Summary:
NtCallbackReturn(>) | 1 | NtOpenThreadTokenEx(>) | 2 | NtQueryVirtualMemory(>) | 9 | NtContinue(>) | 88 |
NtGdiCreateBitmap(>) | 1 | NtQueryDefaultLocale(>) | 2 | NtSetInformationThread(>) | 9 | NtOpenKey(>) | 105 |
NtGdiInit(>) | 1 | NtQueryPerformanceCounter(>) | 2 | NtUserFindExistingCursorIcon(>) | 9 | NtQuerySystemInformation(>) | 108 |
NtGdiQueryFontAssocInfo(>) | 1 | NtQuerySystemTime(>) | 2 | NtOpenThreadToken(>) | 10 | NtTestAlert(>) | 165 |
NtGdiSelectBitmap(>) | 1 | NtSetInformationObject(>) | 2 | NtSetInformationFile(>) | 10 | NtRegisterThreadTerminatePort(>) | 168 |
NtOpenKeyedEvent(>) | 1 | NtFreeVirtualMemory(>) | 3 | NtQuerySection(>) | 12 | NtDuplicateObject(>) | 172 |
NtOpenSymbolicLinkObject(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtQueryDirectoryFile(>) | 14 | NtQueryValueKey(>) | 225 |
NtQueryObject(>) | 1 | NtSecureConnectPort(>) | 3 | NtUserRegisterClassExWOW(>) | 14 | NtQueryInformationThread(>) | 232 |
NtQuerySymbolicLinkObject(>) | 1 | NtWriteFile(>) | 3 | NtCreateFile(>) | 15 | NtResumeThread(>) | 232 |
NtRaiseException(>) | 1 | NtCreateIoCompletion(>) | 4 | NtSetValueKey(>) | 17 | NtCreateThread(>) | 245 |
NtSetInformationProcess(>) | 1 | NtGdiGetStockObject(>) | 5 | NtCreateKey(>) | 19 | NtRequestWaitReplyPort(>) | 264 |
NtUserCallNoParam(>) | 1 | NtQueryInformationToken(>) | 5 | NtOpenSection(>) | 21 | NtClose(>) | 291 |
NtUserGetThreadDesktop(>) | 1 | NtQueryVolumeInformationFile(>) | 5 | NtOpenFile(>) | 22 | NtProtectVirtualMemory(>) | 328 |
NtCreateMutant(>) | 2 | NtConnectPort(>) | 6 | NtQueryAttributesFile(>) | 31 | NtSetEventBoostPriority(>) | 437 |
NtGdiCreateSolidBrush(>) | 2 | NtFsControlFile(>) | 6 | NtMapViewOfSection(>) | 32 | NtAllocateVirtualMemory(>) | 605 |
NtNotifyChangeKey(>) | 2 | NtReadFile(>) | 6 | NtDeviceIoControlFile(>) | 36 | NtWaitForSingleObject(>) | 771 |
NtOpenDirectoryObject(>) | 2 | NtUnmapViewOfSection(>) | 7 | NtFlushInstructionCache(>) | 45 | ||
NtOpenProcessToken(>) | 2 | NtQueryInformationFile(>) | 8 | NtCreateEvent(>) | 63 | ||
NtOpenProcessTokenEx(>) | 2 |
YLNy0;J\7\362\253\326\344\177\11]\211\314&\255\260\2\273\361;\343\330\257d2\25\315\332\323f\350vo\355\345\342\347\345\337g\241\251*3j\333\207V\\260]\353\14M(i\202\371\312\363\177\354\5h\222\17\273Hs\337\12\3\261\220\3205K8_\231IX\244\366\301I\203\242\221\236\312\!\315(\24\301\4\352w\304C\210\341uX\200\270yC;-\225|\312E\12\261\207\232\325\236\234h(\214\231\207\204\305\32\356/\277\332\272eV\256>\222\267\24\210\372H4?-\353\206x'\224h\344\315\23\340\261\321\267^m\213\236gXh\253\252\237N\323\20{\363!\324\376\233\302)\330\213!\306M\337\270\317\247J\265\243\351\32%3|\375\335]e\267\\357e\257\220"
, ) , ) == 0x0 02034 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02035 1028 NtDeviceIoControlFile (412, 0, 0x0, 0x0, 0x390008, (412, 0, 0x0, 0x0, 0x390008, "l\37bs\344\237\300Q\246\323\307\355M\264:2vB\323\352fA\vB\323\352fA\vB\323\352fA\vB\323\352fA\vB\323\352fA\vB\323\352f^\276^\311\216\255\306\357g\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 02034 2016 NtAllocateVirtualMemory ... 64749568, 1048576, ) == 0x0 02036 1028 NtQuerySystemInformation (TimeOfDay, 48, ... 02037 2016 NtAllocateVirtualMemory (-1, 65789952, 0, 8192, 4096, 4, ... 02036 1028 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 02037 2016 NtAllocateVirtualMemory ... 65789952, 8192, ) == 0x0 02038 1120 NtTestAlert (... 02039 1028 NtQuerySystemInformation (ProcessorTimes, 48, ... 02038 1120 NtTestAlert ... ) == 0x0 02039 1028 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 02040 1120 NtContinue (64748848, 1, ... 02041 1028 NtQuerySystemInformation (Performance, 312, ... 02042 1120 NtRegisterThreadTerminatePort (24, ... 02041 1028 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 02042 1120 NtRegisterThreadTerminatePort ... ) == 0x0 02043 1028 NtQuerySystemInformation (Exception, 16, ... 02044 2016 NtProtectVirtualMemory (-1, (0x3ebe000), 4096, 260, ... 02043 1028 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 02044 2016 NtProtectVirtualMemory ... (0x3ebe000), 4096, 4, ) == 0x0 02045 1120 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02046 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02045 1120 NtDuplicateObject ... 556, ) == 0x0 02046 2016 NtCreateThread ... 560, {896, 840}, ) == 0x0 02047 1120 NtWaitForSingleObject (64, 0, {0, 0}, ... 02048 2016 NtQueryInformationThread (560, Basic, 28, ... 02047 1120 NtWaitForSingleObject ... ) == 0x102 02048 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff85000,Pid=896,Tid=840,}, 0x0, ) == 0x0 02049 1120 NtWaitForSingleObject (124, 0, 0x0, ... 02050 1028 NtQuerySystemInformation (Lookaside, 32, ... 02051 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81892, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81892, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\200\3\0\0H\3\0\0" ... ... 02050 1028 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 02051 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81893, 0} ... {28, 56, reply, 0, 896, 2016, 81893, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\2\0\0\200\3\0\0H\3\0\0" ) ) == 0x0 02052 1028 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 02053 2016 NtResumeThread (560, ... 02052 1028 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 02053 2016 NtResumeThread ... 1, ) == 0x0 02054 1028 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 02055 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02054 1028 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 02056 840 NtAllocateVirtualMemory (-1, 8806400, 0, 4096, 4096, 4, ... 02055 2016 NtAllocateVirtualMemory ... 65798144, 1048576, ) == 0x0 02056 840 NtAllocateVirtualMemory ... 8806400, 4096, ) == 0x0 02057 2016 NtAllocateVirtualMemory (-1, 66838528, 0, 8192, 4096, 4, ... 02058 840 NtTestAlert (... 02057 2016 NtAllocateVirtualMemory ... 66838528, 8192, ) == 0x0 02058 840 NtTestAlert ... ) == 0x0 02059 2016 NtProtectVirtualMemory (-1, (0x3fbe000), 4096, 260, ... 02060 840 NtContinue (65797424, 1, ... 02059 2016 NtProtectVirtualMemory ... (0x3fbe000), 4096, 4, ) == 0x0 02061 1028 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 02062 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02061 1028 NtCreateKey ... -2147481484, 2, ) == 0x0 02063 840 NtRegisterThreadTerminatePort (24, ... 02064 1028 NtSetValueKey (-2147481484, (-2147481484, "Seed", 0, 3, "\277\317\300\340\335w\272s\273\325\246r$\313\5\15-\361\212\352\273\6w\252OT\200k\213\201OV\242\215L\322\352\213\331\16Q\37\270l\27 \15C\235\36p\375\372\376RDxY\327(\345e\302N\257\321\11\333\324W\222\263e\221\353\227)\354]y", 80, ... , 0, 3, (-2147481484, "Seed", 0, 3, "\277\317\300\340\335w\272s\273\325\246r$\313\5\15-\361\212\352\273\6w\252OT\200k\213\201OV\242\215L\322\352\213\331\16Q\37\270l\27 \15C\235\36p\375\372\376RDxY\327(\345e\302N\257\321\11\333\324W\222\263e\221\353\227)\354]y", 80, ... , 80, ... 02063 840 NtRegisterThreadTerminatePort ... ) == 0x0 02064 1028 NtSetValueKey ... ) == 0x0 02065 840 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02066 1028 NtClose (-2147481484, ... 02065 840 NtDuplicateObject ... 564, ) == 0x0 02066 1028 NtClose ... ) == 0x0 02067 840 NtWaitForSingleObject (64, 0, {0, 0}, ... 02062 2016 NtCreateThread ... 568, {896, 876}, ) == 0x0 02068 2016 NtQueryInformationThread (568, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff84000,Pid=896,Tid=876,}, 0x0, ) == 0x0 02069 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81893, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81893, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\200\3\0\0l\3\0\0" ... {28, 56, reply, 0, 896, 2016, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\200\3\0\0l\3\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81894, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81893, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\200\3\0\0l\3\0\0" ... {28, 56, reply, 0, 896, 2016, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\2\0\0\200\3\0\0l\3\0\0" ) ) == 0x0 02070 2016 NtResumeThread (568, ... 1, ) == 0x0 02071 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 66846720, 1048576, ) == 0x0 02072 2016 NtAllocateVirtualMemory (-1, 67887104, 0, 8192, 4096, 4, ... 67887104, 8192, ) == 0x0 02035 1028 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "]\306M\330x\227\10H[ DD\6\20\336z\253\337\326.\274\23\374\367o\360-}\204\323\331lb\24?\274\305X\270L\321}\344\364\303\375s|\205O\14+2\355\362d\212\376wV\366A,\177Qr$\255R<\32x\274%n\367\260\353\323\3240\2011\204~]6\246>\177\36\326N\355A\267/\316\336\357\330a\200\332mp\20\200\332`49F{\3764\342\336\6\362]\226\313Cx\250\260\311C\246\13\7\317\330\35$=\30\32c)\373O[\375\260\267Z\36\2Q\177\325v\17}v#\273o\261Wa\250\346\204\324k\0x\205\27\334\16\257\25"xD \260\1\33}+\354+>g\26\324e\370\353\233u\326,\237\23\233\32\177\3\17"\247\334]C\364h[\314|\25\313*\225{\205\374\362\247\203K\4`\357\13\331\3210\226\332o6\2046p\20\2453\340\352\\305\1772\252\242h\245o\3008", ) xD \260\1\33}+\354+>g\26\324e\370\353\233u\326,\237\23\233\32\177\3\17 ... {status=0x0, info=256}, "]\306M\330x\227\10H[ DD\6\20\336z\253\337\326.\274\23\374\367o\360-}\204\323\331lb\24?\274\305X\270L\321}\344\364\303\375s|\205O\14+2\355\362d\212\376wV\366A,\177Qr$\255R<\32x\274%n\367\260\353\323\3240\2011\204~]6\246>\177\36\326N\355A\267/\316\336\357\330a\200\332mp\20\200\332`49F{\3764\342\336\6\362]\226\313Cx\250\260\311C\246\13\7\317\330\35$=\30\32c)\373O[\375\260\267Z\36\2Q\177\325v\17}v#\273o\261Wa\250\346\204\324k\0x\205\27\334\16\257\25"xD \260\1\33}+\354+>g\26\324e\370\353\233u\326,\237\23\233\32\177\3\17"\247\334]C\364h[\314|\25\313*\225{\205\374\362\247\203K\4`\357\13\331\3210\226\332o6\2046p\20\2453\340\352\\305\1772\252\242h\245o\3008", ) , ) == 0x0 02073 876 NtTestAlert (... 02067 840 NtWaitForSingleObject ... ) == 0x102 02074 1028 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02073 876 NtTestAlert ... ) == 0x0 02075 840 NtWaitForSingleObject (124, 0, 0x0, ... 02074 1028 NtCreateEvent ... 572, ) == 0x0 02076 876 NtContinue (66846000, 1, ... 02077 1028 NtSetEventBoostPriority (484, ... 02078 876 NtRegisterThreadTerminatePort (24, ... 01868 596 NtWaitForSingleObject ... ) == 0x0 02077 1028 NtSetEventBoostPriority ... ) == 0x0 02079 596 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 02078 876 NtRegisterThreadTerminatePort ... ) == 0x0 02079 596 NtAllocateVirtualMemory ... 1392640, 4096, ) == 0x0 02080 1028 NtWaitForSingleObject (288, 0, 0x0, ... 02081 2016 NtProtectVirtualMemory (-1, (0x40be000), 4096, 260, ... 02082 876 NtWaitForSingleObject (288, 0, 0x0, ... 02083 596 NtSetEventBoostPriority (288, ... 02081 2016 NtProtectVirtualMemory ... (0x40be000), 4096, 4, ) == 0x0 02082 876 NtWaitForSingleObject ... ) == 0x0 02083 596 NtSetEventBoostPriority ... ) == 0x0 02084 876 NtSetEventBoostPriority (288, ... 02085 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02084 876 NtSetEventBoostPriority ... ) == 0x0 02086 596 NtWaitForSingleObject (288, 0, 0x0, ... 02087 876 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02085 2016 NtCreateThread ... 576, {896, 1104}, ) == 0x0 02086 596 NtWaitForSingleObject ... ) == 0x0 02088 2016 NtQueryInformationThread (576, Basic, 28, ... 02089 596 NtSetEventBoostPriority (288, ... 02088 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff83000,Pid=896,Tid=1104,}, 0x0, ) == 0x0 02087 876 NtDuplicateObject ... 580, ) == 0x0 02080 1028 NtWaitForSingleObject ... ) == 0x0 02089 596 NtSetEventBoostPriority ... ) == 0x0 02090 876 NtWaitForSingleObject (288, 0, 0x0, ... 02091 1028 NtSetEventBoostPriority (288, ... 02092 596 NtWaitForSingleObject (288, 0, 0x0, ... 02090 876 NtWaitForSingleObject ... ) == 0x0 02093 876 NtSetEventBoostPriority (288, ... 02092 596 NtWaitForSingleObject ... ) == 0x0 02094 596 NtAllocateVirtualMemory (-1, 1396736, 0, 4096, 4096, 4, ... 1396736, 4096, ) == 0x0 02093 876 NtSetEventBoostPriority ... ) == 0x0 02091 1028 NtSetEventBoostPriority ... ) == 0x0 02095 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81894, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81894, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\200\3\0\0P\4\0\0" ... ... 02096 596 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02097 1028 NtConnectPort ( ("\RPC Control\DNSResolver", {12, 2, 1, 0}, 0x0, 0x0, 15461740, 188, ... , {12, 2, 1, 0}, 0x0, 0x0, 15461740, 188, ... 02095 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81895, 0} ... {28, 56, reply, 0, 896, 2016, 81895, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\2\0\0\200\3\0\0P\4\0\0" ) ) == 0x0 02096 596 NtCreateEvent ... 584, ) == 0x0 02098 2016 NtResumeThread (576, ... 02099 596 NtConnectPort ( ("\RPC Control\epmapper", {12, 2, 1, 1}, 0x0, 0x0, 11006584, 188, ... , {12, 2, 1, 1}, 0x0, 0x0, 11006584, 188, ... 02098 2016 NtResumeThread ... 1, ) == 0x0 02100 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02099 596 NtConnectPort ... 588, 0x0, 0x0, 0x0, 188, ) == 0x0 02101 876 NtWaitForSingleObject (64, 0, {0, 0}, ... 02097 1028 NtConnectPort ... 592, 0x0, 0x0, 0x0, 188, ) == 0x0 02102 1104 NtTestAlert (... 02103 596 NtRequestWaitReplyPort (588, {200, 224, new_msg, 0, 2883626, 1355840, 12, 2} (588, {200, 224, new_msg, 0, 2883626, 1355840, 12, 2} "\0\1\24\0\10\0\0\0\274\0\0\0\10\203\257\341\37]\311\21\221\244\10\0+\24\240\372\3\0\0\0\1\0\0\0\1\0\4\0\4\0\0\0\240<\24\0x\1\24\0\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\25\0\3\0\0\0w\211\253N\321{\363\355XU\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\00U\25\0+#E\333x\1\24\0PU\25\0h\1\24\0\0\0\0\0\0\0\0\0PU\25\0P\0\0\0XU\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\370\360\247\0\372\31\221|\214\370\247\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ... ... 02101 876 NtWaitForSingleObject ... ) == 0x102 02104 1028 NtRequestWaitReplyPort (592, {200, 224, new_msg, 0, 1384432, 12, 2, 1310721} (592, {200, 224, new_msg, 0, 1384432, 12, 2, 1310721} "\0\3\24\0\274\0\0\0$?\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\230`\347w\4\0\0\0x\1\24\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\336\314O6Q\304\201\225\30A\25\0d\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\320=\25\0A\356@9\260\3\24\0\20A\25\0h\1\24\0\0\0\0\0\0\0\0\0\20A\25\0P\0\0\0\30A\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\354\353\353\0\372\31\221|\200\363\353\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... ... 02102 1104 NtTestAlert ... ) == 0x0 02100 2016 NtAllocateVirtualMemory ... 67895296, 1048576, ) == 0x0 02105 876 NtWaitForSingleObject (124, 0, 0x0, ... 02106 1104 NtContinue (67894576, 1, ... 02107 2016 NtAllocateVirtualMemory (-1, 68935680, 0, 8192, 4096, 4, ... 02104 1028 NtRequestWaitReplyPort ... {200, 224, reply, 0, 896, 1028, 81898, 0} ... {200, 224, reply, 0, 896, 1028, 81898, 0} "\7\3\24\0\274\0\0\0$?\24\0\1kwEVY\205D\237\200\364(\367\326\1)\2\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0x\1\24\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\336\314O6Q\304\201\225\30A\25\0d\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\0\320=\25\0A\356@9\260\3\24\0\20A\25\0h\1\24\0\0\0\0\0\0\0\0\0\20A\25\0P\0\0\0\30A\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\354\353\353\0\372\31\221|\200\363\353\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 02108 1104 NtRegisterThreadTerminatePort (24, ... 02107 2016 NtAllocateVirtualMemory ... 68935680, 8192, ) == 0x0 02109 1028 NtRequestWaitReplyPort (592, {44, 68, new_msg, 0, 896, 1028, 81878, 0} (592, {44, 68, new_msg, 0, 896, 1028, 81878, 0} "\1\356\0\0A\2\4\0\30b\202\201\0\300\375\177\220\273\270\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0\0\0\0\0\1\0\0\0" ... ... 02108 1104 NtRegisterThreadTerminatePort ... ) == 0x0 02110 2016 NtProtectVirtualMemory (-1, (0x41be000), 4096, 260, ... 02103 596 NtRequestWaitReplyPort ... {200, 224, reply, 0, 896, 596, 81900, 0} ... {200, 224, reply, 0, 896, 596, 81900, 0} "\7\1\24\0\10\0\0\0\274\0\0\0\10\203\257\341\37]\311\21\221\244\10\0+\24\240\372\3\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\240<\24\0\377\377\377\377\10\0\0\0\5\0\0\0x\1\24\0\0\0\0\0\0\0\25\0\3\0\0\0w\211\253N\321{\363\355XU\25\0h\1\24\0\12\0\0\0\0\0\0\0\0\0\0\0(\0\0\00U\25\0+#E\333x\1\24\0PU\25\0h\1\24\0\0\0\0\0\0\0\0\0PU\25\0P\0\0\0XU\25\0\360\6\221|x\1\24\0P\0\0\0\346\31\0\0\0\0\24\0\370\360\247\0\372\31\221|\214\370\247\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ) ) == 0x0 02110 2016 NtProtectVirtualMemory ... (0x41be000), 4096, 4, ) == 0x0 02111 596 NtRequestWaitReplyPort (588, {44, 68, new_msg, 56, 0, 0, 0, 0} (588, {44, 68, new_msg, 56, 0, 0, 0, 0} "\1\0\0\0B\2\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\1\0\0\0\230W\25\0\322\0\0\0" ... ... 02112 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02111 596 NtRequestWaitReplyPort ... {40, 64, reply, 0, 896, 596, 81901, 0} ... {40, 64, reply, 0, 896, 596, 81901, 0} "\2\356Q\200\4\0\0\0P\306\233\201\0\340\372\177\220\353\10\370\370\37`\300l\353\10\370X\353Q\200\323\1\0\0\350\370\14\0" ) ) == 0x0 02113 1104 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02109 1028 NtRequestWaitReplyPort ... {40, 64, reply, 0, 896, 1028, 81899, 0} ... {40, 64, reply, 0, 896, 1028, 81899, 0} "\2\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\320\1\0\0X-\12\0" ) ) == 0x0 02114 596 NtRequestWaitReplyPort (588, {64, 88, new_msg, 56, 1310720, 11006452, 1398672, 0} (588, {64, 88, new_msg, 56, 1310720, 11006452, 1398672, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\247\0\351\201\347w\214\370\247\0\30\356\220|p\5\221|\1\0\0\0\360X\25\0\323\1\0\0\323\1\0\0\350\370\14\0\0\0\0\0\0\0\0\0\273f\347w" ... ... 02113 1104 NtDuplicateObject ... 596, ) == 0x0 02115 1028 NtRequestWaitReplyPort (592, {64, 88, new_msg, 56, 1373528, 15462252, 15462352, 0} (592, {64, 88, new_msg, 56, 1373528, 15462252, 15462352, 0} "\10\357\353\0@\0\24\0\346\277\347w\320\357\353\0l\357\353\0\20\0\0\0\250.\362v\314\365\24\0\1\0\0\0\320Z\25\0\320\1\0\0\320\1\0\0X-\12\0\0\0\0\0\0\0\0\0h\334\24\0" ... ... 02112 2016 NtCreateThread ... 600, {896, 860}, ) == 0x0 02116 1104 NtWaitForSingleObject (64, 0, {0, 0}, ... 02117 2016 NtQueryInformationThread (600, Basic, 28, ... 02116 1104 NtWaitForSingleObject ... ) == 0x102 02117 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff82000,Pid=896,Tid=860,}, 0x0, ) == 0x0 02118 1104 NtWaitForSingleObject (124, 0, 0x0, ... 02119 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81895, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81895, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\2\0\0\200\3\0\0\\3\0\0" ... ... 02114 596 NtRequestWaitReplyPort ... {64, 88, reply, 56, 896, 596, 81903, 0} ... {64, 88, reply, 56, 896, 596, 81903, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\247\0\351\201\347w\214\370\247\0\30\356\220|p\5\221|\1\0\0\0\360X\25\0\323\1\0\0\323\1\0\0\350\370\14\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02115 1028 NtRequestWaitReplyPort ... {64, 88, reply, 56, 896, 1028, 81902, 0} ... {64, 88, reply, 56, 896, 1028, 81902, 0} "\10\357\353\0@\0\24\0\346\277\347w\320\357\353\0l\357\353\0\20\0\0\0\250.\362v\314\365\24\0\1\0\0\0\320Z\25\0\320\1\0\0\320\1\0\0X-\12\0\0\0\0\0\0\0\0\0h\334\24\0" ) ) == 0x0 02119 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81904, 0} ... {28, 56, reply, 0, 896, 2016, 81904, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\2\0\0\200\3\0\0\\3\0\0" ) ) == 0x0 02120 596 NtAllocateVirtualMemory (-1, 1400832, 0, 4096, 4096, 4, ... 02121 1028 NtWaitForSingleObject (288, 0, 0x0, ... 02120 596 NtAllocateVirtualMemory ... 1400832, 4096, ) == 0x0 02122 596 NtSetEventBoostPriority (288, ... 02121 1028 NtWaitForSingleObject ... ) == 0x0 02123 1028 NtClose (572, ... ) == 0x0 02122 596 NtSetEventBoostPriority ... ) == 0x0 02124 2016 NtResumeThread (600, ... 02125 1028 NtClose (592, ... 02124 2016 NtResumeThread ... 1, ) == 0x0 02125 1028 NtClose ... ) == 0x0 02126 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02127 1028 NtCreateKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... }, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... , 0, ... 02126 2016 NtAllocateVirtualMemory ... 68943872, 1048576, ) == 0x0 02127 1028 NtCreateKey ... 592, 2, ) == 0x0 02128 2016 NtAllocateVirtualMemory (-1, 69984256, 0, 8192, 4096, 4, ... 02129 1028 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... }, ... 02128 2016 NtAllocateVirtualMemory ... 69984256, 8192, ) == 0x0 02129 1028 NtOpenKey ... 572, ) == 0x0 02130 596 NtRequestWaitReplyPort (588, {44, 68, new_msg, 56, 896, 596, 81901, 0} (588, {44, 68, new_msg, 56, 896, 596, 81901, 0} "\1\356\0\0B\2\3\0P\306\233\201\0\340\372\177\220\353\10\370\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\230W\25\0\322\0\0\0" ... ... 02131 860 NtTestAlert (... 02132 2016 NtProtectVirtualMemory (-1, (0x42be000), 4096, 260, ... 02131 860 NtTestAlert ... ) == 0x0 02132 2016 NtProtectVirtualMemory ... (0x42be000), 4096, 4, ) == 0x0 02130 596 NtRequestWaitReplyPort ... {40, 64, reply, 0, 896, 596, 81906, 0} ... {40, 64, reply, 0, 896, 596, 81906, 0} "\2\246\200|\4\0\0\0\0\0\0\0\4\377}\0(\345\12\0\0\0\0\0\230\376}\0\2\0\0\0\351\1\0\0\350\232\14\0" ) ) == 0x0 02133 860 NtContinue (68943152, 1, ... 02134 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02135 596 NtRequestWaitReplyPort (588, {64, 88, new_msg, 56, 1310720, 11006452, 11007196, 0} (588, {64, 88, new_msg, 56, 1310720, 11006452, 11007196, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\247\0\351\201\347w\214\370\247\0\30\356\220|p\5\221|\1\0\0\0@l\25\0\351\1\0\0\351\1\0\0\350\232\14\0\0\0\0\0\0\0\0\0\273f\347w" ... ... 02136 860 NtRegisterThreadTerminatePort (24, ... 02134 2016 NtCreateThread ... 604, {896, 1516}, ) == 0x0 02136 860 NtRegisterThreadTerminatePort ... ) == 0x0 02137 2016 NtQueryInformationThread (604, Basic, 28, ... 02135 596 NtRequestWaitReplyPort ... {64, 88, reply, 56, 896, 596, 81907, 0} ... {64, 88, reply, 56, 896, 596, 81907, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\247\0\351\201\347w\214\370\247\0\30\356\220|p\5\221|\1\0\0\0@l\25\0\351\1\0\0\351\1\0\0\350\232\14\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02138 1028 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... }, ... 02137 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff81000,Pid=896,Tid=1516,}, 0x0, ) == 0x0 02139 860 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02138 1028 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02140 596 NtRequestWaitReplyPort (588, {44, 68, new_msg, 56, 896, 596, 81906, 0} (588, {44, 68, new_msg, 56, 896, 596, 81906, 0} "\1\246\0\0B\2\3\0\0\0\0\0\4\377}\0(\345\12\0\0\0\0\0\377\377\377\377\2\0\0\0\1\0\0\0\230W\25\0\322\0\0\0" ... ... 02139 860 NtDuplicateObject ... 608, ) == 0x0 02141 1028 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\System\DNSClient"}, ... }, ... 02142 860 NtWaitForSingleObject (64, 0, {0, 0}, ... 02141 1028 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02140 596 NtRequestWaitReplyPort ... {40, 64, reply, 0, 896, 596, 81908, 0} ... {40, 64, reply, 0, 896, 596, 81908, 0} "\2\356Q\200\4\0\0\0\250\372\244\201\0\360\372\177\220\253S\371\370\37`\300l\253S\371X\353Q\200|\1\0\0h\236\14\0" ) ) == 0x0 02142 860 NtWaitForSingleObject ... ) == 0x102 02143 1028 NtQueryValueKey (592, (592, "Domain", Partial, 144, ... , Partial, 144, ... 02144 596 NtRequestWaitReplyPort (588, {64, 88, new_msg, 56, 1310720, 11006452, 11007196, 0} (588, {64, 88, new_msg, 56, 1310720, 11006452, 11007196, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\247\0\351\201\347w\214\370\247\0\30\356\220|p\5\221|\1\0\0\0`J\25\0|\1\0\0|\1\0\0h\236\14\0\0\0\0\0\0\0\0\0\273f\347w" ... ... 02145 860 NtWaitForSingleObject (124, 0, 0x0, ... 02143 1028 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02144 596 NtRequestWaitReplyPort ... {64, 88, reply, 56, 896, 596, 81909, 0} ... {64, 88, reply, 56, 896, 596, 81909, 0} "\10\356\220|@\0\1\0\34\0\0\0p\363\247\0\351\201\347w\214\370\247\0\30\356\220|p\5\221|\1\0\0\0`J\25\0|\1\0\0|\1\0\0h\236\14\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02146 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81904, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81904, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\200\3\0\0\354\5\0\0" ... ... 02147 1028 NtQueryValueKey (592, (592, "Domain", Partial, 144, ... , Partial, 144, ... 02146 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81910, 0} ... {28, 56, reply, 0, 896, 2016, 81910, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\2\0\0\200\3\0\0\354\5\0\0" ) ) == 0x0 02147 1028 NtQueryValueKey ... TitleIdx=0, Type=1, Data= ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02148 2016 NtResumeThread (604, ... 02149 1028 NtClose (592, ... 02148 2016 NtResumeThread ... 1, ) == 0x0 02149 1028 NtClose ... ) == 0x0 02150 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02151 1028 NtClose (572, ... 02152 596 NtClose (584, ... 02153 1516 NtTestAlert (... 02151 1028 NtClose ... ) == 0x0 02152 596 NtClose ... ) == 0x0 02153 1516 NtTestAlert ... ) == 0x0 02150 2016 NtAllocateVirtualMemory ... 69992448, 1048576, ) == 0x0 02154 596 NtClose (588, ... 02155 1516 NtContinue (69991728, 1, ... 02156 2016 NtAllocateVirtualMemory (-1, 71032832, 0, 8192, 4096, 4, ... 02154 596 NtClose ... ) == 0x0 02157 1516 NtRegisterThreadTerminatePort (24, ... 02156 2016 NtAllocateVirtualMemory ... 71032832, 8192, ) == 0x0 02158 596 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02157 1516 NtRegisterThreadTerminatePort ... ) == 0x0 02159 2016 NtProtectVirtualMemory (-1, (0x43be000), 4096, 260, ... 02158 596 NtCreateEvent ... 588, ) == 0x0 02160 1028 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, ... }, ... 02159 2016 NtProtectVirtualMemory ... (0x43be000), 4096, 4, ) == 0x0 02161 1516 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 02160 1028 NtOpenKey ... 584, ) == 0x0 02162 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02161 1516 NtDuplicateObject ... 572, ) == 0x0 02163 1028 NtQueryValueKey (584, (584, "DnsNbtLookupOrder", Partial, 144, ... , Partial, 144, ... 02164 596 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... }, ... 02165 1516 NtWaitForSingleObject (64, 0, {0, 0}, ... 02163 1028 NtQueryValueKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02164 596 NtOpenKey ... 592, ) == 0x0 02165 1516 NtWaitForSingleObject ... ) == 0x102 02166 1028 NtClose (584, ... 02167 596 NtOpenKey (0x20019, {24, 592, 0x40, 0, 0, (0x20019, {24, 592, 0x40, 0, 0, "ActiveComputerName"}, ... }, ... 02168 1516 NtWaitForSingleObject (124, 0, 0x0, ... 02166 1028 NtClose ... ) == 0x0 02167 596 NtOpenKey ... 584, ) == 0x0 02162 2016 NtCreateThread ... 612, {896, 780}, ) == 0x0 02169 596 NtQueryValueKey (584, (584, "ComputerName", Full, 108, ... , Full, 108, ... 02170 2016 NtQueryInformationThread (612, Basic, 28, ... 02169 596 NtQueryValueKey ... TitleIdx=0, Type=1, Name= ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 02170 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff80000,Pid=896,Tid=780,}, 0x0, ) == 0x0 02171 1028 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 15461328, ... }, 15461328, ... 02172 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81910, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81910, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\2\0\0\200\3\0\0\14\3\0\0" ... ... 02171 1028 NtQueryAttributesFile ... ) == 0x0 02172 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81912, 0} ... {28, 56, reply, 0, 896, 2016, 81912, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\2\0\0\200\3\0\0\14\3\0\0" ) ) == 0x0 02173 1028 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 5, 96, ... }, 5, 96, ... 02174 596 NtClose (584, ... 02173 1028 NtOpenFile ... 616, {status=0x0, info=1}, ) == 0x0 02174 596 NtClose ... ) == 0x0 02175 1028 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 616, ... 02176 596 NtClose (592, ... 02175 1028 NtCreateSection ... 584, ) == 0x0 02176 596 NtClose ... ) == 0x0 02177 2016 NtResumeThread (612, ... 02178 596 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 02177 2016 NtResumeThread ... 1, ) == 0x0 02178 596 NtCreateIoCompletion ... 592, ) == 0x0 02179 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02180 1028 NtClose (616, ... 02181 780 NtWaitForSingleObject (88, 0, 0x0, ... 02179 2016 NtAllocateVirtualMemory ... 71041024, 1048576, ) == 0x0 02180 1028 NtClose ... ) == 0x0 02182 2016 NtAllocateVirtualMemory (-1, 72081408, 0, 8192, 4096, 4, ... 02183 1028 NtMapViewOfSection (584, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... 02182 2016 NtAllocateVirtualMemory ... 72081408, 8192, ) == 0x0 02183 1028 NtMapViewOfSection ... (0x850000), 0x0, 20480, ) == 0x0 02184 596 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 02185 1028 NtClose (584, ... 02184 596 NtCreateIoCompletion ... 616, ) == 0x0 02185 1028 NtClose ... ) == 0x0 02186 596 NtDuplicateObject (-1, 592, -1, 0x0, 0, 2, ... 02187 2016 NtProtectVirtualMemory (-1, (0x44be000), 4096, 260, ... 02186 596 NtDuplicateObject ... 584, ) == 0x0 02187 2016 NtProtectVirtualMemory ... (0x44be000), 4096, 4, ) == 0x0 02188 596 NtOpenThreadToken (-2, 0xc, 1, ... 02189 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02188 596 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02189 2016 NtCreateThread ... 620, {896, 940}, ) == 0x0 02190 2016 NtQueryInformationThread (620, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7f000,Pid=896,Tid=940,}, 0x0, ) == 0x0 02191 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81912, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81912, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\200\3\0\0\254\3\0\0" ... {28, 56, reply, 0, 896, 2016, 81913, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\200\3\0\0\254\3\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81913, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81912, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\200\3\0\0\254\3\0\0" ... {28, 56, reply, 0, 896, 2016, 81913, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\2\0\0\200\3\0\0\254\3\0\0" ) ) == 0x0 02192 2016 NtResumeThread (620, ... 1, ) == 0x0 02193 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02194 596 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 02195 940 NtWaitForSingleObject (88, 0, 0x0, ... 02196 1028 NtUnmapViewOfSection (-1, 0x850000, ... 02194 596 NtCreateEvent ... 624, ) == 0x0 02193 2016 NtAllocateVirtualMemory ... 72089600, 1048576, ) == 0x0 02197 596 NtOpenThreadToken (-2, 0xc, 1, ... 02198 2016 NtAllocateVirtualMemory (-1, 73129984, 0, 8192, 4096, 4, ... 02197 596 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02198 2016 NtAllocateVirtualMemory ... 73129984, 8192, ) == 0x0 02199 596 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02200 2016 NtProtectVirtualMemory (-1, (0x45be000), 4096, 260, ... 02199 596 NtSetInformationThread ... ) == 0x0 02200 2016 NtProtectVirtualMemory ... (0x45be000), 4096, 4, ) == 0x0 02196 1028 NtUnmapViewOfSection ... ) == 0x0 02201 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02202 1028 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 15461636, ... }, 15461636, ... 02203 596 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 11006144, (0xc0100080, {24, 0, 0x40, 0, 11006144, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... }, 0x0, 0, 3, 1, 64, 0, 0, ... 02202 1028 NtQueryAttributesFile ... ) == 0x0 02203 596 NtCreateFile ... 628, {status=0x0, info=1}, ) == 0x0 02204 1028 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\winrnr.dll"}, 5, 96, ... }, 5, 96, ... 02205 596 NtSetInformationFile (628, 11006200, 8, Pipe, ... 02204 1028 NtOpenFile ... 632, {status=0x0, info=1}, ) == 0x0 02205 596 NtSetInformationFile ... {status=0x0, info=0}, ) == 0x0 02206 1028 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 632, ... 02207 596 NtSetInformationFile (628, 11006188, 8, Completion, ... 02201 2016 NtCreateThread ... 636, {896, 1268}, ) == 0x0 02207 596 NtSetInformationFile ... {status=0x0, info=0}, ) == 0x0 02208 2016 NtQueryInformationThread (636, Basic, 28, ... 02206 1028 NtCreateSection ... 640, ) == 0x0 02208 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff7e000,Pid=896,Tid=1268,}, 0x0, ) == 0x0 02209 1028 NtQuerySection (640, Image, 48, ... 02210 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81913, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81913, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\2\0\0\200\3\0\0\364\4\0\0" ... ... 02209 1028 NtQuerySection ... {section info, class 1, size 48}, 0x0, ) == 0x0 02210 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81914, 0} ... {28, 56, reply, 0, 896, 2016, 81914, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\2\0\0\200\3\0\0\364\4\0\0" ) ) == 0x0 02211 1028 NtClose (632, ... 02212 596 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02211 1028 NtClose ... ) == 0x0 02212 596 NtSetInformationThread ... ) == 0x0 02213 1028 NtMapViewOfSection (640, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... 02214 596 NtWriteFile (628, 257, 0, 0, (628, 257, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... , 72, {0, 0}, 0, ... 02215 2016 NtResumeThread (636, ... 02214 596 NtWriteFile ... {status=0x0, info=72}, ) == 0x0 02215 2016 NtResumeThread ... 1, ) == 0x0 02216 596 NtReadFile (628, 257, 0, 0, 1024, {0, 0}, 0, ... 02217 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02216 596 NtReadFile ... {status=0x0, info=68}, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20k+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02217 2016 NtAllocateVirtualMemory ... 73138176, 1048576, ) == 0x0 02213 1028 NtMapViewOfSection ... (0x76fb0000), 0x0, 32768, ) == 0x0 02218 1268 NtWaitForSingleObject (88, 0, 0x0, ... 02219 2016 NtAllocateVirtualMemory (-1, 74178560, 0, 8192, 4096, 4, ... 02220 1028 NtClose (640, ... 02219 2016 NtAllocateVirtualMemory ... 74178560, 8192, ) == 0x0 02220 1028 NtClose ... ) == 0x0 02221 596 NtFsControlFile (628, 257, 0x0, 0x0, 0x11c017, (628, 257, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\210\367\247\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... , 64, 1024, ... 02222 1028 NtProtectVirtualMemory (-1, (0x76fb1000), 232, 4, ... 02221 596 NtFsControlFile ... {status=0x103, info=68}, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20k+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02222 1028 NtProtectVirtualMemory ... (0x76fb1000), 4096, 32, ) == 0x0 02223 596 NtFsControlFile (628, 257, 0x0, 0x0, 0x11c017, (628, 257, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\210\0\0\0\2\0\0\0p\0\0\0\0\0D\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28\1\0\0\0\1\0\0\0&\0(\0\200o\25\0\24\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0u\0t\0h\0o\0r\0i\0t\0y\0\\0s\0y\0s\0t\0e\0m\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 136, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28\0\0\0\0", ) , 136, 1024, ... {status=0x103, info=48}, (628, 257, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\210\0\0\0\2\0\0\0p\0\0\0\0\0D\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28\1\0\0\0\1\0\0\0&\0(\0\200o\25\0\24\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0u\0t\0h\0o\0r\0i\0t\0y\0\\0s\0y\0s\0t\0e\0m\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 136, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28\0\0\0\0", ) , ) == 0x103 02224 596 NtFsControlFile (628, 257, 0x0, 0x0, 0x11c017, (628, 257, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28", 44, 1024, ... {status=0x103, info=156}, "\5\0\2\3\20\0\0\0\234\0\0\0\2\0\0\0\204\0\0\0\0\0\0\0\220c\25\0\1\0\0\0\234c\25\0 \0\0\0\1\0\0\0\30\0\32\0\250c\25\0\304c\25\0\15\0\0\0\0\0\0\0\14\0\0\0N\0T\0 \0A\0U\0T\0H\0O\0R\0I\0T\0Y\0\0\0\0\0\1\0\0\0\0\0\0\5\1\0\0\0\230k\25\0\1\0\0\0\5\0i\0\250k\25\0\0\0\0\0\0\0\0\0\1\0\0\0\1\1\0\0\0\0\0\5\22\0\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=156}, (628, 257, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\201\262\254?gS\263F\252\227\2L\355h\28", 44, 1024, ... {status=0x103, info=156}, "\5\0\2\3\20\0\0\0\234\0\0\0\2\0\0\0\204\0\0\0\0\0\0\0\220c\25\0\1\0\0\0\234c\25\0 \0\0\0\1\0\0\0\30\0\32\0\250c\25\0\304c\25\0\15\0\0\0\0\0\0\0\14\0\0\0N\0T\0 \0A\0U\0T\0H\0O\0R\0I\0T\0Y\0\0\0\0\0\1\0\0\0\0\0\0\5\1\0\0\0\230k\25\0\1\0\0\0\5\0i\0\250k\25\0\0\0\0\0\0\0\0\0\1\0\0\0\1\1\0\0\0\0\0\5\22\0\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 02225 596 NtClose (624, ... ) == 0x0 02226 596 NtClose (628, ... ) == 0x0 02227 596 NtSecureConnectPort ( ("\RPC Control\unimdmsvc", {12, 2, 1, 1}, 0x0, 1384432, 0x0, 11008068, 188, ... , {12, 2, 1, 1}, 0x0, 1384432, 0x0, 11008068, 188, ... 02228 2016 NtProtectVirtualMemory (-1, (0x46be000), 4096, 260, ... (0x46be000), 4096, 4, ) == 0x0 02229 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 628, {896, 644}, ) == 0x0 02230 2016 NtQueryInformationThread (628, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7d000,Pid=896,Tid=644,}, 0x0, ) == 0x0 02231 1028 NtProtectVirtualMemory (-1, (0x76fb1000), 4096, 32, ... 02227 596 NtSecureConnectPort ... 624, 0x0, 0x0, 0x0, 188, ) == 0x0 02231 1028 NtProtectVirtualMemory ... (0x76fb1000), 4096, 4, ) == 0x0 02232 596 NtOpenThreadToken (-2, 0xc, 1, ... 02233 1028 NtFlushInstructionCache (-1, 1996165120, 232, ... 02232 596 NtOpenThreadToken ... ) == STATUS_NO_TOKEN 02233 1028 NtFlushInstructionCache ... ) == 0x0 02234 596 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02235 1028 NtProtectVirtualMemory (-1, (0x76fb1000), 232, 4, ... 02234 596 NtSetInformationThread ... ) == 0x0 02236 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81914, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81914, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\2\0\0\200\3\0\0\204\2\0\0" ... ... 02237 596 NtRequestWaitReplyPort (624, {200, 224, new_msg, 0, 1355840, 12, 2, 1310977} (624, {200, 224, new_msg, 0, 1355840, 12, 2, 1310977} "\0\0\0\0\274\0\0\0\0\0\0\03\242t\326)X\335I\220\360`\317\234\353q)\1\0\0\0\1\0\0\0\230`\347w\26\0\0\0\4\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0\362\3521W\377<\12\224R\215\243_HQ\240\14\12\0\0\0\365wWqU\264\277U\0\0\0\0\0*\25\0\360=\270\15R\322(\27(\0\0\0\33\14\0u\0\0\24\0\240\366\247\0\263\314\20\365\0\0\0\0XU\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\247\0\372\31\221|X\376\247\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... ... 02236 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 81916, 0} ... {28, 56, reply, 0, 896, 2016, 81916, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\2\0\0\200\3\0\0\204\2\0\0" ) ) == 0x0 02235 1028 NtProtectVirtualMemory ... (0x76fb1000), 4096, 32, ) == 0x0 02238 2016 NtResumeThread (628, ... 02239 1028 NtProtectVirtualMemory (-1, (0x76fb1000), 4096, 32, ... 02238 2016 NtResumeThread ... 1, ) == 0x0 02239 1028 NtProtectVirtualMemory ... (0x76fb1000), 4096, 4, ) == 0x0 02240 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02241 1028 NtFlushInstructionCache (-1, 1996165120, 232, ... 02237 596 NtRequestWaitReplyPort ... {200, 224, reply, 0, 896, 596, 81917, 0} ... {200, 224, reply, 0, 896, 596, 81917, 0} "\7\0\0\0\274\0\0\0\0\0\0\03\242t\326)X\335I\220\360`\317\234\353q)\1\0\0\0\1\0\0\0\0\0\0\0\26\0\0\0\4\0\0\0\0\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0\362\3521W\377<\12\224R\215\243_HQ\240\14\12\0\0\0\365wWqU\264\277U\0\0\0\0\0*\25\0\360=\270\15R\322(\27(\0\0\0\33\14\0u\0\0\24\0\240\366\247\0\263\314\20\365\0\0\0\0XU\25\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\304\366\247\0\372\31\221|X\376\247\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 02242 644 NtWaitForSingleObject (88, 0, 0x0, ... 02241 1028 NtFlushInstructionCache ... ) == 0x0 02243 596 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... 02244 1028 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WLDAP32.dll"}, ... }, ... 02243 596 NtSetInformationThread ... ) == 0x0 02240 2016 NtAllocateVirtualMemory ... 74186752, 1048576, ) == 0x0 02245 596 NtRequestWaitReplyPort (624, {56, 80, new_msg, 0, 44, 3, 20, 0} (624, {56, 80, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\2\0gS\263F\252\227\2L\355h\28\1\0\0\0\0\0\0\0&\0(\0\314\1\0\0\0\0\0\0\0\0\0\0\23\0\0\0n\0t\0 \0a\0" ... ... 02246 2016 NtAllocateVirtualMemory (-1, 75227136, 0, 8192, 4096, 4, ... 75227136, 8192, ) == 0x0 02247 2016 NtProtectVirtualMemory (-1, (0x47be000), 4096, 260, ... (0x47be000), 4096, 4, ) == 0x0 02248 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02244 1028 NtOpenSection ... 640, ) == 0x0 02249 1028 NtMapViewOfSection (640, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f60000), 0x0, 180224, ) == 0x0 02250 1028 NtClose (640, ... ) == 0x0 02251 1028 NtProtectVirtualMemory (-1, (0x76f61000), 228, 4, ... (0x76f61000), 4096, 32, ) == 0x0 02248 2016 NtCreateThread ... 640, {896, 1736}, ) == 0x0 02252 2016 NtQueryInformationThread (640, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7c000,Pid=896,Tid=1736,}, 0x0, ) == 0x0 02253 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81916, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81916, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\200\3\0\0\310\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\200\3\0\0\310\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81919, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81916, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\200\3\0\0\310\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\2\0\0\200\3\0\0\310\6\0\0" ) ) == 0x0 02254 2016 NtResumeThread (640, ... 1, ) == 0x0 02255 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 75235328, 1048576, ) == 0x0 02256 2016 NtAllocateVirtualMemory (-1, 76275712, 0, 8192, 4096, 4, ... 76275712, 8192, ) == 0x0 02257 1736 NtWaitForSingleObject (88, 0, 0x0, ... 02258 2016 NtProtectVirtualMemory (-1, (0x48be000), 4096, 260, ... (0x48be000), 4096, 4, ) == 0x0 02259 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 632, {896, 320}, ) == 0x0 02260 2016 NtQueryInformationThread (632, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7b000,Pid=896,Tid=320,}, 0x0, ) == 0x0 02261 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81919, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\200\3\0\0@\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\200\3\0\0@\1\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81920, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\200\3\0\0@\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\2\0\0\200\3\0\0@\1\0\0" ) ) == 0x0 02262 2016 NtResumeThread (632, ... 1, ) == 0x0 02263 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02264 320 NtWaitForSingleObject (88, 0, 0x0, ... 02263 2016 NtAllocateVirtualMemory ... 76283904, 1048576, ) == 0x0 02265 2016 NtAllocateVirtualMemory (-1, 77324288, 0, 8192, 4096, 4, ... 77324288, 8192, ) == 0x0 02266 2016 NtProtectVirtualMemory (-1, (0x49be000), 4096, 260, ... (0x49be000), 4096, 4, ) == 0x0 02267 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 644, {896, 380}, ) == 0x0 02268 2016 NtQueryInformationThread (644, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff7a000,Pid=896,Tid=380,}, 0x0, ) == 0x0 02269 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81920, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\200\3\0\0|\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\200\3\0\0|\1\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81921, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\200\3\0\0|\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\2\0\0\200\3\0\0|\1\0\0" ) ) == 0x0 02270 2016 NtResumeThread (644, ... 1, ) == 0x0 02271 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 77332480, 1048576, ) == 0x0 02272 2016 NtAllocateVirtualMemory (-1, 78372864, 0, 8192, 4096, 4, ... 78372864, 8192, ) == 0x0 02273 380 NtWaitForSingleObject (88, 0, 0x0, ... 02274 2016 NtProtectVirtualMemory (-1, (0x4abe000), 4096, 260, ... (0x4abe000), 4096, 4, ) == 0x0 02275 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 648, {896, 1332}, ) == 0x0 02276 2016 NtQueryInformationThread (648, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff79000,Pid=896,Tid=1332,}, 0x0, ) == 0x0 02277 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81921, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\200\3\0\04\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\200\3\0\04\5\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81922, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\200\3\0\04\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\2\0\0\200\3\0\04\5\0\0" ) ) == 0x0 02278 2016 NtResumeThread (648, ... 1, ) == 0x0 02279 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02280 1332 NtWaitForSingleObject (88, 0, 0x0, ... 02279 2016 NtAllocateVirtualMemory ... 78381056, 1048576, ) == 0x0 02281 2016 NtAllocateVirtualMemory (-1, 79421440, 0, 8192, 4096, 4, ... 79421440, 8192, ) == 0x0 02282 2016 NtProtectVirtualMemory (-1, (0x4bbe000), 4096, 260, ... (0x4bbe000), 4096, 4, ) == 0x0 02283 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 652, {896, 1336}, ) == 0x0 02284 2016 NtQueryInformationThread (652, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff78000,Pid=896,Tid=1336,}, 0x0, ) == 0x0 02285 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81922, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\200\3\0\08\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\200\3\0\08\5\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81923, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\200\3\0\08\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\2\0\0\200\3\0\08\5\0\0" ) ) == 0x0 02286 2016 NtResumeThread (652, ... 1, ) == 0x0 02287 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 79429632, 1048576, ) == 0x0 02288 2016 NtAllocateVirtualMemory (-1, 80470016, 0, 8192, 4096, 4, ... 80470016, 8192, ) == 0x0 02289 1336 NtWaitForSingleObject (88, 0, 0x0, ... 02290 2016 NtProtectVirtualMemory (-1, (0x4cbe000), 4096, 260, ... (0x4cbe000), 4096, 4, ) == 0x0 02291 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 656, {896, 1808}, ) == 0x0 02292 2016 NtQueryInformationThread (656, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff77000,Pid=896,Tid=1808,}, 0x0, ) == 0x0 02293 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81923, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\200\3\0\0\20\7\0\0" ... {28, 56, reply, 0, 896, 2016, 81924, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\200\3\0\0\20\7\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81924, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81923, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\200\3\0\0\20\7\0\0" ... {28, 56, reply, 0, 896, 2016, 81924, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\2\0\0\200\3\0\0\20\7\0\0" ) ) == 0x0 02294 2016 NtResumeThread (656, ... 1, ) == 0x0 02295 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02296 1808 NtWaitForSingleObject (88, 0, 0x0, ... 02295 2016 NtAllocateVirtualMemory ... 80478208, 1048576, ) == 0x0 02297 2016 NtAllocateVirtualMemory (-1, 81518592, 0, 8192, 4096, 4, ... 81518592, 8192, ) == 0x0 02298 2016 NtProtectVirtualMemory (-1, (0x4dbe000), 4096, 260, ... (0x4dbe000), 4096, 4, ) == 0x0 02299 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 660, {896, 468}, ) == 0x0 02300 2016 NtQueryInformationThread (660, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff76000,Pid=896,Tid=468,}, 0x0, ) == 0x0 02301 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81924, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81924, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\200\3\0\0\324\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81925, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\200\3\0\0\324\1\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81925, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81924, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\200\3\0\0\324\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81925, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\2\0\0\200\3\0\0\324\1\0\0" ) ) == 0x0 02302 2016 NtResumeThread (660, ... 1, ) == 0x0 02303 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 81526784, 1048576, ) == 0x0 02304 2016 NtAllocateVirtualMemory (-1, 82567168, 0, 8192, 4096, 4, ... 82567168, 8192, ) == 0x0 02305 468 NtWaitForSingleObject (88, 0, 0x0, ... 02306 2016 NtProtectVirtualMemory (-1, (0x4ebe000), 4096, 260, ... (0x4ebe000), 4096, 4, ) == 0x0 02307 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 664, {896, 752}, ) == 0x0 02308 2016 NtQueryInformationThread (664, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff75000,Pid=896,Tid=752,}, 0x0, ) == 0x0 02309 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81925, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81925, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\200\3\0\0\360\2\0\0" ... {28, 56, reply, 0, 896, 2016, 81926, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\200\3\0\0\360\2\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81926, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81925, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\200\3\0\0\360\2\0\0" ... {28, 56, reply, 0, 896, 2016, 81926, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\2\0\0\200\3\0\0\360\2\0\0" ) ) == 0x0 02310 2016 NtResumeThread (664, ... 1, ) == 0x0 02311 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02312 752 NtWaitForSingleObject (88, 0, 0x0, ... 02311 2016 NtAllocateVirtualMemory ... 82575360, 1048576, ) == 0x0 02313 2016 NtAllocateVirtualMemory (-1, 83615744, 0, 8192, 4096, 4, ... 83615744, 8192, ) == 0x0 02314 2016 NtProtectVirtualMemory (-1, (0x4fbe000), 4096, 260, ... (0x4fbe000), 4096, 4, ) == 0x0 02315 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 668, {896, 1512}, ) == 0x0 02316 2016 NtQueryInformationThread (668, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff74000,Pid=896,Tid=1512,}, 0x0, ) == 0x0 02317 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81926, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81926, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\200\3\0\0\350\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\200\3\0\0\350\5\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81927, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81926, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\200\3\0\0\350\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\2\0\0\200\3\0\0\350\5\0\0" ) ) == 0x0 02318 2016 NtResumeThread (668, ... 1, ) == 0x0 02319 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 83623936, 1048576, ) == 0x0 02320 2016 NtAllocateVirtualMemory (-1, 84664320, 0, 8192, 4096, 4, ... 84664320, 8192, ) == 0x0 02321 1512 NtWaitForSingleObject (88, 0, 0x0, ... 02322 2016 NtProtectVirtualMemory (-1, (0x50be000), 4096, 260, ... (0x50be000), 4096, 4, ) == 0x0 02323 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 672, {896, 1380}, ) == 0x0 02324 2016 NtQueryInformationThread (672, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff73000,Pid=896,Tid=1380,}, 0x0, ) == 0x0 02325 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81927, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\200\3\0\0d\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81928, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\200\3\0\0d\5\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81928, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81927, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\200\3\0\0d\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81928, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\2\0\0\200\3\0\0d\5\0\0" ) ) == 0x0 02326 2016 NtResumeThread (672, ... 1, ) == 0x0 02327 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 84672512, 1048576, ) == 0x0 02328 2016 NtAllocateVirtualMemory (-1, 85712896, 0, 8192, 4096, 4, ... 85712896, 8192, ) == 0x0 02329 1380 NtWaitForSingleObject (88, 0, 0x0, ... 02330 2016 NtProtectVirtualMemory (-1, (0x51be000), 4096, 260, ... (0x51be000), 4096, 4, ) == 0x0 02331 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 676, {896, 1564}, ) == 0x0 02332 2016 NtQueryInformationThread (676, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff72000,Pid=896,Tid=1564,}, 0x0, ) == 0x0 02333 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81928, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81928, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\200\3\0\0\34\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\200\3\0\0\34\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81929, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81928, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\200\3\0\0\34\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\2\0\0\200\3\0\0\34\6\0\0" ) ) == 0x0 02334 2016 NtResumeThread (676, ... 1, ) == 0x0 02335 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02336 1564 NtWaitForSingleObject (88, 0, 0x0, ... 02335 2016 NtAllocateVirtualMemory ... 85721088, 1048576, ) == 0x0 02337 2016 NtAllocateVirtualMemory (-1, 86761472, 0, 8192, 4096, 4, ... 86761472, 8192, ) == 0x0 02338 2016 NtProtectVirtualMemory (-1, (0x52be000), 4096, 260, ... (0x52be000), 4096, 4, ) == 0x0 02339 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 680, {896, 164}, ) == 0x0 02340 2016 NtQueryInformationThread (680, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff71000,Pid=896,Tid=164,}, 0x0, ) == 0x0 02341 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81929, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\200\3\0\0\244\0\0\0" ... {28, 56, reply, 0, 896, 2016, 81930, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\200\3\0\0\244\0\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81930, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81929, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\200\3\0\0\244\0\0\0" ... {28, 56, reply, 0, 896, 2016, 81930, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\2\0\0\200\3\0\0\244\0\0\0" ) ) == 0x0 02342 2016 NtResumeThread (680, ... 1, ) == 0x0 02343 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 86769664, 1048576, ) == 0x0 02344 2016 NtAllocateVirtualMemory (-1, 87810048, 0, 8192, 4096, 4, ... 87810048, 8192, ) == 0x0 02345 164 NtWaitForSingleObject (88, 0, 0x0, ... 02346 2016 NtProtectVirtualMemory (-1, (0x53be000), 4096, 260, ... (0x53be000), 4096, 4, ) == 0x0 02347 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 684, {896, 312}, ) == 0x0 02348 2016 NtQueryInformationThread (684, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff70000,Pid=896,Tid=312,}, 0x0, ) == 0x0 02349 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81930, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81930, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\200\3\0\08\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81931, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\200\3\0\08\1\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81931, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81930, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\200\3\0\08\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81931, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\2\0\0\200\3\0\08\1\0\0" ) ) == 0x0 02350 2016 NtResumeThread (684, ... 1, ) == 0x0 02351 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02352 312 NtWaitForSingleObject (88, 0, 0x0, ... 02351 2016 NtAllocateVirtualMemory ... 87818240, 1048576, ) == 0x0 02353 2016 NtAllocateVirtualMemory (-1, 88858624, 0, 8192, 4096, 4, ... 88858624, 8192, ) == 0x0 02354 2016 NtProtectVirtualMemory (-1, (0x54be000), 4096, 260, ... (0x54be000), 4096, 4, ) == 0x0 02355 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 688, {896, 1964}, ) == 0x0 02356 2016 NtQueryInformationThread (688, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6f000,Pid=896,Tid=1964,}, 0x0, ) == 0x0 02357 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81931, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81931, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\200\3\0\0\254\7\0\0" ... {28, 56, reply, 0, 896, 2016, 81932, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\200\3\0\0\254\7\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81932, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81931, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\200\3\0\0\254\7\0\0" ... {28, 56, reply, 0, 896, 2016, 81932, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\2\0\0\200\3\0\0\254\7\0\0" ) ) == 0x0 02358 2016 NtResumeThread (688, ... 1, ) == 0x0 02359 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 88866816, 1048576, ) == 0x0 02360 2016 NtAllocateVirtualMemory (-1, 89907200, 0, 8192, 4096, 4, ... 89907200, 8192, ) == 0x0 02361 1964 NtWaitForSingleObject (88, 0, 0x0, ... 02362 2016 NtProtectVirtualMemory (-1, (0x55be000), 4096, 260, ... (0x55be000), 4096, 4, ) == 0x0 02363 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 692, {896, 1568}, ) == 0x0 02364 2016 NtQueryInformationThread (692, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6e000,Pid=896,Tid=1568,}, 0x0, ) == 0x0 02365 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81932, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81932, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\200\3\0\0 \6\0\0" ... {28, 56, reply, 0, 896, 2016, 81933, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\200\3\0\0 \6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81933, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81932, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\200\3\0\0 \6\0\0" ... {28, 56, reply, 0, 896, 2016, 81933, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\2\0\0\200\3\0\0 \6\0\0" ) ) == 0x0 02366 2016 NtResumeThread (692, ... 1, ) == 0x0 02367 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02368 1568 NtWaitForSingleObject (88, 0, 0x0, ... 02367 2016 NtAllocateVirtualMemory ... 89915392, 1048576, ) == 0x0 02369 2016 NtAllocateVirtualMemory (-1, 90955776, 0, 8192, 4096, 4, ... 90955776, 8192, ) == 0x0 02370 2016 NtProtectVirtualMemory (-1, (0x56be000), 4096, 260, ... (0x56be000), 4096, 4, ) == 0x0 02371 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 696, {896, 1624}, ) == 0x0 02372 2016 NtQueryInformationThread (696, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6d000,Pid=896,Tid=1624,}, 0x0, ) == 0x0 02373 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81933, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81933, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\200\3\0\0X\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\200\3\0\0X\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81934, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81933, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\200\3\0\0X\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\2\0\0\200\3\0\0X\6\0\0" ) ) == 0x0 02374 2016 NtResumeThread (696, ... 1, ) == 0x0 02375 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 90963968, 1048576, ) == 0x0 02376 2016 NtAllocateVirtualMemory (-1, 92004352, 0, 8192, 4096, 4, ... 92004352, 8192, ) == 0x0 02377 1624 NtWaitForSingleObject (88, 0, 0x0, ... 02378 2016 NtProtectVirtualMemory (-1, (0x57be000), 4096, 260, ... (0x57be000), 4096, 4, ) == 0x0 02379 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 700, {896, 1716}, ) == 0x0 02380 2016 NtQueryInformationThread (700, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6c000,Pid=896,Tid=1716,}, 0x0, ) == 0x0 02381 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81934, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\200\3\0\0\264\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\200\3\0\0\264\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81935, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81934, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\200\3\0\0\264\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\2\0\0\200\3\0\0\264\6\0\0" ) ) == 0x0 02382 2016 NtResumeThread (700, ... 1, ) == 0x0 02383 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02384 1716 NtWaitForSingleObject (88, 0, 0x0, ... 02383 2016 NtAllocateVirtualMemory ... 92012544, 1048576, ) == 0x0 02385 2016 NtAllocateVirtualMemory (-1, 93052928, 0, 8192, 4096, 4, ... 93052928, 8192, ) == 0x0 02386 2016 NtProtectVirtualMemory (-1, (0x58be000), 4096, 260, ... (0x58be000), 4096, 4, ) == 0x0 02387 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 704, {896, 1440}, ) == 0x0 02388 2016 NtQueryInformationThread (704, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6b000,Pid=896,Tid=1440,}, 0x0, ) == 0x0 02389 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81935, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\200\3\0\0\240\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\200\3\0\0\240\5\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81936, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81935, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\200\3\0\0\240\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\2\0\0\200\3\0\0\240\5\0\0" ) ) == 0x0 02390 2016 NtResumeThread (704, ... 1, ) == 0x0 02391 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 93061120, 1048576, ) == 0x0 02392 2016 NtAllocateVirtualMemory (-1, 94101504, 0, 8192, 4096, 4, ... 94101504, 8192, ) == 0x0 02393 1440 NtWaitForSingleObject (88, 0, 0x0, ... 02394 2016 NtProtectVirtualMemory (-1, (0x59be000), 4096, 260, ... (0x59be000), 4096, 4, ) == 0x0 02395 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 708, {896, 1664}, ) == 0x0 02396 2016 NtQueryInformationThread (708, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff6a000,Pid=896,Tid=1664,}, 0x0, ) == 0x0 02397 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81936, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\200\3\0\0\200\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\200\3\0\0\200\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81937, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81936, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\200\3\0\0\200\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\2\0\0\200\3\0\0\200\6\0\0" ) ) == 0x0 02398 2016 NtResumeThread (708, ... 1, ) == 0x0 02399 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02400 1664 NtWaitForSingleObject (88, 0, 0x0, ... 02399 2016 NtAllocateVirtualMemory ... 94109696, 1048576, ) == 0x0 02401 2016 NtAllocateVirtualMemory (-1, 95150080, 0, 8192, 4096, 4, ... 95150080, 8192, ) == 0x0 02402 2016 NtProtectVirtualMemory (-1, (0x5abe000), 4096, 260, ... (0x5abe000), 4096, 4, ) == 0x0 02403 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 712, {896, 1972}, ) == 0x0 02404 2016 NtQueryInformationThread (712, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff69000,Pid=896,Tid=1972,}, 0x0, ) == 0x0 02405 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81937, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\200\3\0\0\264\7\0\0" ... {28, 56, reply, 0, 896, 2016, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\200\3\0\0\264\7\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81938, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81937, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\200\3\0\0\264\7\0\0" ... {28, 56, reply, 0, 896, 2016, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\2\0\0\200\3\0\0\264\7\0\0" ) ) == 0x0 02406 2016 NtResumeThread (712, ... 1, ) == 0x0 02407 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 95158272, 1048576, ) == 0x0 02408 2016 NtAllocateVirtualMemory (-1, 96198656, 0, 8192, 4096, 4, ... 96198656, 8192, ) == 0x0 02409 1972 NtWaitForSingleObject (88, 0, 0x0, ... 02410 2016 NtProtectVirtualMemory (-1, (0x5bbe000), 4096, 260, ... (0x5bbe000), 4096, 4, ) == 0x0 02411 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 716, {896, 1036}, ) == 0x0 02412 2016 NtQueryInformationThread (716, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff68000,Pid=896,Tid=1036,}, 0x0, ) == 0x0 02413 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81938, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\200\3\0\0\14\4\0\0" ... {28, 56, reply, 0, 896, 2016, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\200\3\0\0\14\4\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81939, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81938, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\200\3\0\0\14\4\0\0" ... {28, 56, reply, 0, 896, 2016, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\2\0\0\200\3\0\0\14\4\0\0" ) ) == 0x0 02414 2016 NtResumeThread (716, ... 1, ) == 0x0 02415 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02416 1036 NtWaitForSingleObject (88, 0, 0x0, ... 02415 2016 NtAllocateVirtualMemory ... 96206848, 1048576, ) == 0x0 02417 2016 NtAllocateVirtualMemory (-1, 97247232, 0, 8192, 4096, 4, ... 97247232, 8192, ) == 0x0 02418 2016 NtProtectVirtualMemory (-1, (0x5cbe000), 4096, 260, ... (0x5cbe000), 4096, 4, ) == 0x0 02419 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 720, {896, 1248}, ) == 0x0 02420 2016 NtQueryInformationThread (720, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff67000,Pid=896,Tid=1248,}, 0x0, ) == 0x0 02421 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81939, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\200\3\0\0\340\4\0\0" ... {28, 56, reply, 0, 896, 2016, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\200\3\0\0\340\4\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81940, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81939, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\200\3\0\0\340\4\0\0" ... {28, 56, reply, 0, 896, 2016, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\2\0\0\200\3\0\0\340\4\0\0" ) ) == 0x0 02422 2016 NtResumeThread (720, ... 1, ) == 0x0 02423 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 97255424, 1048576, ) == 0x0 02424 2016 NtAllocateVirtualMemory (-1, 98295808, 0, 8192, 4096, 4, ... 98295808, 8192, ) == 0x0 02425 1248 NtWaitForSingleObject (88, 0, 0x0, ... 02426 2016 NtProtectVirtualMemory (-1, (0x5dbe000), 4096, 260, ... (0x5dbe000), 4096, 4, ) == 0x0 02427 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 724, {896, 1656}, ) == 0x0 02428 2016 NtQueryInformationThread (724, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff66000,Pid=896,Tid=1656,}, 0x0, ) == 0x0 02429 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81940, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\200\3\0\0x\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\200\3\0\0x\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81941, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81940, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\200\3\0\0x\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\2\0\0\200\3\0\0x\6\0\0" ) ) == 0x0 02430 2016 NtResumeThread (724, ... 1, ) == 0x0 02431 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02432 1656 NtWaitForSingleObject (88, 0, 0x0, ... 02431 2016 NtAllocateVirtualMemory ... 98304000, 1048576, ) == 0x0 02433 2016 NtAllocateVirtualMemory (-1, 99344384, 0, 8192, 4096, 4, ... 99344384, 8192, ) == 0x0 02434 2016 NtProtectVirtualMemory (-1, (0x5ebe000), 4096, 260, ... (0x5ebe000), 4096, 4, ) == 0x0 02435 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 728, {896, 760}, ) == 0x0 02436 2016 NtQueryInformationThread (728, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff65000,Pid=896,Tid=760,}, 0x0, ) == 0x0 02437 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81941, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\200\3\0\0\370\2\0\0" ... {28, 56, reply, 0, 896, 2016, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\200\3\0\0\370\2\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81942, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81941, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\200\3\0\0\370\2\0\0" ... {28, 56, reply, 0, 896, 2016, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\2\0\0\200\3\0\0\370\2\0\0" ) ) == 0x0 02438 2016 NtResumeThread (728, ... 1, ) == 0x0 02439 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 99352576, 1048576, ) == 0x0 02440 2016 NtAllocateVirtualMemory (-1, 100392960, 0, 8192, 4096, 4, ... 100392960, 8192, ) == 0x0 02441 760 NtWaitForSingleObject (88, 0, 0x0, ... 02442 2016 NtProtectVirtualMemory (-1, (0x5fbe000), 4096, 260, ... (0x5fbe000), 4096, 4, ) == 0x0 02443 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 732, {896, 484}, ) == 0x0 02444 2016 NtQueryInformationThread (732, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff64000,Pid=896,Tid=484,}, 0x0, ) == 0x0 02445 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81942, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\200\3\0\0\344\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\200\3\0\0\344\1\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81943, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81942, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\200\3\0\0\344\1\0\0" ... {28, 56, reply, 0, 896, 2016, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\2\0\0\200\3\0\0\344\1\0\0" ) ) == 0x0 02446 2016 NtResumeThread (732, ... 1, ) == 0x0 02447 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02448 484 NtWaitForSingleObject (88, 0, 0x0, ... 02447 2016 NtAllocateVirtualMemory ... 100401152, 1048576, ) == 0x0 02449 2016 NtAllocateVirtualMemory (-1, 101441536, 0, 8192, 4096, 4, ... 101441536, 8192, ) == 0x0 02450 2016 NtProtectVirtualMemory (-1, (0x60be000), 4096, 260, ... (0x60be000), 4096, 4, ) == 0x0 02451 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 736, {896, 1580}, ) == 0x0 02452 2016 NtQueryInformationThread (736, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff63000,Pid=896,Tid=1580,}, 0x0, ) == 0x0 02453 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81943, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\200\3\0\0,\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\200\3\0\0,\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81944, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81943, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\200\3\0\0,\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\2\0\0\200\3\0\0,\6\0\0" ) ) == 0x0 02454 2016 NtResumeThread (736, ... 1, ) == 0x0 02455 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 101449728, 1048576, ) == 0x0 02456 2016 NtAllocateVirtualMemory (-1, 102490112, 0, 8192, 4096, 4, ... 102490112, 8192, ) == 0x0 02457 1580 NtWaitForSingleObject (88, 0, 0x0, ... 02458 2016 NtProtectVirtualMemory (-1, (0x61be000), 4096, 260, ... (0x61be000), 4096, 4, ) == 0x0 02459 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 740, {896, 1756}, ) == 0x0 02460 2016 NtQueryInformationThread (740, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff62000,Pid=896,Tid=1756,}, 0x0, ) == 0x0 02461 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81944, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\200\3\0\0\334\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\200\3\0\0\334\6\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81945, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81944, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\200\3\0\0\334\6\0\0" ... {28, 56, reply, 0, 896, 2016, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\2\0\0\200\3\0\0\334\6\0\0" ) ) == 0x0 02462 2016 NtResumeThread (740, ... 1, ) == 0x0 02463 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02464 1756 NtWaitForSingleObject (88, 0, 0x0, ... 02463 2016 NtAllocateVirtualMemory ... 102498304, 1048576, ) == 0x0 02465 2016 NtAllocateVirtualMemory (-1, 103538688, 0, 8192, 4096, 4, ... 103538688, 8192, ) == 0x0 02466 2016 NtProtectVirtualMemory (-1, (0x62be000), 4096, 260, ... (0x62be000), 4096, 4, ) == 0x0 02467 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 744, {896, 1304}, ) == 0x0 02468 2016 NtQueryInformationThread (744, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff61000,Pid=896,Tid=1304,}, 0x0, ) == 0x0 02469 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81945, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\200\3\0\0\30\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\200\3\0\0\30\5\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81946, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81945, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\200\3\0\0\30\5\0\0" ... {28, 56, reply, 0, 896, 2016, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\2\0\0\200\3\0\0\30\5\0\0" ) ) == 0x0 02470 2016 NtResumeThread (744, ... 1, ) == 0x0 02471 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 103546880, 1048576, ) == 0x0 02472 2016 NtAllocateVirtualMemory (-1, 104587264, 0, 8192, 4096, 4, ... 104587264, 8192, ) == 0x0 02473 1304 NtWaitForSingleObject (88, 0, 0x0, ... 02474 2016 NtProtectVirtualMemory (-1, (0x63be000), 4096, 260, ... (0x63be000), 4096, 4, ) == 0x0 02475 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 748, {896, 2052}, ) == 0x0 02476 2016 NtQueryInformationThread (748, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff60000,Pid=896,Tid=2052,}, 0x0, ) == 0x0 02477 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81946, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\200\3\0\0\4\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\200\3\0\0\4\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81947, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81946, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\200\3\0\0\4\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\2\0\0\200\3\0\0\4\10\0\0" ) ) == 0x0 02478 2016 NtResumeThread (748, ... 1, ) == 0x0 02479 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 104595456, 1048576, ) == 0x0 02480 2016 NtAllocateVirtualMemory (-1, 105635840, 0, 8192, 4096, 4, ... 105635840, 8192, ) == 0x0 02481 2052 NtWaitForSingleObject (88, 0, 0x0, ... 02482 2016 NtProtectVirtualMemory (-1, (0x64be000), 4096, 260, ... (0x64be000), 4096, 4, ) == 0x0 02483 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 752, {896, 2056}, ) == 0x0 02484 2016 NtQueryInformationThread (752, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5f000,Pid=896,Tid=2056,}, 0x0, ) == 0x0 02485 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81947, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\200\3\0\0\10\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\200\3\0\0\10\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81948, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81947, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\200\3\0\0\10\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\2\0\0\200\3\0\0\10\10\0\0" ) ) == 0x0 02486 2016 NtResumeThread (752, ... 1, ) == 0x0 02487 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02488 2056 NtWaitForSingleObject (88, 0, 0x0, ... 02487 2016 NtAllocateVirtualMemory ... 105644032, 1048576, ) == 0x0 02489 2016 NtAllocateVirtualMemory (-1, 106684416, 0, 8192, 4096, 4, ... 106684416, 8192, ) == 0x0 02490 2016 NtProtectVirtualMemory (-1, (0x65be000), 4096, 260, ... (0x65be000), 4096, 4, ) == 0x0 02491 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 756, {896, 2060}, ) == 0x0 02492 2016 NtQueryInformationThread (756, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5e000,Pid=896,Tid=2060,}, 0x0, ) == 0x0 02493 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81948, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\200\3\0\0\14\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\200\3\0\0\14\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81949, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81948, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\200\3\0\0\14\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\2\0\0\200\3\0\0\14\10\0\0" ) ) == 0x0 02494 2016 NtResumeThread (756, ... 1, ) == 0x0 02495 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 106692608, 1048576, ) == 0x0 02496 2016 NtAllocateVirtualMemory (-1, 107732992, 0, 8192, 4096, 4, ... 107732992, 8192, ) == 0x0 02497 2060 NtWaitForSingleObject (88, 0, 0x0, ... 02498 2016 NtProtectVirtualMemory (-1, (0x66be000), 4096, 260, ... (0x66be000), 4096, 4, ) == 0x0 02499 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 760, {896, 2064}, ) == 0x0 02500 2016 NtQueryInformationThread (760, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5d000,Pid=896,Tid=2064,}, 0x0, ) == 0x0 02501 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81949, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\200\3\0\0\20\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\200\3\0\0\20\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81950, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81949, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\200\3\0\0\20\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\2\0\0\200\3\0\0\20\10\0\0" ) ) == 0x0 02502 2016 NtResumeThread (760, ... 1, ) == 0x0 02503 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02504 2064 NtWaitForSingleObject (88, 0, 0x0, ... 02503 2016 NtAllocateVirtualMemory ... 107741184, 1048576, ) == 0x0 02505 2016 NtAllocateVirtualMemory (-1, 108781568, 0, 8192, 4096, 4, ... 108781568, 8192, ) == 0x0 02506 2016 NtProtectVirtualMemory (-1, (0x67be000), 4096, 260, ... (0x67be000), 4096, 4, ) == 0x0 02507 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 764, {896, 2068}, ) == 0x0 02508 2016 NtQueryInformationThread (764, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5c000,Pid=896,Tid=2068,}, 0x0, ) == 0x0 02509 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81950, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\200\3\0\0\24\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\200\3\0\0\24\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81951, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81950, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\200\3\0\0\24\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\2\0\0\200\3\0\0\24\10\0\0" ) ) == 0x0 02510 2016 NtResumeThread (764, ... 1, ) == 0x0 02511 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 108789760, 1048576, ) == 0x0 02512 2016 NtAllocateVirtualMemory (-1, 109830144, 0, 8192, 4096, 4, ... 109830144, 8192, ) == 0x0 02513 2068 NtWaitForSingleObject (88, 0, 0x0, ... 02514 2016 NtProtectVirtualMemory (-1, (0x68be000), 4096, 260, ... (0x68be000), 4096, 4, ) == 0x0 02515 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 768, {896, 2072}, ) == 0x0 02516 2016 NtQueryInformationThread (768, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5b000,Pid=896,Tid=2072,}, 0x0, ) == 0x0 02517 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81951, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\200\3\0\0\30\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\200\3\0\0\30\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81952, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81951, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\200\3\0\0\30\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\3\0\0\200\3\0\0\30\10\0\0" ) ) == 0x0 02518 2016 NtResumeThread (768, ... 1, ) == 0x0 02519 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02520 2072 NtWaitForSingleObject (88, 0, 0x0, ... 02519 2016 NtAllocateVirtualMemory ... 109838336, 1048576, ) == 0x0 02521 2016 NtAllocateVirtualMemory (-1, 110878720, 0, 8192, 4096, 4, ... 110878720, 8192, ) == 0x0 02522 2016 NtProtectVirtualMemory (-1, (0x69be000), 4096, 260, ... (0x69be000), 4096, 4, ) == 0x0 02523 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 772, {896, 2076}, ) == 0x0 02524 2016 NtQueryInformationThread (772, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff5a000,Pid=896,Tid=2076,}, 0x0, ) == 0x0 02525 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81952, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\200\3\0\0\34\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\200\3\0\0\34\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81953, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81952, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\200\3\0\0\34\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\3\0\0\200\3\0\0\34\10\0\0" ) ) == 0x0 02526 2016 NtResumeThread (772, ... 1, ) == 0x0 02527 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 110886912, 1048576, ) == 0x0 02528 2016 NtAllocateVirtualMemory (-1, 111927296, 0, 8192, 4096, 4, ... 111927296, 8192, ) == 0x0 02529 2076 NtWaitForSingleObject (88, 0, 0x0, ... 02530 2016 NtProtectVirtualMemory (-1, (0x6abe000), 4096, 260, ... (0x6abe000), 4096, 4, ) == 0x0 02531 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 776, {896, 2080}, ) == 0x0 02532 2016 NtQueryInformationThread (776, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff59000,Pid=896,Tid=2080,}, 0x0, ) == 0x0 02533 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81953, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\3\0\0\200\3\0\0 \10\0\0" ... {28, 56, reply, 0, 896, 2016, 81954, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\3\0\0\200\3\0\0 \10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81954, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81953, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\3\0\0\200\3\0\0 \10\0\0" ... {28, 56, reply, 0, 896, 2016, 81954, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\3\0\0\200\3\0\0 \10\0\0" ) ) == 0x0 02534 2016 NtResumeThread (776, ... 1, ) == 0x0 02535 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02536 2080 NtWaitForSingleObject (88, 0, 0x0, ... 02535 2016 NtAllocateVirtualMemory ... 111935488, 1048576, ) == 0x0 02537 2016 NtAllocateVirtualMemory (-1, 112975872, 0, 8192, 4096, 4, ... 112975872, 8192, ) == 0x0 02538 2016 NtProtectVirtualMemory (-1, (0x6bbe000), 4096, 260, ... (0x6bbe000), 4096, 4, ) == 0x0 02539 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 780, {896, 2084}, ) == 0x0 02540 2016 NtQueryInformationThread (780, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff58000,Pid=896,Tid=2084,}, 0x0, ) == 0x0 02541 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81954, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81954, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\3\0\0\200\3\0\0$\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81955, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\3\0\0\200\3\0\0$\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81955, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81954, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\3\0\0\200\3\0\0$\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81955, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\3\0\0\200\3\0\0$\10\0\0" ) ) == 0x0 02542 2016 NtResumeThread (780, ... 1, ) == 0x0 02543 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 112984064, 1048576, ) == 0x0 02544 2016 NtAllocateVirtualMemory (-1, 114024448, 0, 8192, 4096, 4, ... 114024448, 8192, ) == 0x0 02545 2084 NtWaitForSingleObject (88, 0, 0x0, ... 02546 2016 NtProtectVirtualMemory (-1, (0x6cbe000), 4096, 260, ... (0x6cbe000), 4096, 4, ) == 0x0 02547 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 784, {896, 2088}, ) == 0x0 02548 2016 NtQueryInformationThread (784, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff57000,Pid=896,Tid=2088,}, 0x0, ) == 0x0 02549 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81955, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81955, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\200\3\0\0(\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\200\3\0\0(\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81956, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81955, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\200\3\0\0(\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\3\0\0\200\3\0\0(\10\0\0" ) ) == 0x0 02550 2016 NtResumeThread (784, ... 1, ) == 0x0 02551 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02552 2088 NtWaitForSingleObject (88, 0, 0x0, ... 02551 2016 NtAllocateVirtualMemory ... 114032640, 1048576, ) == 0x0 02553 2016 NtAllocateVirtualMemory (-1, 115073024, 0, 8192, 4096, 4, ... 115073024, 8192, ) == 0x0 02554 2016 NtProtectVirtualMemory (-1, (0x6dbe000), 4096, 260, ... (0x6dbe000), 4096, 4, ) == 0x0 02555 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 788, {896, 2092}, ) == 0x0 02556 2016 NtQueryInformationThread (788, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff56000,Pid=896,Tid=2092,}, 0x0, ) == 0x0 02557 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81956, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\200\3\0\0,\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81957, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\200\3\0\0,\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81957, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81956, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\200\3\0\0,\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81957, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\3\0\0\200\3\0\0,\10\0\0" ) ) == 0x0 02558 2016 NtResumeThread (788, ... 1, ) == 0x0 02559 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 115081216, 1048576, ) == 0x0 02560 2016 NtAllocateVirtualMemory (-1, 116121600, 0, 8192, 4096, 4, ... 116121600, 8192, ) == 0x0 02561 2092 NtWaitForSingleObject (88, 0, 0x0, ... 02562 2016 NtProtectVirtualMemory (-1, (0x6ebe000), 4096, 260, ... (0x6ebe000), 4096, 4, ) == 0x0 02563 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 792, {896, 2096}, ) == 0x0 02564 2016 NtQueryInformationThread (792, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff55000,Pid=896,Tid=2096,}, 0x0, ) == 0x0 02565 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81957, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81957, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\200\3\0\00\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\200\3\0\00\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81958, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81957, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\200\3\0\00\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\3\0\0\200\3\0\00\10\0\0" ) ) == 0x0 02566 2016 NtResumeThread (792, ... 1, ) == 0x0 02567 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02568 2096 NtWaitForSingleObject (88, 0, 0x0, ... 02567 2016 NtAllocateVirtualMemory ... 116129792, 1048576, ) == 0x0 02569 2016 NtAllocateVirtualMemory (-1, 117170176, 0, 8192, 4096, 4, ... 117170176, 8192, ) == 0x0 02570 2016 NtProtectVirtualMemory (-1, (0x6fbe000), 4096, 260, ... (0x6fbe000), 4096, 4, ) == 0x0 02571 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 796, {896, 2100}, ) == 0x0 02572 2016 NtQueryInformationThread (796, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff54000,Pid=896,Tid=2100,}, 0x0, ) == 0x0 02573 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81958, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\3\0\0\200\3\0\04\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\3\0\0\200\3\0\04\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81959, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81958, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\3\0\0\200\3\0\04\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\3\0\0\200\3\0\04\10\0\0" ) ) == 0x0 02574 2016 NtResumeThread (796, ... 1, ) == 0x0 02575 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 117178368, 1048576, ) == 0x0 02576 2016 NtAllocateVirtualMemory (-1, 118218752, 0, 8192, 4096, 4, ... 118218752, 8192, ) == 0x0 02577 2100 NtWaitForSingleObject (88, 0, 0x0, ... 02578 2016 NtProtectVirtualMemory (-1, (0x70be000), 4096, 260, ... (0x70be000), 4096, 4, ) == 0x0 02579 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 800, {896, 2104}, ) == 0x0 02580 2016 NtQueryInformationThread (800, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff53000,Pid=896,Tid=2104,}, 0x0, ) == 0x0 02581 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81959, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \3\0\0\200\3\0\08\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \3\0\0\200\3\0\08\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81960, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81959, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \3\0\0\200\3\0\08\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \3\0\0\200\3\0\08\10\0\0" ) ) == 0x0 02582 2016 NtResumeThread (800, ... 1, ) == 0x0 02583 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02584 2104 NtWaitForSingleObject (88, 0, 0x0, ... 02583 2016 NtAllocateVirtualMemory ... 118226944, 1048576, ) == 0x0 02585 2016 NtAllocateVirtualMemory (-1, 119267328, 0, 8192, 4096, 4, ... 119267328, 8192, ) == 0x0 02586 2016 NtProtectVirtualMemory (-1, (0x71be000), 4096, 260, ... (0x71be000), 4096, 4, ) == 0x0 02587 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 804, {896, 2108}, ) == 0x0 02588 2016 NtQueryInformationThread (804, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff52000,Pid=896,Tid=2108,}, 0x0, ) == 0x0 02589 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81960, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\3\0\0\200\3\0\0<\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\3\0\0\200\3\0\0<\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81961, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81960, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\3\0\0\200\3\0\0<\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\3\0\0\200\3\0\0<\10\0\0" ) ) == 0x0 02590 2016 NtResumeThread (804, ... 1, ) == 0x0 02591 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 119275520, 1048576, ) == 0x0 02592 2016 NtAllocateVirtualMemory (-1, 120315904, 0, 8192, 4096, 4, ... 120315904, 8192, ) == 0x0 02593 2108 NtWaitForSingleObject (88, 0, 0x0, ... 02594 2016 NtProtectVirtualMemory (-1, (0x72be000), 4096, 260, ... (0x72be000), 4096, 4, ) == 0x0 02595 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 808, {896, 2112}, ) == 0x0 02596 2016 NtQueryInformationThread (808, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff51000,Pid=896,Tid=2112,}, 0x0, ) == 0x0 02597 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81961, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\3\0\0\200\3\0\0@\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\3\0\0\200\3\0\0@\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81962, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81961, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\3\0\0\200\3\0\0@\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\3\0\0\200\3\0\0@\10\0\0" ) ) == 0x0 02598 2016 NtResumeThread (808, ... 1, ) == 0x0 02599 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02600 2112 NtWaitForSingleObject (88, 0, 0x0, ... 02599 2016 NtAllocateVirtualMemory ... 120324096, 1048576, ) == 0x0 02601 2016 NtAllocateVirtualMemory (-1, 121364480, 0, 8192, 4096, 4, ... 121364480, 8192, ) == 0x0 02602 2016 NtProtectVirtualMemory (-1, (0x73be000), 4096, 260, ... (0x73be000), 4096, 4, ) == 0x0 02603 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 812, {896, 2116}, ) == 0x0 02604 2016 NtQueryInformationThread (812, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff50000,Pid=896,Tid=2116,}, 0x0, ) == 0x0 02605 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81962, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\3\0\0\200\3\0\0D\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\3\0\0\200\3\0\0D\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81963, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81962, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\3\0\0\200\3\0\0D\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\3\0\0\200\3\0\0D\10\0\0" ) ) == 0x0 02606 2016 NtResumeThread (812, ... 1, ) == 0x0 02607 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 121372672, 1048576, ) == 0x0 02608 2016 NtAllocateVirtualMemory (-1, 122413056, 0, 8192, 4096, 4, ... 122413056, 8192, ) == 0x0 02609 2116 NtWaitForSingleObject (88, 0, 0x0, ... 02610 2016 NtProtectVirtualMemory (-1, (0x74be000), 4096, 260, ... (0x74be000), 4096, 4, ) == 0x0 02611 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 816, {896, 2120}, ) == 0x0 02612 2016 NtQueryInformationThread (816, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4f000,Pid=896,Tid=2120,}, 0x0, ) == 0x0 02613 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81963, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\3\0\0\200\3\0\0H\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\3\0\0\200\3\0\0H\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81964, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81963, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\3\0\0\200\3\0\0H\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\3\0\0\200\3\0\0H\10\0\0" ) ) == 0x0 02614 2016 NtResumeThread (816, ... 1, ) == 0x0 02615 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02616 2120 NtWaitForSingleObject (88, 0, 0x0, ... 02615 2016 NtAllocateVirtualMemory ... 122421248, 1048576, ) == 0x0 02617 2016 NtAllocateVirtualMemory (-1, 123461632, 0, 8192, 4096, 4, ... 123461632, 8192, ) == 0x0 02618 2016 NtProtectVirtualMemory (-1, (0x75be000), 4096, 260, ... (0x75be000), 4096, 4, ) == 0x0 02619 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 820, {896, 2124}, ) == 0x0 02620 2016 NtQueryInformationThread (820, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4e000,Pid=896,Tid=2124,}, 0x0, ) == 0x0 02621 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81964, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\3\0\0\200\3\0\0L\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\3\0\0\200\3\0\0L\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81965, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81964, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\3\0\0\200\3\0\0L\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\3\0\0\200\3\0\0L\10\0\0" ) ) == 0x0 02622 2016 NtResumeThread (820, ... 1, ) == 0x0 02623 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 123469824, 1048576, ) == 0x0 02624 2016 NtAllocateVirtualMemory (-1, 124510208, 0, 8192, 4096, 4, ... 124510208, 8192, ) == 0x0 02625 2124 NtWaitForSingleObject (88, 0, 0x0, ... 02626 2016 NtProtectVirtualMemory (-1, (0x76be000), 4096, 260, ... (0x76be000), 4096, 4, ) == 0x0 02627 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 824, {896, 2128}, ) == 0x0 02628 2016 NtQueryInformationThread (824, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4d000,Pid=896,Tid=2128,}, 0x0, ) == 0x0 02629 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81965, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\3\0\0\200\3\0\0P\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\3\0\0\200\3\0\0P\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81966, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81965, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\3\0\0\200\3\0\0P\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\3\0\0\200\3\0\0P\10\0\0" ) ) == 0x0 02630 2016 NtResumeThread (824, ... 1, ) == 0x0 02631 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02632 2128 NtWaitForSingleObject (88, 0, 0x0, ... 02631 2016 NtAllocateVirtualMemory ... 124518400, 1048576, ) == 0x0 02633 2016 NtAllocateVirtualMemory (-1, 125558784, 0, 8192, 4096, 4, ... 125558784, 8192, ) == 0x0 02634 2016 NtProtectVirtualMemory (-1, (0x77be000), 4096, 260, ... (0x77be000), 4096, 4, ) == 0x0 02635 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 828, {896, 2132}, ) == 0x0 02636 2016 NtQueryInformationThread (828, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4c000,Pid=896,Tid=2132,}, 0x0, ) == 0x0 02637 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81966, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\3\0\0\200\3\0\0T\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\3\0\0\200\3\0\0T\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81967, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81966, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\3\0\0\200\3\0\0T\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\3\0\0\200\3\0\0T\10\0\0" ) ) == 0x0 02638 2016 NtResumeThread (828, ... 1, ) == 0x0 02639 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 125566976, 1048576, ) == 0x0 02640 2016 NtAllocateVirtualMemory (-1, 126607360, 0, 8192, 4096, 4, ... 126607360, 8192, ) == 0x0 02641 2132 NtWaitForSingleObject (88, 0, 0x0, ... 02642 2016 NtProtectVirtualMemory (-1, (0x78be000), 4096, 260, ... (0x78be000), 4096, 4, ) == 0x0 02643 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 832, {896, 2136}, ) == 0x0 02644 2016 NtQueryInformationThread (832, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4b000,Pid=896,Tid=2136,}, 0x0, ) == 0x0 02645 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81967, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\3\0\0\200\3\0\0X\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\3\0\0\200\3\0\0X\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81968, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81967, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\3\0\0\200\3\0\0X\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\3\0\0\200\3\0\0X\10\0\0" ) ) == 0x0 02646 2016 NtResumeThread (832, ... 1, ) == 0x0 02647 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02648 2136 NtWaitForSingleObject (88, 0, 0x0, ... 02647 2016 NtAllocateVirtualMemory ... 126615552, 1048576, ) == 0x0 02649 2016 NtAllocateVirtualMemory (-1, 127655936, 0, 8192, 4096, 4, ... 127655936, 8192, ) == 0x0 02650 2016 NtProtectVirtualMemory (-1, (0x79be000), 4096, 260, ... (0x79be000), 4096, 4, ) == 0x0 02651 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 836, {896, 2140}, ) == 0x0 02652 2016 NtQueryInformationThread (836, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff4a000,Pid=896,Tid=2140,}, 0x0, ) == 0x0 02653 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81968, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\3\0\0\200\3\0\0\\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\3\0\0\200\3\0\0\\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81969, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81968, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\3\0\0\200\3\0\0\\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\3\0\0\200\3\0\0\\10\0\0" ) ) == 0x0 02654 2016 NtResumeThread (836, ... 1, ) == 0x0 02655 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 127664128, 1048576, ) == 0x0 02656 2016 NtAllocateVirtualMemory (-1, 128704512, 0, 8192, 4096, 4, ... 128704512, 8192, ) == 0x0 02657 2140 NtWaitForSingleObject (88, 0, 0x0, ... 02658 2016 NtProtectVirtualMemory (-1, (0x7abe000), 4096, 260, ... (0x7abe000), 4096, 4, ) == 0x0 02659 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 840, {896, 2144}, ) == 0x0 02660 2016 NtQueryInformationThread (840, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff49000,Pid=896,Tid=2144,}, 0x0, ) == 0x0 02661 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81969, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\3\0\0\200\3\0\0`\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\3\0\0\200\3\0\0`\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81970, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81969, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\3\0\0\200\3\0\0`\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\3\0\0\200\3\0\0`\10\0\0" ) ) == 0x0 02662 2016 NtResumeThread (840, ... 1, ) == 0x0 02663 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02664 2144 NtWaitForSingleObject (88, 0, 0x0, ... 02663 2016 NtAllocateVirtualMemory ... 128712704, 1048576, ) == 0x0 02665 2016 NtAllocateVirtualMemory (-1, 129753088, 0, 8192, 4096, 4, ... 129753088, 8192, ) == 0x0 02666 2016 NtProtectVirtualMemory (-1, (0x7bbe000), 4096, 260, ... (0x7bbe000), 4096, 4, ) == 0x0 02667 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 844, {896, 2148}, ) == 0x0 02668 2016 NtQueryInformationThread (844, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff48000,Pid=896,Tid=2148,}, 0x0, ) == 0x0 02669 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81970, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\3\0\0\200\3\0\0d\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\3\0\0\200\3\0\0d\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81971, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81970, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\3\0\0\200\3\0\0d\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\3\0\0\200\3\0\0d\10\0\0" ) ) == 0x0 02670 2016 NtResumeThread (844, ... 1, ) == 0x0 02671 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 129761280, 1048576, ) == 0x0 02672 2016 NtAllocateVirtualMemory (-1, 130801664, 0, 8192, 4096, 4, ... 130801664, 8192, ) == 0x0 02673 2148 NtWaitForSingleObject (88, 0, 0x0, ... 02674 2016 NtProtectVirtualMemory (-1, (0x7cbe000), 4096, 260, ... (0x7cbe000), 4096, 4, ) == 0x0 02675 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 848, {896, 2152}, ) == 0x0 02676 2016 NtQueryInformationThread (848, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff47000,Pid=896,Tid=2152,}, 0x0, ) == 0x0 02677 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81971, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\3\0\0\200\3\0\0h\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\3\0\0\200\3\0\0h\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81972, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81971, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\3\0\0\200\3\0\0h\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\3\0\0\200\3\0\0h\10\0\0" ) ) == 0x0 02678 2016 NtResumeThread (848, ... 1, ) == 0x0 02679 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02680 2152 NtWaitForSingleObject (88, 0, 0x0, ... 02679 2016 NtAllocateVirtualMemory ... 130809856, 1048576, ) == 0x0 02681 2016 NtAllocateVirtualMemory (-1, 131850240, 0, 8192, 4096, 4, ... 131850240, 8192, ) == 0x0 02682 2016 NtProtectVirtualMemory (-1, (0x7dbe000), 4096, 260, ... (0x7dbe000), 4096, 4, ) == 0x0 02683 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 852, {896, 2156}, ) == 0x0 02684 2016 NtQueryInformationThread (852, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff46000,Pid=896,Tid=2156,}, 0x0, ) == 0x0 02685 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81972, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\3\0\0\200\3\0\0l\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\3\0\0\200\3\0\0l\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81973, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81972, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\3\0\0\200\3\0\0l\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\3\0\0\200\3\0\0l\10\0\0" ) ) == 0x0 02686 2016 NtResumeThread (852, ... 1, ) == 0x0 02687 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 131858432, 1048576, ) == 0x0 02688 2016 NtAllocateVirtualMemory (-1, 132898816, 0, 8192, 4096, 4, ... 132898816, 8192, ) == 0x0 02689 2156 NtWaitForSingleObject (88, 0, 0x0, ... 02690 2016 NtProtectVirtualMemory (-1, (0x7ebe000), 4096, 260, ... (0x7ebe000), 4096, 4, ) == 0x0 02691 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 856, {896, 2160}, ) == 0x0 02692 2016 NtQueryInformationThread (856, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff45000,Pid=896,Tid=2160,}, 0x0, ) == 0x0 02693 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81973, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\3\0\0\200\3\0\0p\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\3\0\0\200\3\0\0p\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81974, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81973, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\3\0\0\200\3\0\0p\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\3\0\0\200\3\0\0p\10\0\0" ) ) == 0x0 02694 2016 NtResumeThread (856, ... 1, ) == 0x0 02695 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02696 2160 NtWaitForSingleObject (88, 0, 0x0, ... 02695 2016 NtAllocateVirtualMemory ... 132907008, 1048576, ) == 0x0 02697 2016 NtAllocateVirtualMemory (-1, 133947392, 0, 8192, 4096, 4, ... 133947392, 8192, ) == 0x0 02698 2016 NtProtectVirtualMemory (-1, (0x7fbe000), 4096, 260, ... (0x7fbe000), 4096, 4, ) == 0x0 02699 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 860, {896, 2164}, ) == 0x0 02700 2016 NtQueryInformationThread (860, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff44000,Pid=896,Tid=2164,}, 0x0, ) == 0x0 02701 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81974, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\3\0\0\200\3\0\0t\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\3\0\0\200\3\0\0t\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81975, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81974, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\3\0\0\200\3\0\0t\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\3\0\0\200\3\0\0t\10\0\0" ) ) == 0x0 02702 2016 NtResumeThread (860, ... 1, ) == 0x0 02703 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02704 2164 NtWaitForSingleObject (88, 0, 0x0, ... 02703 2016 NtAllocateVirtualMemory ... 133955584, 1048576, ) == 0x0 02705 2016 NtAllocateVirtualMemory (-1, 134995968, 0, 8192, 4096, 4, ... 134995968, 8192, ) == 0x0 02706 2016 NtProtectVirtualMemory (-1, (0x80be000), 4096, 260, ... (0x80be000), 4096, 4, ) == 0x0 02707 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 864, {896, 2168}, ) == 0x0 02708 2016 NtQueryInformationThread (864, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff43000,Pid=896,Tid=2168,}, 0x0, ) == 0x0 02709 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81975, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\3\0\0\200\3\0\0x\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\3\0\0\200\3\0\0x\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81976, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81975, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\3\0\0\200\3\0\0x\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\3\0\0\200\3\0\0x\10\0\0" ) ) == 0x0 02710 2016 NtResumeThread (864, ... 1, ) == 0x0 02711 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 135004160, 1048576, ) == 0x0 02712 2016 NtAllocateVirtualMemory (-1, 136044544, 0, 8192, 4096, 4, ... 136044544, 8192, ) == 0x0 02713 2168 NtWaitForSingleObject (88, 0, 0x0, ... 02714 2016 NtProtectVirtualMemory (-1, (0x81be000), 4096, 260, ... (0x81be000), 4096, 4, ) == 0x0 02715 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 868, {896, 2172}, ) == 0x0 02716 2016 NtQueryInformationThread (868, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff42000,Pid=896,Tid=2172,}, 0x0, ) == 0x0 02717 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81976, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\3\0\0\200\3\0\0|\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\3\0\0\200\3\0\0|\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81977, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81976, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\3\0\0\200\3\0\0|\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\3\0\0\200\3\0\0|\10\0\0" ) ) == 0x0 02718 2016 NtResumeThread (868, ... 1, ) == 0x0 02719 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02720 2172 NtWaitForSingleObject (88, 0, 0x0, ... 02719 2016 NtAllocateVirtualMemory ... 136052736, 1048576, ) == 0x0 02721 2016 NtAllocateVirtualMemory (-1, 137093120, 0, 8192, 4096, 4, ... 137093120, 8192, ) == 0x0 02722 2016 NtProtectVirtualMemory (-1, (0x82be000), 4096, 260, ... (0x82be000), 4096, 4, ) == 0x0 02723 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 872, {896, 2176}, ) == 0x0 02724 2016 NtQueryInformationThread (872, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff41000,Pid=896,Tid=2176,}, 0x0, ) == 0x0 02725 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81977, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\3\0\0\200\3\0\0\200\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\3\0\0\200\3\0\0\200\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81978, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\3\0\0\200\3\0\0\200\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\3\0\0\200\3\0\0\200\10\0\0" ) ) == 0x0 02726 2016 NtResumeThread (872, ... 1, ) == 0x0 02727 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 137101312, 1048576, ) == 0x0 02728 2016 NtAllocateVirtualMemory (-1, 138141696, 0, 8192, 4096, 4, ... 138141696, 8192, ) == 0x0 02729 2176 NtWaitForSingleObject (88, 0, 0x0, ... 02730 2016 NtProtectVirtualMemory (-1, (0x83be000), 4096, 260, ... (0x83be000), 4096, 4, ) == 0x0 02731 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 876, {896, 2180}, ) == 0x0 02732 2016 NtQueryInformationThread (876, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff40000,Pid=896,Tid=2180,}, 0x0, ) == 0x0 02733 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81978, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\3\0\0\200\3\0\0\204\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\3\0\0\200\3\0\0\204\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81979, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81978, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\3\0\0\200\3\0\0\204\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\3\0\0\200\3\0\0\204\10\0\0" ) ) == 0x0 02734 2016 NtResumeThread (876, ... 1, ) == 0x0 02735 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02736 2180 NtWaitForSingleObject (88, 0, 0x0, ... 02735 2016 NtAllocateVirtualMemory ... 138149888, 1048576, ) == 0x0 02737 2016 NtAllocateVirtualMemory (-1, 139190272, 0, 8192, 4096, 4, ... 139190272, 8192, ) == 0x0 02738 2016 NtProtectVirtualMemory (-1, (0x84be000), 4096, 260, ... (0x84be000), 4096, 4, ) == 0x0 02739 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 880, {896, 2184}, ) == 0x0 02740 2016 NtQueryInformationThread (880, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3f000,Pid=896,Tid=2184,}, 0x0, ) == 0x0 02741 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81979, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\3\0\0\200\3\0\0\210\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\3\0\0\200\3\0\0\210\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81980, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81979, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\3\0\0\200\3\0\0\210\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\3\0\0\200\3\0\0\210\10\0\0" ) ) == 0x0 02742 2016 NtResumeThread (880, ... 1, ) == 0x0 02743 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 139198464, 1048576, ) == 0x0 02744 2016 NtAllocateVirtualMemory (-1, 140238848, 0, 8192, 4096, 4, ... 140238848, 8192, ) == 0x0 02745 2184 NtWaitForSingleObject (88, 0, 0x0, ... 02746 2016 NtProtectVirtualMemory (-1, (0x85be000), 4096, 260, ... (0x85be000), 4096, 4, ) == 0x0 02747 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 884, {896, 2188}, ) == 0x0 02748 2016 NtQueryInformationThread (884, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3e000,Pid=896,Tid=2188,}, 0x0, ) == 0x0 02749 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81980, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\3\0\0\200\3\0\0\214\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\3\0\0\200\3\0\0\214\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81981, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\3\0\0\200\3\0\0\214\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\3\0\0\200\3\0\0\214\10\0\0" ) ) == 0x0 02750 2016 NtResumeThread (884, ... 1, ) == 0x0 02751 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02752 2188 NtWaitForSingleObject (88, 0, 0x0, ... 02751 2016 NtAllocateVirtualMemory ... 140247040, 1048576, ) == 0x0 02753 2016 NtAllocateVirtualMemory (-1, 141287424, 0, 8192, 4096, 4, ... 141287424, 8192, ) == 0x0 02754 2016 NtProtectVirtualMemory (-1, (0x86be000), 4096, 260, ... (0x86be000), 4096, 4, ) == 0x0 02755 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 888, {896, 2192}, ) == 0x0 02756 2016 NtQueryInformationThread (888, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3d000,Pid=896,Tid=2192,}, 0x0, ) == 0x0 02757 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81981, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\3\0\0\200\3\0\0\220\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\3\0\0\200\3\0\0\220\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81982, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81981, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\3\0\0\200\3\0\0\220\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\3\0\0\200\3\0\0\220\10\0\0" ) ) == 0x0 02758 2016 NtResumeThread (888, ... 1, ) == 0x0 02759 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 141295616, 1048576, ) == 0x0 02760 2016 NtAllocateVirtualMemory (-1, 142336000, 0, 8192, 4096, 4, ... 142336000, 8192, ) == 0x0 02761 2192 NtWaitForSingleObject (88, 0, 0x0, ... 02762 2016 NtProtectVirtualMemory (-1, (0x87be000), 4096, 260, ... (0x87be000), 4096, 4, ) == 0x0 02763 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 892, {896, 2196}, ) == 0x0 02764 2016 NtQueryInformationThread (892, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3c000,Pid=896,Tid=2196,}, 0x0, ) == 0x0 02765 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81982, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\3\0\0\200\3\0\0\224\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\3\0\0\200\3\0\0\224\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81983, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81982, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\3\0\0\200\3\0\0\224\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\3\0\0\200\3\0\0\224\10\0\0" ) ) == 0x0 02766 2016 NtResumeThread (892, ... 1, ) == 0x0 02767 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02768 2196 NtWaitForSingleObject (88, 0, 0x0, ... 02767 2016 NtAllocateVirtualMemory ... 142344192, 1048576, ) == 0x0 02769 2016 NtAllocateVirtualMemory (-1, 143384576, 0, 8192, 4096, 4, ... 143384576, 8192, ) == 0x0 02770 2016 NtProtectVirtualMemory (-1, (0x88be000), 4096, 260, ... (0x88be000), 4096, 4, ) == 0x0 02771 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 896, {896, 2200}, ) == 0x0 02772 2016 NtQueryInformationThread (896, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3b000,Pid=896,Tid=2200,}, 0x0, ) == 0x0 02773 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81983, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\3\0\0\200\3\0\0\230\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\3\0\0\200\3\0\0\230\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81984, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81983, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\3\0\0\200\3\0\0\230\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\3\0\0\200\3\0\0\230\10\0\0" ) ) == 0x0 02774 2016 NtResumeThread (896, ... 1, ) == 0x0 02775 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 143392768, 1048576, ) == 0x0 02776 2016 NtAllocateVirtualMemory (-1, 144433152, 0, 8192, 4096, 4, ... 144433152, 8192, ) == 0x0 02777 2200 NtWaitForSingleObject (88, 0, 0x0, ... 02778 2016 NtProtectVirtualMemory (-1, (0x89be000), 4096, 260, ... (0x89be000), 4096, 4, ) == 0x0 02779 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 900, {896, 2204}, ) == 0x0 02780 2016 NtQueryInformationThread (900, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff3a000,Pid=896,Tid=2204,}, 0x0, ) == 0x0 02781 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81984, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\3\0\0\200\3\0\0\234\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\3\0\0\200\3\0\0\234\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81985, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81984, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\3\0\0\200\3\0\0\234\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\3\0\0\200\3\0\0\234\10\0\0" ) ) == 0x0 02782 2016 NtResumeThread (900, ... 1, ) == 0x0 02783 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02784 2204 NtWaitForSingleObject (88, 0, 0x0, ... 02783 2016 NtAllocateVirtualMemory ... 144441344, 1048576, ) == 0x0 02785 2016 NtAllocateVirtualMemory (-1, 145481728, 0, 8192, 4096, 4, ... 145481728, 8192, ) == 0x0 02786 2016 NtProtectVirtualMemory (-1, (0x8abe000), 4096, 260, ... (0x8abe000), 4096, 4, ) == 0x0 02787 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 904, {896, 2208}, ) == 0x0 02788 2016 NtQueryInformationThread (904, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff39000,Pid=896,Tid=2208,}, 0x0, ) == 0x0 02789 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81985, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\3\0\0\200\3\0\0\240\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\3\0\0\200\3\0\0\240\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81986, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81985, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\3\0\0\200\3\0\0\240\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\3\0\0\200\3\0\0\240\10\0\0" ) ) == 0x0 02790 2016 NtResumeThread (904, ... 1, ) == 0x0 02791 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 145489920, 1048576, ) == 0x0 02792 2016 NtAllocateVirtualMemory (-1, 146530304, 0, 8192, 4096, 4, ... 146530304, 8192, ) == 0x0 02793 2208 NtWaitForSingleObject (88, 0, 0x0, ... 02794 2016 NtProtectVirtualMemory (-1, (0x8bbe000), 4096, 260, ... (0x8bbe000), 4096, 4, ) == 0x0 02795 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 908, {896, 2212}, ) == 0x0 02796 2016 NtQueryInformationThread (908, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff38000,Pid=896,Tid=2212,}, 0x0, ) == 0x0 02797 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81986, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\3\0\0\200\3\0\0\244\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\3\0\0\200\3\0\0\244\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81987, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81986, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\3\0\0\200\3\0\0\244\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\3\0\0\200\3\0\0\244\10\0\0" ) ) == 0x0 02798 2016 NtResumeThread (908, ... 1, ) == 0x0 02799 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02800 2212 NtWaitForSingleObject (88, 0, 0x0, ... 02799 2016 NtAllocateVirtualMemory ... 146538496, 1048576, ) == 0x0 02801 2016 NtAllocateVirtualMemory (-1, 147578880, 0, 8192, 4096, 4, ... 147578880, 8192, ) == 0x0 02802 2016 NtProtectVirtualMemory (-1, (0x8cbe000), 4096, 260, ... (0x8cbe000), 4096, 4, ) == 0x0 02803 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 912, {896, 2216}, ) == 0x0 02804 2016 NtQueryInformationThread (912, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff37000,Pid=896,Tid=2216,}, 0x0, ) == 0x0 02805 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81987, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\3\0\0\200\3\0\0\250\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\3\0\0\200\3\0\0\250\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81988, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81987, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\3\0\0\200\3\0\0\250\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\3\0\0\200\3\0\0\250\10\0\0" ) ) == 0x0 02806 2016 NtResumeThread (912, ... 1, ) == 0x0 02807 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 147587072, 1048576, ) == 0x0 02808 2016 NtAllocateVirtualMemory (-1, 148627456, 0, 8192, 4096, 4, ... 148627456, 8192, ) == 0x0 02809 2216 NtWaitForSingleObject (88, 0, 0x0, ... 02810 2016 NtProtectVirtualMemory (-1, (0x8dbe000), 4096, 260, ... (0x8dbe000), 4096, 4, ) == 0x0 02811 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 916, {896, 2220}, ) == 0x0 02812 2016 NtQueryInformationThread (916, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff36000,Pid=896,Tid=2220,}, 0x0, ) == 0x0 02813 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81988, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\3\0\0\200\3\0\0\254\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\3\0\0\200\3\0\0\254\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81989, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81988, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\3\0\0\200\3\0\0\254\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\3\0\0\200\3\0\0\254\10\0\0" ) ) == 0x0 02814 2016 NtResumeThread (916, ... 1, ) == 0x0 02815 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02816 2220 NtWaitForSingleObject (88, 0, 0x0, ... 02815 2016 NtAllocateVirtualMemory ... 148635648, 1048576, ) == 0x0 02817 2016 NtAllocateVirtualMemory (-1, 149676032, 0, 8192, 4096, 4, ... 149676032, 8192, ) == 0x0 02818 2016 NtProtectVirtualMemory (-1, (0x8ebe000), 4096, 260, ... (0x8ebe000), 4096, 4, ) == 0x0 02819 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 920, {896, 2224}, ) == 0x0 02820 2016 NtQueryInformationThread (920, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff35000,Pid=896,Tid=2224,}, 0x0, ) == 0x0 02821 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81989, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\3\0\0\200\3\0\0\260\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\3\0\0\200\3\0\0\260\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81990, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81989, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\3\0\0\200\3\0\0\260\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\3\0\0\200\3\0\0\260\10\0\0" ) ) == 0x0 02822 2016 NtResumeThread (920, ... 1, ) == 0x0 02823 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 149684224, 1048576, ) == 0x0 02824 2016 NtAllocateVirtualMemory (-1, 150724608, 0, 8192, 4096, 4, ... 150724608, 8192, ) == 0x0 02825 2224 NtWaitForSingleObject (88, 0, 0x0, ... 02826 2016 NtProtectVirtualMemory (-1, (0x8fbe000), 4096, 260, ... (0x8fbe000), 4096, 4, ) == 0x0 02827 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 924, {896, 2228}, ) == 0x0 02828 2016 NtQueryInformationThread (924, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff34000,Pid=896,Tid=2228,}, 0x0, ) == 0x0 02829 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81990, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\3\0\0\200\3\0\0\264\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\3\0\0\200\3\0\0\264\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81991, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81990, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\3\0\0\200\3\0\0\264\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\3\0\0\200\3\0\0\264\10\0\0" ) ) == 0x0 02830 2016 NtResumeThread (924, ... 1, ) == 0x0 02831 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02832 2228 NtWaitForSingleObject (88, 0, 0x0, ... 02831 2016 NtAllocateVirtualMemory ... 150732800, 1048576, ) == 0x0 02833 2016 NtAllocateVirtualMemory (-1, 151773184, 0, 8192, 4096, 4, ... 151773184, 8192, ) == 0x0 02834 2016 NtProtectVirtualMemory (-1, (0x90be000), 4096, 260, ... (0x90be000), 4096, 4, ) == 0x0 02835 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 928, {896, 2232}, ) == 0x0 02836 2016 NtQueryInformationThread (928, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff33000,Pid=896,Tid=2232,}, 0x0, ) == 0x0 02837 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81991, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\3\0\0\200\3\0\0\270\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\3\0\0\200\3\0\0\270\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81992, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81991, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\3\0\0\200\3\0\0\270\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\240\3\0\0\200\3\0\0\270\10\0\0" ) ) == 0x0 02838 2016 NtResumeThread (928, ... 1, ) == 0x0 02839 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 151781376, 1048576, ) == 0x0 02840 2016 NtAllocateVirtualMemory (-1, 152821760, 0, 8192, 4096, 4, ... 152821760, 8192, ) == 0x0 02841 2232 NtWaitForSingleObject (88, 0, 0x0, ... 02842 2016 NtProtectVirtualMemory (-1, (0x91be000), 4096, 260, ... (0x91be000), 4096, 4, ) == 0x0 02843 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 932, {896, 2236}, ) == 0x0 02844 2016 NtQueryInformationThread (932, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff32000,Pid=896,Tid=2236,}, 0x0, ) == 0x0 02845 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81992, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\3\0\0\200\3\0\0\274\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\3\0\0\200\3\0\0\274\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81993, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81992, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\3\0\0\200\3\0\0\274\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\3\0\0\200\3\0\0\274\10\0\0" ) ) == 0x0 02846 2016 NtResumeThread (932, ... 1, ) == 0x0 02847 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02848 2236 NtWaitForSingleObject (88, 0, 0x0, ... 02847 2016 NtAllocateVirtualMemory ... 152829952, 1048576, ) == 0x0 02849 2016 NtAllocateVirtualMemory (-1, 153870336, 0, 8192, 4096, 4, ... 153870336, 8192, ) == 0x0 02850 2016 NtProtectVirtualMemory (-1, (0x92be000), 4096, 260, ... (0x92be000), 4096, 4, ) == 0x0 02851 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 936, {896, 2240}, ) == 0x0 02852 2016 NtQueryInformationThread (936, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff31000,Pid=896,Tid=2240,}, 0x0, ) == 0x0 02853 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81993, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\200\3\0\0\300\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\200\3\0\0\300\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81994, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81993, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\200\3\0\0\300\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\250\3\0\0\200\3\0\0\300\10\0\0" ) ) == 0x0 02854 2016 NtResumeThread (936, ... 1, ) == 0x0 02855 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02856 2240 NtWaitForSingleObject (88, 0, 0x0, ... 02855 2016 NtAllocateVirtualMemory ... 153878528, 1048576, ) == 0x0 02857 2016 NtAllocateVirtualMemory (-1, 154918912, 0, 8192, 4096, 4, ... 154918912, 8192, ) == 0x0 02858 2016 NtProtectVirtualMemory (-1, (0x93be000), 4096, 260, ... (0x93be000), 4096, 4, ) == 0x0 02859 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 940, {896, 2244}, ) == 0x0 02860 2016 NtQueryInformationThread (940, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff30000,Pid=896,Tid=2244,}, 0x0, ) == 0x0 02861 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81994, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\3\0\0\200\3\0\0\304\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\3\0\0\200\3\0\0\304\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81995, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81994, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\3\0\0\200\3\0\0\304\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\254\3\0\0\200\3\0\0\304\10\0\0" ) ) == 0x0 02862 2016 NtResumeThread (940, ... 1, ) == 0x0 02863 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 154927104, 1048576, ) == 0x0 02864 2016 NtAllocateVirtualMemory (-1, 155967488, 0, 8192, 4096, 4, ... 155967488, 8192, ) == 0x0 02865 2244 NtWaitForSingleObject (88, 0, 0x0, ... 02866 2016 NtProtectVirtualMemory (-1, (0x94be000), 4096, 260, ... (0x94be000), 4096, 4, ) == 0x0 02867 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 944, {896, 2248}, ) == 0x0 02868 2016 NtQueryInformationThread (944, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff2f000,Pid=896,Tid=2248,}, 0x0, ) == 0x0 02869 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81995, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\3\0\0\200\3\0\0\310\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\3\0\0\200\3\0\0\310\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81996, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81995, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\3\0\0\200\3\0\0\310\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\260\3\0\0\200\3\0\0\310\10\0\0" ) ) == 0x0 02870 2016 NtResumeThread (944, ... 1, ) == 0x0 02871 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02872 2248 NtWaitForSingleObject (88, 0, 0x0, ... 02871 2016 NtAllocateVirtualMemory ... 155975680, 1048576, ) == 0x0 02873 2016 NtAllocateVirtualMemory (-1, 157016064, 0, 8192, 4096, 4, ... 157016064, 8192, ) == 0x0 02874 2016 NtProtectVirtualMemory (-1, (0x95be000), 4096, 260, ... (0x95be000), 4096, 4, ) == 0x0 02875 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 948, {896, 2252}, ) == 0x0 02876 2016 NtQueryInformationThread (948, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff2e000,Pid=896,Tid=2252,}, 0x0, ) == 0x0 02877 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81996, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\3\0\0\200\3\0\0\314\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\3\0\0\200\3\0\0\314\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81997, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81996, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\3\0\0\200\3\0\0\314\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\264\3\0\0\200\3\0\0\314\10\0\0" ) ) == 0x0 02878 2016 NtResumeThread (948, ... 1, ) == 0x0 02879 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 157024256, 1048576, ) == 0x0 02880 2016 NtAllocateVirtualMemory (-1, 158064640, 0, 8192, 4096, 4, ... 158064640, 8192, ) == 0x0 02881 2252 NtWaitForSingleObject (88, 0, 0x0, ... 02882 2016 NtProtectVirtualMemory (-1, (0x96be000), 4096, 260, ... (0x96be000), 4096, 4, ) == 0x0 02883 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 952, {896, 2256}, ) == 0x0 02884 2016 NtQueryInformationThread (952, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff2d000,Pid=896,Tid=2256,}, 0x0, ) == 0x0 02885 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81997, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\3\0\0\200\3\0\0\320\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\3\0\0\200\3\0\0\320\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81998, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81997, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\3\0\0\200\3\0\0\320\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\270\3\0\0\200\3\0\0\320\10\0\0" ) ) == 0x0 02886 2016 NtResumeThread (952, ... 1, ) == 0x0 02887 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02888 2256 NtWaitForSingleObject (88, 0, 0x0, ... 02887 2016 NtAllocateVirtualMemory ... 158072832, 1048576, ) == 0x0 02889 2016 NtAllocateVirtualMemory (-1, 159113216, 0, 8192, 4096, 4, ... 159113216, 8192, ) == 0x0 02890 2016 NtProtectVirtualMemory (-1, (0x97be000), 4096, 260, ... (0x97be000), 4096, 4, ) == 0x0 02891 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 956, {896, 2260}, ) == 0x0 02892 2016 NtQueryInformationThread (956, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff2c000,Pid=896,Tid=2260,}, 0x0, ) == 0x0 02893 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81998, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\3\0\0\200\3\0\0\324\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\3\0\0\200\3\0\0\324\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 81999, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81998, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\3\0\0\200\3\0\0\324\10\0\0" ... {28, 56, reply, 0, 896, 2016, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\274\3\0\0\200\3\0\0\324\10\0\0" ) ) == 0x0 02894 2016 NtResumeThread (956, ... 1, ) == 0x0 02895 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 159121408, 1048576, ) == 0x0 02896 2016 NtAllocateVirtualMemory (-1, 160161792, 0, 8192, 4096, 4, ... 160161792, 8192, ) == 0x0 02897 2260 NtWaitForSingleObject (88, 0, 0x0, ... 02898 2016 NtProtectVirtualMemory (-1, (0x98be000), 4096, 260, ... (0x98be000), 4096, 4, ) == 0x0 02899 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 960, {896, 2264}, ) == 0x0 02900 2016 NtQueryInformationThread (960, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff2b000,Pid=896,Tid=2264,}, 0x0, ) == 0x0 02901 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 81999, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\3\0\0\200\3\0\0\330\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\3\0\0\200\3\0\0\330\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82000, 0} (24, {28, 56, new_msg, 0, 896, 2016, 81999, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\3\0\0\200\3\0\0\330\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\300\3\0\0\200\3\0\0\330\10\0\0" ) ) == 0x0 02902 2016 NtResumeThread (960, ... 1, ) == 0x0 02903 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02904 2264 NtWaitForSingleObject (88, 0, 0x0, ... 02903 2016 NtAllocateVirtualMemory ... 160169984, 1048576, ) == 0x0 02905 2016 NtAllocateVirtualMemory (-1, 161210368, 0, 8192, 4096, 4, ... 161210368, 8192, ) == 0x0 02906 2016 NtProtectVirtualMemory (-1, (0x99be000), 4096, 260, ... (0x99be000), 4096, 4, ) == 0x0 02907 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 964, {896, 2268}, ) == 0x0 02908 2016 NtQueryInformationThread (964, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff2a000,Pid=896,Tid=2268,}, 0x0, ) == 0x0 02909 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82000, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\3\0\0\200\3\0\0\334\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\3\0\0\200\3\0\0\334\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82001, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82000, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\3\0\0\200\3\0\0\334\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\304\3\0\0\200\3\0\0\334\10\0\0" ) ) == 0x0 02910 2016 NtResumeThread (964, ... 1, ) == 0x0 02911 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 161218560, 1048576, ) == 0x0 02912 2016 NtAllocateVirtualMemory (-1, 162258944, 0, 8192, 4096, 4, ... 162258944, 8192, ) == 0x0 02913 2268 NtWaitForSingleObject (88, 0, 0x0, ... 02914 2016 NtProtectVirtualMemory (-1, (0x9abe000), 4096, 260, ... (0x9abe000), 4096, 4, ) == 0x0 02915 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 968, {896, 2272}, ) == 0x0 02916 2016 NtQueryInformationThread (968, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff29000,Pid=896,Tid=2272,}, 0x0, ) == 0x0 02917 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82001, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\3\0\0\200\3\0\0\340\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\3\0\0\200\3\0\0\340\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82002, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82001, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\3\0\0\200\3\0\0\340\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\310\3\0\0\200\3\0\0\340\10\0\0" ) ) == 0x0 02918 2016 NtResumeThread (968, ... 1, ) == 0x0 02919 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02920 2272 NtWaitForSingleObject (88, 0, 0x0, ... 02919 2016 NtAllocateVirtualMemory ... 162267136, 1048576, ) == 0x0 02921 2016 NtAllocateVirtualMemory (-1, 163307520, 0, 8192, 4096, 4, ... 163307520, 8192, ) == 0x0 02922 2016 NtProtectVirtualMemory (-1, (0x9bbe000), 4096, 260, ... (0x9bbe000), 4096, 4, ) == 0x0 02923 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 972, {896, 2276}, ) == 0x0 02924 2016 NtQueryInformationThread (972, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff28000,Pid=896,Tid=2276,}, 0x0, ) == 0x0 02925 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82002, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\3\0\0\200\3\0\0\344\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\3\0\0\200\3\0\0\344\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82003, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82002, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\3\0\0\200\3\0\0\344\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\314\3\0\0\200\3\0\0\344\10\0\0" ) ) == 0x0 02926 2016 NtResumeThread (972, ... 1, ) == 0x0 02927 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 163315712, 1048576, ) == 0x0 02928 2016 NtAllocateVirtualMemory (-1, 164356096, 0, 8192, 4096, 4, ... 164356096, 8192, ) == 0x0 02929 2276 NtWaitForSingleObject (88, 0, 0x0, ... 02930 2016 NtProtectVirtualMemory (-1, (0x9cbe000), 4096, 260, ... (0x9cbe000), 4096, 4, ) == 0x0 02931 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 976, {896, 2280}, ) == 0x0 02932 2016 NtQueryInformationThread (976, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff27000,Pid=896,Tid=2280,}, 0x0, ) == 0x0 02933 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82003, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\3\0\0\200\3\0\0\350\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\3\0\0\200\3\0\0\350\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82004, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82003, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\3\0\0\200\3\0\0\350\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\320\3\0\0\200\3\0\0\350\10\0\0" ) ) == 0x0 02934 2016 NtResumeThread (976, ... 1, ) == 0x0 02935 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02936 2280 NtWaitForSingleObject (88, 0, 0x0, ... 02935 2016 NtAllocateVirtualMemory ... 164364288, 1048576, ) == 0x0 02937 2016 NtAllocateVirtualMemory (-1, 165404672, 0, 8192, 4096, 4, ... 165404672, 8192, ) == 0x0 02938 2016 NtProtectVirtualMemory (-1, (0x9dbe000), 4096, 260, ... (0x9dbe000), 4096, 4, ) == 0x0 02939 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 980, {896, 2284}, ) == 0x0 02940 2016 NtQueryInformationThread (980, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff26000,Pid=896,Tid=2284,}, 0x0, ) == 0x0 02941 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82004, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\3\0\0\200\3\0\0\354\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\3\0\0\200\3\0\0\354\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82005, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82004, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\3\0\0\200\3\0\0\354\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\324\3\0\0\200\3\0\0\354\10\0\0" ) ) == 0x0 02942 2016 NtResumeThread (980, ... 1, ) == 0x0 02943 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 165412864, 1048576, ) == 0x0 02944 2016 NtAllocateVirtualMemory (-1, 166453248, 0, 8192, 4096, 4, ... 166453248, 8192, ) == 0x0 02945 2284 NtWaitForSingleObject (88, 0, 0x0, ... 02946 2016 NtProtectVirtualMemory (-1, (0x9ebe000), 4096, 260, ... (0x9ebe000), 4096, 4, ) == 0x0 02947 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 984, {896, 2288}, ) == 0x0 02948 2016 NtQueryInformationThread (984, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff25000,Pid=896,Tid=2288,}, 0x0, ) == 0x0 02949 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82005, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\3\0\0\200\3\0\0\360\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\3\0\0\200\3\0\0\360\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82006, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82005, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\3\0\0\200\3\0\0\360\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\330\3\0\0\200\3\0\0\360\10\0\0" ) ) == 0x0 02950 2016 NtResumeThread (984, ... 1, ) == 0x0 02951 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02952 2288 NtWaitForSingleObject (88, 0, 0x0, ... 02951 2016 NtAllocateVirtualMemory ... 166461440, 1048576, ) == 0x0 02953 2016 NtAllocateVirtualMemory (-1, 167501824, 0, 8192, 4096, 4, ... 167501824, 8192, ) == 0x0 02954 2016 NtProtectVirtualMemory (-1, (0x9fbe000), 4096, 260, ... (0x9fbe000), 4096, 4, ) == 0x0 02955 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 988, {896, 2292}, ) == 0x0 02956 2016 NtQueryInformationThread (988, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff24000,Pid=896,Tid=2292,}, 0x0, ) == 0x0 02957 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82006, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\3\0\0\200\3\0\0\364\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\3\0\0\200\3\0\0\364\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82007, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82006, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\3\0\0\200\3\0\0\364\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\334\3\0\0\200\3\0\0\364\10\0\0" ) ) == 0x0 02958 2016 NtResumeThread (988, ... 1, ) == 0x0 02959 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 167510016, 1048576, ) == 0x0 02960 2016 NtAllocateVirtualMemory (-1, 168550400, 0, 8192, 4096, 4, ... 168550400, 8192, ) == 0x0 02961 2292 NtWaitForSingleObject (88, 0, 0x0, ... 02962 2016 NtProtectVirtualMemory (-1, (0xa0be000), 4096, 260, ... (0xa0be000), 4096, 4, ) == 0x0 02963 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 992, {896, 2296}, ) == 0x0 02964 2016 NtQueryInformationThread (992, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff23000,Pid=896,Tid=2296,}, 0x0, ) == 0x0 02965 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82007, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\3\0\0\200\3\0\0\370\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\3\0\0\200\3\0\0\370\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82008, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82007, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\3\0\0\200\3\0\0\370\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\340\3\0\0\200\3\0\0\370\10\0\0" ) ) == 0x0 02966 2016 NtResumeThread (992, ... 1, ) == 0x0 02967 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02968 2296 NtWaitForSingleObject (88, 0, 0x0, ... 02967 2016 NtAllocateVirtualMemory ... 168558592, 1048576, ) == 0x0 02969 2016 NtAllocateVirtualMemory (-1, 169598976, 0, 8192, 4096, 4, ... 169598976, 8192, ) == 0x0 02970 2016 NtProtectVirtualMemory (-1, (0xa1be000), 4096, 260, ... (0xa1be000), 4096, 4, ) == 0x0 02971 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 996, {896, 2300}, ) == 0x0 02972 2016 NtQueryInformationThread (996, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff22000,Pid=896,Tid=2300,}, 0x0, ) == 0x0 02973 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82008, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\3\0\0\200\3\0\0\374\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\3\0\0\200\3\0\0\374\10\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82009, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82008, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\3\0\0\200\3\0\0\374\10\0\0" ... {28, 56, reply, 0, 896, 2016, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\344\3\0\0\200\3\0\0\374\10\0\0" ) ) == 0x0 02974 2016 NtResumeThread (996, ... 1, ) == 0x0 02975 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 169607168, 1048576, ) == 0x0 02976 2016 NtAllocateVirtualMemory (-1, 170647552, 0, 8192, 4096, 4, ... 170647552, 8192, ) == 0x0 02977 2300 NtWaitForSingleObject (88, 0, 0x0, ... 02978 2016 NtProtectVirtualMemory (-1, (0xa2be000), 4096, 260, ... (0xa2be000), 4096, 4, ) == 0x0 02979 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1000, {896, 2304}, ) == 0x0 02980 2016 NtQueryInformationThread (1000, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff21000,Pid=896,Tid=2304,}, 0x0, ) == 0x0 02981 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82009, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\3\0\0\200\3\0\0\0\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\3\0\0\200\3\0\0\0\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82010, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82009, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\3\0\0\200\3\0\0\0\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\350\3\0\0\200\3\0\0\0\11\0\0" ) ) == 0x0 02982 2016 NtResumeThread (1000, ... 1, ) == 0x0 02983 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02984 2304 NtWaitForSingleObject (88, 0, 0x0, ... 02983 2016 NtAllocateVirtualMemory ... 170655744, 1048576, ) == 0x0 02985 2016 NtAllocateVirtualMemory (-1, 171696128, 0, 8192, 4096, 4, ... 171696128, 8192, ) == 0x0 02986 2016 NtProtectVirtualMemory (-1, (0xa3be000), 4096, 260, ... (0xa3be000), 4096, 4, ) == 0x0 02987 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1004, {896, 2308}, ) == 0x0 02988 2016 NtQueryInformationThread (1004, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff20000,Pid=896,Tid=2308,}, 0x0, ) == 0x0 02989 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82010, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\3\0\0\200\3\0\0\4\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\3\0\0\200\3\0\0\4\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82011, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82010, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\3\0\0\200\3\0\0\4\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\354\3\0\0\200\3\0\0\4\11\0\0" ) ) == 0x0 02990 2016 NtResumeThread (1004, ... 1, ) == 0x0 02991 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02992 2308 NtWaitForSingleObject (88, 0, 0x0, ... 02991 2016 NtAllocateVirtualMemory ... 171704320, 1048576, ) == 0x0 02993 2016 NtAllocateVirtualMemory (-1, 172744704, 0, 8192, 4096, 4, ... 172744704, 8192, ) == 0x0 02994 2016 NtProtectVirtualMemory (-1, (0xa4be000), 4096, 260, ... (0xa4be000), 4096, 4, ) == 0x0 02995 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1008, {896, 2312}, ) == 0x0 02996 2016 NtQueryInformationThread (1008, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff1f000,Pid=896,Tid=2312,}, 0x0, ) == 0x0 02997 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82011, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\3\0\0\200\3\0\0\10\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\3\0\0\200\3\0\0\10\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82012, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82011, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\3\0\0\200\3\0\0\10\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\360\3\0\0\200\3\0\0\10\11\0\0" ) ) == 0x0 02998 2016 NtResumeThread (1008, ... 1, ) == 0x0 02999 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 172752896, 1048576, ) == 0x0 03000 2016 NtAllocateVirtualMemory (-1, 173793280, 0, 8192, 4096, 4, ... 173793280, 8192, ) == 0x0 03001 2312 NtWaitForSingleObject (88, 0, 0x0, ... 03002 2016 NtProtectVirtualMemory (-1, (0xa5be000), 4096, 260, ... (0xa5be000), 4096, 4, ) == 0x0 03003 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1012, {896, 2316}, ) == 0x0 03004 2016 NtQueryInformationThread (1012, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff1e000,Pid=896,Tid=2316,}, 0x0, ) == 0x0 03005 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82012, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\3\0\0\200\3\0\0\14\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\3\0\0\200\3\0\0\14\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82013, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82012, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\3\0\0\200\3\0\0\14\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\364\3\0\0\200\3\0\0\14\11\0\0" ) ) == 0x0 03006 2016 NtResumeThread (1012, ... 1, ) == 0x0 03007 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03008 2316 NtWaitForSingleObject (88, 0, 0x0, ... 03007 2016 NtAllocateVirtualMemory ... 173801472, 1048576, ) == 0x0 03009 2016 NtAllocateVirtualMemory (-1, 174841856, 0, 8192, 4096, 4, ... 174841856, 8192, ) == 0x0 03010 2016 NtProtectVirtualMemory (-1, (0xa6be000), 4096, 260, ... (0xa6be000), 4096, 4, ) == 0x0 03011 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1016, {896, 2320}, ) == 0x0 03012 2016 NtQueryInformationThread (1016, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff1d000,Pid=896,Tid=2320,}, 0x0, ) == 0x0 03013 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82013, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\3\0\0\200\3\0\0\20\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\3\0\0\200\3\0\0\20\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82014, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82013, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\3\0\0\200\3\0\0\20\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\370\3\0\0\200\3\0\0\20\11\0\0" ) ) == 0x0 03014 2016 NtResumeThread (1016, ... 1, ) == 0x0 03015 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 174850048, 1048576, ) == 0x0 03016 2016 NtAllocateVirtualMemory (-1, 175890432, 0, 8192, 4096, 4, ... 175890432, 8192, ) == 0x0 03017 2320 NtWaitForSingleObject (88, 0, 0x0, ... 03018 2016 NtProtectVirtualMemory (-1, (0xa7be000), 4096, 260, ... (0xa7be000), 4096, 4, ) == 0x0 03019 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1020, {896, 2324}, ) == 0x0 03020 2016 NtQueryInformationThread (1020, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff1c000,Pid=896,Tid=2324,}, 0x0, ) == 0x0 03021 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82014, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\3\0\0\200\3\0\0\24\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\3\0\0\200\3\0\0\24\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82015, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82014, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\3\0\0\200\3\0\0\24\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\3\0\0\200\3\0\0\24\11\0\0" ) ) == 0x0 03022 2016 NtResumeThread (1020, ... 1, ) == 0x0 03023 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03024 2324 NtWaitForSingleObject (88, 0, 0x0, ... 03023 2016 NtAllocateVirtualMemory ... 175898624, 1048576, ) == 0x0 03025 2016 NtAllocateVirtualMemory (-1, 176939008, 0, 8192, 4096, 4, ... 176939008, 8192, ) == 0x0 03026 2016 NtProtectVirtualMemory (-1, (0xa8be000), 4096, 260, ... (0xa8be000), 4096, 4, ) == 0x0 03027 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1024, {896, 2328}, ) == 0x0 03028 2016 NtQueryInformationThread (1024, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff1b000,Pid=896,Tid=2328,}, 0x0, ) == 0x0 03029 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82015, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\4\0\0\200\3\0\0\30\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\4\0\0\200\3\0\0\30\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82016, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82015, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\4\0\0\200\3\0\0\30\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\0\4\0\0\200\3\0\0\30\11\0\0" ) ) == 0x0 03030 2016 NtResumeThread (1024, ... 1, ) == 0x0 03031 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 176947200, 1048576, ) == 0x0 03032 2016 NtAllocateVirtualMemory (-1, 177987584, 0, 8192, 4096, 4, ... 177987584, 8192, ) == 0x0 03033 2328 NtWaitForSingleObject (88, 0, 0x0, ... 03034 2016 NtProtectVirtualMemory (-1, (0xa9be000), 4096, 260, ... (0xa9be000), 4096, 4, ) == 0x0 03035 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1028, {896, 2332}, ) == 0x0 03036 2016 NtQueryInformationThread (1028, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff1a000,Pid=896,Tid=2332,}, 0x0, ) == 0x0 03037 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82016, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\4\0\0\200\3\0\0\34\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\4\0\0\200\3\0\0\34\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82017, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82016, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\4\0\0\200\3\0\0\34\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\4\0\0\200\3\0\0\34\11\0\0" ) ) == 0x0 03038 2016 NtResumeThread (1028, ... 1, ) == 0x0 03039 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03040 2332 NtWaitForSingleObject (88, 0, 0x0, ... 03039 2016 NtAllocateVirtualMemory ... 177995776, 1048576, ) == 0x0 03041 2016 NtAllocateVirtualMemory (-1, 179036160, 0, 8192, 4096, 4, ... 179036160, 8192, ) == 0x0 03042 2016 NtProtectVirtualMemory (-1, (0xaabe000), 4096, 260, ... (0xaabe000), 4096, 4, ) == 0x0 03043 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1032, {896, 2336}, ) == 0x0 03044 2016 NtQueryInformationThread (1032, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff19000,Pid=896,Tid=2336,}, 0x0, ) == 0x0 03045 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82017, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\4\0\0\200\3\0\0 \11\0\0" ... {28, 56, reply, 0, 896, 2016, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\4\0\0\200\3\0\0 \11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82018, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82017, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\4\0\0\200\3\0\0 \11\0\0" ... {28, 56, reply, 0, 896, 2016, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\10\4\0\0\200\3\0\0 \11\0\0" ) ) == 0x0 03046 2016 NtResumeThread (1032, ... 1, ) == 0x0 03047 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 179044352, 1048576, ) == 0x0 03048 2016 NtAllocateVirtualMemory (-1, 180084736, 0, 8192, 4096, 4, ... 180084736, 8192, ) == 0x0 03049 2336 NtWaitForSingleObject (88, 0, 0x0, ... 03050 2016 NtProtectVirtualMemory (-1, (0xabbe000), 4096, 260, ... (0xabbe000), 4096, 4, ) == 0x0 03051 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1036, {896, 2340}, ) == 0x0 03052 2016 NtQueryInformationThread (1036, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff18000,Pid=896,Tid=2340,}, 0x0, ) == 0x0 03053 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82018, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\4\0\0\200\3\0\0$\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\4\0\0\200\3\0\0$\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82019, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82018, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\4\0\0\200\3\0\0$\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\14\4\0\0\200\3\0\0$\11\0\0" ) ) == 0x0 03054 2016 NtResumeThread (1036, ... 1, ) == 0x0 03055 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03056 2340 NtWaitForSingleObject (88, 0, 0x0, ... 03055 2016 NtAllocateVirtualMemory ... 180092928, 1048576, ) == 0x0 03057 2016 NtAllocateVirtualMemory (-1, 181133312, 0, 8192, 4096, 4, ... 181133312, 8192, ) == 0x0 03058 2016 NtProtectVirtualMemory (-1, (0xacbe000), 4096, 260, ... (0xacbe000), 4096, 4, ) == 0x0 03059 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1040, {896, 2344}, ) == 0x0 03060 2016 NtQueryInformationThread (1040, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff17000,Pid=896,Tid=2344,}, 0x0, ) == 0x0 03061 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82019, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\4\0\0\200\3\0\0(\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\4\0\0\200\3\0\0(\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82020, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82019, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\4\0\0\200\3\0\0(\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\4\0\0\200\3\0\0(\11\0\0" ) ) == 0x0 03062 2016 NtResumeThread (1040, ... 1, ) == 0x0 03063 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 181141504, 1048576, ) == 0x0 03064 2016 NtAllocateVirtualMemory (-1, 182181888, 0, 8192, 4096, 4, ... 182181888, 8192, ) == 0x0 03065 2344 NtWaitForSingleObject (88, 0, 0x0, ... 03066 2016 NtProtectVirtualMemory (-1, (0xadbe000), 4096, 260, ... (0xadbe000), 4096, 4, ) == 0x0 03067 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1044, {896, 2348}, ) == 0x0 03068 2016 NtQueryInformationThread (1044, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff16000,Pid=896,Tid=2348,}, 0x0, ) == 0x0 03069 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82020, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\4\0\0\200\3\0\0,\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\4\0\0\200\3\0\0,\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82021, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82020, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\4\0\0\200\3\0\0,\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\24\4\0\0\200\3\0\0,\11\0\0" ) ) == 0x0 03070 2016 NtResumeThread (1044, ... 1, ) == 0x0 03071 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03072 2348 NtWaitForSingleObject (88, 0, 0x0, ... 03071 2016 NtAllocateVirtualMemory ... 182190080, 1048576, ) == 0x0 03073 2016 NtAllocateVirtualMemory (-1, 183230464, 0, 8192, 4096, 4, ... 183230464, 8192, ) == 0x0 03074 2016 NtProtectVirtualMemory (-1, (0xaebe000), 4096, 260, ... (0xaebe000), 4096, 4, ) == 0x0 03075 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1048, {896, 2352}, ) == 0x0 03076 2016 NtQueryInformationThread (1048, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff15000,Pid=896,Tid=2352,}, 0x0, ) == 0x0 03077 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82021, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\4\0\0\200\3\0\00\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\4\0\0\200\3\0\00\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82022, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82021, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\4\0\0\200\3\0\00\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\30\4\0\0\200\3\0\00\11\0\0" ) ) == 0x0 03078 2016 NtResumeThread (1048, ... 1, ) == 0x0 03079 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 183238656, 1048576, ) == 0x0 03080 2016 NtAllocateVirtualMemory (-1, 184279040, 0, 8192, 4096, 4, ... 184279040, 8192, ) == 0x0 03081 2352 NtWaitForSingleObject (88, 0, 0x0, ... 03082 2016 NtProtectVirtualMemory (-1, (0xafbe000), 4096, 260, ... (0xafbe000), 4096, 4, ) == 0x0 03083 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1052, {896, 2356}, ) == 0x0 03084 2016 NtQueryInformationThread (1052, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff14000,Pid=896,Tid=2356,}, 0x0, ) == 0x0 03085 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82022, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\4\0\0\200\3\0\04\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\4\0\0\200\3\0\04\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82023, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82022, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\4\0\0\200\3\0\04\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\34\4\0\0\200\3\0\04\11\0\0" ) ) == 0x0 03086 2016 NtResumeThread (1052, ... 1, ) == 0x0 03087 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03088 2356 NtWaitForSingleObject (88, 0, 0x0, ... 03087 2016 NtAllocateVirtualMemory ... 184287232, 1048576, ) == 0x0 03089 2016 NtAllocateVirtualMemory (-1, 185327616, 0, 8192, 4096, 4, ... 185327616, 8192, ) == 0x0 03090 2016 NtProtectVirtualMemory (-1, (0xb0be000), 4096, 260, ... (0xb0be000), 4096, 4, ) == 0x0 03091 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1056, {896, 2360}, ) == 0x0 03092 2016 NtQueryInformationThread (1056, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff13000,Pid=896,Tid=2360,}, 0x0, ) == 0x0 03093 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82023, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \4\0\0\200\3\0\08\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \4\0\0\200\3\0\08\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82024, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82023, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \4\0\0\200\3\0\08\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG \4\0\0\200\3\0\08\11\0\0" ) ) == 0x0 03094 2016 NtResumeThread (1056, ... 1, ) == 0x0 03095 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 185335808, 1048576, ) == 0x0 03096 2016 NtAllocateVirtualMemory (-1, 186376192, 0, 8192, 4096, 4, ... 186376192, 8192, ) == 0x0 03097 2360 NtWaitForSingleObject (88, 0, 0x0, ... 03098 2016 NtProtectVirtualMemory (-1, (0xb1be000), 4096, 260, ... (0xb1be000), 4096, 4, ) == 0x0 03099 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1060, {896, 2364}, ) == 0x0 03100 2016 NtQueryInformationThread (1060, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff12000,Pid=896,Tid=2364,}, 0x0, ) == 0x0 03101 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82024, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\4\0\0\200\3\0\0<\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\4\0\0\200\3\0\0<\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82025, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82024, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\4\0\0\200\3\0\0<\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG$\4\0\0\200\3\0\0<\11\0\0" ) ) == 0x0 03102 2016 NtResumeThread (1060, ... 1, ) == 0x0 03103 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03104 2364 NtWaitForSingleObject (88, 0, 0x0, ... 03103 2016 NtAllocateVirtualMemory ... 186384384, 1048576, ) == 0x0 03105 2016 NtAllocateVirtualMemory (-1, 187424768, 0, 8192, 4096, 4, ... 187424768, 8192, ) == 0x0 03106 2016 NtProtectVirtualMemory (-1, (0xb2be000), 4096, 260, ... (0xb2be000), 4096, 4, ) == 0x0 03107 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1064, {896, 2368}, ) == 0x0 03108 2016 NtQueryInformationThread (1064, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff11000,Pid=896,Tid=2368,}, 0x0, ) == 0x0 03109 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82025, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\4\0\0\200\3\0\0@\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\4\0\0\200\3\0\0@\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82026, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82025, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\4\0\0\200\3\0\0@\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG(\4\0\0\200\3\0\0@\11\0\0" ) ) == 0x0 03110 2016 NtResumeThread (1064, ... 1, ) == 0x0 03111 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 187432960, 1048576, ) == 0x0 03112 2016 NtAllocateVirtualMemory (-1, 188473344, 0, 8192, 4096, 4, ... 188473344, 8192, ) == 0x0 03113 2368 NtWaitForSingleObject (88, 0, 0x0, ... 03114 2016 NtProtectVirtualMemory (-1, (0xb3be000), 4096, 260, ... (0xb3be000), 4096, 4, ) == 0x0 03115 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1068, {896, 2372}, ) == 0x0 03116 2016 NtQueryInformationThread (1068, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff10000,Pid=896,Tid=2372,}, 0x0, ) == 0x0 03117 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82026, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\4\0\0\200\3\0\0D\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\4\0\0\200\3\0\0D\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82027, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82026, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\4\0\0\200\3\0\0D\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG,\4\0\0\200\3\0\0D\11\0\0" ) ) == 0x0 03118 2016 NtResumeThread (1068, ... 1, ) == 0x0 03119 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03120 2372 NtWaitForSingleObject (88, 0, 0x0, ... 03119 2016 NtAllocateVirtualMemory ... 188481536, 1048576, ) == 0x0 03121 2016 NtAllocateVirtualMemory (-1, 189521920, 0, 8192, 4096, 4, ... 189521920, 8192, ) == 0x0 03122 2016 NtProtectVirtualMemory (-1, (0xb4be000), 4096, 260, ... (0xb4be000), 4096, 4, ) == 0x0 03123 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1072, {896, 2376}, ) == 0x0 03124 2016 NtQueryInformationThread (1072, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff0f000,Pid=896,Tid=2376,}, 0x0, ) == 0x0 03125 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82027, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\4\0\0\200\3\0\0H\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\4\0\0\200\3\0\0H\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82028, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82027, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\4\0\0\200\3\0\0H\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG0\4\0\0\200\3\0\0H\11\0\0" ) ) == 0x0 03126 2016 NtResumeThread (1072, ... 1, ) == 0x0 03127 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 189530112, 1048576, ) == 0x0 03128 2016 NtAllocateVirtualMemory (-1, 190570496, 0, 8192, 4096, 4, ... 190570496, 8192, ) == 0x0 03129 2376 NtWaitForSingleObject (88, 0, 0x0, ... 03130 2016 NtProtectVirtualMemory (-1, (0xb5be000), 4096, 260, ... (0xb5be000), 4096, 4, ) == 0x0 03131 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1076, {896, 2380}, ) == 0x0 03132 2016 NtQueryInformationThread (1076, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff0e000,Pid=896,Tid=2380,}, 0x0, ) == 0x0 03133 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82028, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\4\0\0\200\3\0\0L\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\4\0\0\200\3\0\0L\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82029, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82028, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\4\0\0\200\3\0\0L\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG4\4\0\0\200\3\0\0L\11\0\0" ) ) == 0x0 03134 2016 NtResumeThread (1076, ... 1, ) == 0x0 03135 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03136 2380 NtWaitForSingleObject (88, 0, 0x0, ... 03135 2016 NtAllocateVirtualMemory ... 190578688, 1048576, ) == 0x0 03137 2016 NtAllocateVirtualMemory (-1, 191619072, 0, 8192, 4096, 4, ... 191619072, 8192, ) == 0x0 03138 2016 NtProtectVirtualMemory (-1, (0xb6be000), 4096, 260, ... (0xb6be000), 4096, 4, ) == 0x0 03139 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1080, {896, 2384}, ) == 0x0 03140 2016 NtQueryInformationThread (1080, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff0d000,Pid=896,Tid=2384,}, 0x0, ) == 0x0 03141 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82029, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\4\0\0\200\3\0\0P\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\4\0\0\200\3\0\0P\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82030, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82029, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\4\0\0\200\3\0\0P\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG8\4\0\0\200\3\0\0P\11\0\0" ) ) == 0x0 03142 2016 NtResumeThread (1080, ... 1, ) == 0x0 03143 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 191627264, 1048576, ) == 0x0 03144 2016 NtAllocateVirtualMemory (-1, 192667648, 0, 8192, 4096, 4, ... 192667648, 8192, ) == 0x0 03145 2384 NtWaitForSingleObject (88, 0, 0x0, ... 03146 2016 NtProtectVirtualMemory (-1, (0xb7be000), 4096, 260, ... (0xb7be000), 4096, 4, ) == 0x0 03147 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03148 1028 NtProtectVirtualMemory (-1, (0x76f61000), 4096, 32, ... (0x76f61000), 4096, 4, ) == 0x0 03149 1028 NtFlushInstructionCache (-1, 1995837440, 228, ... 03147 2016 NtCreateThread ... 1084, {896, 2388}, ) == 0x0 03150 2016 NtQueryInformationThread (1084, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff0c000,Pid=896,Tid=2388,}, 0x0, ) == 0x0 03151 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82030, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\4\0\0\200\3\0\0T\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\4\0\0\200\3\0\0T\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82031, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82030, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\4\0\0\200\3\0\0T\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG<\4\0\0\200\3\0\0T\11\0\0" ) ) == 0x0 03152 2016 NtResumeThread (1084, ... 1, ) == 0x0 03153 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 192675840, 1048576, ) == 0x0 03154 2016 NtAllocateVirtualMemory (-1, 193716224, 0, 8192, 4096, 4, ... 193716224, 8192, ) == 0x0 03149 1028 NtFlushInstructionCache ... ) == 0x0 03155 2388 NtWaitForSingleObject (88, 0, 0x0, ... 03156 1028 NtProtectVirtualMemory (-1, (0x76f61000), 228, 4, ... (0x76f61000), 4096, 32, ) == 0x0 03157 1028 NtProtectVirtualMemory (-1, (0x76f61000), 4096, 32, ... (0x76f61000), 4096, 4, ) == 0x0 03158 1028 NtFlushInstructionCache (-1, 1995837440, 228, ... ) == 0x0 03159 1028 NtProtectVirtualMemory (-1, (0x76fb1000), 232, 4, ... (0x76fb1000), 4096, 32, ) == 0x0 03160 1028 NtProtectVirtualMemory (-1, (0x76fb1000), 4096, 32, ... (0x76fb1000), 4096, 4, ) == 0x0 03161 1028 NtFlushInstructionCache (-1, 1996165120, 232, ... 03162 2016 NtProtectVirtualMemory (-1, (0xb8be000), 4096, 260, ... (0xb8be000), 4096, 4, ) == 0x0 03163 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1088, {896, 2392}, ) == 0x0 03164 2016 NtQueryInformationThread (1088, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff0b000,Pid=896,Tid=2392,}, 0x0, ) == 0x0 03165 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82031, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\4\0\0\200\3\0\0X\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\4\0\0\200\3\0\0X\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82032, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82031, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\4\0\0\200\3\0\0X\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG@\4\0\0\200\3\0\0X\11\0\0" ) ) == 0x0 03166 2016 NtResumeThread (1088, ... 1, ) == 0x0 03167 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03161 1028 NtFlushInstructionCache ... ) == 0x0 03168 2392 NtWaitForSingleObject (88, 0, 0x0, ... 03167 2016 NtAllocateVirtualMemory ... 193724416, 1048576, ) == 0x0 03169 2016 NtAllocateVirtualMemory (-1, 194764800, 0, 8192, 4096, 4, ... 194764800, 8192, ) == 0x0 03170 2016 NtProtectVirtualMemory (-1, (0xb9be000), 4096, 260, ... (0xb9be000), 4096, 4, ) == 0x0 03171 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1092, {896, 2396}, ) == 0x0 03172 2016 NtQueryInformationThread (1092, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff0a000,Pid=896,Tid=2396,}, 0x0, ) == 0x0 03173 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82032, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\4\0\0\200\3\0\0\\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\4\0\0\200\3\0\0\\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82033, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82032, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\4\0\0\200\3\0\0\\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGD\4\0\0\200\3\0\0\\11\0\0" ) ) == 0x0 03174 2016 NtResumeThread (1092, ... 1, ) == 0x0 03175 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 194772992, 1048576, ) == 0x0 03176 2016 NtAllocateVirtualMemory (-1, 195813376, 0, 8192, 4096, 4, ... 195813376, 8192, ) == 0x0 03177 2396 NtWaitForSingleObject (88, 0, 0x0, ... 03178 2016 NtProtectVirtualMemory (-1, (0xbabe000), 4096, 260, ... (0xbabe000), 4096, 4, ) == 0x0 03179 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1096, {896, 2400}, ) == 0x0 03180 2016 NtQueryInformationThread (1096, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff09000,Pid=896,Tid=2400,}, 0x0, ) == 0x0 03181 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82033, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\4\0\0\200\3\0\0`\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\4\0\0\200\3\0\0`\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82034, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82033, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\4\0\0\200\3\0\0`\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGH\4\0\0\200\3\0\0`\11\0\0" ) ) == 0x0 03182 2016 NtResumeThread (1096, ... 1, ) == 0x0 03183 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03184 2400 NtWaitForSingleObject (88, 0, 0x0, ... 03183 2016 NtAllocateVirtualMemory ... 195821568, 1048576, ) == 0x0 03185 2016 NtAllocateVirtualMemory (-1, 196861952, 0, 8192, 4096, 4, ... 196861952, 8192, ) == 0x0 03186 2016 NtProtectVirtualMemory (-1, (0xbbbe000), 4096, 260, ... (0xbbbe000), 4096, 4, ) == 0x0 03187 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1100, {896, 2404}, ) == 0x0 03188 2016 NtQueryInformationThread (1100, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff08000,Pid=896,Tid=2404,}, 0x0, ) == 0x0 03189 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82034, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\4\0\0\200\3\0\0d\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\4\0\0\200\3\0\0d\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82035, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82034, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\4\0\0\200\3\0\0d\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGL\4\0\0\200\3\0\0d\11\0\0" ) ) == 0x0 03190 2016 NtResumeThread (1100, ... 1, ) == 0x0 03191 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 196870144, 1048576, ) == 0x0 03192 2016 NtAllocateVirtualMemory (-1, 197910528, 0, 8192, 4096, 4, ... 197910528, 8192, ) == 0x0 03193 2404 NtWaitForSingleObject (88, 0, 0x0, ... 03194 2016 NtProtectVirtualMemory (-1, (0xbcbe000), 4096, 260, ... (0xbcbe000), 4096, 4, ) == 0x0 03195 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1104, {896, 2408}, ) == 0x0 03196 2016 NtQueryInformationThread (1104, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff07000,Pid=896,Tid=2408,}, 0x0, ) == 0x0 03197 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82035, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\4\0\0\200\3\0\0h\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\4\0\0\200\3\0\0h\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82036, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82035, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\4\0\0\200\3\0\0h\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\4\0\0\200\3\0\0h\11\0\0" ) ) == 0x0 03198 2016 NtResumeThread (1104, ... 1, ) == 0x0 03199 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03200 2408 NtWaitForSingleObject (88, 0, 0x0, ... 03199 2016 NtAllocateVirtualMemory ... 197918720, 1048576, ) == 0x0 03201 2016 NtAllocateVirtualMemory (-1, 198959104, 0, 8192, 4096, 4, ... 198959104, 8192, ) == 0x0 03202 2016 NtProtectVirtualMemory (-1, (0xbdbe000), 4096, 260, ... (0xbdbe000), 4096, 4, ) == 0x0 03203 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1108, {896, 2412}, ) == 0x0 03204 2016 NtQueryInformationThread (1108, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff06000,Pid=896,Tid=2412,}, 0x0, ) == 0x0 03205 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82036, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\4\0\0\200\3\0\0l\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\4\0\0\200\3\0\0l\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82037, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82036, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\4\0\0\200\3\0\0l\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\4\0\0\200\3\0\0l\11\0\0" ) ) == 0x0 03206 2016 NtResumeThread (1108, ... 1, ) == 0x0 03207 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 198967296, 1048576, ) == 0x0 03208 2016 NtAllocateVirtualMemory (-1, 200007680, 0, 8192, 4096, 4, ... 200007680, 8192, ) == 0x0 03209 2412 NtWaitForSingleObject (88, 0, 0x0, ... 03210 2016 NtProtectVirtualMemory (-1, (0xbebe000), 4096, 260, ... (0xbebe000), 4096, 4, ) == 0x0 03211 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1112, {896, 2416}, ) == 0x0 03212 2016 NtQueryInformationThread (1112, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff05000,Pid=896,Tid=2416,}, 0x0, ) == 0x0 03213 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82037, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\4\0\0\200\3\0\0p\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\4\0\0\200\3\0\0p\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82038, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82037, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\4\0\0\200\3\0\0p\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\4\0\0\200\3\0\0p\11\0\0" ) ) == 0x0 03214 2016 NtResumeThread (1112, ... 1, ) == 0x0 03215 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03216 2416 NtWaitForSingleObject (88, 0, 0x0, ... 03215 2016 NtAllocateVirtualMemory ... 200015872, 1048576, ) == 0x0 03217 2016 NtAllocateVirtualMemory (-1, 201056256, 0, 8192, 4096, 4, ... 201056256, 8192, ) == 0x0 03218 2016 NtProtectVirtualMemory (-1, (0xbfbe000), 4096, 260, ... (0xbfbe000), 4096, 4, ) == 0x0 03219 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1116, {896, 2420}, ) == 0x0 03220 2016 NtQueryInformationThread (1116, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff04000,Pid=896,Tid=2420,}, 0x0, ) == 0x0 03221 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82038, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\4\0\0\200\3\0\0t\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\4\0\0\200\3\0\0t\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82039, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82038, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\4\0\0\200\3\0\0t\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\4\0\0\200\3\0\0t\11\0\0" ) ) == 0x0 03222 2016 NtResumeThread (1116, ... 1, ) == 0x0 03223 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 201064448, 1048576, ) == 0x0 03224 2016 NtAllocateVirtualMemory (-1, 202104832, 0, 8192, 4096, 4, ... 202104832, 8192, ) == 0x0 03225 2420 NtWaitForSingleObject (88, 0, 0x0, ... 03226 2016 NtProtectVirtualMemory (-1, (0xc0be000), 4096, 260, ... (0xc0be000), 4096, 4, ) == 0x0 03227 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1120, {896, 2424}, ) == 0x0 03228 2016 NtQueryInformationThread (1120, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff03000,Pid=896,Tid=2424,}, 0x0, ) == 0x0 03229 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82039, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\4\0\0\200\3\0\0x\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\4\0\0\200\3\0\0x\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82040, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82039, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\4\0\0\200\3\0\0x\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\4\0\0\200\3\0\0x\11\0\0" ) ) == 0x0 03230 2016 NtResumeThread (1120, ... 1, ) == 0x0 03231 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03232 2424 NtWaitForSingleObject (88, 0, 0x0, ... 03231 2016 NtAllocateVirtualMemory ... 202113024, 1048576, ) == 0x0 03233 2016 NtAllocateVirtualMemory (-1, 203153408, 0, 8192, 4096, 4, ... 203153408, 8192, ) == 0x0 03234 2016 NtProtectVirtualMemory (-1, (0xc1be000), 4096, 260, ... (0xc1be000), 4096, 4, ) == 0x0 03235 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1124, {896, 2428}, ) == 0x0 03236 2016 NtQueryInformationThread (1124, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff02000,Pid=896,Tid=2428,}, 0x0, ) == 0x0 03237 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82040, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\4\0\0\200\3\0\0|\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\4\0\0\200\3\0\0|\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82041, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82040, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\4\0\0\200\3\0\0|\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGd\4\0\0\200\3\0\0|\11\0\0" ) ) == 0x0 03238 2016 NtResumeThread (1124, ... 1, ) == 0x0 03239 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 203161600, 1048576, ) == 0x0 03240 2016 NtAllocateVirtualMemory (-1, 204201984, 0, 8192, 4096, 4, ... 204201984, 8192, ) == 0x0 03241 2428 NtWaitForSingleObject (88, 0, 0x0, ... 03242 2016 NtProtectVirtualMemory (-1, (0xc2be000), 4096, 260, ... (0xc2be000), 4096, 4, ) == 0x0 03243 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1128, {896, 2432}, ) == 0x0 03244 2016 NtQueryInformationThread (1128, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff01000,Pid=896,Tid=2432,}, 0x0, ) == 0x0 03245 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82041, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\4\0\0\200\3\0\0\200\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\4\0\0\200\3\0\0\200\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82042, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82041, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\4\0\0\200\3\0\0\200\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGh\4\0\0\200\3\0\0\200\11\0\0" ) ) == 0x0 03246 2016 NtResumeThread (1128, ... 1, ) == 0x0 03247 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03248 2432 NtWaitForSingleObject (88, 0, 0x0, ... 03247 2016 NtAllocateVirtualMemory ... 204210176, 1048576, ) == 0x0 03249 2016 NtAllocateVirtualMemory (-1, 205250560, 0, 8192, 4096, 4, ... 205250560, 8192, ) == 0x0 03250 2016 NtProtectVirtualMemory (-1, (0xc3be000), 4096, 260, ... (0xc3be000), 4096, 4, ) == 0x0 03251 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1132, {896, 2436}, ) == 0x0 03252 2016 NtQueryInformationThread (1132, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff00000,Pid=896,Tid=2436,}, 0x0, ) == 0x0 03253 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82042, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\4\0\0\200\3\0\0\204\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\4\0\0\200\3\0\0\204\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82043, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82042, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\4\0\0\200\3\0\0\204\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGl\4\0\0\200\3\0\0\204\11\0\0" ) ) == 0x0 03254 2016 NtResumeThread (1132, ... 1, ) == 0x0 03255 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 205258752, 1048576, ) == 0x0 03256 2016 NtAllocateVirtualMemory (-1, 206299136, 0, 8192, 4096, 4, ... 206299136, 8192, ) == 0x0 03257 2436 NtWaitForSingleObject (88, 0, 0x0, ... 03258 2016 NtProtectVirtualMemory (-1, (0xc4be000), 4096, 260, ... (0xc4be000), 4096, 4, ) == 0x0 03259 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1136, {896, 2440}, ) == 0x0 03260 2016 NtQueryInformationThread (1136, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7feff000,Pid=896,Tid=2440,}, 0x0, ) == 0x0 03261 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82043, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\4\0\0\200\3\0\0\210\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\4\0\0\200\3\0\0\210\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82044, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82043, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\4\0\0\200\3\0\0\210\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGp\4\0\0\200\3\0\0\210\11\0\0" ) ) == 0x0 03262 2016 NtResumeThread (1136, ... 1, ) == 0x0 03263 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03264 2440 NtWaitForSingleObject (88, 0, 0x0, ... 03263 2016 NtAllocateVirtualMemory ... 206307328, 1048576, ) == 0x0 03265 2016 NtAllocateVirtualMemory (-1, 207347712, 0, 8192, 4096, 4, ... 207347712, 8192, ) == 0x0 03266 2016 NtProtectVirtualMemory (-1, (0xc5be000), 4096, 260, ... (0xc5be000), 4096, 4, ) == 0x0 03267 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1140, {896, 2444}, ) == 0x0 03268 2016 NtQueryInformationThread (1140, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fefe000,Pid=896,Tid=2444,}, 0x0, ) == 0x0 03269 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82044, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\4\0\0\200\3\0\0\214\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\4\0\0\200\3\0\0\214\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82045, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82044, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\4\0\0\200\3\0\0\214\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGt\4\0\0\200\3\0\0\214\11\0\0" ) ) == 0x0 03270 2016 NtResumeThread (1140, ... 1, ) == 0x0 03271 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 207355904, 1048576, ) == 0x0 03272 2016 NtAllocateVirtualMemory (-1, 208396288, 0, 8192, 4096, 4, ... 208396288, 8192, ) == 0x0 03273 2444 NtWaitForSingleObject (88, 0, 0x0, ... 03274 2016 NtProtectVirtualMemory (-1, (0xc6be000), 4096, 260, ... (0xc6be000), 4096, 4, ) == 0x0 03275 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1144, {896, 2448}, ) == 0x0 03276 2016 NtQueryInformationThread (1144, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fefd000,Pid=896,Tid=2448,}, 0x0, ) == 0x0 03277 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82045, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\4\0\0\200\3\0\0\220\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\4\0\0\200\3\0\0\220\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82046, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82045, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\4\0\0\200\3\0\0\220\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGx\4\0\0\200\3\0\0\220\11\0\0" ) ) == 0x0 03278 2016 NtResumeThread (1144, ... 1, ) == 0x0 03279 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03280 2448 NtWaitForSingleObject (88, 0, 0x0, ... 03279 2016 NtAllocateVirtualMemory ... 208404480, 1048576, ) == 0x0 03281 2016 NtAllocateVirtualMemory (-1, 209444864, 0, 8192, 4096, 4, ... 209444864, 8192, ) == 0x0 03282 2016 NtProtectVirtualMemory (-1, (0xc7be000), 4096, 260, ... (0xc7be000), 4096, 4, ) == 0x0 03283 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1148, {896, 2452}, ) == 0x0 03284 2016 NtQueryInformationThread (1148, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fefc000,Pid=896,Tid=2452,}, 0x0, ) == 0x0 03285 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82046, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\4\0\0\200\3\0\0\224\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\4\0\0\200\3\0\0\224\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82047, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82046, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\4\0\0\200\3\0\0\224\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG|\4\0\0\200\3\0\0\224\11\0\0" ) ) == 0x0 03286 2016 NtResumeThread (1148, ... 1, ) == 0x0 03287 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 209453056, 1048576, ) == 0x0 03288 2016 NtAllocateVirtualMemory (-1, 210493440, 0, 8192, 4096, 4, ... 210493440, 8192, ) == 0x0 03289 2452 NtWaitForSingleObject (88, 0, 0x0, ... 03290 2016 NtProtectVirtualMemory (-1, (0xc8be000), 4096, 260, ... (0xc8be000), 4096, 4, ) == 0x0 03291 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1152, {896, 2456}, ) == 0x0 03292 2016 NtQueryInformationThread (1152, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fefb000,Pid=896,Tid=2456,}, 0x0, ) == 0x0 03293 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82047, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\4\0\0\200\3\0\0\230\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\4\0\0\200\3\0\0\230\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82048, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82047, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\4\0\0\200\3\0\0\230\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\200\4\0\0\200\3\0\0\230\11\0\0" ) ) == 0x0 03294 2016 NtResumeThread (1152, ... 1, ) == 0x0 03295 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03296 2456 NtWaitForSingleObject (88, 0, 0x0, ... 03295 2016 NtAllocateVirtualMemory ... 210501632, 1048576, ) == 0x0 03297 2016 NtAllocateVirtualMemory (-1, 211542016, 0, 8192, 4096, 4, ... 211542016, 8192, ) == 0x0 03298 2016 NtProtectVirtualMemory (-1, (0xc9be000), 4096, 260, ... (0xc9be000), 4096, 4, ) == 0x0 03299 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1156, {896, 2460}, ) == 0x0 03300 2016 NtQueryInformationThread (1156, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fefa000,Pid=896,Tid=2460,}, 0x0, ) == 0x0 03301 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82048, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\4\0\0\200\3\0\0\234\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82049, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\4\0\0\200\3\0\0\234\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82049, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82048, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\4\0\0\200\3\0\0\234\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82049, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\204\4\0\0\200\3\0\0\234\11\0\0" ) ) == 0x0 03302 2016 NtResumeThread (1156, ... 1, ) == 0x0 03303 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 211550208, 1048576, ) == 0x0 03304 2016 NtAllocateVirtualMemory (-1, 212590592, 0, 8192, 4096, 4, ... 212590592, 8192, ) == 0x0 03305 2460 NtWaitForSingleObject (88, 0, 0x0, ... 03306 2016 NtProtectVirtualMemory (-1, (0xcabe000), 4096, 260, ... (0xcabe000), 4096, 4, ) == 0x0 03307 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1160, {896, 2464}, ) == 0x0 03308 2016 NtQueryInformationThread (1160, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fef9000,Pid=896,Tid=2464,}, 0x0, ) == 0x0 03309 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82049, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82049, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\4\0\0\200\3\0\0\240\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82050, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\4\0\0\200\3\0\0\240\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82050, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82049, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\4\0\0\200\3\0\0\240\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82050, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\210\4\0\0\200\3\0\0\240\11\0\0" ) ) == 0x0 03310 2016 NtResumeThread (1160, ... 1, ) == 0x0 03311 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03312 2464 NtWaitForSingleObject (88, 0, 0x0, ... 03311 2016 NtAllocateVirtualMemory ... 212598784, 1048576, ) == 0x0 03313 2016 NtAllocateVirtualMemory (-1, 213639168, 0, 8192, 4096, 4, ... 213639168, 8192, ) == 0x0 03314 2016 NtProtectVirtualMemory (-1, (0xcbbe000), 4096, 260, ... (0xcbbe000), 4096, 4, ) == 0x0 03315 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1164, {896, 2468}, ) == 0x0 03316 2016 NtQueryInformationThread (1164, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fef8000,Pid=896,Tid=2468,}, 0x0, ) == 0x0 03317 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82050, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82050, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\4\0\0\200\3\0\0\244\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82051, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\4\0\0\200\3\0\0\244\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82051, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82050, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\4\0\0\200\3\0\0\244\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82051, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\214\4\0\0\200\3\0\0\244\11\0\0" ) ) == 0x0 03318 2016 NtResumeThread (1164, ... 1, ) == 0x0 03319 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 213647360, 1048576, ) == 0x0 03320 2016 NtAllocateVirtualMemory (-1, 214687744, 0, 8192, 4096, 4, ... 214687744, 8192, ) == 0x0 03321 2468 NtWaitForSingleObject (88, 0, 0x0, ... 03322 2016 NtProtectVirtualMemory (-1, (0xccbe000), 4096, 260, ... (0xccbe000), 4096, 4, ) == 0x0 03323 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1168, {896, 2472}, ) == 0x0 03324 2016 NtQueryInformationThread (1168, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fef7000,Pid=896,Tid=2472,}, 0x0, ) == 0x0 03325 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82051, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82051, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\4\0\0\200\3\0\0\250\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82052, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\4\0\0\200\3\0\0\250\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82052, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82051, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\4\0\0\200\3\0\0\250\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82052, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\220\4\0\0\200\3\0\0\250\11\0\0" ) ) == 0x0 03326 2016 NtResumeThread (1168, ... 1, ) == 0x0 03327 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03328 2472 NtWaitForSingleObject (88, 0, 0x0, ... 03327 2016 NtAllocateVirtualMemory ... 214695936, 1048576, ) == 0x0 03329 2016 NtAllocateVirtualMemory (-1, 215736320, 0, 8192, 4096, 4, ... 215736320, 8192, ) == 0x0 03330 2016 NtProtectVirtualMemory (-1, (0xcdbe000), 4096, 260, ... (0xcdbe000), 4096, 4, ) == 0x0 03331 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1172, {896, 2476}, ) == 0x0 03332 2016 NtQueryInformationThread (1172, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fef6000,Pid=896,Tid=2476,}, 0x0, ) == 0x0 03333 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82052, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82052, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\4\0\0\200\3\0\0\254\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82053, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\4\0\0\200\3\0\0\254\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82053, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82052, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\4\0\0\200\3\0\0\254\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82053, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\224\4\0\0\200\3\0\0\254\11\0\0" ) ) == 0x0 03334 2016 NtResumeThread (1172, ... 1, ) == 0x0 03335 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 215744512, 1048576, ) == 0x0 03336 2016 NtAllocateVirtualMemory (-1, 216784896, 0, 8192, 4096, 4, ... 216784896, 8192, ) == 0x0 03337 2476 NtWaitForSingleObject (88, 0, 0x0, ... 03338 2016 NtProtectVirtualMemory (-1, (0xcebe000), 4096, 260, ... (0xcebe000), 4096, 4, ) == 0x0 03339 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1176, {896, 2480}, ) == 0x0 03340 2016 NtQueryInformationThread (1176, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7fef5000,Pid=896,Tid=2480,}, 0x0, ) == 0x0 03341 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82053, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82053, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\4\0\0\200\3\0\0\260\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82054, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\4\0\0\200\3\0\0\260\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82054, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82053, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\4\0\0\200\3\0\0\260\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82054, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\230\4\0\0\200\3\0\0\260\11\0\0" ) ) == 0x0 03342 2016 NtResumeThread (1176, ... 1, ) == 0x0 03343 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03344 2480 NtWaitForSingleObject (88, 0, 0x0, ... 03343 2016 NtAllocateVirtualMemory ... 216793088, 1048576, ) == 0x0 03345 2016 NtAllocateVirtualMemory (-1, 217833472, 0, 8192, 4096, 4, ... 217833472, 8192, ) == 0x0 03346 2016 NtProtectVirtualMemory (-1, (0xcfbe000), 4096, 260, ... (0xcfbe000), 4096, 4, ) == 0x0 03347 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 1180, {896, 2484}, ) == 0x0 03348 2016 NtQueryInformationThread (1180, Basic, 28, ... 03349 1028 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WLDAP32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03350 1028 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 1184, ) == 0x0 03351 1028 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\LDAP"}, ... 1188, ) }, ... 1188, ) == 0x0 03352 1028 NtQueryValueKey (1188, (1188, "LdapClientIntegrity", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (1188, "LdapClientIntegrity", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03353 1028 NtClose (1188, ... 03348 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7fef4000,Pid=896,Tid=2484,}, 0x0, ) == 0x0 03354 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82054, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82054, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\4\0\0\200\3\0\0\264\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82055, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\4\0\0\200\3\0\0\264\11\0\0" ) ... {28, 56, reply, 0, 896, 2016, 82055, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82054, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\4\0\0\200\3\0\0\264\11\0\0" ... {28, 56, reply, 0, 896, 2016, 82055, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\234\4\0\0\200\3\0\0\264\11\0\0" ) ) == 0x0 03355 2016 NtResumeThread (1180, ... 1, ) == 0x0 03356 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 217841664, 1048576, ) == 0x0 03357 2016 NtAllocateVirtualMemory (-1, 218882048, 0, 8192, 4096, 4, ... 218882048, 8192, ) == 0x0 03353 1028 NtClose ... ) == 0x0 02245 596 NtRequestWaitReplyPort ... {44, 68, reply, 0, 896, 596, 81918, 0} ... {44, 68, reply, 0, 896, 596, 81918, 0} "\4\376\255\201\0\0\0\0\200Y\274\201\356\12$\342\264\311\275\201:\332R\200X\253v\367\324\376\255\201\2\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 03358 2484 NtWaitForSingleObject (88, 0, 0x0, ... 03359 1028 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrnr.dll"}, ... }, ... 03360 596 NtRaiseException (11008528, 11007788, 1, ... 03359 1028 NtOpenKey ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03361 596 NtQueryVirtualMemory (-1, 0x77ea0470, BasicVlm, 16, ... 03362 1028 NtQueryPerformanceCounter (... 03361 596 NtQueryVirtualMemory ... {memory info, class 3, size 16}, 0x0, ) == 0x0 03363 2016 NtProtectVirtualMemory (-1, (0xd0be000), 4096, 260, ... 03364 596 NtQueryVirtualMemory (-1, 0x77e7a298, Basic, 28, ... 03363 2016 NtProtectVirtualMemory ... (0xd0be000), 4096, 4, ) == 0x0 03364 596 NtQueryVirtualMemory ... {BaseAddress=0x77e7a000,AllocationBase=0x77e70000,AllocationProtect=0x80,RegionSize=0x80000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 03365 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03362 1028 NtQueryPerformanceCounter ... {-1448496027, 16}, {3579545, 0}, ) == 0x0 03366 1028 NtSetEventBoostPriority (88, ... 02181 780 NtWaitForSingleObject ... ) == 0x0 03367 780 NtSetEventBoostPriority (88, ... 02195 940 NtWaitForSingleObject ... ) == 0x0 03368 940 NtSetEventBoostPriority (88, ... 02218 1268 NtWaitForSingleObject ... ) == 0x0 03369 1268 NtSetEventBoostPriority (88, ... 02242 644 NtWaitForSingleObject ... ) == 0x0 03370 644 NtSetEventBoostPriority (88, ... 02257 1736 NtWaitForSingleObject ... ) == 0x0 03371 1736 NtSetEventBoostPriority (88, ... 02264 320 NtWaitForSingleObject ... ) == 0x0 03372 320 NtSetEventBoostPriority (88, ... 02273 380 NtWaitForSingleObject ... ) == 0x0 03373 380 NtSetEventBoostPriority (88, ... 02280 1332 NtWaitForSingleObject ... ) == 0x0 03374 1332 NtSetEventBoostPriority (88, ... 02289 1336 NtWaitForSingleObject ... ) == 0x0 03375 1336 NtSetEventBoostPriority (88, ... 02296 1808 NtWaitForSingleObject ... ) == 0x0 03376 1808 NtSetEventBoostPriority (88, ... 02305 468 NtWaitForSingleObject ... ) == 0x0 03377 468 NtSetEventBoostPriority (88, ... 02312 752 NtWaitForSingleObject ... ) == 0x0 03378 752 NtSetEventBoostPriority (88, ... 02321 1512 NtWaitForSingleObject ... ) == 0x0 03379 1512 NtSetEventBoostPriority (88, ... 02329 1380 NtWaitForSingleObject ... ) == 0x0 03380 1380 NtSetEventBoostPriority (88, ... 02336 1564 NtWaitForSingleObject ... ) == 0x0 03381 1564 NtSetEventBoostPriority (88, ... 02345 164 NtWaitForSingleObject ... ) == 0x0 03382 164 NtSetEventBoostPriority (88, ... 02352 312 NtWaitForSingleObject ... ) == 0x0 03383 312 NtSetEventBoostPriority (88, ... 02361 1964 NtWaitForSingleObject ... ) == 0x0 03384 1964 NtSetEventBoostPriority (88, ... 02368 1568 NtWaitForSingleObject ... ) == 0x0 03385 1568 NtSetEventBoostPriority (88, ... 02377 1624 NtWaitForSingleObject ... ) == 0x0 03386 1624 NtSetEventBoostPriority (88, ... 02384 1716 NtWaitForSingleObject ... ) == 0x0 03387 1716 NtSetEventBoostPriority (88, ... 02393 1440 NtWaitForSingleObject ... ) == 0x0 03388 1440 NtSetEventBoostPriority (88, ... 02400 1664 NtWaitForSingleObject ... ) == 0x0 03389 1664 NtAllocateVirtualMemory (-1, 8810496, 0, 4096, 4096, 4, ... 8810496, 4096, ) == 0x0 03388 1440 NtSetEventBoostPriority ... ) == 0x0 03387 1716 NtSetEventBoostPriority ... ) == 0x0 03386 1624 NtSetEventBoostPriority ... ) == 0x0 03385 1568 NtSetEventBoostPriority ... ) == 0x0 03384 1964 NtSetEventBoostPriority ... ) == 0x0 03383 312 NtSetEventBoostPriority ... ) == 0x0 03382 164 NtSetEventBoostPriority ... ) == 0x0 03381 1564 NtSetEventBoostPriority ... ) == 0x0 03380 1380 NtSetEventBoostPriority ... ) == 0x0 03379 1512 NtSetEventBoostPriority ... ) == 0x0 03378 752 NtSetEventBoostPriority ... ) == 0x0 03377 468 NtSetEventBoostPriority ... ) == 0x0 03376 1808 NtSetEventBoostPriority ... ) == 0x0 03375 1336 NtSetEventBoostPriority ... ) == 0x0 03374 1332 NtSetEventBoostPriority ... ) == 0x0 03373 380 NtSetEventBoostPriority ... ) == 0x0 03372 320 NtSetEventBoostPriority ... ) == 0x0 03371 1736 NtSetEventBoostPriority ... ) == 0x0 03370 644 NtSetEventBoostPriority ... ) == 0x0 03369 1268 NtSetEventBoostPriority ... ) == 0x0 03368 940 NtSetEventBoostPriority ... ) == 0x0 03367 780 NtSetEventBoostPriority ... ) == 0x0 03366 1028 NtSetEventBoostPriority ... ) == 0x0 03390 596 NtContinue (11006756, 0, ... 03365 2016 NtCreateThread ... 1188, {896, 2488}, ) == 0x0 03391 1664 NtAllocateVirtualMemory (-1, 1404928, 0, 4096, 4096, 4, ... 03392 1440 NtTestAlert (... 03393 1716 NtTestAlert (... 03394 1624 NtTestAlert (... 03395 1568 NtTestAlert (... 03396 1964 NtTestAlert (... 03397 312 NtTestAlert (... 03398 164 NtTestAlert (... 03399 1564 NtTestAlert (... 03400 1380 NtTestAlert (... 03401 1512 NtTestAlert (... 03402 752 NtTestAlert (... 03403 468 NtTestAlert (... 03404 1808 NtTestAlert (... 03405 1336 NtTestAlert (... 03406 1332 NtTestAlert (... 03407 380 NtTestAlert (... 03408 320 NtTestAlert (... 03409 1736 NtTestAlert (... 03410 644 NtTestAlert (... 03411 1268 NtTestAlert (... 03412 940 NtTestAlert (... 03413 1028 NtWaitForSingleObject (88, 0, 0x0, ... 03414 596 NtDeviceIoControlFile (460, 96, 0x0, 0x0, 0x1200c, 0x0, 0, 26, ... 03415 2016 NtQueryInformationThread (1188, Basic, 28, ... 03391 1664 NtAllocateVirtualMemory ... 1404928, 4096, ) == 0x0 03392 1440 NtTestAlert ... ) == 0x0 03393 1716 NtTestAlert ... ) == 0x0 03394 1624 NtTestAlert ... ) == 0x0 03395 1568 NtTestAlert ... ) == 0x0 03396 1964 NtTestAlert ... ) == 0x0 03397 312 NtTestAlert ... ) == 0x0 03398 164 NtTestAlert ... ) == 0x0 03399 1564 NtTestAlert ... ) == 0x0 03400 1380 NtTestAlert ... ) == 0x0 03401 1512 NtTestAlert ... ) == 0x0 03402 752 NtTestAlert ... ) == 0x0 03403 468 NtTestAlert ... ) == 0x0 03404 1808 NtTestAlert ... ) == 0x0 03405 1336 NtTestAlert ... ) == 0x0 03406 1332 NtTestAlert ... ) == 0x0 03407 380 NtTestAlert ... ) == 0x0 03408 320 NtTestAlert ... ) == 0x0 03409 1736 NtTestAlert ... ) == 0x0 03410 644 NtTestAlert ... ) == 0x0 03411 1268 NtTestAlert ... ) == 0x0 03412 940 NtTestAlert ... ) == 0x0 03414 596 NtDeviceIoControlFile ... {status=0x0, info=0}, "", ) == 0x103 03415 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7fef3000,Pid=896,Tid=2488,}, 0x0, ) == 0x0 03416 1664 NtSetEventBoostPriority (88, ... 03417 1440 NtContinue (93060400, 1, ... 03418 1716 NtContinue (92011824, 1, ... 03419 1624 NtContinue (90963248, 1, ... 03420 1568 NtContinue (89914672, 1, ... 03421 1964 NtContinue (88866096, 1, ... 03422 312 NtContinue (87817520, 1, ... 03423 164 NtContinue (86768944, 1, ... 03424 1564 NtContinue (85720368, 1, ... 03425 1380 NtContinue (84671792, 1, ... 03426 1512 NtContinue (83623216, 1, ... 03427 752 NtContinue (82574640, 1, ... 03428 468 NtContinue (81526064, 1, ... 03429 1808 NtContinue (80477488, 1, ... 03430 1336 NtContinue (79428912, 1, ... 03431 1332 NtContinue (78380336, 1, ... 03432 380 NtContinue (77331760, 1, ... 03433 320 NtContinue (76283184, 1, ... 03434 1736 NtContinue (75234608, 1, ... 03435 644 NtContinue (74186032, 1, ... 03436 1268 NtContinue (73137456, 1, ... 03437 940 NtContinue (72088880, 1, ... 03438 596 NtWaitForSingleObject (96, 1, {-5000000, -1}, ... 03439 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82055, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82055, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\4\0\0\200\3\0\0\270\11\0\0" ... ... 02409 1972 NtWaitForSingleObject ... ) == 0x0 03416 1664 NtSetEventBoostPriority ... ) == 0x0 03440 1440 NtRegisterThreadTerminatePort (24, ... 03441 1716 NtRegisterThreadTerminatePort (24, ... 03442 1624 NtRegisterThreadTerminatePort (24, ... 03443 1568 NtRegisterThreadTerminatePort (24, ... 03444 1964 NtRegisterThreadTerminatePort (24, ... 03445 312 NtRegisterThreadTerminatePort (24, ... 03446 164 NtRegisterThreadTerminatePort (24, ... 03447 1564 NtRegisterThreadTerminatePort (24, ... 03448 1380 NtRegisterThreadTerminatePort (24, ... 03449 1512 NtRegisterThreadTerminatePort (24, ... 03450 752 NtRegisterThreadTerminatePort (24, ... 03451 468 NtRegisterThreadTerminatePort (24, ... 03452 1808 NtRegisterThreadTerminatePort (24, ... 03453 1336 NtRegisterThreadTerminatePort (24, ... 03454 1332 NtRegisterThreadTerminatePort (24, ... 03455 380 NtRegisterThreadTerminatePort (24, ... 03456 320 NtRegisterThreadTerminatePort (24, ... 03457 1736 NtRegisterThreadTerminatePort (24, ... 03458 644 NtRegisterThreadTerminatePort (24, ... 03459 1268 NtRegisterThreadTerminatePort (24, ... 03460 940 NtRegisterThreadTerminatePort (24, ... 03461 1972 NtSetEventBoostPriority (88, ... 03439 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 82056, 0} ... {28, 56, reply, 0, 896, 2016, 82056, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\244\4\0\0\200\3\0\0\270\11\0\0" ) ) == 0x0 03462 1664 NtTestAlert (... 03440 1440 NtRegisterThreadTerminatePort ... ) == 0x0 03441 1716 NtRegisterThreadTerminatePort ... ) == 0x0 03442 1624 NtRegisterThreadTerminatePort ... ) == 0x0 03443 1568 NtRegisterThreadTerminatePort ... ) == 0x0 03444 1964 NtRegisterThreadTerminatePort ... ) == 0x0 03445 312 NtRegisterThreadTerminatePort ... ) == 0x0 03446 164 NtRegisterThreadTerminatePort ... ) == 0x0 03447 1564 NtRegisterThreadTerminatePort ... ) == 0x0 03448 1380 NtRegisterThreadTerminatePort ... ) == 0x0 03449 1512 NtRegisterThreadTerminatePort ... ) == 0x0 03450 752 NtRegisterThreadTerminatePort ... ) == 0x0 03451 468 NtRegisterThreadTerminatePort ... ) == 0x0 03452 1808 NtRegisterThreadTerminatePort ... ) == 0x0 03453 1336 NtRegisterThreadTerminatePort ... ) == 0x0 03454 1332 NtRegisterThreadTerminatePort ... ) == 0x0 03455 380 NtRegisterThreadTerminatePort ... ) == 0x0 03456 320 NtRegisterThreadTerminatePort ... ) == 0x0 03457 1736 NtRegisterThreadTerminatePort ... ) == 0x0 03458 644 NtRegisterThreadTerminatePort ... ) == 0x0 03459 1268 NtRegisterThreadTerminatePort ... ) == 0x0 02416 1036 NtWaitForSingleObject ... ) == 0x0 03461 1972 NtSetEventBoostPriority ... ) == 0x0 03460 940 NtRegisterThreadTerminatePort ... ) == 0x0 03463 780 NtTestAlert (... 03462 1664 NtTestAlert ... ) == 0x0 03464 1440 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03465 1716 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03466 1624 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03467 1568 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03468 1964 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03469 312 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03470 164 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03471 1564 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03472 1380 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03473 1512 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03474 752 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03475 468 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03476 1808 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03477 1336 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03478 1332 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03479 380 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03480 320 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03481 1736 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03482 644 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03483 1036 NtSetEventBoostPriority (88, ... 03484 1268 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03485 2016 NtResumeThread (1188, ... 03486 940 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03463 780 NtTestAlert ... ) == 0x0 03487 1972 NtTestAlert (... 03488 1664 NtContinue (94108976, 1, ... 03464 1440 NtDuplicateObject ... 1192, ) == 0x0 03465 1716 NtDuplicateObject ... 1196, ) == 0x0 03466 1624 NtDuplicateObject ... 1200, ) == 0x0 03467 1568 NtDuplicateObject ... 1204, ) == 0x0 03468 1964 NtDuplicateObject ... 1208, ) == 0x0 03469 312 NtDuplicateObject ... 1212, ) == 0x0 03470 164 NtDuplicateObject ... 1216, ) == 0x0 03471 1564 NtDuplicateObject ... 1220, ) == 0x0 03472 1380 NtDuplicateObject ... 1224, ) == 0x0 03473 1512 NtDuplicateObject ... 1228, ) == 0x0 03474 752 NtDuplicateObject ... 1232, ) == 0x0 03475 468 NtDuplicateObject ... 1236, ) == 0x0 03476 1808 NtDuplicateObject ... 1240, ) == 0x0 03477 1336 NtDuplicateObject ... 1244, ) == 0x0 03478 1332 NtDuplicateObject ... 1248, ) == 0x0 03479 380 NtDuplicateObject ... 1252, ) == 0x0 03480 320 NtDuplicateObject ... 1256, ) == 0x0 03481 1736 NtDuplicateObject ... 1260, ) == 0x0 02425 1248 NtWaitForSingleObject ... ) == 0x0 03483 1036 NtSetEventBoostPriority ... ) == 0x0 03482 644 NtDuplicateObject ... 1264, ) == 0x0 03485 2016 NtResumeThread ... 1, ) == 0x0 03484 1268 NtDuplicateObject ... 1268, ) == 0x0 03489 780 NtContinue (71040304, 1, ... 03487 1972 NtTestAlert ... ) == 0x0 03490 1664 NtRegisterThreadTerminatePort (24, ... 03491 1440 NtWaitForSingleObject (64, 0, {0, 0}, ... 03492 1716 NtWaitForSingleObject (64, 0, {0, 0}, ... 03493 1624 NtWaitForSingleObject (64, 0, {0, 0}, ... 03494 1568 NtWaitForSingleObject (64, 0, {0, 0}, ... 03495 1964 NtWaitForSingleObject (64, 0, {0, 0}, ... 03496 312 NtWaitForSingleObject (64, 0, {0, 0}, ... 03497 164 NtWaitForSingleObject (64, 0, {0, 0}, ... 03498 1564 NtWaitForSingleObject (64, 0, {0, 0}, ... 03499 1380 NtAllocateVirtualMemory (-1, 1409024, 0, 4096, 4096, 4, ... 03500 1512 NtWaitForSingleObject (288, 0, 0x0, ... 03501 752 NtWaitForSingleObject (288, 0, 0x0, ... 03502 468 NtWaitForSingleObject (288, 0, 0x0, ... 03503 1808 NtWaitForSingleObject (288, 0, 0x0, ... 03504 1336 NtWaitForSingleObject (288, 0, 0x0, ... 03505 1332 NtWaitForSingleObject (288, 0, 0x0, ... 03506 380 NtWaitForSingleObject (288, 0, 0x0, ... 03507 320 NtWaitForSingleObject (288, 0, 0x0, ... 03508 1248 NtWaitForSingleObject (288, 0, 0x0, ... 03509 1736 NtWaitForSingleObject (288, 0, 0x0, ... 03486 940 NtDuplicateObject ... 1272, ) == 0x0 03510 2488 NtWaitForSingleObject (88, 0, 0x0, ... 03511 644 NtWaitForSingleObject (288, 0, 0x0, ... 03512 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03513 1268 NtWaitForSingleObject (288, 0, 0x0, ... 03514 780 NtRegisterThreadTerminatePort (24, ... 03515 1972 NtContinue (95157552, 1, ... 03490 1664 NtRegisterThreadTerminatePort ... ) == 0x0 03491 1440 NtWaitForSingleObject ... ) == 0x102 03492 1716 NtWaitForSingleObject ... ) == 0x102 03493 1624 NtWaitForSingleObject ... ) == 0x102 03494 1568 NtWaitForSingleObject ... ) == 0x102 03495 1964 NtWaitForSingleObject ... ) == 0x102 03496 312 NtWaitForSingleObject ... ) == 0x102 03497 164 NtWaitForSingleObject ... ) == 0x102 03498 1564 NtWaitForSingleObject ... ) == 0x102 03499 1380 NtAllocateVirtualMemory ... 1409024, 4096, ) == 0x0 03516 940 NtWaitForSingleObject (288, 0, 0x0, ... 03512 2016 NtAllocateVirtualMemory ... 218890240, 1048576, ) == 0x0 03514 780 NtRegisterThreadTerminatePort ... ) == 0x0 03517 1972 NtRegisterThreadTerminatePort (24, ... 03518 1664 NtWaitForSingleObject (288, 0, 0x0, ... 03519 1440 NtWaitForSingleObject (288, 0, 0x0, ... 03520 1716 NtWaitForSingleObject (288, 0, 0x0, ... 03521 1624 NtWaitForSingleObject (288, 0, 0x0, ... 03522 1568 NtWaitForSingleObject (288, 0, 0x0, ... 03523 1964 NtWaitForSingleObject (288, 0, 0x0, ... 03524 312 NtWaitForSingleObject (288, 0, 0x0, ... 03525 164 NtWaitForSingleObject (288, 0, 0x0, ... 03526 1564 NtWaitForSingleObject (288, 0, 0x0, ... 03527 1380 NtSetEventBoostPriority (288, ... 03528 2016 NtAllocateVirtualMemory (-1, 219930624, 0, 8192, 4096, 4, ... 03529 780 NtWaitForSingleObject (288, 0, 0x0, ... 03517 1972 NtRegisterThreadTerminatePort ... ) == 0x0 03500 1512 NtWaitForSingleObject ... ) == 0x0 03527 1380 NtSetEventBoostPriority ... ) == 0x0 03528 2016 NtAllocateVirtualMemory ... 219930624, 8192, ) == 0x0 03530 1036 NtTestAlert (... 03531 1512 NtSetEventBoostPriority (288, ... 03532 1972 NtWaitForSingleObject (288, 0, 0x0, ... 03533 1380 NtWaitForSingleObject (288, 0, 0x0, ... 03501 752 NtWaitForSingleObject ... ) == 0x0 03531 1512 NtSetEventBoostPriority ... ) == 0x0 03530 1036 NtTestAlert ... ) == 0x0 03534 2016 NtProtectVirtualMemory (-1, (0xd1be000), 4096, 260, ... 03535 752 NtSetEventBoostPriority (288, ... 03536 1036 NtContinue (96206128, 1, ... 03502 468 NtWaitForSingleObject ... ) == 0x0 03535 752 NtSetEventBoostPriority ... ) == 0x0 03534 2016 NtProtectVirtualMemory ... (0xd1be000), 4096, 4, ) == 0x0 03537 468 NtSetEventBoostPriority (288, ... 03538 1036 NtRegisterThreadTerminatePort (24, ... 03539 1512 NtWaitForSingleObject (288, 0, 0x0, ... 03503 1808 NtWaitForSingleObject ... ) == 0x0 03537 468 NtSetEventBoostPriority ... ) == 0x0 03540 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03538 1036 NtRegisterThreadTerminatePort ... ) == 0x0 03541 1808 NtSetEventBoostPriority (288, ... 03542 752 NtWaitForSingleObject (288, 0, 0x0, ... 03540 2016 NtCreateThread ... 1276, {896, 2492}, ) == 0x0 03504 1336 NtWaitForSingleObject ... ) == 0x0 03541 1808 NtSetEventBoostPriority ... ) == 0x0 03543 1036 NtWaitForSingleObject (288, 0, 0x0, ... 03544 1336 NtSetEventBoostPriority (288, ... 03545 2016 NtQueryInformationThread (1276, Basic, 28, ... 03546 468 NtWaitForSingleObject (288, 0, 0x0, ... 03547 1808 NtWaitForSingleObject (288, 0, 0x0, ... 03505 1332 NtWaitForSingleObject ... ) == 0x0 03544 1336 NtSetEventBoostPriority ... ) == 0x0 03545 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7fef2000,Pid=896,Tid=2492,}, 0x0, ) == 0x0 03548 1332 NtSetEventBoostPriority (288, ... 03549 1336 NtWaitForSingleObject (288, 0, 0x0, ... 03506 380 NtWaitForSingleObject ... ) == 0x0 03548 1332 NtSetEventBoostPriority ... ) == 0x0 03550 380 NtSetEventBoostPriority (288, ... 03551 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82056, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82056, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\4\0\0\200\3\0\0\274\11\0\0" ... ... 03508 1248 NtWaitForSingleObject ... ) == 0x0 03550 380 NtSetEventBoostPriority ... ) == 0x0 03552 1248 NtSetEventBoostPriority (288, ... 03551 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 82057, 0} ... {28, 56, reply, 0, 896, 2016, 82057, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\374\4\0\0\200\3\0\0\274\11\0\0" ) ) == 0x0 03553 1332 NtWaitForSingleObject (288, 0, 0x0, ... 03507 320 NtWaitForSingleObject ... ) == 0x0 03552 1248 NtSetEventBoostPriority ... ) == 0x0 03554 2016 NtResumeThread (1276, ... 03555 320 NtSetEventBoostPriority (288, ... 03556 380 NtWaitForSingleObject (288, 0, 0x0, ... 03509 1736 NtWaitForSingleObject ... ) == 0x0 03555 320 NtSetEventBoostPriority ... ) == 0x0 03554 2016 NtResumeThread ... 1, ) == 0x0 03557 1736 NtSetEventBoostPriority (288, ... 03558 1248 NtSetEventBoostPriority (88, ... 03559 2492 NtWaitForSingleObject (88, 0, 0x0, ... 03511 644 NtWaitForSingleObject ... ) == 0x0 03557 1736 NtSetEventBoostPriority ... ) == 0x0 03560 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02432 1656 NtWaitForSingleObject ... ) == 0x0 03558 1248 NtSetEventBoostPriority ... ) == 0x0 03561 644 NtSetEventBoostPriority (288, ... 03562 320 NtWaitForSingleObject (288, 0, 0x0, ... 03563 1736 NtWaitForSingleObject (288, 0, 0x0, ... 03564 1656 NtWaitForSingleObject (288, 0, 0x0, ... 03513 1268 NtWaitForSingleObject ... ) == 0x0 03561 644 NtSetEventBoostPriority ... ) == 0x0 03565 1248 NtTestAlert (... 03566 1268 NtSetEventBoostPriority (288, ... 03560 2016 NtAllocateVirtualMemory ... 219938816, 1048576, ) == 0x0 03516 940 NtWaitForSingleObject ... ) == 0x0 03566 1268 NtSetEventBoostPriority ... ) == 0x0 03565 1248 NtTestAlert ... ) == 0x0 03567 940 NtSetEventBoostPriority (288, ... 03568 2016 NtAllocateVirtualMemory (-1, 220979200, 0, 8192, 4096, 4, ... 03569 644 NtWaitForSingleObject (288, 0, 0x0, ... 03518 1664 NtWaitForSingleObject ... ) == 0x0 03567 940 NtSetEventBoostPriority ... ) == 0x0 03570 1248 NtContinue (97254704, 1, ... 03568 2016 NtAllocateVirtualMemory ... 220979200, 8192, ) == 0x0 03571 1664 NtSetEventBoostPriority (288, ... 03572 1268 NtWaitForSingleObject (288, 0, 0x0, ... 03573 1248 NtRegisterThreadTerminatePort (24, ... 03519 1440 NtWaitForSingleObject ... ) == 0x0 03571 1664 NtSetEventBoostPriority ... ) == 0x0 03574 2016 NtProtectVirtualMemory (-1, (0xd2be000), 4096, 260, ... 03575 940 NtWaitForSingleObject (288, 0, 0x0, ... 03576 1440 NtSetEventBoostPriority (288, ... 03573 1248 NtRegisterThreadTerminatePort ... ) == 0x0 03574 2016 NtProtectVirtualMemory ... (0xd2be000), 4096, 4, ) == 0x0 03520 1716 NtWaitForSingleObject ... ) == 0x0 03576 1440 NtSetEventBoostPriority ... ) == 0x0 03577 1248 NtWaitForSingleObject (288, 0, 0x0, ... 03578 1716 NtSetEventBoostPriority (288, ... 03579 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03580 1664 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03521 1624 NtWaitForSingleObject ... ) == 0x0 03578 1716 NtSetEventBoostPriority ... ) == 0x0 03581 1440 NtWaitForSingleObject (124, 0, 0x0, ... 03582 1624 NtSetEventBoostPriority (288, ... 03580 1664 NtDuplicateObject ... 1280, ) == 0x0 03579 2016 NtCreateThread ... 1284, {896, 2496}, ) == 0x0 03522 1568 NtWaitForSingleObject ... ) == 0x0 03582 1624 NtSetEventBoostPriority ... ) == 0x0 03583 1664 NtWaitForSingleObject (288, 0, 0x0, ... 03584 1568 NtSetEventBoostPriority (288, ... 03585 2016 NtQueryInformationThread (1284, Basic, 28, ... 03586 1716 NtWaitForSingleObject (124, 0, 0x0, ... 03523 1964 NtWaitForSingleObject ... ) == 0x0 03584 1568 NtSetEventBoostPriority ... ) == 0x0 03585 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7fef1000,Pid=896,Tid=2496,}, 0x0, ) == 0x0 03587 1964 NtSetEventBoostPriority (288, ... 03588 1624 NtWaitForSingleObject (124, 0, 0x0, ... 03524 312 NtWaitForSingleObject ... ) == 0x0 03587 1964 NtSetEventBoostPriority ... ) == 0x0 03589 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82057, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82057, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\5\0\0\200\3\0\0\300\11\0\0" ... ... 03590 312 NtSetEventBoostPriority (288, ... 03591 1568 NtWaitForSingleObject (124, 0, 0x0, ... 03525 164 NtWaitForSingleObject ... ) == 0x0 03590 312 NtSetEventBoostPriority ... ) == 0x0 03589 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 82058, 0} ... {28, 56, reply, 0, 896, 2016, 82058, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\4\5\0\0\200\3\0\0\300\11\0\0" ) ) == 0x0 03592 164 NtSetEventBoostPriority (288, ... 03593 1964 NtWaitForSingleObject (124, 0, 0x0, ... 03594 312 NtWaitForSingleObject (124, 0, 0x0, ... 03526 1564 NtWaitForSingleObject ... ) == 0x0 03592 164 NtSetEventBoostPriority ... ) == 0x0 03595 1564 NtSetEventBoostPriority (288, ... 03596 2016 NtResumeThread (1284, ... 03529 780 NtWaitForSingleObject ... ) == 0x0 03595 1564 NtSetEventBoostPriority ... ) == 0x0 03597 780 NtSetEventBoostPriority (288, ... 03596 2016 NtResumeThread ... 1, ) == 0x0 03598 164 NtWaitForSingleObject (124, 0, 0x0, ... 03532 1972 NtWaitForSingleObject ... ) == 0x0 03599 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03600 1972 NtSetEventBoostPriority (288, ... 03599 2016 NtAllocateVirtualMemory ... 220987392, 1048576, ) == 0x0 03533 1380 NtWaitForSingleObject ... ) == 0x0 03601 2016 NtAllocateVirtualMemory (-1, 222027776, 0, 8192, 4096, 4, ... 03602 1380 NtSetEventBoostPriority (288, ... 03601 2016 NtAllocateVirtualMemory ... 222027776, 8192, ) == 0x0 03539 1512 NtWaitForSingleObject ... ) == 0x0 03602 1380 NtSetEventBoostPriority ... ) == 0x0 03600 1972 NtSetEventBoostPriority ... ) == 0x0 03597 780 NtSetEventBoostPriority ... ) == 0x0 03603 1564 NtWaitForSingleObject (124, 0, 0x0, ... 03604 2496 NtWaitForSingleObject (88, 0, 0x0, ... 03605 1512 NtSetEventBoostPriority (288, ... 03606 1380 NtWaitForSingleObject (64, 0, {0, 0}, ... 03607 1972 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03608 780 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03542 752 NtWaitForSingleObject ... ) == 0x0 03605 1512 NtSetEventBoostPriority ... ) == 0x0 03607 1972 NtDuplicateObject ... 1288, ) == 0x0 03609 752 NtSetEventBoostPriority (288, ... 03608 780 NtDuplicateObject ... 1292, ) == 0x0 03610 1512 NtWaitForSingleObject (288, 0, 0x0, ... 03611 2016 NtProtectVirtualMemory (-1, (0xd3be000), 4096, 260, ... 03606 1380 NtWaitForSingleObject ... ) == 0x102 03546 468 NtWaitForSingleObject ... ) == 0x0 03609 752 NtSetEventBoostPriority ... ) == 0x0 03612 1972 NtWaitForSingleObject (288, 0, 0x0, ... 03613 780 NtWaitForSingleObject (288, 0, 0x0, ... 03611 2016 NtProtectVirtualMemory ... (0xd3be000), 4096, 4, ) == 0x0 03614 468 NtSetEventBoostPriority (288, ... 03615 1380 NtWaitForSingleObject (288, 0, 0x0, ... 03616 752 NtWaitForSingleObject (368, 0, 0x0, ... 03547 1808 NtWaitForSingleObject ... ) == 0x0 03614 468 NtSetEventBoostPriority ... ) == 0x0 03617 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03618 1808 NtSetEventBoostPriority (288, ... 03619 468 NtWaitForSingleObject (368, 0, 0x0, ... 03543 1036 NtWaitForSingleObject ... ) == 0x0 03618 1808 NtSetEventBoostPriority ... ) == 0x0 03617 2016 NtCreateThread ... 1296, {896, 2500}, ) == 0x0 03620 1036 NtSetEventBoostPriority (288, ... 03621 1808 NtWaitForSingleObject (368, 0, 0x0, ... 03549 1336 NtWaitForSingleObject ... ) == 0x0 03622 2016 NtQueryInformationThread (1296, Basic, 28, ... 03620 1036 NtSetEventBoostPriority ... ) == 0x0 03623 1336 NtSetEventBoostPriority (288, ... 03622 2016 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7fef0000,Pid=896,Tid=2500,}, 0x0, ) == 0x0 03624 1036 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03553 1332 NtWaitForSingleObject ... ) == 0x0 03623 1336 NtSetEventBoostPriority ... ) == 0x0 03625 1332 NtSetEventBoostPriority (288, ... 03624 1036 NtDuplicateObject ... 1300, ) == 0x0 03556 380 NtWaitForSingleObject ... ) == 0x0 03625 1332 NtSetEventBoostPriority ... ) == 0x0 03626 1336 NtWaitForSingleObject (368, 0, 0x0, ... 03627 2016 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 896, 2016, 82058, 0} (24, {28, 56, new_msg, 0, 896, 2016, 82058, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\5\0\0\200\3\0\0\304\11\0\0" ... ... 03628 380 NtSetEventBoostPriority (288, ... 03629 1332 NtWaitForSingleObject (368, 0, 0x0, ... 03630 1036 NtWaitForSingleObject (288, 0, 0x0, ... 03562 320 NtWaitForSingleObject ... ) == 0x0 03628 380 NtSetEventBoostPriority ... ) == 0x0 03627 2016 NtRequestWaitReplyPort ... {28, 56, reply, 0, 896, 2016, 82059, 0} ... {28, 56, reply, 0, 896, 2016, 82059, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\20\5\0\0\200\3\0\0\304\11\0\0" ) ) == 0x0 03631 320 NtSetEventBoostPriority (288, ... 03632 380 NtWaitForSingleObject (368, 0, 0x0, ... 03564 1656 NtWaitForSingleObject ... ) == 0x0 03631 320 NtSetEventBoostPriority ... ) == 0x0 03633 2016 NtResumeThread (1296, ... 03634 1656 NtSetEventBoostPriority (288, ... 03635 320 NtWaitForSingleObject (368, 0, 0x0, ... 03563 1736 NtWaitForSingleObject ... ) == 0x0 03634 1656 NtSetEventBoostPriority ... ) == 0x0 03633 2016 NtResumeThread ... 1, ) == 0x0 03636 1736 NtSetEventBoostPriority (288, ... 03637 2500 NtWaitForSingleObject (88, 0, 0x0, ... 03569 644 NtWaitForSingleObject ... ) == 0x0 03636 1736 NtSetEventBoostPriority ... ) == 0x0 03638 2016 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 03639 644 NtSetEventBoostPriority (288, ... 03640 1736 NtWaitForSingleObject (368, 0, 0x0, ... 03641 1656 NtSetEventBoostPriority (88, ... 03572 1268 NtWaitForSingleObject ... ) == 0x0 03639 644 NtSetEventBoostPriority ... ) == 0x0 03638 2016 NtAllocateVirtualMemory ... 222035968, 1048576, ) == 0x0 03642 1268 NtSetEventBoostPriority (288, ... 02441 760 NtWaitForSingleObject ... ) == 0x0 03641 1656 NtSetEventBoostPriority ... ) == 0x0 03643 644 NtWaitForSingleObject (368, 0, 0x0, ... 03575 940 NtWaitForSingleObject ... ) == 0x0 03644 760 NtWaitForSingleObject (288, 0, 0x0, ... 03642 1268 NtSetEventBoostPriority ... ) == 0x0 03645 2016 NtAllocateVirtualMemory (-1, 223076352, 0, 8192, 4096, 4, ... 03646 1656 NtTestAlert (... 03647 940 NtSetEventBoostPriority (288, ... 03648 1268 NtWaitForSingleObject (368, 0, 0x0, ... 03645 2016 NtAllocateVirtualMemory ... 223076352, 8192, ) == 0x0 03577 1248 NtWaitForSingleObject ... ) == 0x0 03647 940 NtSetEventBoostPriority ... ) == 0x0 03646 1656 NtTestAlert ... ) == 0x0 03649 1248 NtSetEventBoostPriority (288, ... 03650 2016 NtProtectVirtualMemory (-1, (0xd4be000), 4096, 260, ... 03651 940 NtWaitForSingleObject (368, 0, 0x0, ... 03583 1664 NtWaitForSingleObject ... ) == 0x0 03649 1248 NtSetEventBoostPriority ... ) == 0x0 03652 1656 NtContinue (98303280, 1, ... 03650 2016 NtProtectVirtualMemory ... (0xd4be000), 4096, 4, ) == 0x0 03653 1664 NtSetEventBoostPriority (288, ... 03654 1656 NtRegisterThreadTerminatePort (24, ... 03612 1972 NtWaitForSingleObject ... ) == 0x0 03653 1664 NtSetEventBoostPriority ... ) == 0x0 03655 2016 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 03656 1248 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 03657 1972 NtSetEventBoostPriority (288, ... 03654 1656 NtRegisterThreadTerminatePort ... ) == 0x0 03658 1664 NtWaitForSingleObject (288, 0, 0x0, ... 03613 780 NtWaitForSingleObject ... ) == 0x0