Summary:
| NtAdjustPrivilegesToken(>) | 1 | NtConnectPort(>) | 2 | NtQueryInformationProcess(>) | 7 | NtOpenSection(>) | 57 | 
| NtCreateMutant(>) | 1 | NtCreateIoCompletion(>) | 2 | NtDuplicateObject(>) | 8 | NtQueryAttributesFile(>) | 58 | 
| NtDelayExecution(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtReleaseMutant(>) | 8 | NtQueryVirtualMemory(>) | 59 | 
| NtDuplicateToken(>) | 1 | NtNotifyChangeKey(>) | 2 | NtOpenProcessTokenEx(>) | 11 | NtUserRegisterClassExWOW(>) | 61 | 
| NtEnumerateValueKey(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtOpenThreadTokenEx(>) | 11 | NtSetEventBoostPriority(>) | 70 | 
| NtGdiCreateBitmap(>) | 1 | NtQueryPerformanceCounter(>) | 2 | NtQuerySection(>) | 11 | NtCreateSection(>) | 80 | 
| NtGdiInit(>) | 1 | NtUserGetDC(>) | 2 | NtQueryDefaultUILanguage(>) | 12 | NtFlushInstructionCache(>) | 87 | 
| NtGdiQueryFontAssocInfo(>) | 1 | NtWaitForMultipleObjects(>) | 2 | NtUserSystemParametersInfo(>) | 12 | NtMapViewOfSection(>) | 114 | 
| NtGdiSelectBitmap(>) | 1 | NtDeleteValueKey(>) | 3 | NtFsControlFile(>) | 13 | NtWriteVirtualMemory(>) | 116 | 
| NtOpenEvent(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtQueryInformationFile(>) | 13 | NtQuerySystemInformation(>) | 120 | 
| NtOpenKeyedEvent(>) | 1 | NtReleaseSemaphore(>) | 3 | NtQueryDirectoryFile(>) | 14 | NtContinue(>) | 135 | 
| NtOpenSymbolicLinkObject(>) | 1 | NtSecureConnectPort(>) | 3 | NtQueryInformationToken(>) | 14 | NtQueryInformationThread(>) | 151 | 
| NtQueryEvent(>) | 1 | NtSetInformationObject(>) | 3 | NtOpenThreadToken(>) | 18 | NtResumeThread(>) | 151 | 
| NtQueryInstallUILanguage(>) | 1 | NtUserRegisterWindowMessage(>) | 3 | NtQueryDebugFilterState(>) | 21 | NtCreateThread(>) | 154 | 
| NtQueryObject(>) | 1 | NtAccessCheck(>) | 4 | NtSetValueKey(>) | 21 | NtTestAlert(>) | 166 | 
| NtQuerySymbolicLinkObject(>) | 1 | NtEnumerateKey(>) | 4 | NtCreateKey(>) | 23 | NtRegisterThreadTerminatePort(>) | 168 | 
| NtQuerySystemTime(>) | 1 | NtSetEvent(>) | 4 | NtFreeVirtualMemory(>) | 29 | NtRequestWaitReplyPort(>) | 177 | 
| NtRaiseException(>) | 1 | NtGdiGetStockObject(>) | 5 | NtCreateFile(>) | 30 | NtWaitForSingleObject(>) | 216 | 
| NtSetInformationProcess(>) | 1 | NtQueryVolumeInformationFile(>) | 5 | NtOpenProcess(>) | 30 | NtOpenKey(>) | 232 | 
| NtUserCallNoParam(>) | 1 | NtCreateSemaphore(>) | 6 | NtSetInformationFile(>) | 30 | NtSetInformationThread(>) | 267 | 
| NtUserCallOneParam(>) | 1 | NtQueryDefaultLocale(>) | 6 | NtCreateEvent(>) | 39 | NtQueryValueKey(>) | 307 | 
| NtUserGetThreadDesktop(>) | 1 | NtReadFile(>) | 6 | NtDeviceIoControlFile(>) | 45 | NtProtectVirtualMemory(>) | 449 | 
| NtUserGetThreadState(>) | 1 | NtWriteFile(>) | 6 | NtOpenFile(>) | 48 | NtClose(>) | 452 | 
| NtAddAtom(>) | 2 | NtOpenMutant(>) | 7 | NtUserFindExistingCursorIcon(>) | 50 | NtAllocateVirtualMemory(>) | 461 | 
| NtCallbackReturn(>) | 2 | NtOpenProcessToken(>) | 7 | NtUnmapViewOfSection(>) | 53 | 
\352~Q\260\310\320L\377D\275QL\7"\1\365\337\362\16\201Fi5\302\252\336\320\210\232\275\257\343\272\24h\344tK\221\206\216hI\36R\255\221\204\376Qd\250\0Si\326\207\217\355\271\314\316\234\13\374O\230\323\3544\12\2XCn&X\202+\27\346\257n=8\212\300\21\0I\316l\262\361\221\243\307\364\260\325\327=\276\225\364\3410\2654\241\10\371\6m_\4(\2+\3319\377@]\265\204\356\202Y9\217\221?\3211\375\24@\373'(\207ss\335zJJ\374\356\365\267\317\23\206Y\0\254a\315f\301\326J2\351\302\343S\230\20O\215\11\326\316QW(\344\221\345\212\200\363\343K\314\221]P0\236\322\307f\337\354\250L=\236\336\322$\240.I\216\231\6\335\2311\303\220\374\323\235"t\3638\3\254\307\23", ) \1\365\337\362\16\201Fi5\302\252\336\320\210\232\275\257\343\272\24h\344tK\221\206\216hI\36R\255\221\204\376Qd\250\0Si\326\207\217\355\271\314\316\234\13\374O\230\323\3544\12\2XCn&X\202+\27\346\257n=8\212\300\21\0I\316l\262\361\221\243\307\364\260\325\327=\276\225\364\3410\2654\241\10\371\6m_\4(\2+\3319\377@]\265\204\356\202Y9\217\221?\3211\375\24@\373'(\207ss\335zJJ\374\356\365\267\317\23\206Y\0\254a\315f\301\326J2\351\302\343S\230\20O\215\11\326\316QW(\344\221\345\212\200\363\343K\314\221]P0\236\322\307f\337\354\250L=\236\336\322$\240.I\216\231\6\335\2311\303\220\374\323\235 ... {status=0x0, info=256}, "\25\242Age\221\354\254\220|
\352~Q\260\310\320L\377D\275QL\7"\1\365\337\362\16\201Fi5\302\252\336\320\210\232\275\257\343\272\24h\344tK\221\206\216hI\36R\255\221\204\376Qd\250\0Si\326\207\217\355\271\314\316\234\13\374O\230\323\3544\12\2XCn&X\202+\27\346\257n=8\212\300\21\0I\316l\262\361\221\243\307\364\260\325\327=\276\225\364\3410\2654\241\10\371\6m_\4(\2+\3319\377@]\265\204\356\202Y9\217\221?\3211\375\24@\373'(\207ss\335zJJ\374\356\365\267\317\23\206Y\0\254a\315f\301\326J2\351\302\343S\230\20O\215\11\326\316QW(\344\221\345\212\200\363\343K\314\221]P0\236\322\307f\337\354\250L=\236\336\322$\240.I\216\231\6\335\2311\303\220\374\323\235"t\3638\3\254\307\23", ) , ) == 0x0 02303 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81917, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81917, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\1\0\0\344\4\0\0\0\6\0\0" ... ... 02304 1256 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02303 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81918, 0} ... {28, 56, reply, 0, 1252, 896, 81918, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGP\1\0\0\344\4\0\0\0\6\0\0" ) ) == 0x0 02305 896 NtResumeThread (336, ... 1, ) == 0x0 02306 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 39059456, 1048576, ) == 0x0 02307 896 NtAllocateVirtualMemory (-1, 40099840, 0, 8192, 4096, 4, ... 40099840, 8192, ) == 0x0 02308 896 NtProtectVirtualMemory (-1, (0x263e000), 4096, 260, ... (0x263e000), 4096, 4, ) == 0x0 02309 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02310 1808 NtDeviceIoControlFile (308, 0, 0x0, 0x0, 0x390008, (308, 0, 0x0, 0x0, 0x390008, "3\262{\26\326>\371\224\217.\6,\3206$\253\343\346\1\2262i\246\343\346\1\2262i\246\343\346\1\2262 \15\17\246^)p\241u\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 02304 1256 NtSetInformationThread ... ) == 0x0 02311 1536 NtTestAlert (... 02312 1808 NtQuerySystemInformation (TimeOfDay, 48, ... 02309 896 NtCreateThread ... 340, {1252, 1936}, ) == 0x0 02311 1536 NtTestAlert ... ) == 0x0 02312 1808 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 02313 896 NtQueryInformationThread (340, Basic, 28, ... 02314 1536 NtContinue (39058736, 1, ... 02313 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff97000,Pid=1252,Tid=1936,}, 0x0, ) == 0x0 02315 1536 NtRegisterThreadTerminatePort (24, ... 02316 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81918, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81918, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\1\0\0\344\4\0\0\220\7\0\0" ... ... 02315 1536 NtRegisterThreadTerminatePort ... ) == 0x0 02316 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81919, 0} ... {28, 56, reply, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGT\1\0\0\344\4\0\0\220\7\0\0" ) ) == 0x0 02317 1808 NtQuerySystemInformation (ProcessorTimes, 48, ... 02318 1256 NtWaitForSingleObject (240, 0, 0x0, ... 02319 1536 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02317 1808 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 02320 896 NtResumeThread (340, ... 02321 1808 NtQuerySystemInformation (Performance, 312, ... 02320 896 NtResumeThread ... 1, ) == 0x0 02321 1808 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 02322 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02323 1808 NtQuerySystemInformation (Exception, 16, ... 02322 896 NtAllocateVirtualMemory ... 40108032, 1048576, ) == 0x0 02323 1808 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 02324 896 NtAllocateVirtualMemory (-1, 41148416, 0, 8192, 4096, 4, ... 02319 1536 NtSetInformationThread ... ) == 0x0 02325 1936 NtTestAlert (... 02324 896 NtAllocateVirtualMemory ... 41148416, 8192, ) == 0x0 02326 1808 NtQuerySystemInformation (Lookaside, 32, ... 02325 1936 NtTestAlert ... ) == 0x0 02327 1536 NtWaitForSingleObject (240, 0, 0x0, ... 02326 1808 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 02328 1936 NtContinue (40107312, 1, ... 02329 896 NtProtectVirtualMemory (-1, (0x273e000), 4096, 260, ... 02330 1808 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 02331 1936 NtRegisterThreadTerminatePort (24, ... 02329 896 NtProtectVirtualMemory ... (0x273e000), 4096, 4, ) == 0x0 02330 1808 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 02331 1936 NtRegisterThreadTerminatePort ... ) == 0x0 02332 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02333 1808 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 02332 896 NtCreateThread ... 344, {1252, 968}, ) == 0x0 02333 1808 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 02334 896 NtQueryInformationThread (344, Basic, 28, ... 02335 1936 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02334 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff96000,Pid=1252,Tid=968,}, 0x0, ) == 0x0 02335 1936 NtSetInformationThread ... ) == 0x0 02336 1808 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 02337 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81919, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\1\0\0\344\4\0\0\310\3\0\0" ... ... 02336 1808 NtCreateKey ... -2147481484, 2, ) == 0x0 02337 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81920, 0} ... {28, 56, reply, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFGX\1\0\0\344\4\0\0\310\3\0\0" ) ) == 0x0 02338 1808 NtSetValueKey (-2147481484, (-2147481484, "Seed", 0, 3, "X\211\271\262\303\321\200\210\316\15\305K\217\275\242\374\330\242Y\260\305\243?\6_\211\34)r\341\367\223\266i\277\332\115\50\342\223#V?\30\246\326\32\337\322\257\370\340\226\334`\243=(|\307\344\374\276\342\210\346;\322\316 \307\365\143^\235\360\235", 80, ... , 0, 3, (-2147481484, "Seed", 0, 3, "X\211\271\262\303\321\200\210\316\15\305K\217\275\242\374\330\242Y\260\305\243?\6_\211\34)r\341\367\223\266i\277\332\115\50\342\223#V?\30\246\326\32\337\322\257\370\340\226\334`\243=(|\307\344\374\276\342\210\346;\322\316 \307\365\143^\235\360\235", 80, ... , 80, ... 02339 896 NtResumeThread (344, ... 02338 1808 NtSetValueKey ... ) == 0x0 02339 896 NtResumeThread ... 1, ) == 0x0 02340 1808 NtClose (-2147481484, ... 02341 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02340 1808 NtClose ... ) == 0x0 02342 1936 NtWaitForSingleObject (240, 0, 0x0, ... 02343 968 NtTestAlert (... 02341 896 NtAllocateVirtualMemory ... 41156608, 1048576, ) == 0x0 02310 1808 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "MJ\276\2315\312\\356U\214\361\275\25\207J\252\363&o\207`\206\227\36+\300\335\3255\335\264\330f\253\364\351\344\254H|\266\231\365\312z\4\16\203;p\224\1\255\211\342\352\230=(\247pK6\32\251l\202\10\263\2767\271\213\235\274u\351\214W-\226\265\213Z\240\21\223\13\365\334\264\315wr\34\264\319\256\331\261+}\344^\321pv\27,\251\364\254\32\27\225a\267*\364\330\4z\3005\376\335\324zrG\Gtz\344U\271\352ymx\227+\267z9\24\262\303\262\210"\276\302-\201x\347\316\203\264\221%\344\212$\273\210\2\325/\245\335\277o\365\344\326\236\376\207( +\31\315\331\260\321\356\361\263\1773UM_\375\252Z\374\10\37+\220\243\263b'~\327\246\357\221N\322Q\375\321\352\204\202"\322\366\326s\17\211'\257(\267Y\203\274`\303\214\214\302\31\5@\203\361N\325\227\5Lp\\350", ) \276\302-\201x\347\316\203\264\221%\344\212$\273\210\2\325/\245\335\277o\365\344\326\236\376\207( +\31\315\331\260\321\356\361\263\1773UM_\375\252Z\374\10\37+\220\243\263b'~\327\246\357\221N\322Q\375\321\352\204\202 ... {status=0x0, info=256}, "MJ\276\2315\312\\356U\214\361\275\25\207J\252\363&o\207`\206\227\36+\300\335\3255\335\264\330f\253\364\351\344\254H|\266\231\365\312z\4\16\203;p\224\1\255\211\342\352\230=(\247pK6\32\251l\202\10\263\2767\271\213\235\274u\351\214W-\226\265\213Z\240\21\223\13\365\334\264\315wr\34\264\319\256\331\261+}\344^\321pv\27,\251\364\254\32\27\225a\267*\364\330\4z\3005\376\335\324zrG\Gtz\344U\271\352ymx\227+\267z9\24\262\303\262\210"\276\302-\201x\347\316\203\264\221%\344\212$\273\210\2\325/\245\335\277o\365\344\326\236\376\207( +\31\315\331\260\321\356\361\263\1773UM_\375\252Z\374\10\37+\220\243\263b'~\327\246\357\221N\322Q\375\321\352\204\202"\322\366\326s\17\211'\257(\267Y\203\274`\303\214\214\302\31\5@\203\361N\325\227\5Lp\\350", ) , ) == 0x0 02343 968 NtTestAlert ... ) == 0x0 02344 896 NtAllocateVirtualMemory (-1, 42196992, 0, 8192, 4096, 4, ... 02345 1808 NtDeviceIoControlFile (308, 0, 0x0, 0x0, 0x390008, (308, 0, 0x0, 0x0, 0x390008, "3\262{\26\326>\371\224\217.\6,\3206$\253\343\346\1\2262i\246\343\346\1\2262i\246\343\346\1\2262i\246\343\346\1\2262 \15\17\246^)p\241u\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 02346 968 NtContinue (41155888, 1, ... 02344 896 NtAllocateVirtualMemory ... 42196992, 8192, ) == 0x0 02347 1808 NtQuerySystemInformation (TimeOfDay, 48, ... 02348 968 NtRegisterThreadTerminatePort (24, ... 02349 896 NtProtectVirtualMemory (-1, (0x283e000), 4096, 260, ... 02347 1808 NtQuerySystemInformation ... {system info, class 3, size 48}, 48, ) == 0x0 02348 968 NtRegisterThreadTerminatePort ... ) == 0x0 02349 896 NtProtectVirtualMemory ... (0x283e000), 4096, 4, ) == 0x0 02350 1808 NtQuerySystemInformation (ProcessorTimes, 48, ... 02351 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02350 1808 NtQuerySystemInformation ... {system info, class 8, size 48}, 48, ) == 0x0 02352 968 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02351 896 NtCreateThread ... 348, {1252, 1688}, ) == 0x0 02353 896 NtQueryInformationThread (348, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ff95000,Pid=1252,Tid=1688,}, 0x0, ) == 0x0 02354 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81920, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\1\0\0\344\4\0\0\230\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\1\0\0\344\4\0\0\230\6\0\0" ) ... {28, 56, reply, 0, 1252, 896, 81921, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81920, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\1\0\0\344\4\0\0\230\6\0\0" ... {28, 56, reply, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG\\1\0\0\344\4\0\0\230\6\0\0" ) ) == 0x0 02355 896 NtResumeThread (348, ... 1, ) == 0x0 02356 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 42205184, 1048576, ) == 0x0 02357 896 NtAllocateVirtualMemory (-1, 43245568, 0, 8192, 4096, 4, ... 43245568, 8192, ) == 0x0 02358 1808 NtQuerySystemInformation (Performance, 312, ... 02359 1688 NtTestAlert (... 02352 968 NtSetInformationThread ... ) == 0x0 02358 1808 NtQuerySystemInformation ... {system info, class 2, size 312}, 312, ) == 0x0 02359 1688 NtTestAlert ... ) == 0x0 02360 896 NtProtectVirtualMemory (-1, (0x293e000), 4096, 260, ... 02361 1808 NtQuerySystemInformation (Exception, 16, ... 02362 1688 NtContinue (42204464, 1, ... 02360 896 NtProtectVirtualMemory ... (0x293e000), 4096, 4, ) == 0x0 02361 1808 NtQuerySystemInformation ... {system info, class 33, size 16}, 16, ) == 0x0 02363 1688 NtRegisterThreadTerminatePort (24, ... 02364 896 NtCreateThread (0x1f03ff, 0x0, -1, 1243956, 1243900, 1, ... 02365 1808 NtQuerySystemInformation (Lookaside, 32, ... 02363 1688 NtRegisterThreadTerminatePort ... ) == 0x0 02364 896 NtCreateThread ... 352, {1252, 308}, ) == 0x0 02365 1808 NtQuerySystemInformation ... {system info, class 45, size 32}, 32, ) == 0x0 02366 968 NtWaitForSingleObject (240, 0, 0x0, ... 02367 896 NtQueryInformationThread (352, Basic, 28, ... 02368 1688 NtSetInformationThread (-2, BasePriority, {thread info, class 3, size 4}, 4, ... 02369 1808 NtQuerySystemInformation (ProcessorStatistics, 3016, ... 02367 896 NtQueryInformationThread ... {ExitStatus=0x103,TebBaseAddress=0x7ff94000,Pid=1252,Tid=308,}, 0x0, ) == 0x0 02369 1808 NtQuerySystemInformation ... {system info, class 23, size 0}, 0, ) == 0x0 02368 1688 NtSetInformationThread ... ) == 0x0 02370 1808 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... 02371 896 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1252, 896, 81921, 0} (24, {28, 56, new_msg, 0, 1252, 896, 81921, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\1\0\0\344\4\0\04\1\0\0" ... ... 02370 1808 NtQuerySystemInformation ... ) == STATUS_INFO_LENGTH_MISMATCH 02371 896 NtRequestWaitReplyPort ... {28, 56, reply, 0, 1252, 896, 81922, 0} ... {28, 56, reply, 0, 1252, 896, 81922, 0} "\0\0\0\0\1\0\1\0\0\0\0\0DEFG`\1\0\0\344\4\0\04\1\0\0" ) ) == 0x0 02372 1808 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... }, 0, 0x0, 0, ... 02373 896 NtResumeThread (352, ... 02372 1808 NtCreateKey ... -2147481484, 2, ) == 0x0 02373 896 NtResumeThread ... 1, ) == 0x0 02374 1688 NtWaitForSingleObject (240, 0, 0x0, ... 02375 896 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 02376 1808 NtSetValueKey (-2147481484, (-2147481484, "Seed", 0, 3, "\370)*\25\31_X\327Fs55\361\300\202\277wD!\342\210^\10\264\14\223X\243\342\254\366\275\375\317\265\244c\237\323_\260\25\256\346\360r\306q\302$h\244\31hu4NY\32\33\214\277\242e\264\12\177S_}\212\267\376"d\371\267\14\14", 80, ... , 0, 3, (-2147481484, "Seed", 0, 3, "\370)*\25\31_X\327Fs55\361\300\202\277wD!\342\210^\10\264\14\223X\243\342\254\366\275\375\317\265\244c\237\323_\260\25\256\346\360r\306q\302$h\244\31hu4NY\32\33\214\277\242e\264\12\177S_}\212\267\376"d\371\267\14\14", 80, ... d\371\267\14\14", 80, ... 02377 308 NtTestAlert (... 02376 1808 NtSetValueKey ... ) == 0x0 02377 308 NtTestAlert ... ) == 0x0 02378 1808 NtClose (-2147481484, ... 02379 308 NtContinue (43253040, 1, ... 02378 1808 NtClose ... ) == 0x0 02380 308 NtRegisterThreadTerminatePort (24, ... 02345 1808 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "9\330h\36\204G\13B&\216We\331\372\243\241Z\1\320\341\364\232.\17g0h<\217I \301B\331\330\356\353\251\223 P\305D\301\372\33\241T\223N\250\237h\232\245\23\366\25\301\7\37\263\236\17C\262g)\241;\25~UK&\264\227GF\222^\213\3342(\250c\360\373\352\264\311\303=xcm\14\336Dj\24\2646\243\250\343\330\330\336\274\363U\331\310ZS?\342\266\271\224\21\236\2\366:>K\302\231S\20\236\5\375 \3617\250\314\27\325\271kJ\331n\350\357