVolumeInformationFile (328, 1236380, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02919 896 NtQueryInformationFile (328, 1236496, 528, Name, ... {status=0x0, info=60}, ) == 0x0 02920 896 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02921 896 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02922 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\spools.exe"}, 1235668, ... ) }, 1235668, ... ) == 0x0 02923 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02924 896 NtQueryDirectoryFile (356, 0, 0, 0, 1235096, 616, BothDirectory, 1, (356, 0, 0, 0, 1235096, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02925 896 NtClose (356, ... ) == 0x0 02926 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02927 896 NtQueryDirectoryFile (356, 0, 0, 0, 1235096, 616, BothDirectory, 1, (356, 0, 0, 0, 1235096, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02928 896 NtClose (356, ... ) == 0x0 02929 896 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02930 896 NtQueryDirectoryFile (356, 0, 0, 0, 1235096, 616, BothDirectory, 1, (356, 0, 0, 0, 1235096, 616, BothDirectory, 1, "spools.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 02931 896 NtClose (356, ... ) == 0x0 02932 896 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02933 896 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02934 896 NtQueryInformationFile (328, 1238536, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02935 896 NtCreateSection (0xf0005, 0x0, {235520, 0}, 2, 134217728, 328, ... 356, ) == 0x0 02936 896 NtMapViewOfSection (356, -1, (0x0), 0, 0, {0, 0}, 235520, 1, 0, 2, ... (0x1470000), {0, 0}, 237568, ) == 0x0 02937 896 NtClose (356, ... ) == 0x0 02938 896 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02939 896 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02940 896 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02941 896 NtClose (356, ... ) == 0x0 02942 896 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 356, ) }, ... 356, ) == 0x0 02943 896 NtOpenKey (0x20019, {24, 356, 0x40, 0, 0, (0x20019, {24, 356, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 352, ) }, ... 352, ) == 0x0 02944 896 NtClose (356, ... ) == 0x0 02945 896 NtQueryValueKey (352, (352, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02946 896 NtQueryValueKey (352, (352, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) , Partial, 174, ... TitleIdx=0, Type=1, Data= (352, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) }, 174, ) == 0x0 02947 896 NtClose (352, ... ) == 0x0 02948 896 NtUnmapViewOfSection (-1, 0x1470000, ... ) == 0x0 02949 896 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 21430272, 4096, ) == 0x0 02950 896 NtAllocateVirtualMemory (-1, 21430272, 0, 4096, 4096, 4, ... 21430272, 4096, ) == 0x0 02951 896 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 352, ) }, ... 352, ) == 0x0 02952 896 NtQueryValueKey (352, (352, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02953 896 NtClose (352, ... ) == 0x0 02954 896 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02955 896 NtQueryInformationToken (348, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 02956 896 NtQueryInformationToken (348, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 02957 896 NtClose (348, ... ) == 0x0 02958 896 NtQuerySection (336, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02959 896 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spools.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02960 896 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0 02961 896 NtCreateProcessEx (1240460, 2035711, 0, -1, 4, 336, 0, 0, 0, ... ) == 0x0 02962 896 NtSetInformationProcess (348, PriorityClass, {process info, class 18, size 2}, 512, ... ) == 0x0 02963 896 NtQueryInformationProcess (348, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffd8000,AffinityMask=0x1,BasePriority=8,Pid=220,ParentPid=1252,}, 0x0, ) == 0x0 02964 896 NtReadVirtualMemory (348, 0x7ffd8008, 4, ... (348, 0x7ffd8008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 02965 896 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\spools.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02966 896 NtAllocateVirtualMemory (-1, 1400832, 0, 8192, 4096, 4, ... 1400832, 8192, ) == 0x0 02967 896 NtReadVirtualMemory (348, 0x400000, 4096, ... (348, 0x400000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0\0\324\341\7D\265\217TD\265\217TD\265\217T?\251\203TF\265\217T\307\251\201T]\265\217T\254\252\205T8\265\217TD\265\216T\310\265\217T&\252\234TC\265\217T\254\252\204T\16\265\217TRichD\265\217T\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0\343\356\374G\0\0\0\0\0\0\0\0\340\0\17\1\13\1\6\0\0\0\0\0\0\220\3\0\0\360\17\0-\2\20\0\0\20\0\0\0\0\20\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\240\23\0\0\4\0\0\206q\4\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\330\0\20\0x\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3349\16\0\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0.nsp0\0\0\0\0\360\17\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 4096, ) , 4096, ) == 0x0 02968 896 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02969 896 NtQueryInformationProcess (348, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffd8000,AffinityMask=0x1,BasePriority=8,Pid=220,ParentPid=1252,}, 0x0, ) == 0x0 02970 896 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 1239412, ... ) }, 1239412, ... ) == 0x0 02971 896 NtAllocateVirtualMemory (-1, 0, 0, 2408, 4096, 4, ... 21495808, 4096, ) == 0x0 02972 896 NtAllocateVirtualMemory (348, 0, 0, 6432, 4096, 4, ... 65536, 8192, ) == 0x0 02973 896 NtWriteVirtualMemory (348, 0x10000, (348, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6432, ... 0x0, ) , 6432, ... 0x0, ) == 0x0 02974 896 NtAllocateVirtualMemory (348, 0, 0, 2408, 4096, 4, ... 131072, 4096, ) == 0x0 02975 896 NtWriteVirtualMemory (348, 0x20000, (348, 0x20000, "\0\20\0\0h\11\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0&\0\10\2\220\2\0\0\16\0\0\0\364\3\366\3\230\4\0\0<\0>\0\220\10\0\0n\0p\0\320\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\2\0@\11\0\0\36\0 \0D\11\0\0\0\0\2\0d\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2408, ... 0x0, ) , 2408, ... 0x0, ) == 0x0 02976 896 NtWriteVirtualMemory (348, 0x7ffd8010, (348, 0x7ffd8010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02977 896 NtWriteVirtualMemory (348, 0x7ffd81e8, (348, 0x7ffd81e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02978 896 NtFreeVirtualMemory (-1, (0x1480000), 0, 32768, ... (0x1480000), 4096, ) == 0x0 02979 896 NtAllocateVirtualMemory (348, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 02980 896 NtAllocateVirtualMemory (348, 1236992, 0, 8192, 4096, 4, ... 1236992, 8192, ) == 0x0 02981 896 NtProtectVirtualMemory (348, (0x12e000), 4096, 260, ... (0x12e000), 4096, 4, ) == 0x0 02982 896 NtCreateThread (0x1f03ff, 0x0, 348, 1240468, 1240132, 1, ... 352, {220, 1328}, ) == 0x0 02983 896 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 0, 0, 0, 2088821759} (24, {168, 196, new_msg, 0, 0, 0, 0, 2088821759} "\0\0\0\0\0\0\1\0\11\344\200|\334\343\200|_\1\0\0`\1\0\0\334\0\0\00\5\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\375\177\0\0\0\0\0\0\375\177\5\20\220|" ... {168, 196, reply, 0, 1252, 896, 81848, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\334\343\200|\\1\0\0`\1\0\0\334\0\0\00\5\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\375\177\0\0\0\0\0\0\375\177\5\20\220|" ) ... {168, 196, reply, 0, 1252, 896, 81848, 0} (24, {168, 196, new_msg, 0, 0, 0, 0, 2088821759} "\0\0\0\0\0\0\1\0\11\344\200|\334\343\200|_\1\0\0`\1\0\0\334\0\0\00\5\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\375\177\0\0\0\0\0\0\375\177\5\20\220|" ... {168, 196, reply, 0, 1252, 896, 81848, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\334\343\200|\\1\0\0`\1\0\0\334\0\0\00\5\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\0\0\0\0\0\340\375\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\375\177\0\0\0\0\0\0\375\177\5\20\220|" ) ) == 0x0 02984 896 NtResumeThread (352, ... 1, ) == 0x0 02985 896 NtClose (328, ... ) == 0x0 02986 896 NtClose (336, ... ) == 0x0 02987 896 NtDelayExecution (0, {-2000000, -1}, ... ) == 0x0 02988 896 NtClose (348, ... ) == 0x0 02989 896 NtClose (352, ... ) == 0x0 02990 896 NtTerminateProcess (0, 0, ... 01422 2016 NtWaitForMultipleObjects ... ) == 0xc0 02990 896 NtTerminateProcess ... ) == 0x0 02991 896 NtClose (320, ... ) == 0x0 02992 896 NtClose (308, ... ) == 0x0 02993 896 NtClose (312, ... ) == 0x0 02994 896 NtClose (316, ... ) == 0x0 02995 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x14,}, 4, ... ) == 0x0 02996 896 NtFreeVirtualMemory (-1, (0x1090000), 0, 32768, ... (0x1090000), 65536, ) == 0x0 02997 896 NtClose (264, ... ) == 0x0 02998 896 NtClose (268, ... ) == 0x0 02999 896 NtClose (276, ... ) == 0x0 03000 896 NtClose (272, ... ) == 0x0 03001 896 NtClose (280, ... ) == 0x0 03002 896 NtClose (284, ... ) == 0x0 03003 896 NtClose (288, ... ) == 0x0 03004 896 NtClose (304, ... ) == 0x0 03005 896 NtClose (300, ... ) == 0x0 03006 896 NtClose (296, ... ) == 0x0 03007 896 NtClose (292, ... ) == 0x0 03008 896 NtUserGetAtomName (49211, 1241268, ... ) == 0xf 03009 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03010 896 NtUserGetAtomName (49213, 1241268, ... ) == 0xd 03011 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03012 896 NtUserGetAtomName (49215, 1241268, ... ) == 0x10 03013 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03014 896 NtUserGetAtomName (49217, 1241268, ... ) == 0x12 03015 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03016 896 NtUserGetAtomName (49219, 1241268, ... ) == 0xd 03017 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03018 896 NtUserGetAtomName (49221, 1241268, ... ) == 0xb 03019 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03020 896 NtUserGetAtomName (49223, 1241268, ... ) == 0xf 03021 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03022 896 NtUserGetAtomName (49225, 1241268, ... ) == 0xd 03023 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03024 896 NtUserGetAtomName (49227, 1241268, ... ) == 0x11 03025 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03026 896 NtUserGetAtomName (49229, 1241268, ... ) == 0xf 03027 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03028 896 NtUserGetAtomName (49231, 1241268, ... ) == 0x11 03029 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03030 896 NtUserGetAtomName (49233, 1241268, ... ) == 0xf 03031 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03032 896 NtUserGetAtomName (49235, 1241268, ... ) == 0xc 03033 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03034 896 NtUserGetAtomName (49237, 1241260, ... ) == 0xd 03035 896 NtUserUnregisterClass (1241320, 1560870912, 1241308, ... ) == 0x1 03036 896 NtUserGetAtomName (49239, 1241260, ... ) == 0x11 03037 896 NtUserUnregisterClass (1241320, 1560870912, 1241308, ... ) == 0x1 03038 896 NtUserGetAtomName (49241, 1241268, ... ) == 0xc 03039 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03040 896 NtUserGetAtomName (49243, 1241268, ... ) == 0xe 03041 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03042 896 NtUserGetAtomName (49245, 1241268, ... ) == 0x8 03043 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03044 896 NtUserGetAtomName (49247, 1241268, ... ) == 0xd 03045 896 NtUserUnregisterClass (1241328, 1560870912, 1241316, ... ) == 0x1 03046 896 NtUnmapViewOfSection (-1, 0x1100000, ... ) == 0x0 03047 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xe,}, 4, ... ) == 0x0 03048 896 NtFreeVirtualMemory (-1, (0x1050000), 0, 32768, ... (0x1050000), 65536, ) == 0x0 03049 896 NtClose (208, ... ) == 0x0 03050 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xf,}, 4, ... ) == 0x0 03051 896 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 03052 896 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 03053 896 NtUnmapViewOfSection (-1, 0x1030000, ... ) == 0x0 03054 896 NtClose (204, ... ) == 0x0 03055 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xc,}, 4, ... ) == 0x0 03056 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xd,}, 4, ... ) == 0x0 03057 896 NtClose (180, ... ) == 0x0 03058 896 NtClose (176, ... ) == 0x0 03059 896 NtClose (184, ... ) == 0x0 03060 896 NtUserGetAtomName (49211, 1241300, ... ) == 0xf 03061 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03062 896 NtUserGetAtomName (49213, 1241300, ... ) == 0xd 03063 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03064 896 NtUserGetAtomName (49215, 1241300, ... ) == 0x10 03065 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03066 896 NtUserGetAtomName (49217, 1241300, ... ) == 0x12 03067 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03068 896 NtUserGetAtomName (49219, 1241300, ... ) == 0xd 03069 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03070 896 NtUserGetAtomName (49221, 1241300, ... ) == 0xb 03071 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03072 896 NtUserGetAtomName (49223, 1241300, ... ) == 0xf 03073 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03074 896 NtUserGetAtomName (49225, 1241300, ... ) == 0xd 03075 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03076 896 NtUserGetAtomName (49227, 1241300, ... ) == 0x11 03077 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03078 896 NtUserGetAtomName (49229, 1241300, ... ) == 0xf 03079 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03080 896 NtUserGetAtomName (49231, 1241300, ... ) == 0x11 03081 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03082 896 NtUserGetAtomName (49233, 1241300, ... ) == 0xf 03083 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03084 896 NtUserGetAtomName (49235, 1241300, ... ) == 0xc 03085 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03086 896 NtUserGetAtomName (49237, 1241292, ... ) == 0xd 03087 896 NtUserUnregisterClass (1241352, 2000486400, 1241340, ... ) == 0x1 03088 896 NtUserGetAtomName (49239, 1241292, ... ) == 0x11 03089 896 NtUserUnregisterClass (1241352, 2000486400, 1241340, ... ) == 0x1 03090 896 NtUserGetAtomName (49241, 1241300, ... ) == 0xc 03091 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03092 896 NtUserGetAtomName (49243, 1241300, ... ) == 0xe 03093 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03094 896 NtUserGetAtomName (49245, 1241300, ... ) == 0x8 03095 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03096 896 NtUserGetAtomName (49247, 1241300, ... ) == 0xd 03097 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03098 896 NtUserGetAtomName (49175, 1241300, ... ) == 0x6 03099 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03100 896 NtUserGetAtomName (49177, 1241300, ... ) == 0x6 03101 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03102 896 NtUserGetAtomName (49176, 1241300, ... ) == 0x4 03103 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03104 896 NtUserGetAtomName (49178, 1241300, ... ) == 0x7 03105 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03106 896 NtUserGetAtomName (49180, 1241300, ... ) == 0x8 03107 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03108 896 NtUserGetAtomName (49182, 1241300, ... ) == 0x9 03109 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03110 896 NtUserGetAtomName (49179, 1241292, ... ) == 0x9 03111 896 NtUserUnregisterClass (1241352, 2000486400, 1241340, ... ) == 0x1 03112 896 NtUserGetAtomName (49256, 1241300, ... ) == 0x7 03113 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03114 896 NtUserGetAtomName (49258, 1241300, ... ) == 0xd 03115 896 NtUserUnregisterClass (1241360, 2000486400, 1241348, ... ) == 0x1 03116 896 NtUnmapViewOfSection (-1, 0x1040000, ... ) == 0x0 03117 896 NtDeviceIoControlFile (116, 120, 0x0, 0x12f1f8, 0x22415c, (116, 120, 0x0, 0x12f1f8, 0x22415c, "U\4\376\14\272\223\15D\243\376U9s\320\267#|\0\0\0\0\0\0\0\10 \342\0\306\205\337w", 32, 32, ... {status=0x0, info=32}, "U\4\376\14\272\223\15D\243\376U9s\320\267#|\0\0\0\0\0\0\0\10 \342\0\306\205\337w", ) , 32, 32, ... {status=0x0, info=32}, (116, 120, 0x0, 0x12f1f8, 0x22415c, "U\4\376\14\272\223\15D\243\376U9s\320\267#|\0\0\0\0\0\0\0\10 \342\0\306\205\337w", 32, 32, ... {status=0x0, info=32}, "U\4\376\14\272\223\15D\243\376U9s\320\267#|\0\0\0\0\0\0\0\10 \342\0\306\205\337w", ) , ) == 0x0 03118 896 NtDeviceIoControlFile (116, 120, 0x0, 0x12f1c0, 0x228168, (116, 120, 0x0, 0x12f1c0, 0x228168, "|\0\0\0\0\0\0\0", 8, 0, ... {status=0x0, info=0}, 0x0, ) , 8, 0, ... {status=0x0, info=0}, 0x0, ) == 0x0 03119 896 NtDeviceIoControlFile (116, 120, 0x0, 0x12f1f8, 0x22415c, (116, 120, 0x0, 0x12f1f8, 0x22415c, "\254\253\177yX{\226G\271$\325\21x\245\234\344\224\0\0\0\0\0\0\0\10 \342\0\306\205\337w", 32, 32, ... {status=0x0, info=32}, "\254\253\177yX{\226G\271$\325\21x\245\234\344\224\0\0\0\0\0\0\0\10 \342\0\306\205\337w", ) , 32, 32, ... {status=0x0, info=32}, (116, 120, 0x0, 0x12f1f8, 0x22415c, "\254\253\177yX{\226G\271$\325\21x\245\234\344\224\0\0\0\0\0\0\0\10 \342\0\306\205\337w", 32, 32, ... {status=0x0, info=32}, "\254\253\177yX{\226G\271$\325\21x\245\234\344\224\0\0\0\0\0\0\0\10 \342\0\306\205\337w", ) , ) == 0x0 03120 896 NtDeviceIoControlFile (116, 120, 0x0, 0x12f1c0, 0x228168, (116, 120, 0x0, 0x12f1c0, 0x228168, "\224\0\0\0\0\0\0\0", 8, 0, ... {status=0x0, info=0}, 0x0, ) , 8, 0, ... {status=0x0, info=0}, 0x0, ) == 0x0 03121 896 NtWaitForSingleObject (240, 0, 0x0, ... ) == 0x0 03122 896 NtClearEvent (240, ... ) == 0x0 03123 896 NtSetEvent (240, ... 0x0, ) == 0x0 03124 896 NtClose (240, ... ) == 0x0 03125 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x8,}, 4, ... ) == 0x0 03126 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x9,}, 4, ... ) == 0x0 03127 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 03128 896 NtClose (112, ... ) == 0x0 03129 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x7,}, 4, ... ) == 0x0 03130 896 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 03131 896 NtClose (80, ... ) == 0x0 03132 896 NtGdiDeleteObjectApp (-1190131992, ... ) == 0x1 03133 896 NtUserGetProcessWindowStation (... ) == 0x1c 03134 896 NtUserBuildNameList (28, 522, 1333648, 1241544, ... ) == 0x0 03135 896 NtUserGetProcessWindowStation (... ) == 0x1c 03136 896 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Default"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x50 03137 896 NtUserBuildHwndList (80, 0, 0, 0, 64, ... (0x10070, 0x1a00f4, 0x5009e, 0x400fa, 0x10080, 0x10074, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x1401b6, 0xc01d2, 0xd0102, 0xd011a, 0x100d0, 0x200b0, 0x100cc, 0xf0104, 0x1500a4, 0x7012e, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 57, ) == 0x0 03138 896 NtUserValidateHandleSecure (65648, ... ) == 0x1 03139 896 NtUserQueryWindow (65648, 0, ... ) == 0x6b8 03140 896 NtUserQueryWindow (65648, 1, ... ) == 0x6d4 03141 896 NtUserValidateHandleSecure (65648, ... ) == 0x1 03142 896 NtUserValidateHandleSecure (1704180, ... ) == 0x1 03143 896 NtUserQueryWindow (1704180, 0, ... ) == 0x6b8 03144 896 NtUserQueryWindow (1704180, 1, ... ) == 0x6d4 03145 896 NtUserValidateHandleSecure (1704180, ... ) == 0x1 03146 896 NtUserValidateHandleSecure (327838, ... ) == 0x1 03147 896 NtUserQueryWindow (327838, 0, ... ) == 0x6b8 03148 896 NtUserQueryWindow (327838, 1, ... ) == 0x6d4 03149 896 NtUserValidateHandleSecure (327838, ... ) == 0x1 03150 896 NtUserValidateHandleSecure (262394, ... ) == 0x1 03151 896 NtUserQueryWindow (262394, 0, ... ) == 0x6b8 03152 896 NtUserQueryWindow (262394, 1, ... ) == 0x6d4 03153 896 NtUserValidateHandleSecure (262394, ... ) == 0x1 03154 896 NtUserBuildHwndList (0, 262394, 1, 0, 64, ... (0x80064, 0x60068, 0x6006c, 0x50094, 0x50096, 0x60066, 0x7006a, 0x90058, 0x6006e, 0x5008a, 0x50088, 0x500a0, 0x1, ), 13, ) == 0x0 03155 896 NtUserValidateHandleSecure (524388, ... ) == 0x1 03156 896 NtUserQueryWindow (524388, 0, ... ) == 0x6b8 03157 896 NtUserQueryWindow (524388, 1, ... ) == 0x6d4 03158 896 NtUserValidateHandleSecure (393320, ... ) == 0x1 03159 896 NtUserQueryWindow (393320, 0, ... ) == 0x6b8 03160 896 NtUserQueryWindow (393320, 1, ... ) == 0x6d4 03161 896 NtUserValidateHandleSecure (393324, ... ) == 0x1 03162 896 NtUserQueryWindow (393324, 0, ... ) == 0x6b8 03163 896 NtUserQueryWindow (393324, 1, ... ) == 0x6d4 03164 896 NtUserValidateHandleSecure (327828, ... ) == 0x1 03165 896 NtUserQueryWindow (327828, 0, ... ) == 0x6b8 03166 896 NtUserQueryWindow (327828, 1, ... ) == 0x6d4 03167 896 NtUserValidateHandleSecure (327830, ... ) == 0x1 03168 896 NtUserQueryWindow (327830, 0, ... ) == 0x6b8 03169 896 NtUserQueryWindow (327830, 1, ... ) == 0x6d4 03170 896 NtUserValidateHandleSecure (393318, ... ) == 0x1 03171 896 NtUserQueryWindow (393318, 0, ... ) == 0x6b8 03172 896 NtUserQueryWindow (393318, 1, ... ) == 0x6d4 03173 896 NtUserValidateHandleSecure (458858, ... ) == 0x1 03174 896 NtUserQueryWindow (458858, 0, ... ) == 0x6b8 03175 896 NtUserQueryWindow (458858, 1, ... ) == 0x6d4 03176 896 NtUserValidateHandleSecure (589912, ... ) == 0x1 03177 896 NtUserQueryWindow (589912, 0, ... ) == 0x6b8 03178 896 NtUserQueryWindow (589912, 1, ... ) == 0x6d4 03179 896 NtUserValidateHandleSecure (393326, ... ) == 0x1 03180 896 NtUserQueryWindow (393326, 0, ... ) == 0x6b8 03181 896 NtUserQueryWindow (393326, 1, ... ) == 0x6d4 03182 896 NtUserValidateHandleSecure (327818, ... ) == 0x1 03183 896 NtUserQueryWindow (327818, 0, ... ) == 0x6b8 03184 896 NtUserQueryWindow (327818, 1, ... ) == 0x6d4 03185 896 NtUserValidateHandleSecure (327816, ... ) == 0x1 03186 896 NtUserQueryWindow (327816, 0, ... ) == 0x6b8 03187 896 NtUserQueryWindow (327816, 1, ... ) == 0x6d4 03188 896 NtUserValidateHandleSecure (327840, ... ) == 0x1 03189 896 NtUserQueryWindow (327840, 0, ... ) == 0x6b8 03190 896 NtUserQueryWindow (327840, 1, ... ) == 0x6d4 03191 896 NtUserValidateHandleSecure (65664, ... ) == 0x1 03192 896 NtUserQueryWindow (65664, 0, ... ) == 0x6b8 03193 896 NtUserQueryWindow (65664, 1, ... ) == 0x6d4 03194 896 NtUserValidateHandleSecure (65664, ... ) == 0x1 03195 896 NtUserValidateHandleSecure (65652, ... ) == 0x1 03196 896 NtUserQueryWindow (65652, 0, ... ) == 0x6b8 03197 896 NtUserQueryWindow (65652, 1, ... ) == 0x6d4 03198 896 NtUserValidateHandleSecure (65652, ... ) == 0x1 03199 896 NtUserValidateHandleSecure (65668, ... ) == 0x1 03200 896 NtUserQueryWindow (65668, 0, ... ) == 0x6b8 03201 896 NtUserQueryWindow (65668, 1, ... ) == 0x6d4 03202 896 NtUserValidateHandleSecure (65668, ... ) == 0x1 03203 896 NtUserValidateHandleSecure (196680, ... ) == 0x1 03204 896 NtUserQueryWindow (196680, 0, ... ) == 0x6b8 03205 896 NtUserQueryWindow (196680, 1, ... ) == 0x6d4 03206 896 NtUserValidateHandleSecure (196680, ... ) == 0x1 03207 896 NtUserValidateHandleSecure (65650, ... ) == 0x1 03208 896 NtUserQueryWindow (65650, 0, ... ) == 0x6b8 03209 896 NtUserQueryWindow (65650, 1, ... ) == 0x6d4 03210 896 NtUserValidateHandleSecure (65650, ... ) == 0x1 03211 896 NtUserValidateHandleSecure (131154, ... ) == 0x1 03212 896 NtUserQueryWindow (131154, 0, ... ) == 0x6b8 03213 896 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 03214 896 NtUserValidateHandleSecure (131154, ... ) == 0x1 03215 896 NtUserBuildHwndList (0, 131154, 1, 0, 64, ... (0x3003e, 0x3003c, 0x30040, 0x30042, 0x30044, 0x30046, 0x10076, 0x10082, 0x1007a, 0x1007e, 0x1, ), 11, ) == 0x0 03216 896 NtUserValidateHandleSecure (196670, ... ) == 0x1 03217 896 NtUserQueryWindow (196670, 0, ... ) == 0x6b8 03218 896 NtUserQueryWindow (196670, 1, ... ) == 0x6d4 03219 896 NtUserValidateHandleSecure (196668, ... ) == 0x1 03220 896 NtUserQueryWindow (196668, 0, ... ) == 0x6b8 03221 896 NtUserQueryWindow (196668, 1, ... ) == 0x6d4 03222 896 NtUserValidateHandleSecure (196672, ... ) == 0x1 03223 896 NtUserQueryWindow (196672, 0, ... ) == 0x6b8 03224 896 NtUserQueryWindow (196672, 1, ... ) == 0x6d4 03225 896 NtUserValidateHandleSecure (196674, ... ) == 0x1 03226 896 NtUserQueryWindow (196674, 0, ... ) == 0x6b8 03227 896 NtUserQueryWindow (196674, 1, ... ) == 0x6d4 03228 896 NtUserValidateHandleSecure (196676, ... ) == 0x1 03229 896 NtUserQueryWindow (196676, 0, ... ) == 0x6b8 03230 896 NtUserQueryWindow (196676, 1, ... ) == 0x6d4 03231 896 NtUserValidateHandleSecure (196678, ... ) == 0x1 03232 896 NtUserQueryWindow (196678, 0, ... ) == 0x6b8 03233 896 NtUserQueryWindow (196678, 1, ... ) == 0x6d4 03234 896 NtUserValidateHandleSecure (65654, ... ) == 0x1 03235 896 NtUserQueryWindow (65654, 0, ... ) == 0x6b8 03236 896 NtUserQueryWindow (65654, 1, ... ) == 0x6d4 03237 896 NtUserValidateHandleSecure (65666, ... ) == 0x1 03238 896 NtUserQueryWindow (65666, 0, ... ) == 0x6b8 03239 896 NtUserQueryWindow (65666, 1, ... ) == 0x6d4 03240 896 NtUserValidateHandleSecure (65658, ... ) == 0x1 03241 896 NtUserQueryWindow (65658, 0, ... ) == 0x6b8 03242 896 NtUserQueryWindow (65658, 1, ... ) == 0x6d4 03243 896 NtUserValidateHandleSecure (65662, ... ) == 0x1 03244 896 NtUserQueryWindow (65662, 0, ... ) == 0x6b8 03245 896 NtUserQueryWindow (65662, 1, ... ) == 0x6d4 03246 896 NtUserValidateHandleSecure (327836, ... ) == 0x1 03247 896 NtUserQueryWindow (327836, 0, ... ) == 0x6b8 03248 896 NtUserQueryWindow (327836, 1, ... ) == 0x6d4 03249 896 NtUserValidateHandleSecure (327836, ... ) == 0x1 03250 896 NtUserValidateHandleSecure (65680, ... ) == 0x1 03251 896 NtUserQueryWindow (65680, 0, ... ) == 0x6b8 03252 896 NtUserQueryWindow (65680, 1, ... ) == 0x6bc 03253 896 NtUserValidateHandleSecure (65680, ... ) == 0x1 03254 896 NtUserValidateHandleSecure (327842, ... ) == 0x1 03255 896 NtUserQueryWindow (327842, 0, ... ) == 0x6b8 03256 896 NtUserQueryWindow (327842, 1, ... ) == 0x6d4 03257 896 NtUserValidateHandleSecure (327842, ... ) == 0x1 03258 896 NtUserValidateHandleSecure (1311158, ... ) == 0x1 03259 896 NtUserQueryWindow (1311158, 0, ... ) == 0x6b8 03260 896 NtUserQueryWindow (1311158, 1, ... ) == 0x6d4 03261 896 NtUserValidateHandleSecure (1311158, ... ) == 0x1 03262 896 NtUserBuildHwndList (0, 1311158, 1, 0, 64, ... (0xf0192, 0x80198, 0x1, ), 3, ) == 0x0 03263 896 NtUserValidateHandleSecure (983442, ... ) == 0x1 03264 896 NtUserQueryWindow (983442, 0, ... ) == 0x6b8 03265 896 NtUserQueryWindow (983442, 1, ... ) == 0x6d4 03266 896 NtUserValidateHandleSecure (524696, ... ) == 0x1 03267 896 NtUserQueryWindow (524696, 0, ... ) == 0x6b8 03268 896 NtUserQueryWindow (524696, 1, ... ) == 0x6d4 03269 896 NtUserValidateHandleSecure (786898, ... ) == 0x1 03270 896 NtUserQueryWindow (786898, 0, ... ) == 0x6b8 03271 896 NtUserQueryWindow (786898, 1, ... ) == 0x6d4 03272 896 NtUserValidateHandleSecure (786898, ... ) == 0x1 03273 896 NtUserValidateHandleSecure (852226, ... ) == 0x1 03274 896 NtUserQueryWindow (852226, 0, ... ) == 0x6b8 03275 896 NtUserQueryWindow (852226, 1, ... ) == 0x6d4 03276 896 NtUserValidateHandleSecure (852226, ... ) == 0x1 03277 896 NtUserBuildHwndList (0, 852226, 1, 0, 64, ... (0x700fc, 0xc0114, 0x1, ), 3, ) == 0x0 03278 896 NtUserValidateHandleSecure (459004, ... ) == 0x1 03279 896 NtUserQueryWindow (459004, 0, ... ) == 0x6b8 03280 896 NtUserQueryWindow (459004, 1, ... ) == 0x6d4 03281 896 NtUserValidateHandleSecure (786708, ... ) == 0x1 03282 896 NtUserQueryWindow (786708, 0, ... ) == 0x6b8 03283 896 NtUserQueryWindow (786708, 1, ... ) == 0x6d4 03284 896 NtUserValidateHandleSecure (852250, ... ) == 0x1 03285 896 NtUserQueryWindow (852250, 0, ... ) == 0x6b8 03286 896 NtUserQueryWindow (852250, 1, ... ) == 0x6d4 03287 896 NtUserValidateHandleSecure (852250, ... ) == 0x1 03288 896 NtUserValidateHandleSecure (65744, ... ) == 0x1 03289 896 NtUserQueryWindow (65744, 0, ... ) == 0x19c 03290 896 NtUserQueryWindow (65744, 1, ... ) == 0x1a0 03291 896 NtUserValidateHandleSecure (65744, ... ) == 0x1 03292 896 NtUserValidateHandleSecure (131248, ... ) == 0x1 03293 896 NtUserQueryWindow (131248, 0, ... ) == 0xa0 03294 896 NtUserQueryWindow (131248, 1, ... ) == 0xe4 03295 896 NtUserValidateHandleSecure (131248, ... ) == 0x1 03296 896 NtUserValidateHandleSecure (65740, ... ) == 0x1 03297 896 NtUserQueryWindow (65740, 0, ... ) == 0x19c 03298 896 NtUserQueryWindow (65740, 1, ... ) == 0x1a0 03299 896 NtUserValidateHandleSecure (65740, ... ) == 0x1 03300 896 NtUserValidateHandleSecure (983300, ... ) == 0x1 03301 896 NtUserQueryWindow (983300, 0, ... ) == 0x2fc 03302 896 NtUserQueryWindow (983300, 1, ... ) == 0x544 03303 896 NtUserValidateHandleSecure (983300, ... ) == 0x1 03304 896 NtUserValidateHandleSecure (1376420, ... ) == 0x1 03305 896 NtUserQueryWindow (1376420, 0, ... ) == 0x1e8 03306 896 NtUserQueryWindow (1376420, 1, ... ) == 0x708 03307 896 NtUserValidateHandleSecure (1376420, ... ) == 0x1 03308 896 NtUserValidateHandleSecure (459054, ... ) == 0x1 03309 896 NtUserQueryWindow (459054, 0, ... ) == 0x4b8 03310 896 NtUserQueryWindow (459054, 1, ... ) == 0x3dc 03311 896 NtUserValidateHandleSecure (459054, ... ) == 0x1 03312 896 NtUserValidateHandleSecure (196940, ... ) == 0x1 03313 896 NtUserQueryWindow (196940, 0, ... ) == 0x4b4 03314 896 NtUserQueryWindow (196940, 1, ... ) == 0x474 03315 896 NtUserValidateHandleSecure (196940, ... ) == 0x1 03316 896 NtUserValidateHandleSecure (65820, ... ) == 0x1 03317 896 NtUserQueryWindow (65820, 0, ... ) == 0x22c 03318 896 NtUserQueryWindow (65820, 1, ... ) == 0x220 03319 896 NtUserValidateHandleSecure (65820, ... ) == 0x1 03320 896 NtUserValidateHandleSecure (65766, ... ) == 0x1 03321 896 NtUserQueryWindow (65766, 0, ... ) == 0x6b8 03322 896 NtUserQueryWindow (65766, 1, ... ) == 0x13c 03323 896 NtUserValidateHandleSecure (65766, ... ) == 0x1 03324 896 NtUserValidateHandleSecure (65750, ... ) == 0x1 03325 896 NtUserQueryWindow (65750, 0, ... ) == 0x6b8 03326 896 NtUserQueryWindow (65750, 1, ... ) == 0x13c 03327 896 NtUserValidateHandleSecure (65750, ... ) == 0x1 03328 896 NtUserBuildHwndList (0, 65750, 1, 0, 64, ... (0x100da, 0x100dc, 0x100de, 0x100e0, 0x1, ), 5, ) == 0x0 03329 896 NtUserValidateHandleSecure (65754, ... ) == 0x1 03330 896 NtUserQueryWindow (65754, 0, ... ) == 0x6b8 03331 896 NtUserQueryWindow (65754, 1, ... ) == 0x13c 03332 896 NtUserValidateHandleSecure (65756, ... ) == 0x1 03333 896 NtUserQueryWindow (65756, 0, ... ) == 0x6b8 03334 896 NtUserQueryWindow (65756, 1, ... ) == 0x13c 03335 896 NtUserValidateHandleSecure (65758, ... ) == 0x1 03336 896 NtUserQueryWindow (65758, 0, ... ) == 0x6b8 03337 896 NtUserQueryWindow (65758, 1, ... ) == 0x13c 03338 896 NtUserValidateHandleSecure (65760, ... ) == 0x1 03339 896 NtUserQueryWindow (65760, 0, ... ) == 0x6b8 03340 896 NtUserQueryWindow (65760, 1, ... ) == 0x13c 03341 896 NtUserValidateHandleSecure (65746, ... ) == 0x1 03342 896 NtUserQueryWindow (65746, 0, ... ) == 0x6b8 03343 896 NtUserQueryWindow (65746, 1, ... ) == 0x6d4 03344 896 NtUserValidateHandleSecure (65746, ... ) == 0x1 03345 896 NtUserValidateHandleSecure (65738, ... ) == 0x1 03346 896 NtUserQueryWindow (65738, 0, ... ) == 0x19c 03347 896 NtUserQueryWindow (65738, 1, ... ) == 0x1a0 03348 896 NtUserValidateHandleSecure (65738, ... ) == 0x1 03349 896 NtUserValidateHandleSecure (65736, ... ) == 0x1 03350 896 NtUserQueryWindow (65736, 0, ... ) == 0xa0 03351 896 NtUserQueryWindow (65736, 1, ... ) == 0xe4 03352 896 NtUserValidateHandleSecure (65736, ... ) == 0x1 03353 896 NtUserValidateHandleSecure (65722, ... ) == 0x1 03354 896 NtUserQueryWindow (65722, 0, ... ) == 0x104 03355 896 NtUserQueryWindow (65722, 1, ... ) == 0x108 03356 896 NtUserValidateHandleSecure (65722, ... ) == 0x1 03357 896 NtUserValidateHandleSecure (65710, ... ) == 0x1 03358 896 NtUserQueryWindow (65710, 0, ... ) == 0x104 03359 896 NtUserQueryWindow (65710, 1, ... ) == 0x108 03360 896 NtUserValidateHandleSecure (65710, ... ) == 0x1 03361 896 NtUserValidateHandleSecure (65708, ... ) == 0x1 03362 896 NtUserQueryWindow (65708, 0, ... ) == 0x120 03363 896 NtUserQueryWindow (65708, 1, ... ) == 0x124 03364 896 NtUserValidateHandleSecure (65708, ... ) == 0x1 03365 896 NtUserValidateHandleSecure (196774, ... ) == 0x1 03366 896 NtUserQueryWindow (196774, 0, ... ) == 0xc4 03367 896 NtUserQueryWindow (196774, 1, ... ) == 0xc8 03368 896 NtUserValidateHandleSecure (196774, ... ) == 0x1 03369 896 NtUserValidateHandleSecure (65656, ... ) == 0x1 03370 896 NtUserQueryWindow (65656, 0, ... ) == 0x6b8 03371 896 NtUserQueryWindow (65656, 1, ... ) == 0x6ec 03372 896 NtUserValidateHandleSecure (65656, ... ) == 0x1 03373 896 NtUserValidateHandleSecure (196706, ... ) == 0x1 03374 896 NtUserQueryWindow (196706, 0, ... ) == 0x6b8 03375 896 NtUserQueryWindow (196706, 1, ... ) == 0x6bc 03376 896 NtUserValidateHandleSecure (196706, ... ) == 0x1 03377 896 NtUserValidateHandleSecure (327734, ... ) == 0x1 03378 896 NtUserQueryWindow (327734, 0, ... ) == 0x6b8 03379 896 NtUserQueryWindow (327734, 1, ... ) == 0x6bc 03380 896 NtUserValidateHandleSecure (327734, ... ) == 0x1 03381 896 NtUserValidateHandleSecure (327772, ... ) == 0x1 03382 896 NtUserQueryWindow (327772, 0, ... ) == 0x6b8 03383 896 NtUserQueryWindow (327772, 1, ... ) == 0x6bc 03384 896 NtUserValidateHandleSecure (327772, ... ) == 0x1 03385 896 NtUserValidateHandleSecure (65726, ... ) == 0x1 03386 896 NtUserQueryWindow (65726, 0, ... ) == 0x19c 03387 896 NtUserQueryWindow (65726, 1, ... ) == 0x1a0 03388 896 NtUserValidateHandleSecure (65726, ... ) == 0x1 03389 896 NtUserValidateHandleSecure (262398, ... ) == 0x1 03390 896 NtUserQueryWindow (262398, 0, ... ) == 0x6b8 03391 896 NtUserQueryWindow (262398, 1, ... ) == 0x6d4 03392 896 NtUserValidateHandleSecure (262398, ... ) == 0x1 03393 896 NtUserValidateHandleSecure (65682, ... ) == 0x1 03394 896 NtUserQueryWindow (65682, 0, ... ) == 0x6b8 03395 896 NtUserQueryWindow (65682, 1, ... ) == 0x6bc 03396 896 NtUserValidateHandleSecure (65682, ... ) == 0x1 03397 896 NtUserValidateHandleSecure (65670, ... ) == 0x1 03398 896 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 03399 896 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 03400 896 NtUserValidateHandleSecure (65670, ... ) == 0x1 03401 896 NtUserBuildHwndList (0, 65670, 1, 0, 64, ... (0x1008c, 0x1008e, 0x1, ), 3, ) == 0x0 03402 896 NtUserValidateHandleSecure (65676, ... ) == 0x1 03403 896 NtUserQueryWindow (65676, 0, ... ) == 0x6b8 03404 896 NtUserQueryWindow (65676, 1, ... ) == 0x6bc 03405 896 NtUserValidateHandleSecure (65678, ... ) == 0x1 03406 896 NtUserQueryWindow (65678, 0, ... ) == 0x6b8 03407 896 NtUserQueryWindow (65678, 1, ... ) == 0x6bc 03408 896 NtUserValidateHandleSecure (262196, ... ) == 0x1 03409 896 NtUserQueryWindow (262196, 0, ... ) == 0x6b8 03410 896 NtUserQueryWindow (262196, 1, ... ) == 0x6d4 03411 896 NtUserValidateHandleSecure (262196, ... ) == 0x1 03412 896 NtUserValidateHandleSecure (327760, ... ) == 0x1 03413 896 NtUserQueryWindow (327760, 0, ... ) == 0x6b8 03414 896 NtUserQueryWindow (327760, 1, ... ) == 0x6d4 03415 896 NtUserValidateHandleSecure (327760, ... ) == 0x1 03416 896 NtUserValidateHandleSecure (65852, ... ) == 0x1 03417 896 NtUserQueryWindow (65852, 0, ... ) == 0x22c 03418 896 NtUserQueryWindow (65852, 1, ... ) == 0x220 03419 896 NtUserValidateHandleSecure (65852, ... ) == 0x1 03420 896 NtUserValidateHandleSecure (65824, ... ) == 0x1 03421 896 NtUserQueryWindow (65824, 0, ... ) == 0x22c 03422 896 NtUserQueryWindow (65824, 1, ... ) == 0x220 03423 896 NtUserValidateHandleSecure (65824, ... ) == 0x1 03424 896 NtUserValidateHandleSecure (65730, ... ) == 0x1 03425 896 NtUserQueryWindow (65730, 0, ... ) == 0xa0 03426 896 NtUserQueryWindow (65730, 1, ... ) == 0xe4 03427 896 NtUserValidateHandleSecure (65730, ... ) == 0x1 03428 896 NtUserValidateHandleSecure (65724, ... ) == 0x1 03429 896 NtUserQueryWindow (65724, 0, ... ) == 0xa0 03430 896 NtUserQueryWindow (65724, 1, ... ) == 0xe4 03431 896 NtUserValidateHandleSecure (65724, ... ) == 0x1 03432 896 NtUserValidateHandleSecure (131406, ... ) == 0x1 03433 896 NtUserQueryWindow (131406, 0, ... ) == 0x4b4 03434 896 NtUserQueryWindow (131406, 1, ... ) == 0x474 03435 896 NtUserValidateHandleSecure (131406, ... ) == 0x1 03436 896 NtUserValidateHandleSecure (65752, ... ) == 0x1 03437 896 NtUserQueryWindow (65752, 0, ... ) == 0x6b8 03438 896 NtUserQueryWindow (65752, 1, ... ) == 0x13c 03439 896 NtUserValidateHandleSecure (65752, ... ) == 0x1 03440 896 NtUserValidateHandleSecure (65718, ... ) == 0x1 03441 896 NtUserQueryWindow (65718, 0, ... ) == 0x104 03442 896 NtUserQueryWindow (65718, 1, ... ) == 0x108 03443 896 NtUserValidateHandleSecure (65718, ... ) == 0x1 03444 896 NtUserValidateHandleSecure (65720, ... ) == 0x1 03445 896 NtUserQueryWindow (65720, 0, ... ) == 0x120 03446 896 NtUserQueryWindow (65720, 1, ... ) == 0x124 03447 896 NtUserValidateHandleSecure (65720, ... ) == 0x1 03448 896 NtUserValidateHandleSecure (65716, ... ) == 0x1 03449 896 NtUserQueryWindow (65716, 0, ... ) == 0xc4 03450 896 NtUserQueryWindow (65716, 1, ... ) == 0xc8 03451 896 NtUserValidateHandleSecure (65716, ... ) == 0x1 03452 896 NtUserValidateHandleSecure (65728, ... ) == 0x1 03453 896 NtUserQueryWindow (65728, 0, ... ) == 0x19c 03454 896 NtUserQueryWindow (65728, 1, ... ) == 0x1a0 03455 896 NtUserValidateHandleSecure (65728, ... ) == 0x1 03456 896 NtUserValidateHandleSecure (65690, ... ) == 0x1 03457 896 NtUserQueryWindow (65690, 0, ... ) == 0x6b8 03458 896 NtUserQueryWindow (65690, 1, ... ) == 0x6bc 03459 896 NtUserValidateHandleSecure (65690, ... ) == 0x1 03460 896 NtUserValidateHandleSecure (327774, ... ) == 0x1 03461 896 NtUserQueryWindow (327774, 0, ... ) == 0x6b8 03462 896 NtUserQueryWindow (327774, 1, ... ) == 0x6bc 03463 896 NtUserValidateHandleSecure (327774, ... ) == 0x1 03464 896 NtUserCloseDesktop (80, ... ) == 0x1 03465 896 NtUserGetProcessWindowStation (... ) == 0x1c 03466 896 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Disconnect"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 03467 896 NtUserGetProcessWindowStation (... ) == 0x1c 03468 896 NtUserOpenDesktop ({24, 28, 0x40, 0, 0, ({24, 28, 0x40, 0, 0, "Winlogon"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 03469 896 NtGdiDeleteObjectApp (1678378390, ... ) == 0x1 03470 896 NtGdiDeleteObjectApp (1946813918, ... ) == 0x1 03471 896 NtClose (72, ... ) == 0x0 03472 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 03473 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 03474 896 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 03475 896 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 03476 896 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 03477 896 NtQueryVirtualMemory (-1, 0x42456c, Basic, 28, ... {BaseAddress=0x424000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0xdd000,State=0x1000,Protect=0x40,Type=0x1000000,}, 28, ) == 0x0 03478 896 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 72, ) }, ... 72, ) == 0x0 03479 896 NtQueryValueKey (72, (72, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03480 896 NtClose (72, ... ) == 0x0 03481 896 NtClose (64, ... ) == 0x0 03482 896 NtClose (116, ... ) == 0x0 03483 896 NtFreeVirtualMemory (-1, (0x1470000), 4096, 32768, ... (0x1470000), 4096, ) == 0x0 03484 896 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 0, 1392360, 0, 0} (24, {20, 48, new_msg, 0, 0, 1392360, 0, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {20, 48, reply, 0, 1252, 896, 81868, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {20, 48, reply, 0, 1252, 896, 81868, 0} (24, {20, 48, new_msg, 0, 0, 1392360, 0, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {20, 48, reply, 0, 1252, 896, 81868, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 03485 896 NtTerminateProcess (-1, 0, ...