Summary:
NtAddAtom(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtOpenSymbolicLinkObject(>) | 6 | NtContinue(>) | 29 |
NtAllocateLocallyUniqueId(>) | 1 | NtGdiHfontCreate(>) | 2 | NtQuerySymbolicLinkObject(>) | 6 | NtQueryInformationFile(>) | 30 |
NtCallbackReturn(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtCreateSemaphore(>) | 7 | NtEnumerateKey(>) | 31 |
NtClearEvent(>) | 1 | NtQueryInformationJobObject(>) | 2 | NtUserCallNoParam(>) | 7 | NtCreateEvent(>) | 32 |
NtConnectPort(>) | 1 | NtQueryInstallUILanguage(>) | 2 | NtQueryVirtualMemory(>) | 8 | NtOpenThreadToken(>) | 33 |
NtDelayExecution(>) | 1 | NtRegisterThreadTerminatePort(>) | 2 | NtWriteVirtualMemory(>) | 8 | NtReleaseMutant(>) | 38 |
NtDuplicateToken(>) | 1 | NtSetEvent(>) | 2 | NtWriteFile(>) | 9 | NtUnmapViewOfSection(>) | 38 |
NtGdiCreateBitmap(>) | 1 | NtTestAlert(>) | 2 | NtQueryDefaultUILanguage(>) | 10 | NtQueryInformationProcess(>) | 39 |
NtGdiCreateHalftonePalette(>) | 1 | NtUserCloseDesktop(>) | 2 | NtUserGetWindowDC(>) | 10 | NtQueryDefaultLocale(>) | 42 |
NtGdiCreatePaletteInternal(>) | 1 | NtUserCreateWindowEx(>) | 2 | NtSetValueKey(>) | 11 | NtUserUnregisterClass(>) | 47 |
NtGdiCreatePatternBrushInternal(>) | 1 | NtUserDestroyWindow(>) | 2 | NtUserCallOneParam(>) | 11 | NtUserFindExistingCursorIcon(>) | 49 |
NtGdiDoPalette(>) | 1 | NtUserGetObjectInformation(>) | 2 | NtUserSystemParametersInfo(>) | 11 | NtProtectVirtualMemory(>) | 50 |
NtGdiInit(>) | 1 | NtUserMessageCall(>) | 2 | NtFreeVirtualMemory(>) | 12 | NtCreateSection(>) | 56 |
NtGdiQueryFontAssocInfo(>) | 1 | NtCreateThread(>) | 3 | NtOpenProcessToken(>) | 14 | NtUserRegisterClassExWOW(>) | 65 |
NtGdiSelectBitmap(>) | 1 | NtDuplicateObject(>) | 3 | NtQueryVolumeInformationFile(>) | 14 | NtWaitForSingleObject(>) | 66 |
NtOpenKeyedEvent(>) | 1 | NtOpenMutant(>) | 3 | NtRequestWaitReplyPort(>) | 14 | NtOpenSection(>) | 74 |
NtQueryFullAttributesFile(>) | 1 | NtOpenProcess(>) | 3 | NtNotifyChangeKey(>) | 15 | NtReadFile(>) | 77 |
NtQueryInformationThread(>) | 1 | NtResumeThread(>) | 3 | NtCreateKey(>) | 17 | NtAllocateVirtualMemory(>) | 78 |
NtQueryObject(>) | 1 | NtTerminateProcess(>) | 3 | NtDeviceIoControlFile(>) | 17 | NtMapViewOfSection(>) | 80 |
NtQueryPerformanceCounter(>) | 1 | NtUserOpenDesktop(>) | 3 | NtFsControlFile(>) | 17 | NtOpenFile(>) | 88 |
NtQuerySystemTime(>) | 1 | NtUserRemoveProp(>) | 3 | NtUserRegisterWindowMessage(>) | 19 | NtQuerySystemInformation(>) | 89 |
NtSecureConnectPort(>) | 1 | NtWaitForMultipleObjects(>) | 3 | NtQueryDirectoryFile(>) | 20 | NtUserGetClassInfo(>) | 91 |
NtUserBuildNameList(>) | 1 | NtCreateMutant(>) | 4 | NtSetInformationProcess(>) | 21 | NtOpenProcessTokenEx(>) | 110 |
NtUserGetAtomName(>) | 1 | NtGdiCreateCompatibleDC(>) | 4 | NtEnumerateValueKey(>) | 23 | NtOpenThreadTokenEx(>) | 110 |
NtUserGetDC(>) | 1 | NtOpenEvent(>) | 4 | NtFlushInstructionCache(>) | 24 | NtUserQueryWindow(>) | 114 |
NtUserGetForegroundWindow(>) | 1 | NtQuerySecurityObject(>) | 4 | NtQueryDebugFilterState(>) | 24 | NtQueryInformationToken(>) | 126 |
NtUserGetGUIThreadInfo(>) | 1 | NtUserBuildHwndList(>) | 4 | NtRaiseException(>) | 25 | NtQueryKey(>) | 129 |
NtUserGetThreadDesktop(>) | 1 | NtGdiGetStockObject(>) | 5 | NtSetInformationFile(>) | 25 | NtQueryAttributesFile(>) | 147 |
NtUserSetProp(>) | 1 | NtReadVirtualMemory(>) | 5 | NtCreateFile(>) | 27 | NtQueryValueKey(>) | 223 |
NtAccessCheck(>) | 2 | NtSetInformationObject(>) | 5 | NtSetInformationThread(>) | 27 | NtOpenKey(>) | 476 |
NtCreateIoCompletion(>) | 2 | NtUserGetProcessWindowStation(>) | 5 | NtQuerySection(>) | 28 | NtClose(>) | 570 |
NtCreateProcessEx(>) | 2 | NtGdiDeleteObjectApp(>) | 6 | NtReleaseSemaphore(>) | 28 |
"
, 80, ... ) , 0, 3, (-2147482040, "Seed", 0, 3, "\205\356=e\254\312\3561\246t\242s\275\15\270+>\217\362\3\4\254\266\23\336\2P`\3663\255u\324cF\357hl~X"
, 80, ... ) , 80, ... ) == 0x0 00941 424 NtClose (-2147482040, ... ) == 0x0 00931 424 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\366\271\322\302L\5o\372hJ\367\305\246\35\233\33x\355Lv3\377\205S\327\213"\246;\246t\224\34z'\35\275g\275\332\322\251r\313\271\0\27\344\16?a\1|!\343\345[\325a\373\335\353O\222\321{\307\207K8\215\221v\236\377\13B\362\11\2353\206 `J\230AF\364\344\266\337.>\375\222\12\267*\224\376\276\7\267\267\321\361\370\7o\266\361\360\2337\234d\253\356\273\257\333\250\233\10\27O]\244\251\356\27Kp\320\354N\35\323\30oR\306\336\264\302\205\10c4^\230\200M\0\321\264Sq\304,\3224\4\242\322\265\361\5\210O\315\3343\260m$x\230$\3772c\37\273\356\242\243\350\203\327KO\366\343\12H\220\265\340\343\243\227\31g\323A\4+\14e\2664\267\271\315\323\303\304)\357OPD\266=\206\331z\255\324\305\324\17\217\211\340)\237\340\37\265~\253,\324\276"\205\216\fF", ) \246;\246t\224\34z'\35\275g\275\332\322\251r\313\271\0\27\344\16?a\1|!\343\345[\325a\373\335\353O\222\321{\307\207K8\215\221v\236\377\13B\362\11\2353\206 `J\230AF\364\344\266\337.>\375\222\12\267*\224\376\276\7\267\267\321\361\370\7o\266\361\360\2337\234d\253\356\273\257\333\250\233\10\27O]\244\251\356\27Kp\320\354N\35\323\30oR\306\336\264\302\205\10c4^\230\200M\0\321\264Sq\304,\3224\4\242\322\265\361\5\210O\315\3343\260m$x\230$\3772c\37\273\356\242\243\350\203\327KO\366\343\12H\220\265\340\343\243\227\31g\323A\4+\14e\2664\267\271\315\323\303\304)\357OPD\266=\206\331z\255\324\305\324\17\217\211\340)\237\340\37\265~\253,\324\276 ... {status=0x0, info=256}, "\366\271\322\302L\5o\372hJ\367\305\246\35\233\33x\355Lv3\377\205S\327\213"\246;\246t\224\34z'\35\275g\275\332\322\251r\313\271\0\27\344\16?a\1|!\343\345[\325a\373\335\353O\222\321{\307\207K8\215\221v\236\377\13B\362\11\2353\206 `J\230AF\364\344\266\337.>\375\222\12\267*\224\376\276\7\267\267\321\361\370\7o\266\361\360\2337\234d\253\356\273\257\333\250\233\10\27O]\244\251\356\27Kp\320\354N\35\323\30oR\306\336\264\302\205\10c4^\230\200M\0\321\264Sq\304,\3224\4\242\322\265\361\5\210O\315\3343\260m$x\230$\3772c\37\273\356\242\243\350\203\327KO\366\343\12H\220\265\340\343\243\227\31g\323A\4+\14e\2664\267\271\315\323\303\304)\357OPD\266=\206\331z\255\324\305\324\17\217\211\340)\237\340\37\265~\253,\324\276"\205\216\fF", ) , ) == 0x0 00942 424 NtDeviceIoControlFile (112, 0, 0x0, 0x0, 0x390008, (112, 0, 0x0, 0x0, 0x390008, "lP!\304\34g\377\367\21\322\227S2\35Z\347\32l\357l\230\223\312\32l\357l\230\223\312\32l\357l\230\223\312\32l\357l\230\223\312\32l\357l\230\223\312\32l\357l\230\332xr\305\273$sB\215\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00943 424 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00944 424 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00945 424 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00946 424 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00947 424 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00948 424 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00949 424 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00950 424 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482040, 2, ) }, 0, 0x0, 0, ... -2147482040, 2, ) == 0x0 00951 424 NtSetValueKey (-2147482040, (-2147482040, "Seed", 0, 3, "\260\266\14\235?\351\22\346\342\315s\366u\360%My\7^%\243\3\212\303\302\350.Y.Q\345\315\357\277F\244g\265\254\362\271b\263V\326v:\331\337\4\361\343\227\373\276%Y\270\347\356\232$\350~-\357\344\266\257A\304q~\321\12?C\2360", 80, ... ) , 0, 3, (-2147482040, "Seed", 0, 3, "\260\266\14\235?\351\22\346\342\315s\366u\360%My\7^%\243\3\212\303\302\350.Y.Q\345\315\357\277F\244g\265\254\362\271b\263V\326v:\331\337\4\361\343\227\373\276%Y\270\347\356\232$\350~-\357\344\266\257A\304q~\321\12?C\2360", 80, ... ) , 80, ... ) == 0x0 00952 424 NtClose (-2147482040, ... ) == 0x0 00942 424 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\344\315\331\314\16\203&\272\333\271\14\231\242I\325\243\244Z8\300q\347\370\2071\316\314\242\275\365\353m;$k[\211\314;>\237mV\17\375E\316\37+\316\13\362\270\366}\331-\27\374\261"~(=\\226\343\7\364E\225(\321k5\377\346\351\242\262\21~+\21Fo\242\337f$\332\36vO+\27\364\230\231\234ynu\217\3175\357\32\223r\361\3546\326\317\224\370\270=b?t\346c\310\335\2762\317PM8\265\260\357\355\3752\13\24\254\30\11-P\315\205\6q\376\235SX\6\367\0?\222\11\320rE2\2548\374>\217\367\216n\272\366\\31{\306\210\241\275U\334\220z\204\2072\341\3\21\377\317\314\2568\301\266\230;\330y\321\3574g\355!`\7&OB\37\274\264\237\17\2218\224\334\300\205r\34\270\364\357t\24j!4\14i\6v\204\313\177\5[\346\301\207\213\354\253I\301\24\214\272\355\35\31", ) ~(=\\226\343\7\364E\225(\321k5\377\346\351\242\262\21~+\21Fo\242\337f$\332\36vO+\27\364\230\231\234ynu\217\3175\357\32\223r\361\3546\326\317\224\370\270=b?t\346c\310\335\2762\317PM8\265\260\357\355\3752\13\24\254\30\11-P\315\205\6q\376\235SX\6\367\0?\222\11\320rE2\2548\374>\217\367\216n\272\366\\31{\306\210\241\275U\334\220z\204\2072\341\3\21\377\317\314\2568\301\266\230;\330y\321\3574g\355!`\7&OB\37\274\264\237\17\2218\224\334\300\205r\34\270\364\357t\24j!4\14i\6v\204\313\177\5[\346\301\207\213\354\253I\301\24\214\272\355\35\31", ) == 0x0 00953 424 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\u:\work\"}, 3, 33, ... 108, {status=0x0, info=1}, ) }, 3, 33, ... 108, {status=0x0, info=1}, ) == 0x0 00954 424 NtQueryVolumeInformationFile (108, 1238956, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00955 424 NtClose (12, ... ) == 0x0 00956 424 NtOpenFile (0x10080, {24, 0, 0x40, 0, 0, (0x10080, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 7, 2113600, ... ) }, 7, 2113600, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00957 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1238172, (0x80100080, {24, 0, 0x40, 0, 1238172, "\??\u:\work\packed.exe"}, 0x0, 0, 1, 1, 2097252, 0, 0, ... 12, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 2097252, 0, 0, ... 12, {status=0x0, info=1}, ) == 0x0 00958 424 NtQueryInformationFile (12, 1239108, 8, AttributeFlag, ... {status=0x0, info=8}, ) == 0x0 00959 424 NtQueryInformationFile (12, 1239080, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 00960 424 NtQueryInformationFile (12, 1239032, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00961 424 NtAllocateVirtualMemory (-1, 1384448, 0, 8192, 4096, 4, ... 1384448, 8192, ) == 0x0 00962 424 NtQueryInformationFile (12, 1382480, 4094, Stream, ... {status=0x0, info=38}, ) == 0x0 00963 424 NtQueryInformationFile (12, 1237576, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00964 424 NtQueryInformationFile (12, 1237420, 4, Ea, ... {status=0x0, info=4}, ) == 0x0 00965 424 NtCreateFile (0x40110080, {24, 0, 0x40, 0, 1237428, (0x40110080, {24, 0, 0x40, 0, 1237428, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 0x0, 32, 0, 5, 100, 0, 0, ... }, 0x0, 32, 0, 5, 100, 0, 0, ... 00966 424 NtClose (-2147482040, ... ) == 0x0 00965 424 NtCreateFile ... 104, {status=0x0, info=2}, ) == 0x0 00967 424 NtQueryVolumeInformationFile (104, 1236800, 536, Attribute, ... {status=0x0, info=22}, ) == 0x0 00968 424 NtQueryInformationFile (104, 1236760, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00969 424 NtQueryVolumeInformationFile (12, 1236800, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 00970 424 NtSetInformationFile (104, 1236588, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 00971 424 NtCreateSection (0xf001f, 0x0, 0x0, 2, 134217728, 12, ... 116, ) == 0x0 00972 424 NtMapViewOfSection (116, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x3d0000), {0, 0}, 49152, ) == 0x0 00973 424 NtClose (116, ... ) == 0x0 00974 424 NtWriteFile (104, 0, 0, 0, (104, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0V\323\325s\22\262\273 \22\262\273 \22\262\273 L\220\260 \20\262\273 i\256\267 \21\262\273 \221\272\346 \36\262\273 \221\256\265 \25\262\273 }\255\277 \21\262\273 }\255\260 \23\262\273 \22\262\272 \266\262\273 $\224\260 /\262\273 Rich\22\262\273 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0\340\253\231D\0\0\0\0\0\0\0\0\340\0\17\1\13\1\6\0\0\260\0\0\0\20\0\0\0\360\0\0\36\256\1\0\0\0\1\0\0\260\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\300\1\0\0\20\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\260\1\0\220\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0", 46592, 0x0, 0, ... {status=0x0, info=46592}, ) , 46592, 0x0, 0, ... {status=0x0, info=46592}, ) == 0x0 00975 424 NtUnmapViewOfSection (-1, 0x3d0000, ... ) == 0x0 00976 424 NtSetInformationFile (104, 1239032, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00977 424 NtClose (12, ... ) == 0x0 00978 424 NtClose (104, ... ) == 0x0 00979 424 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 7, 2113568, ... 104, {status=0x0, info=1}, ) }, 7, 2113568, ... 104, {status=0x0, info=1}, ) == 0x0 00980 424 NtSetInformationFile (104, 1239232, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00981 424 NtClose (104, ... ) == 0x0 00982 424 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 7, 2113568, ... 104, {status=0x0, info=1}, ) }, 7, 2113568, ... 104, {status=0x0, info=1}, ) == 0x0 00983 424 NtSetInformationFile (104, 1239232, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00984 424 NtClose (104, ... ) == 0x0 00985 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1238928, (0x80100080, {24, 0, 0x40, 0, 1238928, "\??\C:\WINDOWS\explorer.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... 104, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 104, {status=0x0, info=1}, ) == 0x0 00986 424 NtQueryInformationFile (104, 1238980, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00987 424 NtClose (104, ... ) == 0x0 00988 424 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1238928, (0x40100080, {24, 0, 0x40, 0, 1238928, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 0x0, 128, 2, 1, 96, 0, 0, ... 104, {status=0x0, info=1}, ) }, 0x0, 128, 2, 1, 96, 0, 0, ... 104, {status=0x0, info=1}, ) == 0x0 00989 424 NtSetInformationFile (104, 1238980, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00990 424 NtClose (104, ... ) == 0x0 00991 424 NtOpenFile (0x10080, {24, 108, 0x40, 0, 0, (0x10080, {24, 108, 0x40, 0, 0, "xeqfhcg.bat"}, 7, 2113600, ... ) }, 7, 2113600, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00992 424 NtCreateFile (0x40100080, {24, 108, 0x40, 0, 1239184, (0x40100080, {24, 108, 0x40, 0, 1239184, "xeqfhcg.bat"}, 0x0, 0, 0, 5, 96, 0, 0, ... 104, {status=0x0, info=2}, ) }, 0x0, 0, 0, 5, 96, 0, 0, ... 104, {status=0x0, info=2}, ) == 0x0 00993 424 NtWriteFile (104, 0, 0, 0, (104, 0, 0, 0, "@echo off\15\12:deleteagain\15\12del /A:H /F packed.exe\15\12del /F packed.exe\15\12if exist packed.exe goto deleteagain\15\12del xeqfhcg.bat\15\12", 123, 0x0, 0, ... {status=0x0, info=123}, ) , 123, 0x0, 0, ... {status=0x0, info=123}, ) == 0x0 00994 424 NtClose (104, ... ) == 0x0 00995 424 NtOpenKey (0x9, {24, 28, 0x40, 0, 0, (0x9, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00996 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1232524, ... ) }, 1232524, ... ) == 0x0 00997 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 00998 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 104, ... 12, ) == 0x0 00999 424 NtClose (104, ... ) == 0x0 01000 424 NtMapViewOfSection (12, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x900000), 0x0, 262144, ) == 0x0 01001 424 NtClose (12, ... ) == 0x0 01002 424 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 01003 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01004 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01005 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01006 424 NtAllocateVirtualMemory (-1, 1392640, 0, 16384, 4096, 4, ... 1392640, 16384, ) == 0x0 01007 424 NtUserRegisterClassExWOW (1234608, 1234688, 1234672, 1234704, 0, 384, 0, ... ) == 0x810dc038 01008 424 NtUserGetAtomName (49208, 1233372, ... ) == 0x15 01009 424 NtUserCreateWindowEx (0, 49208, 49208, (0, 49208, 49208, "OleMainThreadWndName", -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 1998258176, 0, 1073742848, 0, ... , -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 1998258176, 0, 1073742848, 0, ... 01010 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1230896, ... ) }, 1230896, ... ) == 0x0 01011 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 12, {status=0x0, info=1}, ) }, 5, 96, ... 12, {status=0x0, info=1}, ) == 0x0 01012 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 12, ... 104, ) == 0x0 01013 424 NtClose (12, ... ) == 0x0 01014 424 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x900000), 0x0, 204800, ) == 0x0 01015 424 NtClose (104, ... ) == 0x0 01016 424 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 01017 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1231212, ... ) }, 1231212, ... ) == 0x0 01018 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 01019 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 104, ... 12, ) == 0x0 01020 424 NtQuerySection (12, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01021 424 NtClose (104, ... ) == 0x0 01022 424 NtMapViewOfSection (12, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5ad70000), 0x0, 212992, ) == 0x0 01023 424 NtClose (12, ... ) == 0x0 01024 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01025 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01026 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01027 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 12, ) == 0x0 01028 424 NtQueryInformationToken (12, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01029 424 NtClose (12, ... ) == 0x0 01030 424 NtAllocateVirtualMemory (-1, 1220608, 0, 4096, 4096, 260, ... 1220608, 4096, ) == 0x0 01031 424 NtOpenKey (0x2001f, {24, 0, 0x640, 0, 0, (0x2001f, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 12, ) }, ... 12, ) == 0x0 01032 424 NtOpenKey (0x1, {24, 12, 0x40, 0, 0, (0x1, {24, 12, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\ThemeManager"}, ... 104, ) }, ... 104, ) == 0x0 01033 424 NtQueryValueKey (104, (104, "Compositing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01034 424 NtClose (104, ... ) == 0x0 01035 424 NtClose (12, ... ) == 0x0 01036 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01037 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 12, ) == 0x0 01038 424 NtQueryInformationToken (12, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01039 424 NtClose (12, ... ) == 0x0 01040 424 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 12, ) }, ... 12, ) == 0x0 01041 424 NtOpenKey (0x1, {24, 12, 0x40, 0, 0, (0x1, {24, 12, 0x40, 0, 0, "Control Panel\Desktop"}, ... 104, ) }, ... 104, ) == 0x0 01042 424 NtQueryValueKey (104, (104, "LameButtonText", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01043 424 NtClose (104, ... ) == 0x0 01044 424 NtClose (12, ... ) == 0x0 01045 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\UxTheme.dll"}, 1230712, ... ) }, 1230712, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01046 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "UxTheme.dll"}, 1230712, ... ) }, 1230712, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01047 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\UxTheme.dll"}, 1230712, ... ) }, 1230712, ... ) == 0x0 01048 424 NtUserGetProcessWindowStation (... ) == 0x28 01049 424 NtUserGetObjectInformation (40, 2, 0, 0, 1233008, ... ) == 0x0 01050 424 NtUserGetObjectInformation (40, 2, 1330040, 16, 1233008, ... ) == 0x1 01051 424 NtUserGetGUIThreadInfo (424, 1232964, ... ) == 0x1 01052 424 NtConnectPort ( ("\ThemeApiPort", {12, 2, 1, 1}, 0x0, 0x0, 1232784, 64, ... 12, 0x0, 0x0, 0x0, 64, ) , {12, 2, 1, 1}, 0x0, 0x0, 1232784, 64, ... 12, 0x0, 0x0, 0x0, 64, ) == 0x0 01053 424 NtRequestWaitReplyPort (12, {32, 56, new_msg, 0, 0, 0, 0, 0} (12, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 420, 424, 1515, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 420, 424, 1515, 0} (12, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 420, 424, 1515, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01054 424 NtRequestWaitReplyPort (12, {32, 56, new_msg, 0, 0, 0, 0, 0} (12, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 420, 424, 1516, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 420, 424, 1516, 0} (12, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 420, 424, 1516, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01055 424 NtUserCallNoParam (29, ... 01056 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1230256, ... ) }, 1230256, ... ) == 0x0 01055 424 NtUserCallNoParam ... ) == 0x0 01057 424 NtUserSystemParametersInfo (41, 0, 1524225160, 0, ... ) == 0x1 01058 424 NtGdiHfontCreate (1232336, 356, 0, 0, 1355880, ... ) == 0x380a03ca 01059 424 NtGdiHfontCreate (1232336, 356, 0, 0, 1355872, ... ) == 0x160a03b9 01060 424 NtRequestWaitReplyPort (12, {32, 56, new_msg, 0, 0, 0, 0, 0} (12, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 420, 424, 1517, 0} "\0\0\0\0\0\0\0\0h\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 420, 424, 1517, 0} (12, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 420, 424, 1517, 0} "\0\0\0\0\0\0\0\0h\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01061 424 NtMapViewOfSection (104, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x900000), {0, 0}, 331776, ) == 0x0 01062 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01063 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01064 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01065 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01066 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01067 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01068 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01069 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01070 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01071 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01072 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01073 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01074 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01075 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01076 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01077 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01078 424 NtUserGetWindowDC (0, ... ) == 0x1010050 01079 424 NtGdiCreatePatternBrushInternal (59048369, 0, 0, ... ) == 0x7100382 01080 424 NtUserCallOneParam (16842832, 56, ... ) == 0x1 01081 424 NtUserCallNoParam (29, ... 01082 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1229700, ... ) }, 1229700, ... ) == 0x0 01081 424 NtUserCallNoParam ... ) == 0x0 01083 424 NtUserCallNoParam (29, ... 01084 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1229696, ... ) }, 1229696, ... ) == 0x0 01083 424 NtUserCallNoParam ... ) == 0x0 01085 424 NtUserMessageCall (0x200b2, WM_NCCREATE, 0x0, 0x12d188, 0, 670, 0, ... ) == 0x1 01086 424 NtUserMessageCall (0x200b2, WM_NCCALCSIZE, 0x0, 0x12d1b0, 0, 670, 0, ... ) == 0x0 01087 424 NtUserSetProp (131250, 43288, -1, ... ) == 0x1 01009 424 NtUserCreateWindowEx ... ) == 0x200b2 01088 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 116, ) }, ... 116, ) == 0x0 01089 424 NtQueryValueKey (116, (116, "MaximizeApps", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01090 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 120, ) }, ... 120, ) == 0x0 01091 424 NtQueryValueKey (120, (120, "MaximizeApps", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01092 424 NtClose (120, ... ) == 0x0 01093 424 NtClose (116, ... ) == 0x0 01094 424 NtAllocateVirtualMemory (-1, 1409024, 0, 24576, 4096, 4, ... 1409024, 24576, ) == 0x0 01095 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01096 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Rpc\PagedBuffers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01097 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Rpc"}, ... 116, ) }, ... 116, ) == 0x0 01098 424 NtQueryValueKey (116, (116, "MaxRpcSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01099 424 NtClose (116, ... ) == 0x0 01100 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe\RpcThreadPoolThrottle"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01101 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 116, ) == 0x0 01102 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 120, ) == 0x0 01103 424 NtQuerySystemTime (... {1954665664, 29874991}, ) == 0x0 01104 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 124, ) == 0x0 01105 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\Rpc"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01106 424 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 0x0, ) == 0x0 01107 424 NtQueryInformationProcess (-1, QuotaLimits, 32, ... {process info, class 1, size 32}, 0x0, ) == 0x0 01108 424 NtQueryInformationProcess (-1, VmCounters, 44, ... {process info, class 3, size 44}, 0x0, ) == 0x0 01109 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 128, ) == 0x0 01110 424 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 132, ) == 0x0 01111 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 136, ) }, ... 136, ) == 0x0 01112 424 NtOpenKey (0x20019, {24, 136, 0x40, 0, 0, (0x20019, {24, 136, 0x40, 0, 0, "ActiveComputerName"}, ... 140, ) }, ... 140, ) == 0x0 01113 424 NtQueryValueKey (140, (140, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (140, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (140, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 01114 424 NtClose (140, ... ) == 0x0 01115 424 NtClose (136, ... ) == 0x0 01116 424 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 136, ) == 0x0 01117 424 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 140, ) == 0x0 01118 424 NtDuplicateObject (-1, 136, -1, 0x0, 0, 2, ... 144, ) == 0x0 01119 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01120 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 148, ) == 0x0 01121 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01122 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01123 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1233136, (0xc0100080, {24, 0, 0x40, 0, 1233136, "\??\PIPE\wkssvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 152, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 152, {status=0x0, info=1}, ) == 0x0 01124 424 NtSetInformationFile (152, 1233192, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 01125 424 NtSetInformationFile (152, 1233184, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 01126 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 01127 424 NtWriteFile (152, 129, 0, 0, (152, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\230\320\377k\22\241\206\2303F\303\370~4Z\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 01128 424 NtReadFile (152, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (152, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\335#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 01129 424 NtFsControlFile (152, 129, 0x0, 0x0, 0x11c017, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\335#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 32, 1024, ... {status=0x103, info=68}, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\335#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 01130 424 NtClose (148, ... ) == 0x0 01131 424 NtClose (152, ... ) == 0x0 01132 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work"}, 1233180, ... ) }, 1233180, ... ) == 0x0 01133 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01134 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01135 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "xeqfhcg.bat"}, 1233000, ... ) }, 1233000, ... ) == 0x0 01136 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01137 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01138 424 NtCreateSemaphore (0x1f0003, {24, 52, 0x80, 1355896, 0, (0x1f0003, {24, 52, 0x80, 1355896, 0, "shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}"}, 0, 2147483647, ... 152, ) }, 0, 2147483647, ... 152, ) == STATUS_OBJECT_NAME_EXISTS 01139 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 01140 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 01141 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01142 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 148, ) }, ... 148, ) == 0x0 01143 424 NtQueryValueKey (148, (148, "NoNetHood", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01144 424 NtClose (148, ... ) == 0x0 01145 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 01146 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 01147 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01148 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 148, ) }, ... 148, ) == 0x0 01149 424 NtQueryValueKey (148, (148, "NoPropertiesMyComputer", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01150 424 NtClose (148, ... ) == 0x0 01151 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 01152 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 01153 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01154 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 148, ) }, ... 148, ) == 0x0 01155 424 NtQueryValueKey (148, (148, "NoInternetIcon", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01156 424 NtClose (148, ... ) == 0x0 01157 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 01158 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 01159 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01160 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 148, ) }, ... 148, ) == 0x0 01161 424 NtQueryValueKey (148, (148, "NoCommonGroups", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01162 424 NtClose (148, ... ) == 0x0 01163 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace"}, ... 148, ) }, ... 148, ) == 0x0 01164 424 NtEnumerateKey (148, 0, Basic, 288, ... {LastWrite={0x5aa70706,0x1c73999}, TitleIdx=0, Name= (148, 0, Basic, 288, ... {LastWrite={0x5aa70706,0x1c73999}, TitleIdx=0, Name="{1f4de370-d627-11d1-ba4f-00a0c91eedba}"}, 92, ) }, 92, ) == 0x0 01165 424 NtOpenKey (0x20019, {24, 148, 0x40, 0, 0, (0x20019, {24, 148, 0x40, 0, 0, "{1f4de370-d627-11d1-ba4f-00a0c91eedba}"}, ... 156, ) }, ... 156, ) == 0x0 01166 424 NtQueryValueKey (156, (156, "SuppressionPolicy", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01167 424 NtClose (156, ... ) == 0x0 01168 424 NtEnumerateKey (148, 1, Basic, 288, ... {LastWrite={0x5aa4a4ac,0x1c73999}, TitleIdx=0, Name= (148, 1, Basic, 288, ... {LastWrite={0x5aa4a4ac,0x1c73999}, TitleIdx=0, Name="{450D8FBA-AD25-11D0-98A8-0800361B1103}"}, 92, ) }, 92, ) == 0x0 01169 424 NtOpenKey (0x20019, {24, 148, 0x40, 0, 0, (0x20019, {24, 148, 0x40, 0, 0, "{450D8FBA-AD25-11D0-98A8-0800361B1103}"}, ... 156, ) }, ... 156, ) == 0x0 01170 424 NtQueryValueKey (156, (156, "SuppressionPolicy", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01171 424 NtClose (156, ... ) == 0x0 01172 424 NtEnumerateKey (148, 2, Basic, 288, ... {LastWrite={0x98c5c536,0x1c738c7}, TitleIdx=0, Name= (148, 2, Basic, 288, ... {LastWrite={0x98c5c536,0x1c738c7}, TitleIdx=0, Name="{645FF040-5081-101B-9F08-00AA002F954E}"}, 92, ) }, 92, ) == 0x0 01173 424 NtOpenKey (0x20019, {24, 148, 0x40, 0, 0, (0x20019, {24, 148, 0x40, 0, 0, "{645FF040-5081-101B-9F08-00AA002F954E}"}, ... 156, ) }, ... 156, ) == 0x0 01174 424 NtQueryValueKey (156, (156, "SuppressionPolicy", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01175 424 NtClose (156, ... ) == 0x0 01176 424 NtEnumerateKey (148, 3, Basic, 288, ... {LastWrite={0x5aa70706,0x1c73999}, TitleIdx=0, Name= (148, 3, Basic, 288, ... {LastWrite={0x5aa70706,0x1c73999}, TitleIdx=0, Name="{e17d4fc0-5564-11d1-83f2-00a0c90dc849}"}, 92, ) }, 92, ) == 0x0 01177 424 NtOpenKey (0x20019, {24, 148, 0x40, 0, 0, (0x20019, {24, 148, 0x40, 0, 0, "{e17d4fc0-5564-11d1-83f2-00a0c90dc849}"}, ... 156, ) }, ... 156, ) == 0x0 01178 424 NtQueryValueKey (156, (156, "SuppressionPolicy", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01179 424 NtClose (156, ... ) == 0x0 01180 424 NtEnumerateKey (148, 4, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 01181 424 NtClose (148, ... ) == 0x0 01182 424 NtOpenKey (0x20019, {24, 64, 0x40, 0, 0, (0x20019, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01183 424 NtOpenProcessToken (-1, 0x8, ... 148, ) == 0x0 01184 424 NtQueryInformationToken (148, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 01185 424 NtClose (148, ... ) == 0x0 01186 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01187 424 NtCreateKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, 0, 0x0, 0, ... 148, 2, ) }, 0, 0x0, 0, ... 148, 2, ) == 0x0 01188 424 NtOpenKey (0x2000000, {24, 148, 0x40, 0, 0, ""}, ... 156, ) == 0x0 01189 424 NtCreateKey (0x20019, {24, 156, 0x40, 0, 0, (0x20019, {24, 156, 0x40, 0, 0, "SessionInfo\00000000000092fa"}, 0, 0x0, 1, ... 160, 2, ) }, 0, 0x0, 1, ... 160, 2, ) == 0x0 01190 424 NtClose (156, ... ) == 0x0 01191 424 NtOpenKey (0x20019, {24, 160, 0x40, 0, 0, (0x20019, {24, 160, 0x40, 0, 0, "Desktop\NameSpace"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01192 424 NtClose (160, ... ) == 0x0 01193 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01194 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 160, ) == 0x0 01195 424 NtQueryInformationToken (160, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01196 424 NtClose (160, ... ) == 0x0 01197 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes"}, ... 160, ) }, ... 160, ) == 0x0 01198 424 NtSetInformationObject (162, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 01199 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01200 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01201 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"}, ... 156, ) }, ... 156, ) == 0x0 01202 424 NtQueryKey (158, Name, 392, ... {Name= (158, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolderB"}, 186, ) }, 186, ) == 0x0 01203 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01204 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01205 424 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01206 424 NtClose (164, ... ) == 0x0 01207 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01208 424 NtQueryValueKey (158, (158, "WantsParseDisplayName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01209 424 NtClose (158, ... ) == 0x0 01210 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01211 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01212 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder"}, ... 156, ) }, ... 156, ) == 0x0 01213 424 NtQueryKey (158, Name, 392, ... {Name= (158, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolderB"}, 186, ) }, 186, ) == 0x0 01214 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01215 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01216 424 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01217 424 NtClose (164, ... ) == 0x0 01218 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01219 424 NtQueryValueKey (158, (158, "WantsParseDisplayName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01220 424 NtClose (158, ... ) == 0x0 01221 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01222 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01223 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder"}, ... 156, ) }, ... 156, ) == 0x0 01224 424 NtQueryKey (158, Name, 392, ... {Name= (158, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolderB"}, 186, ) }, 186, ) == 0x0 01225 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01226 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01227 424 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01228 424 NtClose (164, ... ) == 0x0 01229 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01230 424 NtQueryValueKey (158, (158, "WantsParseDisplayName", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (158, "WantsParseDisplayName", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01231 424 NtClose (158, ... ) == 0x0 01232 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01233 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESC"}, 138, ) }, 138, ) == 0x0 01234 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01235 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... 156, ) }, ... 156, ) == 0x0 01236 424 NtQueryKey (158, Name, 392, ... {Name= (158, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01237 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01238 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01239 424 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01240 424 NtClose (164, ... ) == 0x0 01241 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01242 424 NtQueryValueKey (158, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data= (158, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0s\0h\0d\0o\0c\0v\0w\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01243 424 NtQueryKey (158, Name, 392, ... {Name= (158, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01244 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01245 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01246 424 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01247 424 NtClose (164, ... ) == 0x0 01248 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01249 424 NtQueryValueKey (158, (158, "LoadWithoutCOM", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01250 424 NtClose (158, ... ) == 0x0 01251 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 01252 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 01253 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01254 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 156, ) }, ... 156, ) == 0x0 01255 424 NtQueryValueKey (156, (156, "EnforceShellExtensionSecurity", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01256 424 NtClose (156, ... ) == 0x0 01257 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "appHelp.dll"}, ... 156, ) }, ... 156, ) == 0x0 01258 424 NtMapViewOfSection (156, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75f40000), 0x0, 118784, ) == 0x0 01259 424 NtClose (156, ... ) == 0x0 01260 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 156, ) }, ... 156, ) == 0x0 01261 424 NtQueryValueKey (156, (156, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01262 424 NtClose (156, ... ) == 0x0 01263 424 NtAllocateVirtualMemory (-1, 1433600, 0, 4096, 4096, 4, ... 1433600, 4096, ) == 0x0 01264 424 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32"}, ... 156, ) }, ... 156, ) == 0x0 01265 424 NtQueryValueKey (156, " (156, "", Full, 520, ... TitleIdx=0, Type=2, Name="", Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0s\0h\0d\0o\0c\0v\0w\0.\0d\0l\0l\0\0\0"}, 88, ) (156, "", Full, 520, ... TitleIdx=0, Type=2, Name="", Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0s\0h\0d\0o\0c\0v\0w\0.\0d\0l\0l\0\0\0"}, 88, ) %\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0s\0h\0d\0o\0c\0v\0w\0.\0d\0l\0l\0\0\0"}, 88, ) == 0x0 01266 424 NtClose (156, ... ) == 0x0 01267 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll"}, 0x0, 128, 1, 1, 96, 0, 0, ... 156, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 156, {status=0x0, info=1}, ) == 0x0 01268 424 NtQueryVolumeInformationFile (156, 1233320, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01269 424 NtOpenMutant (0x120001, {24, 52, 0x0, 0, 0, (0x120001, {24, 52, 0x0, 0, 0, "ShimCacheMutex"}, ... 164, ) }, ... 164, ) == 0x0 01270 424 NtWaitForSingleObject (164, 0, {-1000000, -1}, ... ) == 0x0 01271 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "ShimSharedMemory"}, ... 168, ) }, ... 168, ) == 0x0 01272 424 NtMapViewOfSection (168, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x3d0000), {0, 0}, 57344, ) == 0x0 01273 424 NtQueryInformationFile (156, 1233284, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01274 424 NtQueryInformationFile (156, 1233324, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01275 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01276 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 172, ) == 0x0 01277 424 NtQueryInformationToken (172, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01278 424 NtClose (172, ... ) == 0x0 01279 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01280 424 NtReleaseMutant (164, ... 0x0, ) == 0x0 01281 424 NtClose (156, ... ) == 0x0 01282 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 156, ) }, ... 156, ) == 0x0 01283 424 NtQueryValueKey (156, (156, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01284 424 NtClose (156, ... ) == 0x0 01285 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CLBCATQ.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01286 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\CLBCATQ.DLL"}, 1231072, ... ) }, 1231072, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01287 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "CLBCATQ.DLL"}, 1231072, ... ) }, 1231072, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01288 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\CLBCATQ.DLL"}, 1231072, ... ) }, 1231072, ... ) == 0x0 01289 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\CLBCATQ.DLL"}, 5, 96, ... 156, {status=0x0, info=1}, ) }, 5, 96, ... 156, {status=0x0, info=1}, ) == 0x0 01290 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 156, ... 172, ) == 0x0 01291 424 NtQuerySection (172, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01292 424 NtClose (156, ... ) == 0x0 01293 424 NtMapViewOfSection (172, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76fd0000), 0x0, 491520, ) == 0x0 01294 424 NtClose (172, ... ) == 0x0 01295 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMRes.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01296 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\COMRes.dll"}, 1230268, ... ) }, 1230268, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01297 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "COMRes.dll"}, 1230268, ... ) }, 1230268, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01298 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\COMRes.dll"}, 1230268, ... ) }, 1230268, ... ) == 0x0 01299 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\COMRes.dll"}, 5, 96, ... 172, {status=0x0, info=1}, ) }, 5, 96, ... 172, {status=0x0, info=1}, ) == 0x0 01300 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 172, ... 156, ) == 0x0 01301 424 NtQuerySection (156, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01302 424 NtClose (172, ... ) == 0x0 01303 424 NtMapViewOfSection (156, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77050000), 0x0, 806912, ) == 0x0 01304 424 NtClose (156, ... ) == 0x0 01305 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "VERSION.dll"}, ... 156, ) }, ... 156, ) == 0x0 01306 424 NtMapViewOfSection (156, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c00000), 0x0, 28672, ) == 0x0 01307 424 NtClose (156, ... ) == 0x0 01308 424 NtOpenKey (0xf003f, {24, 28, 0x40, 0, 0, (0xf003f, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3\Debug"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01309 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3\Debug"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01310 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLE"}, ... 156, ) }, ... 156, ) == 0x0 01311 424 NtQueryValueKey (156, (156, "MinimumFreeMemPercentageToCreateProcess", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01312 424 NtQueryValueKey (156, (156, "MinimumFreeMemPercentageToCreateObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01313 424 NtClose (156, ... ) == 0x0 01314 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\Registration"}, 1231100, ... ) }, 1231100, ... ) == 0x0 01315 424 NtOpenSection (0x4, {24, 52, 0x2, 0, 0, (0x4, {24, 52, 0x2, 0, 0, "Global\ComPlusCOMRegTable"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01316 424 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 01317 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 156, ) }, ... 156, ) == 0x0 01318 424 NtQueryValueKey (156, (156, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01319 424 NtClose (156, ... ) == 0x0 01320 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes"}, ... 156, ) }, ... 156, ) == 0x0 01321 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 172, ) == 0x0 01322 424 NtNotifyChangeKey (156, 172, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01323 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 176, ) }, ... 176, ) == 0x0 01324 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 180, ) == 0x0 01325 424 NtNotifyChangeKey (176, 180, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01326 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 184, ) == 0x0 01327 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER"}, ... 188, ) }, ... 188, ) == 0x0 01328 424 NtSetInformationObject (188, Handle, {Inherit=0,ProtectFromClose=1,}, 2011365632, ... ) == 0x0 01329 424 NtNotifyChangeKey (188, 184, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01330 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes"}, ... 192, ) }, ... 192, ) == 0x0 01331 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 196, ) == 0x0 01332 424 NtNotifyChangeKey (192, 196, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01333 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 200, ) == 0x0 01334 424 NtNotifyChangeKey (188, 200, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01335 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 204, ) }, ... 204, ) == 0x0 01336 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 208, ) == 0x0 01337 424 NtNotifyChangeKey (204, 208, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01338 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 212, ) }, ... 212, ) == 0x0 01339 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 216, ) == 0x0 01340 424 NtNotifyChangeKey (212, 216, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01341 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes\CLSID"}, ... 220, ) }, ... 220, ) == 0x0 01342 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 224, ) == 0x0 01343 424 NtNotifyChangeKey (220, 224, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01344 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes"}, ... 228, ) }, ... 228, ) == 0x0 01345 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 232, ) == 0x0 01346 424 NtNotifyChangeKey (228, 232, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01347 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 236, ) }, ... 236, ) == 0x0 01348 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 240, ) == 0x0 01349 424 NtNotifyChangeKey (236, 240, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01350 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 244, ) == 0x0 01351 424 NtNotifyChangeKey (188, 244, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01352 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 248, ) }, ... 248, ) == 0x0 01353 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 252, ) == 0x0 01354 424 NtNotifyChangeKey (248, 252, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01355 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 256, ) }, ... 256, ) == 0x0 01356 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 260, ) == 0x0 01357 424 NtNotifyChangeKey (256, 260, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01358 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes\CLSID"}, ... 264, ) }, ... 264, ) == 0x0 01359 424 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 268, ) == 0x0 01360 424 NtNotifyChangeKey (264, 268, 0, 0, 2011390432, 5, 1, 0, 0, 1, ... ) == 0x103 01361 424 NtOpenSection (0x4, {24, 52, 0x2, 0, 0, (0x4, {24, 52, 0x2, 0, 0, "Global\ComPlusCOMRegTable"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01362 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 272, ) }, ... 272, ) == 0x0 01363 424 NtQueryValueKey (272, (272, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (272, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01364 424 NtClose (272, ... ) == 0x0 01365 424 NtAllocateVirtualMemory (-1, 1437696, 0, 4096, 4096, 4, ... 1437696, 4096, ) == 0x0 01366 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01367 424 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01368 424 NtOpenSection (0x4, {24, 52, 0x0, 0, 0, (0x4, {24, 52, 0x0, 0, 0, "__R_000000000007_SMem__"}, ... 272, ) }, ... 272, ) == 0x0 01369 424 NtMapViewOfSection (272, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x3e0000), {0, 0}, 24576, ) == 0x0 01370 424 NtAllocateVirtualMemory (-1, 3301376, 0, 8192, 4096, 4, ... 3301376, 8192, ) == 0x0 01371 424 NtAllocateVirtualMemory (-1, 3309568, 0, 8192, 4096, 4, ... 3309568, 8192, ) == 0x0 01372 424 NtOpenSection (0x4, {24, 52, 0x2, 0, 0, (0x4, {24, 52, 0x2, 0, 0, "Global\ComPlusCOMRegTable"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01373 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 276, ) }, ... 276, ) == 0x0 01374 424 NtQueryValueKey (276, (276, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (276, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 01375 424 NtClose (276, ... ) == 0x0 01376 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01377 424 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01378 424 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 1, ... 4128768, 65536, ) == 0x0 01379 424 NtAllocateVirtualMemory (-1, 4128768, 0, 4096, 4096, 4, ... 4128768, 4096, ) == 0x0 01380 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01381 424 NtOpenKey (0x20019, {24, 162, 0x40, 0, 0, (0x20019, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01382 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... 276, ) }, ... 276, ) == 0x0 01383 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}9"}, 162, ) }, 162, ) == 0x0 01384 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01385 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01386 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01387 424 NtClose (280, ... ) == 0x0 01388 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01389 424 NtOpenKey (0x1, {24, 278, 0x40, 0, 0, (0x1, {24, 278, 0x40, 0, 0, "TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01390 424 NtClose (278, ... ) == 0x0 01391 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01392 424 NtOpenKey (0x20019, {24, 162, 0x40, 0, 0, (0x20019, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01393 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... 276, ) }, ... 276, ) == 0x0 01394 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}9"}, 162, ) }, 162, ) == 0x0 01395 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01396 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01397 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01398 424 NtClose (280, ... ) == 0x0 01399 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01400 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "InprocServer32"}, ... 280, ) }, ... 280, ) == 0x0 01401 424 NtQueryKey (282, Name, 392, ... {Name= (282, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01402 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01403 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01404 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01405 424 NtClose (284, ... ) == 0x0 01406 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01407 424 NtQueryValueKey (282, (282, "InprocServer32", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01408 424 NtClose (282, ... ) == 0x0 01409 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01410 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01411 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01412 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01413 424 NtClose (280, ... ) == 0x0 01414 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocServerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01415 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "InprocServerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01416 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01417 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01418 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01419 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01420 424 NtClose (280, ... ) == 0x0 01421 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01422 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01423 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01424 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01425 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01426 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01427 424 NtClose (280, ... ) == 0x0 01428 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01429 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "InprocServer32"}, ... 280, ) }, ... 280, ) == 0x0 01430 424 NtQueryKey (282, Name, 392, ... {Name= (282, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01431 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01432 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01433 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01434 424 NtClose (284, ... ) == 0x0 01435 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01436 424 NtQueryValueKey (282, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data= (282, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0s\0h\0d\0o\0c\0v\0w\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01437 424 NtClose (282, ... ) == 0x0 01438 424 NtAllocateVirtualMemory (-1, 1441792, 0, 4096, 4096, 4, ... 1441792, 4096, ) == 0x0 01439 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01440 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01441 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01442 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01443 424 NtClose (280, ... ) == 0x0 01444 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocHandler32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01445 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "InprocHandler32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01446 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01447 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01448 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01449 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01450 424 NtClose (280, ... ) == 0x0 01451 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocHandlerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01452 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "InprocHandlerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01453 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01454 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01455 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01456 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01457 424 NtClose (280, ... ) == 0x0 01458 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01459 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01460 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}_"}, 162, ) }, 162, ) == 0x0 01461 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01462 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01463 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01464 424 NtClose (280, ... ) == 0x0 01465 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\LocalServer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01466 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "LocalServer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01467 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01468 424 NtOpenKey (0x20019, {24, 162, 0x40, 0, 0, (0x20019, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01469 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... 280, ) }, ... 280, ) == 0x0 01470 424 NtQueryKey (282, Name, 392, ... {Name= (282, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}9"}, 162, ) }, 162, ) == 0x0 01471 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01472 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01473 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01474 424 NtClose (284, ... ) == 0x0 01475 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01476 424 NtQueryValueKey (282, (282, "AppID", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01477 424 NtClose (282, ... ) == 0x0 01478 424 NtClose (278, ... ) == 0x0 01479 424 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {420, 0}, ... 276, ) == 0x0 01480 424 NtQueryInformationProcess (276, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 01481 424 NtClose (276, ... ) == 0x0 01482 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01483 424 NtOpenKey (0x20019, {24, 162, 0x40, 0, 0, (0x20019, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01484 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... 276, ) }, ... 276, ) == 0x0 01485 424 NtClose (278, ... ) == 0x0 01486 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES3"}, 138, ) }, 138, ) == 0x0 01487 424 NtOpenKey (0x20019, {24, 162, 0x40, 0, 0, (0x20019, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01488 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... 276, ) }, ... 276, ) == 0x0 01489 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}9"}, 162, ) }, 162, ) == 0x0 01490 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01491 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01492 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01493 424 NtClose (280, ... ) == 0x0 01494 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01495 424 NtOpenKey (0x2000000, {24, 278, 0x40, 0, 0, (0x2000000, {24, 278, 0x40, 0, 0, "InprocServer32"}, ... 280, ) }, ... 280, ) == 0x0 01496 424 NtQueryKey (282, Name, 392, ... {Name= (282, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01497 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01498 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01499 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01500 424 NtClose (284, ... ) == 0x0 01501 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01502 424 NtQueryValueKey (282, (282, "ThreadingModel", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0p\0a\0r\0t\0m\0e\0n\0t\0\0\0"}, 32, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (282, "ThreadingModel", Partial, 144, ... TitleIdx=0, Type=1, Data="A\0p\0a\0r\0t\0m\0e\0n\0t\0\0\0"}, 32, ) }, 32, ) == 0x0 01503 424 NtClose (282, ... ) == 0x0 01504 424 NtClose (278, ... ) == 0x0 01505 424 NtAllocateVirtualMemory (-1, 1445888, 0, 8192, 4096, 4, ... 1445888, 8192, ) == 0x0 01506 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01507 424 NtOpenKey (0x20019, {24, 162, 0x40, 0, 0, (0x20019, {24, 162, 0x40, 0, 0, "CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01508 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... 276, ) }, ... 276, ) == 0x0 01509 424 NtQueryKey (278, Name, 384, ... {Name= (278, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}9"}, 162, ) }, 162, ) == 0x0 01510 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01511 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 280, ) == 0x0 01512 424 NtQueryInformationToken (280, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01513 424 NtClose (280, ... ) == 0x0 01514 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01515 424 NtOpenKey (0x1, {24, 278, 0x40, 0, 0, (0x1, {24, 278, 0x40, 0, 0, "TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01516 424 NtClose (278, ... ) == 0x0 01517 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll"}, 1227492, ... ) }, 1227492, ... ) == 0x0 01518 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll"}, 5, 96, ... 276, {status=0x0, info=1}, ) }, 5, 96, ... 276, {status=0x0, info=1}, ) == 0x0 01519 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 276, ... 280, ) == 0x0 01520 424 NtClose (276, ... ) == 0x0 01521 424 NtMapViewOfSection (280, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x960000), 0x0, 1339392, ) == 0x0 01522 424 NtClose (280, ... ) == 0x0 01523 424 NtUnmapViewOfSection (-1, 0x960000, ... ) == 0x0 01524 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll"}, 1227808, ... ) }, 1227808, ... ) == 0x0 01525 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll"}, 5, 96, ... 280, {status=0x0, info=1}, ) }, 5, 96, ... 280, {status=0x0, info=1}, ) == 0x0 01526 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 280, ... 276, ) == 0x0 01527 424 NtQuerySection (276, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01528 424 NtClose (280, ... ) == 0x0 01529 424 NtMapViewOfSection (276, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x769c0000), 0x0, 1347584, ) == 0x0 01530 424 NtClose (276, ... ) == 0x0 01531 424 NtAllocateVirtualMemory (-1, 1216512, 0, 4096, 4096, 260, ... 1216512, 4096, ) == 0x0 01532 424 NtQueryDefaultUILanguage (1226172, ... 01533 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01534 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482040, ) == 0x0 01535 424 NtQueryInformationToken (-2147482040, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01536 424 NtClose (-2147482040, ... ) == 0x0 01537 424 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482040, ) }, ... -2147482040, ) == 0x0 01538 424 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01539 424 NtOpenKey (0x80000000, {24, -2147482040, 0x640, 0, 0, (0x80000000, {24, -2147482040, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 01540 424 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01541 424 NtClose (-2147482044, ... ) == 0x0 01542 424 NtClose (-2147482040, ... ) == 0x0 01532 424 NtQueryDefaultUILanguage ... ) == 0x0 01543 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01544 424 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll"}, 1, 96, ... 276, {status=0x0, info=1}, ) }, 1, 96, ... 276, {status=0x0, info=1}, ) == 0x0 01545 424 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 276, ... 280, ) == 0x0 01546 424 NtMapViewOfSection (280, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x960000), 0x0, 1339392, ) == 0x0 01547 424 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01548 424 NtQueryDefaultLocale (1, 1224208, ... ) == 0x0 01549 424 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shdocvw.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01550 424 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1225064, 1, 96, 0} (24, {128, 156, new_msg, 0, 1225064, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\264\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\24\1\0\0\377\377\377\377\0\0\0\0\10\340\241\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\270\22\0\0\0\0\0" ... {128, 156, reply, 0, 420, 424, 1518, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\264\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\24\1\0\0\377\377\377\377\0\0\0\0\10\340\241\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\270\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 420, 424, 1518, 0} (24, {128, 156, new_msg, 0, 1225064, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\264\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\24\1\0\0\377\377\377\377\0\0\0\0\10\340\241\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\270\22\0\0\0\0\0" ... {128, 156, reply, 0, 420, 424, 1518, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\264\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\24\1\0\0\377\377\377\377\0\0\0\0\10\340\241\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\270\22\0\0\0\0\0" ) ) == 0x0 01551 424 NtClose (276, ... ) == 0x0 01552 424 NtClose (280, ... ) == 0x0 01553 424 NtUnmapViewOfSection (-1, 0x960000, ... ) == 0x0 01554 424 NtUnmapViewOfSection (-1, 0x12b868, ... ) == STATUS_NOT_MAPPED_VIEW 01555 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01556 424 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01557 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01558 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01559 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1222748, ... ) }, 1222748, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01560 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01561 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01562 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01563 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1223340, ... ) }, 1223340, ... ) == 0x0 01564 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 280, {status=0x0, info=1}, ) }, 3, 33, ... 280, {status=0x0, info=1}, ) == 0x0 01565 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01566 424 NtUserFindExistingCursorIcon (1227292, 1227308, 1227876, ... ) == 0x10011 01567 424 NtUserRegisterClassExWOW (1227744, 1227824, 1227808, 1227840, 0, 384, 0, ... ) == 0x810d0000 01568 424 NtUserGetClassInfo (1905590272, 1227908, 1227860, 1227936, 0, ... ) == 0xc05f 01569 424 NtGdiCreateHalftonePalette (0, ... ) == 0x408031c 01570 424 NtGdiDoPalette (67633948, 0, 256, 1227000, 2, 0, ... ) == 0x100 01571 424 NtGdiDeleteObjectApp (67633948, ... ) == 0x1 01572 424 NtGdiCreateCompatibleDC (0, ... ) == 0x501031c 01573 424 NtGdiCreatePaletteInternal (1226996, 256, ... ) == 0xc08031a 01574 424 NtGdiDeleteObjectApp (83952412, ... ) == 0x1 01575 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESn"}, 138, ) }, 138, ) == 0x0 01576 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\Typelib"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01577 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\Typelib"}, ... 276, ) }, ... 276, ) == 0x0 01578 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\TypeLib0"}, 186, ) }, 186, ) == 0x0 01579 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01580 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01581 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01582 424 NtClose (284, ... ) == 0x0 01583 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Interface\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\TypeLib"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01584 424 NtQueryValueKey (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="{\0E\0A\0B\02\02\0A\0C\00\0-\03\00\0C\01\0-\01\01\0C\0F\0-\0A\07\0E\0B\0-\00\00\00\00\0C\00\05\0B\0A\0E\00\0B\0}\0\0\0"}, 90, ) }, 90, ) == 0x0 01585 424 NtClose (278, ... ) == 0x0 01586 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01587 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Interface\{b722bccb-4e68-101b-a2bc-00aa00404770}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01588 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{b722bccb-4e68-101b-a2bc-00aa00404770}\ProxyStubClsid32"}, ... 276, ) }, ... 276, ) == 0x0 01589 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32"}, 204, ) }, 204, ) == 0x0 01590 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01591 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01592 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01593 424 NtClose (284, ... ) == 0x0 01594 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01595 424 NtQueryValueKey (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="{\0B\08\0D\0A\06\03\01\00\0-\0E\01\09\0B\0-\01\01\0D\00\0-\09\03\03\0C\0-\00\00\0A\00\0C\09\00\0D\0C\0A\0A\09\0}\0\0\0"}, 90, ) }, 90, ) == 0x0 01596 424 NtClose (278, ... ) == 0x0 01597 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01598 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Interface\{79eac9c4-baf9-11ce-8c82-00aa004ba90b}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01599 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{79eac9c4-baf9-11ce-8c82-00aa004ba90b}\ProxyStubClsid32"}, ... 276, ) }, ... 276, ) == 0x0 01600 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\ProxyStubClsid32"}, 204, ) }, 204, ) == 0x0 01601 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01602 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01603 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01604 424 NtClose (284, ... ) == 0x0 01605 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Interface\{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01606 424 NtQueryValueKey (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="{\0B\08\0D\0A\06\03\01\00\0-\0E\01\09\0B\0-\01\01\0D\00\0-\09\03\03\0C\0-\00\00\0A\00\0C\09\00\0D\0C\0A\0A\09\0}\0\0\0"}, 90, ) }, 90, ) == 0x0 01607 424 NtClose (278, ... ) == 0x0 01608 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01609 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01610 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32"}, ... 276, ) }, ... 276, ) == 0x0 01611 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32"}, 204, ) }, 204, ) == 0x0 01612 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01613 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01614 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01615 424 NtClose (284, ... ) == 0x0 01616 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Interface\{000214E6-0000-0000-C000-000000000046}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01617 424 NtQueryValueKey (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="{\0b\0f\05\00\0b\06\08\0e\0-\02\09\0b\08\0-\04\03\08\06\0-\0a\0e\09\0c\0-\09\07\03\04\0d\05\01\01\07\0c\0d\05\0}\0\0\0"}, 90, ) }, 90, ) == 0x0 01618 424 NtClose (278, ... ) == 0x0 01619 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01620 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01621 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32"}, ... 276, ) }, ... 276, ) == 0x0 01622 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32"}, 204, ) }, 204, ) == 0x0 01623 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01624 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01625 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01626 424 NtClose (284, ... ) == 0x0 01627 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Interface\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\ProxyStubClsid32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01628 424 NtQueryValueKey (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (278, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="{\0b\0f\05\00\0b\06\08\0e\0-\02\09\0b\08\0-\04\03\08\06\0-\0a\0e\09\0c\0-\09\07\03\04\0d\05\01\01\07\0c\0d\05\0}\0\0\0"}, 90, ) }, 90, ) == 0x0 01629 424 NtClose (278, ... ) == 0x0 01630 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{871C5380-42A0-1069-A2EA-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01631 424 NtAllocateVirtualMemory (-1, 1454080, 0, 12288, 4096, 4, ... 1454080, 12288, ) == 0x0 01632 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES"}, 138, ) }, 138, ) == 0x0 01633 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{1F4DE370-D627-11D1-BA4F-00A0C91EEDBA}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01634 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{1F4DE370-D627-11D1-BA4F-00A0C91EEDBA}\ShellFolder"}, ... 276, ) }, ... 276, ) == 0x0 01635 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\ShellFolder9"}, 186, ) }, 186, ) == 0x0 01636 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01637 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01638 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01639 424 NtClose (284, ... ) == 0x0 01640 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01641 424 NtQueryValueKey (278, (278, "WantsParseDisplayName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01642 424 NtClose (278, ... ) == 0x0 01643 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01644 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01645 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder"}, ... 276, ) }, ... 276, ) == 0x0 01646 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder6"}, 186, ) }, 186, ) == 0x0 01647 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01648 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01649 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01650 424 NtClose (284, ... ) == 0x0 01651 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01652 424 NtQueryValueKey (278, (278, "WantsParseDisplayName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01653 424 NtClose (278, ... ) == 0x0 01654 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01655 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01656 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder"}, ... 276, ) }, ... 276, ) == 0x0 01657 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder0"}, 186, ) }, 186, ) == 0x0 01658 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01659 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01660 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01661 424 NtClose (284, ... ) == 0x0 01662 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01663 424 NtQueryValueKey (278, (278, "WantsParseDisplayName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01664 424 NtClose (278, ... ) == 0x0 01665 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 01666 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "CLSID\{E17D4FC0-5564-11D1-83F2-00A0C90DC849}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01667 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{E17D4FC0-5564-11D1-83F2-00A0C90DC849}\ShellFolder"}, ... 276, ) }, ... 276, ) == 0x0 01668 424 NtQueryKey (278, Name, 392, ... {Name= (278, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\ShellFolder9"}, 186, ) }, 186, ) == 0x0 01669 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01670 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 284, ) == 0x0 01671 424 NtQueryInformationToken (284, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01672 424 NtClose (284, ... ) == 0x0 01673 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}\ShellFolder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01674 424 NtQueryValueKey (278, (278, "WantsParseDisplayName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01675 424 NtClose (278, ... ) == 0x0 01676 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks"}, ... 276, ) }, ... 276, ) == 0x0 01677 424 NtEnumerateValueKey (276, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (276, 0, Full, 220, ... TitleIdx=0, Type=1, Name="{AEB6717E-7E19-11d0-97EE-00C04FD91972}", Data="\0\0"}, 98, ) , Data= (276, 0, Full, 220, ... TitleIdx=0, Type=1, Name="{AEB6717E-7E19-11d0-97EE-00C04FD91972}", Data="\0\0"}, 98, ) }, 98, ) == 0x0 01678 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 01679 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01680 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32"}, ... 284, ) }, ... 284, ) == 0x0 01681 424 NtQueryKey (286, Name, 392, ... {Name= (286, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01682 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01683 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 288, ) == 0x0 01684 424 NtQueryInformationToken (288, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01685 424 NtClose (288, ... ) == 0x0 01686 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01687 424 NtQueryValueKey (286, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (286, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="s\0h\0e\0l\0l\03\02\0.\0d\0l\0l\0\0\0"}, 36, ) }, 36, ) == 0x0 01688 424 NtQueryKey (286, Name, 392, ... {Name= (286, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, 192, ) }, 192, ) == 0x0 01689 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01690 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 288, ) == 0x0 01691 424 NtQueryInformationToken (288, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01692 424 NtClose (288, ... ) == 0x0 01693 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01694 424 NtQueryValueKey (286, (286, "LoadWithoutCOM", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01695 424 NtClose (286, ... ) == 0x0 01696 424 NtEnumerateValueKey (276, 1, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 01697 424 NtClose (276, ... ) == 0x0 01698 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01699 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01700 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 1232452, ... ) }, 1232452, ... ) == 0x0 01701 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01702 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01703 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 276, ) }, ... 276, ) == 0x0 01704 424 NtQueryValueKey (276, (276, "TransparentEnabled", Full, 524, ... TitleIdx=0, Type=4, Name="TransparentEnabled", Data="\1\0\0\0"}, 60, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (276, "TransparentEnabled", Full, 524, ... TitleIdx=0, Type=4, Name="TransparentEnabled", Data="\1\0\0\0"}, 60, ) , Data= (276, "TransparentEnabled", Full, 524, ... TitleIdx=0, Type=4, Name="TransparentEnabled", Data="\1\0\0\0"}, 60, ) }, 60, ) == 0x0 01705 424 NtClose (276, ... ) == 0x0 01706 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01707 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01708 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 1233480, ... ) }, 1233480, ... ) == 0x0 01709 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01710 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01711 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 276, ) }, ... 276, ) == 0x0 01712 424 NtQueryValueKey (276, (276, "ExecutableTypes", Partial, 0, ... ) , Partial, 0, ... ) == STATUS_BUFFER_TOO_SMALL 01713 424 NtQueryValueKey (276, (276, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) , Partial, 260, ... TitleIdx=0, Type=7, Data= (276, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) }, 260, ) == 0x0 01714 424 NtClose (276, ... ) == 0x0 01715 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01716 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 276, ) }, ... 276, ) == 0x0 01717 424 NtQueryValueKey (276, (276, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01718 424 NtClose (276, ... ) == 0x0 01719 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01720 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01721 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01722 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01723 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01724 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01725 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01726 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01727 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01728 424 NtQueryDefaultLocale (1, 1233768, ... ) == 0x0 01729 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 276, ) }, ... 276, ) == 0x0 01730 424 NtEnumerateKey (276, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name= (276, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 01731 424 NtOpenKey (0x20019, {24, 276, 0x40, 0, 0, (0x20019, {24, 276, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 284, ) }, ... 284, ) == 0x0 01732 424 NtQueryValueKey (284, (284, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (284, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 01733 424 NtQueryValueKey (284, (284, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (284, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01734 424 NtClose (284, ... ) == 0x0 01735 424 NtEnumerateKey (276, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 01736 424 NtClose (276, ... ) == 0x0 01737 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01738 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01739 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01740 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01741 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01742 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01743 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01744 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01745 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01746 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01747 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01748 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01749 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01750 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01751 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01752 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01753 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01754 424 NtClose (276, ... ) == 0x0 01755 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01756 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01757 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01758 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01759 424 NtClose (276, ... ) == 0x0 01760 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01761 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01762 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01763 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01764 424 NtClose (276, ... ) == 0x0 01765 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01766 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01767 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01768 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01769 424 NtClose (276, ... ) == 0x0 01770 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01771 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01772 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01773 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01774 424 NtClose (276, ... ) == 0x0 01775 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01776 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01777 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01778 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01779 424 NtClose (276, ... ) == 0x0 01780 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01781 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01782 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01783 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01784 424 NtClose (276, ... ) == 0x0 01785 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01786 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01787 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01788 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01789 424 NtClose (276, ... ) == 0x0 01790 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01791 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01792 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01793 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01794 424 NtClose (276, ... ) == 0x0 01795 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01796 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01797 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01798 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01799 424 NtClose (276, ... ) == 0x0 01800 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01801 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01802 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01803 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01804 424 NtClose (276, ... ) == 0x0 01805 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01806 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01807 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01808 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01809 424 NtClose (276, ... ) == 0x0 01810 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01811 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01812 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01813 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01814 424 NtClose (276, ... ) == 0x0 01815 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01816 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01817 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01818 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01819 424 NtClose (276, ... ) == 0x0 01820 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01821 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01822 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01823 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01824 424 NtClose (276, ... ) == 0x0 01825 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01826 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 276, ) }, ... 276, ) == 0x0 01827 424 NtQueryValueKey (276, (276, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (276, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (276, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 01828 424 NtClose (276, ... ) == 0x0 01829 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01830 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 276, ) == 0x0 01831 424 NtQueryInformationToken (276, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01832 424 NtClose (276, ... ) == 0x0 01833 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01834 424 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 01835 424 NtOpenProcessToken (-1, 0xa, ... 276, ) == 0x0 01836 424 NtDuplicateToken (276, 0xc, {24, 0, 0x0, 0, 1234288, 0x0}, 0, 2, ... 284, ) == 0x0 01837 424 NtClose (276, ... ) == 0x0 01838 424 NtAccessCheck (1455280, 284, 0x1, 1234416, 1234360, 56, 1234444, ... (0x1), ) == 0x0 01839 424 NtClose (284, ... ) == 0x0 01840 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 284, ) }, ... 284, ) == 0x0 01841 424 NtQueryValueKey (284, (284, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (284, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01842 424 NtClose (284, ... ) == 0x0 01843 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1234304, (0x80100080, {24, 0, 0x40, 0, 1234304, "\??\u:\work\xeqfhcg.bat"}, 0x0, 128, 1, 1, 96, 0, 0, ... 284, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 284, {status=0x0, info=1}, ) == 0x0 01844 424 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 276, ) }, ... 276, ) == 0x0 01845 424 NtQuerySymbolicLinkObject (276, ... (276, ... "\Device\WinDfs\U:00000000000092fa", 66, ) , 66, ) == 0x0 01846 424 NtClose (276, ... ) == 0x0 01847 424 NtQueryInformationFile (284, 1232748, 528, Name, ... {status=0x0, info=74}, ) == 0x0 01848 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01849 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01850 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\UNC\missouri\binaries\work\xeqfhcg.bat"}, 1231428, ... ) }, 1231428, ... ) == 0x0 01851 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\UNC\missouri\binaries\"}, 3, 16417, ... 276, {status=0x0, info=1}, ) }, 3, 16417, ... 276, {status=0x0, info=1}, ) == 0x0 01852 424 NtQueryDirectoryFile (276, 0, 0, 0, 1230788, 616, BothDirectory, 1, (276, 0, 0, 0, 1230788, 616, BothDirectory, 1, "work", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01853 424 NtClose (276, ... ) == 0x0 01854 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\UNC\missouri\binaries\work\"}, 3, 16417, ... 276, {status=0x0, info=1}, ) }, 3, 16417, ... 276, {status=0x0, info=1}, ) == 0x0 01855 424 NtQueryDirectoryFile (276, 0, 0, 0, 1230788, 616, BothDirectory, 1, (276, 0, 0, 0, 1230788, 616, BothDirectory, 1, "xeqfhcg.bat", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 01856 424 NtClose (276, ... ) == 0x0 01857 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01858 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01859 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WINTRUST.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01860 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WINTRUST.dll"}, 1232160, ... ) }, 1232160, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01861 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "WINTRUST.dll"}, 1232160, ... ) }, 1232160, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01862 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINTRUST.dll"}, 1232160, ... ) }, 1232160, ... ) == 0x0 01863 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINTRUST.dll"}, 5, 96, ... 276, {status=0x0, info=1}, ) }, 5, 96, ... 276, {status=0x0, info=1}, ) == 0x0 01864 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 276, ... 288, ) == 0x0 01865 424 NtQuerySection (288, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01866 424 NtClose (276, ... ) == 0x0 01867 424 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76c30000), 0x0, 176128, ) == 0x0 01868 424 NtClose (288, ... ) == 0x0 01869 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "IMAGEHLP.dll"}, ... 288, ) }, ... 288, ) == 0x0 01870 424 NtMapViewOfSection (288, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76c90000), 0x0, 139264, ) == 0x0 01871 424 NtClose (288, ... ) == 0x0 01872 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01873 424 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 9830400, 262144, ) == 0x0 01874 424 NtAllocateVirtualMemory (-1, 9830400, 0, 4096, 4096, 4, ... 9830400, 4096, ) == 0x0 01875 424 NtAllocateVirtualMemory (-1, 9834496, 0, 8192, 4096, 4, ... 9834496, 8192, ) == 0x0 01876 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01877 424 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 10092544, 1048576, ) == 0x0 01878 424 NtAllocateVirtualMemory (-1, 10092544, 0, 1048576, 4096, 4, ... 10092544, 1048576, ) == 0x0 01879 424 NtCreateMutant (0x1f0001, 0x0, 0, ... 288, ) == 0x0 01880 424 NtCreateEvent (0x1f0003, 0x0, 0, 1, ... 276, ) == 0x0 01881 424 NtCreateMutant (0x1f0001, 0x0, 0, ... 292, ) == 0x0 01882 424 NtCreateEvent (0x1f0003, 0x0, 0, 1, ... 296, ) == 0x0 01883 424 NtCreateEvent (0x1f0003, 0x0, 0, 1, ... 300, ) == 0x0 01884 424 NtSetEvent (300, ... 0x0, ) == 0x0 01885 424 NtSetInformationFile (284, 1234188, 8, Position, ... {status=0x0, info=0}, ) == 0x0 01886 424 NtReadFile (284, 0, 0, 0, 2, 0x0, 0, ... {status=0x0, info=2}, (284, 0, 0, 0, 2, 0x0, 0, ... {status=0x0, info=2}, "@e", ) , ) == 0x0 01887 424 NtWaitForSingleObject (288, 0, 0x0, ... ) == 0x0 01888 424 NtClearEvent (276, ... ) == 0x0 01889 424 NtReleaseMutant (288, ... 0x0, ) == 0x0 01890 424 NtWaitForSingleObject (288, 0, 0x0, ... ) == 0x0 01891 424 NtSetEvent (276, ... 0x0, ) == 0x0 01892 424 NtReleaseMutant (288, ... 0x0, ) == 0x0 01893 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01894 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01895 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0t\0r\0u\0s\0t\0C\0e\0r\0t\0i\0f\0i\0c\0a\0t\0e\0T\0r\0u\0s\0t\0\0\0"}, 62, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0i\0n\0t\0r\0u\0s\0t\0C\0e\0r\0t\0i\0f\0i\0c\0a\0t\0e\0T\0r\0u\0s\0t\0\0\0"}, 62, ) }, 62, ) == 0x0 01896 424 NtClose (304, ... ) == 0x0 01897 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01898 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01899 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0A\0u\0t\0h\0e\0n\0t\0i\0c\0o\0d\0e\0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0A\0u\0t\0h\0e\0n\0t\0i\0c\0o\0d\0e\0\0\0"}, 52, ) }, 52, ) == 0x0 01900 424 NtClose (304, ... ) == 0x0 01901 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01902 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01903 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0I\0n\0i\0t\0i\0a\0l\0i\0z\0e\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0I\0n\0i\0t\0i\0a\0l\0i\0z\0e\0\0\0"}, 48, ) }, 48, ) == 0x0 01904 424 NtClose (304, ... ) == 0x0 01905 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01906 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01907 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0L\0o\0a\0d\0M\0e\0s\0s\0a\0g\0e\0\0\0"}, 50, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0L\0o\0a\0d\0M\0e\0s\0s\0a\0g\0e\0\0\0"}, 50, ) }, 50, ) == 0x0 01908 424 NtClose (304, ... ) == 0x0 01909 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01910 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01911 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0L\0o\0a\0d\0S\0i\0g\0n\0a\0t\0u\0r\0e\0\0\0"}, 54, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0L\0o\0a\0d\0S\0i\0g\0n\0a\0t\0u\0r\0e\0\0\0"}, 54, ) }, 54, ) == 0x0 01912 424 NtClose (304, ... ) == 0x0 01913 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01914 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01915 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0C\0h\0e\0c\0k\0C\0e\0r\0t\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0C\0h\0e\0c\0k\0C\0e\0r\0t\0\0\0"}, 46, ) }, 46, ) == 0x0 01916 424 NtClose (304, ... ) == 0x0 01917 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01918 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"}, ... 304, ) }, ... 304, ) == 0x0 01919 424 NtQueryValueKey (304, (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$DLL", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0I\0N\0T\0R\0U\0S\0T\0.\0D\0L\0L\0\0\0"}, 38, ) }, 38, ) == 0x0 01920 424 NtQueryValueKey (304, (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0C\0l\0e\0a\0n\0u\0p\0\0\0"}, 42, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "$Function", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0o\0f\0t\0p\0u\0b\0C\0l\0e\0a\0n\0u\0p\0\0\0"}, 42, ) }, 42, ) == 0x0 01921 424 NtClose (304, ... ) == 0x0 01922 424 NtWaitForMultipleObjects (2, (288, 276, ), 0, 0, 0x0, ... ) == 0x0 01923 424 NtReleaseMutant (288, ... 0x0, ) == 0x0 01924 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01925 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 304, ) == 0x0 01926 424 NtQueryInformationToken (304, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01927 424 NtClose (304, ... ) == 0x0 01928 424 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 304, ) }, ... 304, ) == 0x0 01929 424 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "SOFTWARE\Microsoft\Cryptography\Providers\Type 001"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01930 424 NtClose (304, ... ) == 0x0 01931 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001"}, ... 304, ) }, ... 304, ) == 0x0 01932 424 NtQueryValueKey (304, (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) }, 92, ) == 0x0 01933 424 NtQueryValueKey (304, (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) }, 92, ) == 0x0 01934 424 NtQueryValueKey (304, (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) }, 92, ) == 0x0 01935 424 NtQueryValueKey (304, (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0S\0t\0r\0o\0n\0g\0 \0C\0r\0y\0p\0t\0o\0g\0r\0a\0p\0h\0i\0c\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0"}, 92, ) }, 92, ) == 0x0 01936 424 NtClose (304, ... ) == 0x0 01937 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider"}, ... 304, ) }, ... 304, ) == 0x0 01938 424 NtQueryValueKey (304, (304, "Type", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (304, "Type", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01939 424 NtQueryValueKey (304, (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) }, 74, ) == 0x0 01940 424 NtQueryValueKey (304, (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) }, 74, ) == 0x0 01941 424 NtQueryValueKey (304, (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) }, 74, ) == 0x0 01942 424 NtQueryValueKey (304, (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Image Path", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0r\0s\0a\0e\0n\0h\0.\0d\0l\0l\0\0\0"}, 74, ) }, 74, ) == 0x0 01943 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rsaenh.dll"}, 1231476, ... ) }, 1231476, ... ) == 0x0 01944 424 NtOpenKey (0x20119, {24, 28, 0x40, 0, 0, (0x20119, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography"}, ... 308, ) }, ... 308, ) == 0x0 01945 424 NtQueryValueKey (308, (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) }, 86, ) == 0x0 01946 424 NtQueryValueKey (308, (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) }, 86, ) == 0x0 01947 424 NtQueryValueKey (308, (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) }, 86, ) == 0x0 01948 424 NtQueryValueKey (308, (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (308, "MachineGuid", Partial, 144, ... TitleIdx=0, Type=1, Data="a\0c\00\0b\04\0d\01\00\0-\0a\02\0c\07\0-\04\0f\03\03\0-\08\0e\06\04\0-\07\08\01\0e\0b\0a\01\0f\0f\0f\0b\0b\0\0\0"}, 86, ) }, 86, ) == 0x0 01949 424 NtClose (308, ... ) == 0x0 01950 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\Offload"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01951 424 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 01952 424 NtOpenProcessToken (-1, 0x8, ... 308, ) == 0x0 01953 424 NtQueryInformationToken (308, User, 1024, ... {token info, class 1, size 36}, 36, ) == 0x0 01954 424 NtClose (308, ... ) == 0x0 01955 424 NtClose (304, ... ) == 0x0 01956 424 NtOpenThreadToken (-2, 0x8, 1, ... ) == STATUS_NO_TOKEN 01957 424 NtOpenProcessToken (-1, 0x8, ... 304, ) == 0x0 01958 424 NtQueryInformationToken (304, User, 256, ... {token info, class 1, size 36}, 36, ) == 0x0 01959 424 NtClose (304, ... ) == 0x0 01960 424 NtOpenKey (0x2000000, {24, 188, 0x40, 0, 0, (0x2000000, {24, 188, 0x40, 0, 0, "S-1-5-21-1078081533-484763869-839522115-1003"}, ... 304, ) }, ... 304, ) == 0x0 01961 424 NtCreateKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing"}, 0, 0x0, 0, ... 308, 2, ) }, 0, 0x0, 0, ... 308, 2, ) == 0x0 01962 424 NtClose (304, ... ) == 0x0 01963 424 NtQueryValueKey (308, (308, "State", Partial, 144, ... TitleIdx=0, Type=4, Data="\0<\2\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (308, "State", Partial, 144, ... TitleIdx=0, Type=4, Data="\0<\2\0"}, 16, ) }, 16, ) == 0x0 01964 424 NtClose (308, ... ) == 0x0 01965 424 NtOpenThreadToken (-2, 0x8, 1, ... ) == STATUS_NO_TOKEN 01966 424 NtOpenProcessToken (-1, 0x8, ... 308, ) == 0x0 01967 424 NtQueryInformationToken (308, User, 256, ... {token info, class 1, size 36}, 36, ) == 0x0 01968 424 NtClose (308, ... ) == 0x0 01969 424 NtOpenKey (0x2000000, {24, 188, 0x40, 0, 0, (0x2000000, {24, 188, 0x40, 0, 0, "S-1-5-21-1078081533-484763869-839522115-1003"}, ... 308, ) }, ... 308, ) == 0x0 01970 424 NtOpenKey (0x20019, {24, 308, 0x40, 0, 0, (0x20019, {24, 308, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Security"}, ... 304, ) }, ... 304, ) == 0x0 01971 424 NtClose (308, ... ) == 0x0 01972 424 NtQueryValueKey (304, (304, "Safety Warning Level", Partial, 144, ... TitleIdx=0, Type=1, Data="Q\0u\0e\0r\0y\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (304, "Safety Warning Level", Partial, 144, ... TitleIdx=0, Type=1, Data="Q\0u\0e\0r\0y\0\0\0"}, 24, ) }, 24, ) == 0x0 01973 424 NtClose (304, ... ) == 0x0 01974 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01975 424 NtOpenThreadToken (-2, 0x8, 1, ... ) == STATUS_NO_TOKEN 01976 424 NtOpenProcessToken (-1, 0x8, ... 304, ) == 0x0 01977 424 NtQueryInformationToken (304, User, 256, ... {token info, class 1, size 36}, 36, ) == 0x0 01978 424 NtClose (304, ... ) == 0x0 01979 424 NtOpenKey (0x2000000, {24, 188, 0x40, 0, 0, (0x2000000, {24, 188, 0x40, 0, 0, "S-1-5-21-1078081533-484763869-839522115-1003"}, ... 304, ) }, ... 304, ) == 0x0 01980 424 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01981 424 NtClose (304, ... ) == 0x0 01982 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\SystemCertificates\TrustedPublisher\Safer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01983 424 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 284, ... 304, ) == 0x0 01984 424 NtMapViewOfSection (304, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xaa0000), {0, 0}, 4096, ) == 0x0 01985 424 NtClose (304, ... ) == 0x0 01986 424 NtQueryInformationFile (284, 1233692, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01987 424 NtUnmapViewOfSection (-1, 0xaa0000, ... ) == 0x0 01988 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\OID"}, ... 304, ) }, ... 304, ) == 0x0 01989 424 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "EncodingType 0"}, ... 308, ) }, ... 308, ) == 0x0 01990 424 NtOpenKey (0x20019, {24, 308, 0x40, 0, 0, (0x20019, {24, 308, 0x40, 0, 0, "CryptSIPDllIsMyFileType"}, ... 312, ) }, ... 312, ) == 0x0 01991 424 NtEnumerateKey (312, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name= (312, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name="{D0BA83B0-DB49-11D2-B886-00C04F866F52}"}, 92, ) }, 92, ) == 0x0 01992 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "{D0BA83B0-DB49-11D2-B886-00C04F866F52}"}, ... 316, ) }, ... 316, ) == 0x0 01993 424 NtQueryKey (316, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 01994 424 NtEnumerateValueKey (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0a\0s\0f\0s\0i\0p\0c\0.\0d\0l\0l\0\0\0"}, 92, ) , Data= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0a\0s\0f\0s\0i\0p\0c\0.\0d\0l\0l\0\0\0"}, 92, ) }, 92, ) == 0x0 01995 424 NtEnumerateValueKey (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 66, ) , Data= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 66, ) }, 66, ) == 0x0 01996 424 NtClose (316, ... ) == 0x0 01997 424 NtEnumerateKey (312, 1, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 01998 424 NtClose (312, ... ) == 0x0 01999 424 NtClose (308, ... ) == 0x0 02000 424 NtClose (304, ... ) == 0x0 02001 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\OID"}, ... 304, ) }, ... 304, ) == 0x0 02002 424 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "EncodingType 0"}, ... 308, ) }, ... 308, ) == 0x0 02003 424 NtOpenKey (0x20019, {24, 308, 0x40, 0, 0, (0x20019, {24, 308, 0x40, 0, 0, "CryptSIPDllIsMyFileType2"}, ... 312, ) }, ... 312, ) == 0x0 02004 424 NtEnumerateKey (312, 0, Basic, 288, ... {LastWrite={0x6f8d23ee,0x1c73999}, TitleIdx=0, Name= (312, 0, Basic, 288, ... {LastWrite={0x6f8d23ee,0x1c73999}, TitleIdx=0, Name="{000C10F1-0000-0000-C000-000000000046}"}, 92, ) }, 92, ) == 0x0 02005 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "{000C10F1-0000-0000-C000-000000000046}"}, ... 316, ) }, ... 316, ) == 0x0 02006 424 NtQueryKey (316, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02007 424 NtEnumerateValueKey (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="M\0S\0I\0S\0I\0P\0.\0D\0L\0L\0\0\0"}, 50, ) , Data= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="M\0S\0I\0S\0I\0P\0.\0D\0L\0L\0\0\0"}, 50, ) }, 50, ) == 0x0 02008 424 NtEnumerateValueKey (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="M\0s\0i\0S\0I\0P\0I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 78, ) , Data= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="M\0s\0i\0S\0I\0P\0I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 78, ) }, 78, ) == 0x0 02009 424 NtClose (316, ... ) == 0x0 02010 424 NtEnumerateKey (312, 1, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name= (312, 1, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name="{06C9E010-38CE-11D4-A2A3-00104BD35090}"}, 92, ) }, 92, ) == 0x0 02011 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "{06C9E010-38CE-11D4-A2A3-00104BD35090}"}, ... 316, ) }, ... 316, ) == 0x0 02012 424 NtQueryKey (316, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02013 424 NtEnumerateValueKey (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) , Data= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) }, 90, ) == 0x0 02014 424 NtEnumerateValueKey (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) , Data= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) }, 76, ) == 0x0 02015 424 NtClose (316, ... ) == 0x0 02016 424 NtEnumerateKey (312, 2, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name= (312, 2, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name="{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"}, 92, ) }, 92, ) == 0x0 02017 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"}, ... 316, ) }, ... 316, ) == 0x0 02018 424 NtQueryKey (316, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02019 424 NtEnumerateValueKey (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) , Data= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) }, 90, ) == 0x0 02020 424 NtEnumerateValueKey (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) , Data= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) }, 76, ) == 0x0 02021 424 NtClose (316, ... ) == 0x0 02022 424 NtEnumerateKey (312, 3, Basic, 288, ... {LastWrite={0x6090fc44,0x1c73999}, TitleIdx=0, Name= (312, 3, Basic, 288, ... {LastWrite={0x6090fc44,0x1c73999}, TitleIdx=0, Name="{1A610570-38CE-11D4-A2A3-00104BD35090}"}, 92, ) }, 92, ) == 0x0 02023 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "{1A610570-38CE-11D4-A2A3-00104BD35090}"}, ... 316, ) }, ... 316, ) == 0x0 02024 424 NtQueryKey (316, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02025 424 NtEnumerateValueKey (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) , Data= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) }, 90, ) == 0x0 02026 424 NtEnumerateValueKey (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) , Data= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) }, 76, ) == 0x0 02027 424 NtClose (316, ... ) == 0x0 02028 424 NtEnumerateKey (312, 4, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 02029 424 NtClose (312, ... ) == 0x0 02030 424 NtClose (308, ... ) == 0x0 02031 424 NtClose (304, ... ) == 0x0 02032 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\OID"}, ... 304, ) }, ... 304, ) == 0x0 02033 424 NtEnumerateKey (304, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name= (304, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name="EncodingType 0"}, 44, ) }, 44, ) == 0x0 02034 424 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "EncodingType 0"}, ... 308, ) }, ... 308, ) == 0x0 02035 424 NtOpenKey (0x20019, {24, 308, 0x40, 0, 0, (0x20019, {24, 308, 0x40, 0, 0, "CryptSIPDllIsMyFileType"}, ... 312, ) }, ... 312, ) == 0x0 02036 424 NtEnumerateKey (312, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name= (312, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name="{D0BA83B0-DB49-11D2-B886-00C04F866F52}"}, 92, ) }, 92, ) == 0x0 02037 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "{D0BA83B0-DB49-11D2-B886-00C04F866F52}"}, ... 316, ) }, ... 316, ) == 0x0 02038 424 NtQueryKey (316, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02039 424 NtEnumerateValueKey (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0a\0s\0f\0s\0i\0p\0c\0.\0d\0l\0l\0\0\0"}, 92, ) , Data= (316, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0a\0s\0f\0s\0i\0p\0c\0.\0d\0l\0l\0\0\0"}, 92, ) }, 92, ) == 0x0 02040 424 NtEnumerateValueKey (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 66, ) , Data= (316, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 66, ) }, 66, ) == 0x0 02041 424 NtClose (316, ... ) == 0x0 02042 424 NtEnumerateKey (312, 1, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 02043 424 NtClose (312, ... ) == 0x0 02044 424 NtClose (308, ... ) == 0x0 02045 424 NtEnumerateKey (304, 1, Basic, 288, ... {LastWrite={0x7492376c,0x1c73999}, TitleIdx=0, Name= (304, 1, Basic, 288, ... {LastWrite={0x7492376c,0x1c73999}, TitleIdx=0, Name="EncodingType 1"}, 44, ) }, 44, ) == 0x0 02046 424 NtOpenKey (0x20019, {24, 304, 0x40, 0, 0, (0x20019, {24, 304, 0x40, 0, 0, "EncodingType 1"}, ... 308, ) }, ... 308, ) == 0x0 02047 424 NtOpenKey (0x20019, {24, 308, 0x40, 0, 0, (0x20019, {24, 308, 0x40, 0, 0, "CryptSIPDllIsMyFileType"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02048 424 NtClose (308, ... ) == 0x0 02049 424 NtEnumerateKey (304, 2, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 02050 424 NtClose (304, ... ) == 0x0 02051 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\asfsipc.dll"}, 1231220, ... ) }, 1231220, ... ) == 0x0 02052 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\asfsipc.dll"}, 5, 96, ... 304, {status=0x0, info=1}, ) }, 5, 96, ... 304, {status=0x0, info=1}, ) == 0x0 02053 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 304, ... 308, ) == 0x0 02054 424 NtClose (304, ... ) == 0x0 02055 424 NtMapViewOfSection (308, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xaa0000), 0x0, 16384, ) == 0x0 02056 424 NtClose (308, ... ) == 0x0 02057 424 NtUnmapViewOfSection (-1, 0xaa0000, ... ) == 0x0 02058 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\asfsipc.dll"}, 1231536, ... ) }, 1231536, ... ) == 0x0 02059 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\asfsipc.dll"}, 5, 96, ... 308, {status=0x0, info=1}, ) }, 5, 96, ... 308, {status=0x0, info=1}, ) == 0x0 02060 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 308, ... 304, ) == 0x0 02061 424 NtQuerySection (304, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02062 424 NtClose (308, ... ) == 0x0 02063 424 NtMapViewOfSection (304, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x70eb0000), 0x0, 28672, ) == 0x0 02064 424 NtClose (304, ... ) == 0x0 02065 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\CRYPT32.dll"}, 1230796, ... ) }, 1230796, ... ) == 0x0 02066 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 304, ) == 0x0 02067 424 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 11272192, 1048576, ) == 0x0 02068 424 NtAllocateVirtualMemory (-1, 12312576, 0, 8192, 4096, 4, ... 12312576, 8192, ) == 0x0 02069 424 NtProtectVirtualMemory (-1, (0xbbe000), 4096, 260, ... (0xbbe000), 4096, 4, ) == 0x0 02070 424 NtCreateThread (0x1f03ff, 0x0, -1, 1232744, 1233460, 1, ... 308, {420, 576}, ) == 0x0 02071 424 NtQueryInformationThread (308, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ffdd000,Pid=420,Tid=576,}, 0x0, ) == 0x0 02072 424 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 0, 0, 0, 13} (24, {28, 56, new_msg, 0, 0, 0, 0, 13} "\0\0\0\0\1\0\1\0z\25\347w\10\0\0\04\1\0\0\244\1\0\0@\2\0\0" ... {28, 56, reply, 0, 420, 424, 1519, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\10\0\0\04\1\0\0\244\1\0\0@\2\0\0" ) ... {28, 56, reply, 0, 420, 424, 1519, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 13} "\0\0\0\0\1\0\1\0z\25\347w\10\0\0\04\1\0\0\244\1\0\0@\2\0\0" ... {28, 56, reply, 0, 420, 424, 1519, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\10\0\0\04\1\0\0\244\1\0\0@\2\0\0" ) ) == 0x0 02073 424 NtResumeThread (308, ... 1, ) == 0x0 02074 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Cryptography\OID"}, ... }, ... 02075 576 NtTestAlert (... ) == 0x0 02076 576 NtContinue (12320048, 1, ... 02077 576 NtRegisterThreadTerminatePort (24, ... ) == 0x0 02078 576 NtWaitForMultipleObjects (1, (304, ), 1, 0, {-150000000, -1}, ... 02074 424 NtOpenKey ... 312, ) == 0x0 02079 424 NtEnumerateKey (312, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name= (312, 0, Basic, 288, ... {LastWrite={0x6111bb40,0x1c73999}, TitleIdx=0, Name="EncodingType 0"}, 44, ) }, 44, ) == 0x0 02080 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "EncodingType 0"}, ... 316, ) }, ... 316, ) == 0x0 02081 424 NtOpenKey (0x20019, {24, 316, 0x40, 0, 0, (0x20019, {24, 316, 0x40, 0, 0, "CryptSIPDllIsMyFileType2"}, ... 320, ) }, ... 320, ) == 0x0 02082 424 NtEnumerateKey (320, 0, Basic, 288, ... {LastWrite={0x6f8d23ee,0x1c73999}, TitleIdx=0, Name= (320, 0, Basic, 288, ... {LastWrite={0x6f8d23ee,0x1c73999}, TitleIdx=0, Name="{000C10F1-0000-0000-C000-000000000046}"}, 92, ) }, 92, ) == 0x0 02083 424 NtOpenKey (0x20019, {24, 320, 0x40, 0, 0, (0x20019, {24, 320, 0x40, 0, 0, "{000C10F1-0000-0000-C000-000000000046}"}, ... 324, ) }, ... 324, ) == 0x0 02084 424 NtQueryKey (324, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02085 424 NtEnumerateValueKey (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="M\0S\0I\0S\0I\0P\0.\0D\0L\0L\0\0\0"}, 50, ) , Data= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="M\0S\0I\0S\0I\0P\0.\0D\0L\0L\0\0\0"}, 50, ) }, 50, ) == 0x0 02086 424 NtEnumerateValueKey (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="M\0s\0i\0S\0I\0P\0I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 78, ) , Data= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="M\0s\0i\0S\0I\0P\0I\0s\0M\0y\0T\0y\0p\0e\0O\0f\0F\0i\0l\0e\0\0\0"}, 78, ) }, 78, ) == 0x0 02087 424 NtClose (324, ... ) == 0x0 02088 424 NtEnumerateKey (320, 1, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name= (320, 1, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name="{06C9E010-38CE-11D4-A2A3-00104BD35090}"}, 92, ) }, 92, ) == 0x0 02089 424 NtOpenKey (0x20019, {24, 320, 0x40, 0, 0, (0x20019, {24, 320, 0x40, 0, 0, "{06C9E010-38CE-11D4-A2A3-00104BD35090}"}, ... 324, ) }, ... 324, ) == 0x0 02090 424 NtQueryKey (324, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02091 424 NtEnumerateValueKey (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) , Data= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) }, 90, ) == 0x0 02092 424 NtEnumerateValueKey (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) , Data= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) }, 76, ) == 0x0 02093 424 NtClose (324, ... ) == 0x0 02094 424 NtEnumerateKey (320, 2, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name= (320, 2, Basic, 288, ... {LastWrite={0x608e99ea,0x1c73999}, TitleIdx=0, Name="{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"}, 92, ) }, 92, ) == 0x0 02095 424 NtOpenKey (0x20019, {24, 320, 0x40, 0, 0, (0x20019, {24, 320, 0x40, 0, 0, "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"}, ... 324, ) }, ... 324, ) == 0x0 02096 424 NtQueryKey (324, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02097 424 NtEnumerateValueKey (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) , Data= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) }, 90, ) == 0x0 02098 424 NtEnumerateValueKey (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) , Data= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) }, 76, ) == 0x0 02099 424 NtClose (324, ... ) == 0x0 02100 424 NtEnumerateKey (320, 3, Basic, 288, ... {LastWrite={0x6090fc44,0x1c73999}, TitleIdx=0, Name= (320, 3, Basic, 288, ... {LastWrite={0x6090fc44,0x1c73999}, TitleIdx=0, Name="{1A610570-38CE-11D4-A2A3-00104BD35090}"}, 92, ) }, 92, ) == 0x0 02101 424 NtOpenKey (0x20019, {24, 320, 0x40, 0, 0, (0x20019, {24, 320, 0x40, 0, 0, "{1A610570-38CE-11D4-A2A3-00104BD35090}"}, ... 324, ) }, ... 324, ) == 0x0 02102 424 NtQueryKey (324, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 02103 424 NtEnumerateValueKey (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) , Data= (324, 0, Full, 220, ... TitleIdx=0, Type=1, Name="Dll", Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0s\0h\0e\0x\0t\0.\0d\0l\0l\0\0\0"}, 90, ) }, 90, ) == 0x0 02104 424 NtEnumerateValueKey (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) , Data= (324, 1, Full, 220, ... TitleIdx=0, Type=1, Name="FuncName", Data="I\0s\0F\0i\0l\0e\0S\0u\0p\0p\0o\0r\0t\0e\0d\0N\0a\0m\0e\0\0\0"}, 76, ) }, 76, ) == 0x0 02105 424 NtClose (324, ... ) == 0x0 02106 424 NtEnumerateKey (320, 4, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 02107 424 NtClose (320, ... ) == 0x0 02108 424 NtClose (316, ... ) == 0x0 02109 424 NtEnumerateKey (312, 1, Basic, 288, ... {LastWrite={0x7492376c,0x1c73999}, TitleIdx=0, Name= (312, 1, Basic, 288, ... {LastWrite={0x7492376c,0x1c73999}, TitleIdx=0, Name="EncodingType 1"}, 44, ) }, 44, ) == 0x0 02110 424 NtOpenKey (0x20019, {24, 312, 0x40, 0, 0, (0x20019, {24, 312, 0x40, 0, 0, "EncodingType 1"}, ... 316, ) }, ... 316, ) == 0x0 02111 424 NtOpenKey (0x20019, {24, 316, 0x40, 0, 0, (0x20019, {24, 316, 0x40, 0, 0, "CryptSIPDllIsMyFileType2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02112 424 NtClose (316, ... ) == 0x0 02113 424 NtEnumerateKey (312, 2, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 02114 424 NtClose (312, ... ) == 0x0 02115 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSISIP.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02116 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\MSISIP.DLL"}, 1231528, ... ) }, 1231528, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02117 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "MSISIP.DLL"}, 1231528, ... ) }, 1231528, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02118 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\MSISIP.DLL"}, 1231528, ... ) }, 1231528, ... ) == 0x0 02119 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\MSISIP.DLL"}, 5, 96, ... 312, {status=0x0, info=1}, ) }, 5, 96, ... 312, {status=0x0, info=1}, ) == 0x0 02120 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 312, ... 316, ) == 0x0 02121 424 NtQuerySection (316, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02122 424 NtClose (312, ... ) == 0x0 02123 424 NtMapViewOfSection (316, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x605f0000), 0x0, 53248, ) == 0x0 02124 424 NtClose (316, ... ) == 0x0 02125 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02126 424 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 11141120, 65536, ) == 0x0 02127 424 NtAllocateVirtualMemory (-1, 11141120, 0, 4096, 4096, 4, ... 11141120, 4096, ) == 0x0 02128 424 NtAllocateVirtualMemory (-1, 11145216, 0, 8192, 4096, 4, ... 11145216, 8192, ) == 0x0 02129 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1231116, ... ) }, 1231116, ... ) == 0x0 02130 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02131 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 312, ) == 0x0 02132 424 NtClose (316, ... ) == 0x0 02133 424 NtMapViewOfSection (312, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xbc0000), 0x0, 262144, ) == 0x0 02134 424 NtClose (312, ... ) == 0x0 02135 424 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0 02136 424 NtAllocateLocallyUniqueId (... {66439, 0}, ) == 0x0 02137 424 NtOpenThreadToken (-2, 0x20008, 1, ... ) == STATUS_NO_TOKEN 02138 424 NtOpenProcessToken (-1, 0x20008, ... 312, ) == 0x0 02139 424 NtQueryInformationToken (312, User, 52, ... {token info, class 1, size 36}, 36, ) == 0x0 02140 424 NtClose (312, ... ) == 0x0 02141 424 NtCreateSection (0xf0007, {24, 52, 0x80, 1232436, 0, (0xf0007, {24, 52, 0x80, 1232436, 0, "DfSharedHeap10387"}, {4194304, 0}, 4, 67108864, 0, ... 312, ) }, {4194304, 0}, 4, 67108864, 0, ... 312, ) == 0x0 02142 424 NtMapViewOfSection (312, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xbc0000), {0, 0}, 4194304, ) == 0x0 02143 424 NtAllocateVirtualMemory (-1, 12320768, 0, 16376, 4096, 4, ... 12320768, 16384, ) == 0x0 02144 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1229952, (0x80100080, {24, 0, 0x40, 0, 1229952, "\??\UNC\missouri\binaries\work\xeqfhcg.bat"}, 0x0, 128, 3, 1, 2144, 0, 0, ... 316, {status=0x0, info=1}, ) }, 0x0, 128, 3, 1, 2144, 0, 0, ... 316, {status=0x0, info=1}, ) == 0x0 02145 424 NtReadFile (316, 0, 0, 1232656, 512, {0, 0}, 0, ... {status=0x0, info=123}, (316, 0, 0, 1232656, 512, {0, 0}, 0, ... {status=0x0, info=123}, "@echo off\15\12:deleteagain\15\12del /A:H /F packed.exe\15\12del /F packed.exe\15\12if exist packed.exe goto deleteagain\15\12del xeqfhcg.bat\15\12", ) , ) == 0x0 02146 424 NtClose (316, ... ) == 0x0 02147 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshext.dll"}, 1231220, ... ) }, 1231220, ... ) == 0x0 02148 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshext.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02149 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 320, ) == 0x0 02150 424 NtClose (316, ... ) == 0x0 02151 424 NtMapViewOfSection (320, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xfc0000), 0x0, 69632, ) == 0x0 02152 424 NtClose (320, ... ) == 0x0 02153 424 NtUnmapViewOfSection (-1, 0xfc0000, ... ) == 0x0 02154 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshext.dll"}, 1231536, ... ) }, 1231536, ... ) == 0x0 02155 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshext.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02156 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 316, ) == 0x0 02157 424 NtQuerySection (316, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02158 424 NtClose (320, ... ) == 0x0 02159 424 NtMapViewOfSection (316, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x74ea0000), 0x0, 65536, ) == 0x0 02160 424 NtClose (316, ... ) == 0x0 02161 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "comdlg32.dll"}, ... 316, ) }, ... 316, ) == 0x0 02162 424 NtMapViewOfSection (316, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x763b0000), 0x0, 282624, ) == 0x0 02163 424 NtClose (316, ... ) == 0x0 02164 424 NtProtectVirtualMemory (-1, (0x763b1000), 1536, 4, ... (0x763b1000), 4096, 32, ) == 0x0 02165 424 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 02166 424 NtFlushInstructionCache (-1, 1983582208, 1536, ... ) == 0x0 02167 424 NtProtectVirtualMemory (-1, (0x74eaa000), 672, 4, ... (0x74eaa000), 4096, 2, ) == 0x0 02168 424 NtProtectVirtualMemory (-1, (0x74eaa000), 4096, 2, ... (0x74eaa000), 4096, 4, ) == 0x0 02169 424 NtFlushInstructionCache (-1, 1961533440, 672, ... ) == 0x0 02170 424 NtUserRegisterWindowMessage ( ("WOWLFChange", ... ) , ... ) == 0xc06b 02171 424 NtUserRegisterWindowMessage ( ("WOWDirChange", ... ) , ... ) == 0xc06c 02172 424 NtUserRegisterWindowMessage ( ("WOWCHOOSEFONT_GETLOGFONT", ... ) , ... ) == 0xc06d 02173 424 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 02174 424 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 02175 424 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 02176 424 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 02177 424 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 02178 424 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 02179 424 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 02180 424 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 02181 424 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 02182 424 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 02183 424 NtUserRegisterWindowMessage ( ("Shell IDList Array", ... ) , ... ) == 0xc073 02184 424 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 02185 424 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 02186 424 NtOpenProcessToken (-1, 0x8, ... 316, ) == 0x0 02187 424 NtQueryInformationToken (316, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02188 424 NtClose (316, ... ) == 0x0 02189 424 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 02190 424 NtReleaseMutant (16, ... 02191 424 NtContinue (-136249208, 0, ... 02190 424 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 02192 424 NtQueryDefaultLocale (1, 1230216, ... ) == 0x0 02193 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshENU.DLL"}, 1228208, ... ) }, 1228208, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02194 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshENU.DLL"}, 1228524, ... ) }, 1228524, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02195 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "wshENU.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02196 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02197 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02198 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02199 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02200 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02201 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02202 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02203 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Wbem\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02204 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshEN.DLL"}, 1228208, ... ) }, 1228208, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02205 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshEN.DLL"}, 1228524, ... ) }, 1228524, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02206 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "wshEN.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02207 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02208 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02209 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02210 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02211 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02212 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02213 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02214 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Wbem\wshEN.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02215 424 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 02216 424 NtReleaseMutant (16, ... 02217 424 NtContinue (-136249208, 0, ... 02216 424 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 02218 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshENU.DLL"}, 1228208, ... ) }, 1228208, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02219 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshENU.DLL"}, 1228524, ... ) }, 1228524, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02220 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "wshENU.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02221 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02222 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02223 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02224 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02225 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02226 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02227 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02228 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Wbem\wshENU.DLL"}, 1228516, ... ) }, 1228516, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02229 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02230 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 316, ) == 0x0 02231 424 NtQueryInformationToken (316, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02232 424 NtClose (316, ... ) == 0x0 02233 424 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 316, ) }, ... 316, ) == 0x0 02234 424 NtOpenKey (0x20019, {24, 316, 0x40, 0, 0, (0x20019, {24, 316, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 320, ) }, ... 320, ) == 0x0 02235 424 NtClose (316, ... ) == 0x0 02236 424 NtQueryValueKey (320, (320, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02237 424 NtQueryValueKey (320, (320, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=1, Data= (320, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) }, 162, ) == 0x0 02238 424 NtClose (320, ... ) == 0x0 02239 424 NtClose (284, ... ) == 0x0 02240 424 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 16515072, 4096, ) == 0x0 02241 424 NtAllocateVirtualMemory (-1, 16515072, 0, 4096, 4096, 4, ... 16515072, 4096, ) == 0x0 02242 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 284, ) }, ... 284, ) == 0x0 02243 424 NtQueryValueKey (284, (284, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02244 424 NtClose (284, ... ) == 0x0 02245 424 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02246 424 NtOpenThreadToken (-2, 0x2000a, 1, ... ) == STATUS_NO_TOKEN 02247 424 NtOpenProcessToken (-1, 0x2000a, ... 284, ) == 0x0 02248 424 NtQueryInformationToken (284, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 02249 424 NtQueryInformationToken (284, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 02250 424 NtClose (284, ... ) == 0x0 02251 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02252 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02253 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02254 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02255 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 284, ) }, ... 284, ) == 0x0 02256 424 NtQueryValueKey (284, (284, "NoControlPanel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02257 424 NtClose (284, ... ) == 0x0 02258 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02259 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02260 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02261 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 284, ) }, ... 284, ) == 0x0 02262 424 NtQueryValueKey (284, (284, "NoSetFolders", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02263 424 NtClose (284, ... ) == 0x0 02264 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESi"}, 138, ) }, 138, ) == 0x0 02265 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02266 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... 284, ) }, ... 284, ) == 0x0 02267 424 NtQueryKey (286, Name, 392, ... {Name= (286, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 02268 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02269 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 320, ) == 0x0 02270 424 NtQueryInformationToken (320, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02271 424 NtClose (320, ... ) == 0x0 02272 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02273 424 NtQueryValueKey (286, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data= (286, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0s\0y\0s\0t\0e\0m\03\02\0\\0S\0H\0E\0L\0L\03\02\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 02274 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1230824, ... ) }, 1230824, ... ) == 0x0 02275 424 NtClose (286, ... ) == 0x0 02276 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02277 424 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 284, {status=0x0, info=1}, ) }, 3, 96, ... 284, {status=0x0, info=1}, ) == 0x0 02278 424 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 320, ) }, ... 320, ) == 0x0 02279 424 NtQuerySymbolicLinkObject (320, ... (320, ... "\Device\WinDfs\U:00000000000092fa", 66, ) , 66, ) == 0x0 02280 424 NtClose (320, ... ) == 0x0 02281 424 NtQueryVolumeInformationFile (284, 1234176, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02282 424 NtClose (284, ... ) == 0x0 02283 424 NtWaitForSingleObject (68, 0, {0, 0}, ... ) == 0x102 02284 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "system\CurrentControlSet"}, ... 284, ) }, ... 284, ) == 0x0 02285 424 NtOpenKey (0x20019, {24, 284, 0x40, 0, 0, (0x20019, {24, 284, 0x40, 0, 0, "control\NetworkProvider\HwOrder"}, ... 320, ) }, ... 320, ) == 0x0 02286 424 NtQueryValueKey (320, (320, "ProviderOrder", Partial, 144, ... TitleIdx=0, Type=1, Data="R\0D\0P\0N\0P\0,\0L\0a\0n\0m\0a\0n\0W\0o\0r\0k\0s\0t\0a\0t\0i\0o\0n\0,\0W\0e\0b\0C\0l\0i\0e\0n\0t\0,\0h\0g\0f\0s\0\0\0"}, 90, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "ProviderOrder", Partial, 144, ... TitleIdx=0, Type=1, Data="R\0D\0P\0N\0P\0,\0L\0a\0n\0m\0a\0n\0W\0o\0r\0k\0s\0t\0a\0t\0i\0o\0n\0,\0W\0e\0b\0C\0l\0i\0e\0n\0t\0,\0h\0g\0f\0s\0\0\0"}, 90, ) }, 90, ) == 0x0 02287 424 NtQueryValueKey (320, (320, "ProviderOrder", Partial, 144, ... TitleIdx=0, Type=1, Data="R\0D\0P\0N\0P\0,\0L\0a\0n\0m\0a\0n\0W\0o\0r\0k\0s\0t\0a\0t\0i\0o\0n\0,\0W\0e\0b\0C\0l\0i\0e\0n\0t\0,\0h\0g\0f\0s\0\0\0"}, 90, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "ProviderOrder", Partial, 144, ... TitleIdx=0, Type=1, Data="R\0D\0P\0N\0P\0,\0L\0a\0n\0m\0a\0n\0W\0o\0r\0k\0s\0t\0a\0t\0i\0o\0n\0,\0W\0e\0b\0C\0l\0i\0e\0n\0t\0,\0h\0g\0f\0s\0\0\0"}, 90, ) }, 90, ) == 0x0 02288 424 NtClose (320, ... ) == 0x0 02289 424 NtOpenKey (0x20019, {24, 284, 0x40, 0, 0, (0x20019, {24, 284, 0x40, 0, 0, "services\RDPNP\NetworkProvider"}, ... 320, ) }, ... 320, ) == 0x0 02290 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) }, 68, ) == 0x0 02291 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) }, 68, ) == 0x0 02292 424 NtQueryValueKey (320, (320, "Class", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02293 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0r\0p\0r\0o\0v\0.\0d\0l\0l\0\0\0"}, 78, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0r\0p\0r\0o\0v\0.\0d\0l\0l\0\0\0"}, 78, ) }, 78, ) == 0x0 02294 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0r\0p\0r\0o\0v\0.\0d\0l\0l\0\0\0"}, 78, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0r\0p\0r\0o\0v\0.\0d\0l\0l\0\0\0"}, 78, ) }, 78, ) == 0x0 02295 424 NtClose (320, ... ) == 0x0 02296 424 NtOpenKey (0x20019, {24, 284, 0x40, 0, 0, (0x20019, {24, 284, 0x40, 0, 0, "services\LanmanWorkstation\NetworkProvider"}, ... 320, ) }, ... 320, ) == 0x0 02297 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 64, ) }, 64, ) == 0x0 02298 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 64, ) }, 64, ) == 0x0 02299 424 NtQueryValueKey (320, (320, "Class", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02300 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0n\0t\0l\0a\0n\0m\0a\0n\0.\0d\0l\0l\0\0\0"}, 82, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0n\0t\0l\0a\0n\0m\0a\0n\0.\0d\0l\0l\0\0\0"}, 82, ) }, 82, ) == 0x0 02301 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0n\0t\0l\0a\0n\0m\0a\0n\0.\0d\0l\0l\0\0\0"}, 82, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0n\0t\0l\0a\0n\0m\0a\0n\0.\0d\0l\0l\0\0\0"}, 82, ) }, 82, ) == 0x0 02302 424 NtClose (320, ... ) == 0x0 02303 424 NtOpenKey (0x20019, {24, 284, 0x40, 0, 0, (0x20019, {24, 284, 0x40, 0, 0, "services\WebClient\NetworkProvider"}, ... 320, ) }, ... 320, ) == 0x0 02304 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0e\0b\0 \0C\0l\0i\0e\0n\0t\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 50, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0e\0b\0 \0C\0l\0i\0e\0n\0t\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 50, ) }, 50, ) == 0x0 02305 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0e\0b\0 \0C\0l\0i\0e\0n\0t\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 50, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0e\0b\0 \0C\0l\0i\0e\0n\0t\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 50, ) }, 50, ) == 0x0 02306 424 NtQueryValueKey (320, (320, "Class", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02307 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0a\0v\0c\0l\0n\0t\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0a\0v\0c\0l\0n\0t\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 02308 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0a\0v\0c\0l\0n\0t\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0d\0a\0v\0c\0l\0n\0t\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 02309 424 NtClose (320, ... ) == 0x0 02310 424 NtOpenKey (0x20019, {24, 284, 0x40, 0, 0, (0x20019, {24, 284, 0x40, 0, 0, "services\hgfs\NetworkProvider"}, ... 320, ) }, ... 320, ) == 0x0 02311 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0M\0w\0a\0r\0e\0 \0S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0M\0w\0a\0r\0e\0 \0S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 02312 424 NtQueryValueKey (320, (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0M\0w\0a\0r\0e\0 \0S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0M\0w\0a\0r\0e\0 \0S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 02313 424 NtQueryValueKey (320, (320, "Class", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02314 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="s\0y\0s\0t\0e\0m\03\02\0\\0h\0g\0f\0s\01\0.\0d\0l\0l\0\0\0"}, 50, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="s\0y\0s\0t\0e\0m\03\02\0\\0h\0g\0f\0s\01\0.\0d\0l\0l\0\0\0"}, 50, ) }, 50, ) == 0x0 02315 424 NtQueryValueKey (320, (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="s\0y\0s\0t\0e\0m\03\02\0\\0h\0g\0f\0s\01\0.\0d\0l\0l\0\0\0"}, 50, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (320, "ProviderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="s\0y\0s\0t\0e\0m\03\02\0\\0h\0g\0f\0s\01\0.\0d\0l\0l\0\0\0"}, 50, ) }, 50, ) == 0x0 02316 424 NtClose (320, ... ) == 0x0 02317 424 NtClose (284, ... ) == 0x0 02318 424 NtQueryDefaultLocale (1, 1233728, ... ) == 0x0 02319 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\drprov.dll"}, 1231740, ... ) }, 1231740, ... ) == 0x0 02320 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\drprov.dll"}, 5, 96, ... 284, {status=0x0, info=1}, ) }, 5, 96, ... 284, {status=0x0, info=1}, ) == 0x0 02321 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 284, ... 320, ) == 0x0 02322 424 NtClose (284, ... ) == 0x0 02323 424 NtMapViewOfSection (320, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xfd0000), 0x0, 12288, ) == 0x0 02324 424 NtClose (320, ... ) == 0x0 02325 424 NtUnmapViewOfSection (-1, 0xfd0000, ... ) == 0x0 02326 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\drprov.dll"}, 1232056, ... ) }, 1232056, ... ) == 0x0 02327 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\drprov.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02328 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 284, ) == 0x0 02329 424 NtQuerySection (284, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02330 424 NtClose (320, ... ) == 0x0 02331 424 NtMapViewOfSection (284, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75f60000), 0x0, 24576, ) == 0x0 02332 424 NtClose (284, ... ) == 0x0 02333 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\RDPNP\NetworkProvider"}, ... 284, ) }, ... 284, ) == 0x0 02334 424 NtQueryValueKey (284, (284, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (284, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) }, 68, ) == 0x0 02335 424 NtClose (284, ... ) == 0x0 02336 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntlanman.dll"}, 1231740, ... ) }, 1231740, ... ) == 0x0 02337 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntlanman.dll"}, 5, 96, ... 284, {status=0x0, info=1}, ) }, 5, 96, ... 284, {status=0x0, info=1}, ) == 0x0 02338 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 284, ... 320, ) == 0x0 02339 424 NtClose (284, ... ) == 0x0 02340 424 NtMapViewOfSection (320, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xfd0000), 0x0, 40960, ) == 0x0 02341 424 NtClose (320, ... ) == 0x0 02342 424 NtUnmapViewOfSection (-1, 0xfd0000, ... ) == 0x0 02343 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntlanman.dll"}, 1232056, ... ) }, 1232056, ... ) == 0x0 02344 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntlanman.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02345 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 284, ) == 0x0 02346 424 NtQuerySection (284, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02347 424 NtClose (320, ... ) == 0x0 02348 424 NtMapViewOfSection (284, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71c10000), 0x0, 53248, ) == 0x0 02349 424 NtClose (284, ... ) == 0x0 02350 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "NETUI0.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02351 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETUI0.dll"}, 1231244, ... ) }, 1231244, ... ) == 0x0 02352 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETUI0.dll"}, 5, 96, ... 284, {status=0x0, info=1}, ) }, 5, 96, ... 284, {status=0x0, info=1}, ) == 0x0 02353 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 284, ... 320, ) == 0x0 02354 424 NtQuerySection (320, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02355 424 NtClose (284, ... ) == 0x0 02356 424 NtMapViewOfSection (320, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71cd0000), 0x0, 90112, ) == 0x0 02357 424 NtClose (320, ... ) == 0x0 02358 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "NETUI1.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02359 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETUI1.dll"}, 1231244, ... ) }, 1231244, ... ) == 0x0 02360 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETUI1.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02361 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 284, ) == 0x0 02362 424 NtQuerySection (284, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02363 424 NtClose (320, ... ) == 0x0 02364 424 NtMapViewOfSection (284, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71c90000), 0x0, 245760, ) == 0x0 02365 424 NtClose (284, ... ) == 0x0 02366 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "NETRAP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02367 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETRAP.dll"}, 1230440, ... ) }, 1230440, ... ) == 0x0 02368 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETRAP.dll"}, 5, 96, ... 284, {status=0x0, info=1}, ) }, 5, 96, ... 284, {status=0x0, info=1}, ) == 0x0 02369 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 284, ... 320, ) == 0x0 02370 424 NtQuerySection (320, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02371 424 NtClose (284, ... ) == 0x0 02372 424 NtMapViewOfSection (320, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71c80000), 0x0, 24576, ) == 0x0 02373 424 NtClose (320, ... ) == 0x0 02374 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SAMLIB.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02375 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SAMLIB.dll"}, 1230440, ... ) }, 1230440, ... ) == 0x0 02376 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SAMLIB.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02377 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 284, ) == 0x0 02378 424 NtQuerySection (284, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02379 424 NtClose (320, ... ) == 0x0 02380 424 NtMapViewOfSection (284, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71bf0000), 0x0, 69632, ) == 0x0 02381 424 NtClose (284, ... ) == 0x0 02382 424 NtOpenKey (0x80000000, {24, 0, 0xc0, 0, 0, (0x80000000, {24, 0, 0xc0, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Network\World Full Access Shared Parameters"}, ... 284, ) }, ... 284, ) == 0x0 02383 424 NtQueryValueKey (284, (284, "Sort Hyphens", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02384 424 NtCreateSemaphore (0x1f0003, 0x0, 1, 1, ... 320, ) == 0x0 02385 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\davclnt.dll"}, 1231740, ... ) }, 1231740, ... ) == 0x0 02386 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\davclnt.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02387 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 324, ) == 0x0 02388 424 NtClose (316, ... ) == 0x0 02389 424 NtMapViewOfSection (324, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xfd0000), 0x0, 24576, ) == 0x0 02390 424 NtClose (324, ... ) == 0x0 02391 424 NtUnmapViewOfSection (-1, 0xfd0000, ... ) == 0x0 02392 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\davclnt.dll"}, 1232056, ... ) }, 1232056, ... ) == 0x0 02393 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\davclnt.dll"}, 5, 96, ... 324, {status=0x0, info=1}, ) }, 5, 96, ... 324, {status=0x0, info=1}, ) == 0x0 02394 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 324, ... 316, ) == 0x0 02395 424 NtQuerySection (316, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02396 424 NtClose (324, ... ) == 0x0 02397 424 NtMapViewOfSection (316, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75f70000), 0x0, 36864, ) == 0x0 02398 424 NtClose (316, ... ) == 0x0 02399 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\WebClient\NetworkProvider"}, ... 316, ) }, ... 316, ) == 0x0 02400 424 NtQueryValueKey (316, (316, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0e\0b\0 \0C\0l\0i\0e\0n\0t\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 50, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (316, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="W\0e\0b\0 \0C\0l\0i\0e\0n\0t\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 50, ) }, 50, ) == 0x0 02401 424 NtClose (316, ... ) == 0x0 02402 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "system32\system32\hgfs1.dll"}, 1231732, ... ) }, 1231732, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02403 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "system32\hgfs1.dll"}, 1231732, ... ) }, 1231732, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02404 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\system32\hgfs1.dll"}, 1231732, ... ) }, 1231732, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02405 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\system32\hgfs1.dll"}, 1231732, ... ) }, 1231732, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02406 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\hgfs1.dll"}, 1231732, ... ) }, 1231732, ... ) == 0x0 02407 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\hgfs1.dll"}, 5, 96, ... 316, {status=0x0, info=1}, ) }, 5, 96, ... 316, {status=0x0, info=1}, ) == 0x0 02408 424 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 316, ... 324, ) == 0x0 02409 424 NtClose (316, ... ) == 0x0 02410 424 NtMapViewOfSection (324, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xfd0000), 0x0, 122880, ) == 0x0 02411 424 NtClose (324, ... ) == 0x0 02412 424 NtUnmapViewOfSection (-1, 0xfd0000, ... ) == 0x0 02413 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "system32\system32\hgfs1.dll"}, 1232048, ... ) }, 1232048, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02414 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "system32\hgfs1.dll"}, 1232048, ... ) }, 1232048, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02415 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\system32\hgfs1.dll"}, 1232048, ... ) }, 1232048, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02416 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\system32\hgfs1.dll"}, 1232048, ... ) }, 1232048, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02417 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\hgfs1.dll"}, 1232048, ... ) }, 1232048, ... ) == 0x0 02418 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\hgfs1.dll"}, 5, 96, ... 324, {status=0x0, info=1}, ) }, 5, 96, ... 324, {status=0x0, info=1}, ) == 0x0 02419 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 324, ... 316, ) == 0x0 02420 424 NtQuerySection (316, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02421 424 NtClose (324, ... ) == 0x0 02422 424 NtMapViewOfSection (316, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x10000000), 0x0, 131072, ) == 0x0 02423 424 NtClose (316, ... ) == 0x0 02424 424 NtProtectVirtualMemory (-1, (0x10015000), 416, 4, ... (0x10015000), 4096, 2, ) == 0x0 02425 424 NtProtectVirtualMemory (-1, (0x10015000), 4096, 2, ... (0x10015000), 4096, 4, ) == 0x0 02426 424 NtFlushInstructionCache (-1, 268521472, 416, ... ) == 0x0 02427 424 NtProtectVirtualMemory (-1, (0x10015000), 416, 4, ... (0x10015000), 4096, 2, ) == 0x0 02428 424 NtProtectVirtualMemory (-1, (0x10015000), 4096, 2, ... (0x10015000), 4096, 4, ) == 0x0 02429 424 NtFlushInstructionCache (-1, 268521472, 416, ... ) == 0x0 02430 424 NtProtectVirtualMemory (-1, (0x10015000), 416, 4, ... (0x10015000), 4096, 2, ) == 0x0 02431 424 NtProtectVirtualMemory (-1, (0x10015000), 4096, 2, ... (0x10015000), 4096, 4, ) == 0x0 02432 424 NtFlushInstructionCache (-1, 268521472, 416, ... ) == 0x0 02433 424 NtProtectVirtualMemory (-1, (0x10015000), 416, 4, ... (0x10015000), 4096, 2, ) == 0x0 02434 424 NtProtectVirtualMemory (-1, (0x10015000), 4096, 2, ... (0x10015000), 4096, 4, ) == 0x0 02435 424 NtFlushInstructionCache (-1, 268521472, 416, ... ) == 0x0 02436 424 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02437 424 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 16580608, 65536, ) == 0x0 02438 424 NtAllocateVirtualMemory (-1, 16580608, 0, 4096, 4096, 4, ... 16580608, 4096, ) == 0x0 02439 424 NtAllocateVirtualMemory (-1, 16584704, 0, 8192, 4096, 4, ... 16584704, 8192, ) == 0x0 02440 424 NtAllocateVirtualMemory (-1, 16592896, 0, 4096, 4096, 4, ... 16592896, 4096, ) == 0x0 02441 424 NtQueryPerformanceCounter (... {104818406, 0}, {3579545, 0}, ) == 0x0 02442 424 NtRaiseException (1231540, 1230800, 1, ... 02443 424 NtContinue (1229596, 0, ... 02444 424 NtOpenMutant (0x120001, {24, 52, 0x2, 0, 0, (0x120001, {24, 52, 0x2, 0, 0, "DBWinMutex"}, ... 316, ) }, ... 316, ) == 0x0 02445 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02446 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02447 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02448 424 NtRaiseException (1221516, 1220776, 1, ... 02449 424 NtAllocateVirtualMemory (-1, 1212416, 0, 4096, 4096, 260, ... 1212416, 4096, ) == 0x0 02450 424 NtContinue (1219572, 0, ... 02451 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02452 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02453 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02454 424 NtRaiseException (1223276, 1222536, 1, ... 02455 424 NtContinue (1221332, 0, ... 02456 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02457 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02458 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02459 424 NtRaiseException (1223280, 1222540, 1, ... 02460 424 NtContinue (1221336, 0, ... 02461 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02462 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02463 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02464 424 NtRaiseException (1223276, 1222536, 1, ... 02465 424 NtContinue (1221332, 0, ... 02466 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02467 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02468 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02469 424 NtRaiseException (1223280, 1222540, 1, ... 02470 424 NtContinue (1221336, 0, ... 02471 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02472 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02473 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02474 424 NtRaiseException (1223276, 1222536, 1, ... 02475 424 NtContinue (1221332, 0, ... 02476 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02477 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02478 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02479 424 NtRaiseException (1223280, 1222540, 1, ... 02480 424 NtContinue (1221336, 0, ... 02481 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02482 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02483 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02484 424 NtRaiseException (1223276, 1222536, 1, ... 02485 424 NtContinue (1221332, 0, ... 02486 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02487 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02488 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02489 424 NtRaiseException (1223280, 1222540, 1, ... 02490 424 NtContinue (1221336, 0, ... 02491 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02492 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02493 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02494 424 NtRaiseException (1223276, 1222536, 1, ... 02495 424 NtContinue (1221332, 0, ... 02496 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02497 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02498 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02499 424 NtRaiseException (1223280, 1222540, 1, ... 02500 424 NtContinue (1221336, 0, ... 02501 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02502 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02503 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02504 424 NtRaiseException (1223276, 1222536, 1, ... 02505 424 NtContinue (1221332, 0, ... 02506 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02507 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02508 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02509 424 NtRaiseException (1223280, 1222540, 1, ... 02510 424 NtContinue (1221336, 0, ... 02511 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02512 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02513 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02514 424 NtRaiseException (1223276, 1222536, 1, ... 02515 424 NtContinue (1221332, 0, ... 02516 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02517 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02518 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02519 424 NtRaiseException (1223280, 1222540, 1, ... 02520 424 NtContinue (1221336, 0, ... 02521 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02522 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02523 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02524 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\drprov.dll"}, 1231708, ... ) }, 1231708, ... ) == 0x0 02525 424 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {420, 0}, ... 324, ) == 0x0 02526 424 NtQueryInformationProcess (324, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 02527 424 NtClose (324, ... ) == 0x0 02528 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ntlanman.dll"}, 1231708, ... ) }, 1231708, ... ) == 0x0 02529 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02530 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 324, ) == 0x0 02531 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02532 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02533 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1230756, (0xc0100080, {24, 0, 0x40, 0, 1230756, "\??\PIPE\wkssvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 328, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 328, {status=0x0, info=1}, ) == 0x0 02534 424 NtSetInformationFile (328, 1230812, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02535 424 NtSetInformationFile (328, 1230804, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02536 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02537 424 NtWriteFile (328, 129, 0, 0, (328, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\230\320\377k\22\241\206\2303F\303\370~4Z\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02538 424 NtReadFile (328, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (328, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\336#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02539 424 NtFsControlFile (328, 129, 0x0, 0x0, 0x11c017, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\08\0\316q\1\0\0\0\0\0\0\0\1\0\0\0\0\0F\303d\0\0\0", 48, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\336#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 48, 1024, ... {status=0x103, info=68}, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\08\0\316q\1\0\0\0\0\0\0\0\1\0\0\0\0\0F\303d\0\0\0", 48, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\336#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02540 424 NtClose (324, ... ) == 0x0 02541 424 NtClose (328, ... ) == 0x0 02542 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02543 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 328, ) == 0x0 02544 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02545 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02546 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1230756, (0xc0100080, {24, 0, 0x40, 0, 1230756, "\??\PIPE\wkssvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 324, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 324, {status=0x0, info=1}, ) == 0x0 02547 424 NtSetInformationFile (324, 1230812, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02548 424 NtSetInformationFile (324, 1230804, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02549 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02550 424 NtWriteFile (324, 129, 0, 0, (324, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\230\320\377k\22\241\206\2303F\303\370~4Z\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02551 424 NtReadFile (324, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (324, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\337#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02552 424 NtFsControlFile (324, 129, 0x0, 0x0, 0x11c017, (324, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\3\0\0\0\0\0\1\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\337#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 32, 1024, ... {status=0x103, info=68}, (324, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\3\0\0\0\0\0\1\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\337#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02553 424 NtClose (328, ... ) == 0x0 02554 424 NtClose (324, ... ) == 0x0 02555 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider"}, ... 324, ) }, ... 324, ) == 0x0 02556 424 NtQueryKey (324, Full, 176, ... {LastWrite={0xf49de34e,0x1c73998}, TitleIdx=0, Subkeys=0, Values=3, Class=""}, 44, ) == 0x0 02557 424 NtQuerySecurityObject (324, 7, 0, ... ) == STATUS_BUFFER_TOO_SMALL 02558 424 NtQuerySecurityObject (324, 15, 0, ... ) == STATUS_ACCESS_DENIED 02559 424 NtAllocateVirtualMemory (-1, 0, 0, 524280, 8192, 4, ... 16646144, 524288, ) == 0x0 02560 424 NtAllocateVirtualMemory (-1, 16646144, 0, 4096, 4096, 4, ... 16646144, 4096, ) == 0x0 02561 424 NtQueryValueKey (324, (324, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (324, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0"}, 64, ) }, 64, ) == 0x0 02562 424 NtClose (324, ... ) == 0x0 02563 424 NtCreateFile (0x100000, {24, 0, 0x40, 0, 0, (0x100000, {24, 0, 0x40, 0, 0, "\Dfs"}, 0x0, 128, 7, 3, 160, 0, 0, ... 324, {status=0x0, info=1}, ) }, 0x0, 128, 7, 3, 160, 0, 0, ... 324, {status=0x0, info=1}, ) == 0x0 02564 424 NtFsControlFile (324, 0, 0x0, 0x0, 0x600bc, (324, 0, 0x0, 0x0, 0x600bc, "M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0", 52, 1024, ... {status=0x0, info=1024}, "\1\0\0\0\1\0\0\0\0\0\0\0\1\0\0\0\302\3\0\0\232\3\0\0\0\0\0\0\310\3\0\0\1\0\0\0\1\0\0\0\0\0\0\0\1\0\0\0`\3\0\08\3\0\0\0\0\0\0f\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , 52, 1024, ... {status=0x0, info=1024}, (324, 0, 0x0, 0x0, 0x600bc, "M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0W\0i\0n\0d\0o\0w\0s\0 \0N\0e\0t\0w\0o\0r\0k\0\0\0", 52, 1024, ... {status=0x0, info=1024}, "\1\0\0\0\1\0\0\0\0\0\0\0\1\0\0\0\302\3\0\0\232\3\0\0\0\0\0\0\310\3\0\0\1\0\0\0\1\0\0\0\0\0\0\0\1\0\0\0`\3\0\08\3\0\0\0\0\0\0f\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 02565 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02566 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 328, ) == 0x0 02567 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02568 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02569 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1232196, (0xc0100080, {24, 0, 0x40, 0, 1232196, "\??\PIPE\wkssvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 332, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 332, {status=0x0, info=1}, ) == 0x0 02570 424 NtSetInformationFile (332, 1232252, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02571 424 NtSetInformationFile (332, 1232244, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02572 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02573 424 NtWriteFile (332, 129, 0, 0, (332, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\230\320\377k\22\241\206\2303F\303\370~4Z\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02574 424 NtReadFile (332, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (332, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\340#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02575 424 NtFsControlFile (332, 129, 0x0, 0x0, 0x11c017, (332, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\08\0\0\0\1\0\0\0 \0\0\0\0\0\13\0\0\0\0\0\1\0\0\0\1\0\0\0\254\323\22\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0", 56, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\340#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 56, 1024, ... {status=0x103, info=68}, (332, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\08\0\0\0\1\0\0\0 \0\0\0\0\0\13\0\0\0\0\0\1\0\0\0\1\0\0\0\254\323\22\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0", 56, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20\340#\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02576 424 NtClose (328, ... ) == 0x0 02577 424 NtClose (332, ... ) == 0x0 02578 424 NtWaitForSingleObject (320, 0, {-70000000, -1}, ... ) == 0x0 02579 424 NtReleaseSemaphore (320, 1, ... 0x0, ) == 0x0 02580 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\davclnt.dll"}, 1231708, ... ) }, 1231708, ... ) == 0x0 02581 424 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "Global\SvcctrlStartEvent_A3752DX"}, ... 332, ) }, ... 332, ) == 0x0 02582 424 NtWaitForSingleObject (332, 0, {-1800000000, -1}, ... ) == 0x0 02583 424 NtClose (332, ... ) == 0x0 02584 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02585 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 332, ) == 0x0 02586 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02587 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02588 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1232232, (0xc0100080, {24, 0, 0x40, 0, 1232232, "\??\PIPE\svcctl"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 328, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 328, {status=0x0, info=1}, ) == 0x0 02589 424 NtSetInformationFile (328, 1232288, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02590 424 NtSetInformationFile (328, 1232280, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02591 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02592 424 NtWriteFile (328, 129, 0, 0, (328, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\201\273z6D\230\3615\2552\230\3608\0\20\3\2\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02593 424 NtReadFile (328, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (328, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20p"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x0 02594 424 NtFsControlFile (328, 129, 0x0, 0x0, 0x11c017, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\17\0\0\0\0\0\0\0\0\0\1\0\0\0", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20p"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 36, 1024, ... {status=0x103, info=68}, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\17\0\0\0\0\0\0\0\0\0\1\0\0\0", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20p"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x103 02595 424 NtFsControlFile (328, 129, 0x0, 0x0, 0x11c017, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0P\0\0\0\2\0\0\08\0\0\0\0\0\20\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0", 80, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0 (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0P\0\0\0\2\0\0\08\0\0\0\0\0\20\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0", 80, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0-\277\30\255 (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0P\0\0\0\2\0\0\08\0\0\0\0\0\20\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0", 80, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02596 424 NtFsControlFile (328, 129, 0x0, 0x0, 0x11c017, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\6\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305 (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\6\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0.\277\30\255 (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\6\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02597 424 NtFsControlFile (328, 129, 0x0, 0x0, 0x11c017, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\4\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=56}, "\5\0\2\3\20\0\0\08\0\0\0\3\0\0\0 \0\0\0\0\0\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305 (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\4\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0-\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=56}, "\5\0\2\3\20\0\0\08\0\0\0\3\0\0\0 \0\0\0\0\0\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) \5\0\2\3\20\0\0\08\0\0\0\3\0\0\0 \0\0\0\0\0\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) == 0x103 02598 424 NtFsControlFile (328, 129, 0x0, 0x0, 0x11c017, (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\5\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305 (328, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\5\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0.\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) == 0x103 02599 424 NtClose (332, ... ) == 0x0 02600 424 NtClose (328, ... ) == 0x0 02601 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "system32\system32\hgfs1.dll"}, 1231700, ... ) }, 1231700, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02602 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "system32\hgfs1.dll"}, 1231700, ... ) }, 1231700, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02603 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\system32\hgfs1.dll"}, 1231700, ... ) }, 1231700, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02604 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\system32\hgfs1.dll"}, 1231700, ... ) }, 1231700, ... ) == STATUS_OBJECT_PATH_NOT_FOUND 02605 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\hgfs1.dll"}, 1231700, ... ) }, 1231700, ... ) == 0x0 02606 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\hgfs\parameters"}, ... 328, ) }, ... 328, ) == 0x0 02607 424 NtQueryValueKey (328, (328, "ServerName", Partial, 144, ... TitleIdx=0, Type=1, Data=".\0h\0o\0s\0t\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (328, "ServerName", Partial, 144, ... TitleIdx=0, Type=1, Data=".\0h\0o\0s\0t\0\0\0"}, 24, ) }, 24, ) == 0x0 02608 424 NtClose (328, ... ) == 0x0 02609 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\hgfs\parameters"}, ... 328, ) }, ... 328, ) == 0x0 02610 424 NtQueryValueKey (328, (328, "ShareName", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 42, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (328, "ShareName", Partial, 144, ... TitleIdx=0, Type=1, Data="S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 42, ) }, 42, ) == 0x0 02611 424 NtClose (328, ... ) == 0x0 02612 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\hgfs\NetworkProvider"}, ... 328, ) }, ... 328, ) == 0x0 02613 424 NtQueryValueKey (328, (328, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0M\0w\0a\0r\0e\0 \0S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (328, "name", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0M\0w\0a\0r\0e\0 \0S\0h\0a\0r\0e\0d\0 \0F\0o\0l\0d\0e\0r\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 02614 424 NtClose (328, ... ) == 0x0 02615 424 NtRaiseException (1222200, 1221460, 1, ... 02616 424 NtContinue (1220256, 0, ... 02617 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02618 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02619 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02620 424 NtRaiseException (1222196, 1221456, 1, ... 02621 424 NtContinue (1220252, 0, ... 02622 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02623 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02624 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02625 424 NtCreateMutant (0x1f0001, {24, 52, 0x80, 1232864, 0, (0x1f0001, {24, 52, 0x80, 1232864, 0, "HGFSMUTEX"}, 1, ... 328, ) }, 1, ... 328, ) == 0x0 02626 424 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "shfolder.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02627 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\shfolder.dll"}, 1229884, ... ) }, 1229884, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02628 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "shfolder.dll"}, 1229884, ... ) }, 1229884, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02629 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shfolder.dll"}, 1229884, ... ) }, 1229884, ... ) == 0x0 02630 424 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\shfolder.dll"}, 5, 96, ... 332, {status=0x0, info=1}, ) }, 5, 96, ... 332, {status=0x0, info=1}, ) == 0x0 02631 424 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 332, ... 336, ) == 0x0 02632 424 NtQuerySection (336, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02633 424 NtClose (332, ... ) == 0x0 02634 424 NtMapViewOfSection (336, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76780000), 0x0, 32768, ) == 0x0 02635 424 NtClose (336, ... ) == 0x0 02636 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02637 424 NtCreateSemaphore (0x1f0003, {24, 52, 0x80, 1355896, 0, (0x1f0003, {24, 52, 0x80, 1355896, 0, "shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}"}, 0, 2147483647, ... 336, ) }, 0, 2147483647, ... 336, ) == STATUS_OBJECT_NAME_EXISTS 02638 424 NtReleaseSemaphore (336, 1, ... 0, ) == 0x0 02639 424 NtWaitForSingleObject (336, 0, {0, 0}, ... ) == 0x0 02640 424 NtCreateKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 332, 2, ) }, 0, 0x0, 0, ... 332, 2, ) == 0x0 02641 424 NtQueryValueKey (332, (332, "Local AppData", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0"}, 104, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (332, "Local AppData", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0"}, 104, ) }, 104, ) == 0x0 02642 424 NtClose (332, ... ) == 0x0 02643 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Application Data"}, 1230416, ... ) }, 1230416, ... ) == 0x0 02644 424 NtCreateKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 332, 2, ) }, 0, 0x0, 0, ... 332, 2, ) == 0x0 02645 424 NtSetValueKey (332, (332, "Local AppData", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0", 134, ... ) , 0, 1, (332, "Local AppData", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0", 134, ... ) , 134, ... ) == 0x0 02646 424 NtClose (332, ... ) == 0x0 02647 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Application Data\"}, 3, 16417, ... 332, {status=0x0, info=1}, ) }, 3, 16417, ... 332, {status=0x0, info=1}, ) == 0x0 02648 424 NtQueryDirectoryFile (332, 0, 0, 0, 1230556, 616, BothDirectory, 1, (332, 0, 0, 0, 1230556, 616, BothDirectory, 1, "VMware", 0, ... {status=0x0, info=106}, ) , 0, ... {status=0x0, info=106}, ) == 0x0 02649 424 NtUnmapViewOfSection (-1, 0x76780000, ... ) == 0x0 02650 424 NtRaiseException (1221836, 1221096, 1, ... 02651 424 NtContinue (1219892, 0, ... 02652 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02653 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02654 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02655 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 1232864, 1232440, (0xc0100080, {24, 0, 0x40, 1232864, 1232440, "\??\C:\Documents and Settings\SRI-user\Local Settings\Application Data\VMware\hgfs.dat"}, 0x0, 128, 0, 3, 96, 0, 0, ... 340, {status=0x0, info=1}, ) }, 0x0, 128, 0, 3, 96, 0, 0, ... 340, {status=0x0, info=1}, ) == 0x0 02656 424 NtRaiseException (1221836, 1221096, 1, ... 02657 424 NtContinue (1219892, 0, ... 02658 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02659 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02660 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02661 424 NtCreateSection (0xf0007, {24, 52, 0x80, 1232864, 0, (0xf0007, {24, 52, 0x80, 1232864, 0, "HGFSMEMORY"}, {27876, 0}, 4, 134217728, 340, ... 344, ) }, {27876, 0}, 4, 134217728, 340, ... 344, ) == 0x0 02662 424 NtMapViewOfSection (344, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x1060000), {0, 0}, 28672, ) == 0x0 02663 424 NtReleaseMutant (328, ... 0x0, ) == 0x0 02664 424 NtRaiseException (1223252, 1222512, 1, ... 02665 424 NtContinue (1221308, 0, ... 02666 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02667 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02668 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02669 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 1233908, 1233496, (0xc0100080, {24, 0, 0x40, 1233908, 1233496, "\??\Global\HGFS"}, 0x0, 0, 3, 1, 96, 0, 0, ... 348, {status=0x0, info=0}, ) }, 0x0, 0, 3, 1, 96, 0, 0, ... 348, {status=0x0, info=0}, ) == 0x0 02670 424 NtDeviceIoControlFile (348, 0, 0x0, 0x0, 0x84002020, 0x0, 0, 1, ... {status=0x0, info=1}, (348, 0, 0x0, 0x0, 0x84002020, 0x0, 0, 1, ... {status=0x0, info=1}, "\0", ) , ) == 0x0 02671 424 NtClose (348, ... ) == 0x0 02672 424 NtRaiseException (1223232, 1222492, 1, ... 02673 424 NtContinue (1221288, 0, ... 02674 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02675 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02676 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02677 424 NtRaiseException (1223252, 1222512, 1, ... 02678 424 NtContinue (1221308, 0, ... 02679 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 02680 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02681 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 02682 424 NtAllocateVirtualMemory (-1, 1466368, 0, 20480, 4096, 4, ... 1466368, 20480, ) == 0x0 02683 424 NtAllocateVirtualMemory (-1, 1486848, 0, 20480, 4096, 4, ... 1486848, 20480, ) == 0x0 02684 424 NtWaitForSingleObject (320, 0, {-70000000, -1}, ... ) == 0x0 02685 424 NtReleaseSemaphore (320, 1, ... 0x0, ) == 0x0 02686 424 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "Global\SvcctrlStartEvent_A3752DX"}, ... 348, ) }, ... 348, ) == 0x0 02687 424 NtWaitForSingleObject (348, 0, {-1800000000, -1}, ... ) == 0x0 02688 424 NtClose (348, ... ) == 0x0 02689 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02690 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 348, ) == 0x0 02691 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02692 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02693 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1232172, (0xc0100080, {24, 0, 0x40, 0, 1232172, "\??\PIPE\svcctl"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 352, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 352, {status=0x0, info=1}, ) == 0x0 02694 424 NtSetInformationFile (352, 1232228, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02695 424 NtSetInformationFile (352, 1232220, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02696 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02697 424 NtWriteFile (352, 129, 0, 0, (352, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\201\273z6D\230\3615\2552\230\3608\0\20\3\2\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02698 424 NtReadFile (352, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (352, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20q"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x0 02699 424 NtFsControlFile (352, 129, 0x0, 0x0, 0x11c017, (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\17\0\0\0\0\0\0\0\0\0\1\0\0\0", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20q"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 36, 1024, ... {status=0x103, info=68}, (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\17\0\0\0\0\0\0\0\0\0\1\0\0\0", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20q"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x103 02700 424 NtFsControlFile (352, 129, 0x0, 0x0, 0x11c017, (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0P\0\0\0\2\0\0\08\0\0\0\0\0\20\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0", 80, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0 (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0P\0\0\0\2\0\0\08\0\0\0\0\0\20\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0", 80, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0/\277\30\255 (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0P\0\0\0\2\0\0\08\0\0\0\0\0\20\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305\12\0\0\0\0\0\0\0\12\0\0\0W\0e\0b\0C\0l\0i\0e\0n\0t\0\0\0\4\0\0\0", 80, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02701 424 NtFsControlFile (352, 129, 0x0, 0x0, 0x11c017, (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\6\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305 (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\6\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\00\277\30\255 (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\6\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\2\0\0\0\30\0\0\0\0\0\0\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02702 424 NtFsControlFile (352, 129, 0x0, 0x0, 0x11c017, (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\4\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=56}, "\5\0\2\3\20\0\0\08\0\0\0\3\0\0\0 \0\0\0\0\0\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305 (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\4\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0/\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=56}, "\5\0\2\3\20\0\0\08\0\0\0\3\0\0\0 \0\0\0\0\0\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) \5\0\2\3\20\0\0\08\0\0\0\3\0\0\0 \0\0\0\0\0\0\0 \0\0\0\4\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) == 0x103 02703 424 NtFsControlFile (352, 129, 0x0, 0x0, 0x11c017, (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\5\0\0\0\24\0\0\0\0\0\0\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) G\334\21\261\310\0\14)\371\246\305 (352, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\5\0\0\0\24\0\0\0\0\0\0\0\0\0\0\00\277\30\255"G\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) == 0x103 02704 424 NtClose (348, ... ) == 0x0 02705 424 NtClose (352, ... ) == 0x0 02706 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02707 424 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 352, ) == 0x0 02708 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02709 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02710 424 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1232264, (0xc0100080, {24, 0, 0x40, 0, 1232264, "\??\PIPE\DAV RPC SERVICE"}, 0x0, 0, 3, 1, 64, 0, 0, ... 348, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 348, {status=0x0, info=1}, ) == 0x0 02711 424 NtSetInformationFile (348, 1232320, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02712 424 NtSetInformationFile (348, 1232312, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02713 424 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02714 424 NtWriteFile (348, 129, 0, 0, (348, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\207v\313\310\323\346\322\21\251X\0\300Oh.\26\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02715 424 NtReadFile (348, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=76}, (348, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=76}, "\5\0\14\3\20\0\0\0L\0\0\0\1\0\0\0\270\20\270\200'\0\0\26\0\PIPE\DAV RPC SERVICE\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02716 424 NtFsControlFile (348, 129, 0x0, 0x0, 0x11c017, (348, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0;\0\0\0\1\0\0\0#\0\0\0\0\0\3\0\0\0\0\0\1\0\0\0\0\0\0\0\1\0\0\0\0\0\0\300\1\0\0\0\0\0\0\0\1\0\0\0\0\0\0", 59, 1024, ... {status=0x103, info=76}, "\5\0\14\3\20\0\0\0L\0\0\0\1\0\0\0\270\20\270\200'\0\0\26\0\PIPE\DAV RPC SERVICE\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 59, 1024, ... {status=0x103, info=76}, (348, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0;\0\0\0\1\0\0\0#\0\0\0\0\0\3\0\0\0\0\0\1\0\0\0\0\0\0\0\1\0\0\0\0\0\0\300\1\0\0\0\0\0\0\0\1\0\0\0\0\0\0", 59, 1024, ... {status=0x103, info=76}, "\5\0\14\3\20\0\0\0L\0\0\0\1\0\0\0\270\20\270\200'\0\0\26\0\PIPE\DAV RPC SERVICE\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02717 424 NtClose (352, ... ) == 0x0 02718 424 NtClose (348, ... ) == 0x0 02719 424 NtCreateKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##missouri#binaries"}, 0, 0x0, 0, ... 348, 2, ) }, 0, 0x0, 0, ... 348, 2, ) == 0x0 02720 424 NtSetValueKey (348, (348, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (348, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 02721 424 NtClose (348, ... ) == 0x0 02722 424 NtOpenKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##missouri#binaries"}, ... 348, ) }, ... 348, ) == 0x0 02723 424 NtQueryValueKey (348, (348, "_CommentFromDesktopINI", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (348, "_CommentFromDesktopINI", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02724 424 NtClose (348, ... ) == 0x0 02725 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\F\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02726 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 02727 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Applications\Explorer.exe\Drives\F\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02728 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\F\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02729 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\F\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02730 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 02731 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Applications\Explorer.exe\Drives\F\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02732 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\F\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02733 424 NtCreateKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##missouri#binaries"}, 0, 0x0, 0, ... 348, 2, ) }, 0, 0x0, 0, ... 348, 2, ) == 0x0 02734 424 NtSetValueKey (348, (348, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (348, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 02735 424 NtClose (348, ... ) == 0x0 02736 424 NtOpenKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##missouri#binaries"}, ... 348, ) }, ... 348, ) == 0x0 02737 424 NtQueryValueKey (348, (348, "_CommentFromDesktopINI", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (348, "_CommentFromDesktopINI", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02738 424 NtClose (348, ... ) == 0x0 02739 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\U\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02740 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 02741 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Applications\Explorer.exe\Drives\U\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02742 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\U\DefaultIcon"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02743 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\U\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02744 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESr"}, 138, ) }, 138, ) == 0x0 02745 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Applications\Explorer.exe\Drives\U\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02746 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\Explorer.exe\Drives\U\DefaultLabel"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02747 424 NtWaitForSingleObject (320, 0, {-70000000, -1}, ... ) == 0x0 02748 424 NtReleaseSemaphore (320, 1, ... 0x0, ) == 0x0 02749 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02750 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02751 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02752 424 NtClose (348, ... ) == 0x0 02753 424 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 348, ) }, ... 348, ) == 0x0 02754 424 NtOpenKey (0x20019, {24, 348, 0x40, 0, 0, (0x20019, {24, 348, 0x40, 0, 0, "Network"}, ... 352, ) }, ... 352, ) == 0x0 02755 424 NtClose (348, ... ) == 0x0 02756 424 NtQueryKey (352, Full, 176, ... {LastWrite={0x5122c09c,0x1c7a3ae}, TitleIdx=0, Subkeys=2, Values=0, Class= (352, Full, 176, ... {LastWrite={0x5122c09c,0x1c7a3ae}, TitleIdx=0, Subkeys=2, Values=0, Class="GenericClass"}, 68, ) }, 68, ) == 0x0 02757 424 NtQuerySecurityObject (352, 7, 0, ... ) == STATUS_BUFFER_TOO_SMALL 02758 424 NtQuerySecurityObject (352, 15, 0, ... ) == STATUS_ACCESS_DENIED 02759 424 NtWaitForSingleObject (68, 0, {0, 0}, ... ) == 0x102 02760 424 NtEnumerateKey (352, 0, Basic, 288, ... {LastWrite={0x8ac9a296,0x1c7a3ab}, TitleIdx=0, Name= (352, 0, Basic, 288, ... {LastWrite={0x8ac9a296,0x1c7a3ab}, TitleIdx=0, Name="f"}, 18, ) }, 18, ) == 0x0 02761 424 NtOpenKey (0x2001f, {24, 352, 0x40, 0, 0, (0x2001f, {24, 352, 0x40, 0, 0, "f"}, ... 348, ) }, ... 348, ) == 0x0 02762 424 NtQueryValueKey (348, (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) }, 52, ) == 0x0 02763 424 NtQueryValueKey (348, (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) }, 52, ) == 0x0 02764 424 NtQueryValueKey (348, (348, "UserName", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "UserName", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02765 424 NtQueryValueKey (348, (348, "ProviderType", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\2\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "ProviderType", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\2\0"}, 16, ) }, 16, ) == 0x0 02766 424 NtQueryValueKey (348, (348, "ProviderFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "ProviderFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02767 424 NtQueryValueKey (348, (348, "DeferFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "DeferFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) }, 16, ) == 0x0 02768 424 NtQueryValueKey (348, (348, "ConnectionType", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "ConnectionType", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02769 424 NtClose (348, ... ) == 0x0 02770 424 NtEnumerateKey (352, 1, Basic, 288, ... {LastWrite={0xd0d8f568,0x1c7a3ae}, TitleIdx=0, Name= (352, 1, Basic, 288, ... {LastWrite={0xd0d8f568,0x1c7a3ae}, TitleIdx=0, Name="u"}, 18, ) }, 18, ) == 0x0 02771 424 NtOpenKey (0x2001f, {24, 352, 0x40, 0, 0, (0x2001f, {24, 352, 0x40, 0, 0, "u"}, ... 348, ) }, ... 348, ) == 0x0 02772 424 NtQueryValueKey (348, (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) }, 52, ) == 0x0 02773 424 NtQueryValueKey (348, (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (348, "RemotePath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\\0m\0i\0s\0s\0o\0u\0r\0i\0\\0b\0i\0n\0a\0r\0i\0e\0s\0\0\0"}, 52, ) }, 52, ) == 0x0 02774 424 NtQueryValueKey (348, (348, "UserName", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "UserName", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02775 424 NtQueryValueKey (348, (348, "ProviderType", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\2\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "ProviderType", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\2\0"}, 16, ) }, 16, ) == 0x0 02776 424 NtQueryValueKey (348, (348, "ProviderFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "ProviderFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02777 424 NtQueryValueKey (348, (348, "DeferFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "DeferFlags", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) }, 16, ) == 0x0 02778 424 NtQueryValueKey (348, (348, "ConnectionType", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (348, "ConnectionType", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02779 424 NtClose (348, ... ) == 0x0 02780 424 NtClose (352, ... ) == 0x0 02781 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02782 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02783 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02784 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02785 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02786 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02787 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions"}, ... 352, ) }, ... 352, ) == 0x0 02788 424 NtQueryKey (354, Name, 392, ... {Name= (354, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensionsl"}, 134, ) }, 134, ) == 0x0 02789 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02790 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02791 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02792 424 NtClose (348, ... ) == 0x0 02793 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02794 424 NtEnumerateKey (354, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name= (354, 0, Node, 288, ... {LastWrite={0x5abc7c30,0x1c73999}, TitleIdx=0, Name="{fbeb8a05-beee-4442-804e-409d6c4515e9}", Class=""}, 100, ) , Class=""}, 100, ) == 0x0 02795 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02796 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, "Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02797 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... 348, ) }, ... 348, ) == 0x0 02798 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, 212, ) }, 212, ) == 0x0 02799 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02800 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02801 424 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02802 424 NtClose (356, ... ) == 0x0 02803 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02804 424 NtQueryValueKey (350, (350, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (350, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 02805 424 NtClose (350, ... ) == 0x0 02806 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02807 424 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 348, {status=0x0, info=1}, ) }, 3, 96, ... 348, {status=0x0, info=1}, ) == 0x0 02808 424 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 356, ) }, ... 356, ) == 0x0 02809 424 NtQuerySymbolicLinkObject (356, ... (356, ... "\Device\WinDfs\U:00000000000092fa", 66, ) , 66, ) == 0x0 02810 424 NtClose (356, ... ) == 0x0 02811 424 NtQueryVolumeInformationFile (348, 1233584, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02812 424 NtClose (348, ... ) == 0x0 02813 424 NtEnumerateKey (354, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 02814 424 NtClose (354, ... ) == 0x0 02815 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\U:\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02816 424 NtQueryDirectoryFile (352, 0, 0, 0, 1232368, 616, BothDirectory, 1, (352, 0, 0, 0, 1232368, 616, BothDirectory, 1, "work", 0, ... {status=0x0, info=104}, ) , 0, ... {status=0x0, info=104}, ) == 0x0 02817 424 NtClose (352, ... ) == 0x0 02818 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02819 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02820 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Directory"}, ... 352, ) }, ... 352, ) == 0x0 02821 424 NtQueryKey (354, Name, 384, ... {Name= (354, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02822 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02823 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02824 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02825 424 NtClose (348, ... ) == 0x0 02826 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02827 424 NtOpenKey (0x1, {24, 354, 0x40, 0, 0, (0x1, {24, 354, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02828 424 NtQueryKey (354, Name, 384, ... {Name= (354, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02829 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02830 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02831 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02832 424 NtClose (348, ... ) == 0x0 02833 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02834 424 NtOpenKey (0x2000000, {24, 354, 0x40, 0, 0, ""}, ... 348, ) == 0x0 02835 424 NtClose (354, ... ) == 0x0 02836 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02837 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02838 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02839 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02840 424 NtQueryValueKey (352, (352, "DontShowSuperHidden", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02841 424 NtClose (352, ... ) == 0x0 02842 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02843 424 NtOpenKey (0x2000000, {24, 148, 0x40, 0, 0, ""}, ... 352, ) == 0x0 02844 424 NtQueryValueKey (352, (352, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (352, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) }, 48, ) == 0x0 02845 424 NtQueryValueKey (352, (352, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (352, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) }, 48, ) == 0x0 02846 424 NtClose (352, ... ) == 0x0 02847 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02848 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02849 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02850 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02851 424 NtQueryValueKey (352, (352, "ForceActiveDesktopOn", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02852 424 NtClose (352, ... ) == 0x0 02853 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02854 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02855 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02856 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02857 424 NtQueryValueKey (352, (352, "NoActiveDesktop", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02858 424 NtClose (352, ... ) == 0x0 02859 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02860 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02861 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02862 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02863 424 NtQueryValueKey (352, (352, "NoWebView", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02864 424 NtClose (352, ... ) == 0x0 02865 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02866 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02867 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02868 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02869 424 NtQueryValueKey (352, (352, "ClassicShell", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02870 424 NtClose (352, ... ) == 0x0 02871 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02872 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02873 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02874 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02875 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02876 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02877 424 NtQueryValueKey (352, (352, "SeparateProcess", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02878 424 NtClose (352, ... ) == 0x0 02879 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02880 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02881 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02882 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02883 424 NtQueryValueKey (352, (352, "NoNetCrawling", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02884 424 NtClose (352, ... ) == 0x0 02885 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02886 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02887 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02888 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 352, ) }, ... 352, ) == 0x0 02889 424 NtQueryValueKey (352, (352, "NoSimpleStartMenu", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02890 424 NtClose (352, ... ) == 0x0 02891 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02892 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02893 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02894 424 NtOpenKey (0x2000000, {24, 148, 0x40, 0, 0, (0x2000000, {24, 148, 0x40, 0, 0, "Advanced"}, ... 352, ) }, ... 352, ) == 0x0 02895 424 NtQueryValueKey (352, (352, "Hidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\2\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "Hidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\2\0\0\0"}, 16, ) }, 16, ) == 0x0 02896 424 NtQueryValueKey (352, (352, "ShowCompColor", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "ShowCompColor", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02897 424 NtQueryValueKey (352, (352, "HideFileExt", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "HideFileExt", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02898 424 NtQueryValueKey (352, (352, "DontPrettyPath", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "DontPrettyPath", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02899 424 NtQueryValueKey (352, (352, "ShowInfoTip", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "ShowInfoTip", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02900 424 NtQueryValueKey (352, (352, "HideIcons", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "HideIcons", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02901 424 NtQueryValueKey (352, (352, "MapNetDrvBtn", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "MapNetDrvBtn", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02902 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 02903 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 02904 424 NtQueryValueKey (352, (352, "WebView", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "WebView", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02905 424 NtQueryValueKey (352, (352, "Filter", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "Filter", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02906 424 NtQueryValueKey (352, (352, "ShowSuperHidden", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02907 424 NtQueryValueKey (352, (352, "SeparateProcess", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (352, "SeparateProcess", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02908 424 NtQueryValueKey (352, (352, "NoNetCrawling", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02909 424 NtClose (352, ... ) == 0x0 02910 424 NtCreateSemaphore (0x1f0003, {24, 52, 0x80, 1355896, 0, (0x1f0003, {24, 52, 0x80, 1355896, 0, "shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57}"}, 0, 2147483647, ... 352, ) }, 0, 2147483647, ... 352, ) == STATUS_OBJECT_NAME_EXISTS 02911 424 NtReleaseSemaphore (352, 1, ... 0, ) == 0x0 02912 424 NtWaitForSingleObject (352, 0, {0, 0}, ... ) == 0x0 02913 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02914 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02915 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02916 424 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02917 424 NtClose (356, ... ) == 0x0 02918 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory\ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02919 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02920 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02921 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02922 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02923 424 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02924 424 NtClose (356, ... ) == 0x0 02925 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02926 424 NtQueryValueKey (350, (350, "DocObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02927 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02928 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02929 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02930 424 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02931 424 NtClose (356, ... ) == 0x0 02932 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02933 424 NtQueryValueKey (350, (350, "BrowseInPlace", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02934 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02935 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02936 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 356, ) == 0x0 02937 424 NtQueryInformationToken (356, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02938 424 NtClose (356, ... ) == 0x0 02939 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02940 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02941 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02942 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "Folder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02943 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Folder"}, ... 356, ) }, ... 356, ) == 0x0 02944 424 NtQueryKey (358, Name, 384, ... {Name= (358, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Foldert"}, 86, ) }, 86, ) == 0x0 02945 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02946 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 02947 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02948 424 NtClose (360, ... ) == 0x0 02949 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Folder\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02950 424 NtOpenKey (0x1, {24, 358, 0x40, 0, 0, (0x1, {24, 358, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02951 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02952 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02953 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 02954 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02955 424 NtClose (360, ... ) == 0x0 02956 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02957 424 NtQueryValueKey (350, (350, "IsShortcut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02958 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02959 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02960 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 02961 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02962 424 NtClose (360, ... ) == 0x0 02963 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02964 424 NtQueryValueKey (350, (350, "AlwaysShowExt", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (350, "AlwaysShowExt", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02965 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02966 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02967 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 02968 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02969 424 NtClose (360, ... ) == 0x0 02970 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02971 424 NtQueryValueKey (350, (350, "NeverShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02972 424 NtClose (350, ... ) == 0x0 02973 424 NtClose (358, ... ) == 0x0 02974 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\U:\work\"}, 3, 16417, ... 356, {status=0x0, info=1}, ) }, 3, 16417, ... 356, {status=0x0, info=1}, ) == 0x0 02975 424 NtQueryDirectoryFile (356, 0, 0, 0, 1232292, 616, BothDirectory, 1, (356, 0, 0, 0, 1232292, 616, BothDirectory, 1, "xeqfhcg.bat", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 02976 424 NtClose (356, ... ) == 0x0 02977 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02978 424 NtOpenKey (0x2000000, {24, 148, 0x40, 0, 0, (0x2000000, {24, 148, 0x40, 0, 0, "FileExts"}, ... 356, ) }, ... 356, ) == 0x0 02979 424 NtOpenKey (0x2000000, {24, 356, 0x40, 0, 0, (0x2000000, {24, 356, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02980 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02981 424 NtOpenKey (0x2000000, {24, 356, 0x40, 0, 0, (0x2000000, {24, 356, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02982 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02983 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02984 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 348, ) }, ... 348, ) == 0x0 02985 424 NtQueryKey (350, Name, 392, ... {Name= (350, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 02986 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02987 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 02988 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02989 424 NtClose (360, ... ) == 0x0 02990 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02991 424 NtQueryValueKey (350, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (350, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="b\0a\0t\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 02992 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 02993 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02994 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\batfile"}, ... 360, ) }, ... 360, ) == 0x0 02995 424 NtQueryKey (362, Name, 384, ... {Name= (362, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02996 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02997 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 364, ) == 0x0 02998 424 NtQueryInformationToken (364, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02999 424 NtClose (364, ... ) == 0x0 03000 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03001 424 NtOpenKey (0x1, {24, 362, 0x40, 0, 0, (0x1, {24, 362, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03002 424 NtQueryKey (362, Name, 384, ... {Name= (362, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03003 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03004 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 364, ) == 0x0 03005 424 NtQueryInformationToken (364, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03006 424 NtClose (364, ... ) == 0x0 03007 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03008 424 NtOpenKey (0x2000000, {24, 362, 0x40, 0, 0, ""}, ... 364, ) == 0x0 03009 424 NtClose (362, ... ) == 0x0 03010 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 03011 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 03012 424 NtReleaseSemaphore (352, 1, ... 0, ) == 0x0 03013 424 NtWaitForSingleObject (352, 0, {0, 0}, ... ) == 0x0 03014 424 NtQueryKey (366, Name, 384, ... {Name= (366, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03015 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03016 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 03017 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03018 424 NtClose (360, ... ) == 0x0 03019 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03020 424 NtOpenKey (0x1, {24, 366, 0x40, 0, 0, (0x1, {24, 366, 0x40, 0, 0, "ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03021 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03022 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "SystemFileAssociations\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03023 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\SystemFileAssociations\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03024 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESs"}, 138, ) }, 138, ) == 0x0 03025 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03026 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 360, ) }, ... 360, ) == 0x0 03027 424 NtQueryKey (362, Name, 392, ... {Name= (362, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 03028 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03029 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03030 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03031 424 NtClose (368, ... ) == 0x0 03032 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03033 424 NtQueryValueKey (362, (362, "PerceivedType", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03034 424 NtClose (362, ... ) == 0x0 03035 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03036 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03037 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 03038 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03039 424 NtClose (360, ... ) == 0x0 03040 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03041 424 NtQueryValueKey (366, (366, "DocObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03042 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03043 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03044 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 03045 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03046 424 NtClose (360, ... ) == 0x0 03047 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03048 424 NtQueryValueKey (366, (366, "BrowseInPlace", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03049 424 NtQueryKey (366, Name, 384, ... {Name= (366, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03050 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03051 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 03052 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03053 424 NtClose (360, ... ) == 0x0 03054 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03055 424 NtOpenKey (0x1, {24, 366, 0x40, 0, 0, (0x1, {24, 366, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03056 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03057 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "*"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03058 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\*"}, ... 360, ) }, ... 360, ) == 0x0 03059 424 NtQueryKey (362, Name, 384, ... {Name= (362, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\*"}, 76, ) }, 76, ) == 0x0 03060 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03061 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03062 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03063 424 NtClose (368, ... ) == 0x0 03064 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\*\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03065 424 NtOpenKey (0x1, {24, 362, 0x40, 0, 0, (0x1, {24, 362, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03066 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03067 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03068 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03069 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03070 424 NtClose (368, ... ) == 0x0 03071 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03072 424 NtQueryValueKey (366, (366, "IsShortcut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03073 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03074 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03075 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03076 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03077 424 NtClose (368, ... ) == 0x0 03078 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03079 424 NtQueryValueKey (366, (366, "AlwaysShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03080 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03081 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03082 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03083 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03084 424 NtClose (368, ... ) == 0x0 03085 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03086 424 NtQueryValueKey (366, (366, "NeverShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03087 424 NtClose (350, ... ) == 0x0 03088 424 NtClose (366, ... ) == 0x0 03089 424 NtClose (362, ... ) == 0x0 03090 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03091 424 NtOpenKey (0x2000000, {24, 356, 0x40, 0, 0, (0x2000000, {24, 356, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03092 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03093 424 NtOpenKey (0x2000000, {24, 356, 0x40, 0, 0, (0x2000000, {24, 356, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03094 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03095 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03096 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 360, ) }, ... 360, ) == 0x0 03097 424 NtQueryKey (362, Name, 392, ... {Name= (362, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 03098 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03099 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 364, ) == 0x0 03100 424 NtQueryInformationToken (364, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03101 424 NtClose (364, ... ) == 0x0 03102 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03103 424 NtQueryValueKey (362, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (362, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="b\0a\0t\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 03104 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03105 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03106 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\batfile"}, ... 364, ) }, ... 364, ) == 0x0 03107 424 NtQueryKey (366, Name, 384, ... {Name= (366, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03108 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03109 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 03110 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03111 424 NtClose (348, ... ) == 0x0 03112 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03113 424 NtOpenKey (0x1, {24, 366, 0x40, 0, 0, (0x1, {24, 366, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03114 424 NtQueryKey (366, Name, 384, ... {Name= (366, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03115 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03116 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 03117 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03118 424 NtClose (348, ... ) == 0x0 03119 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03120 424 NtOpenKey (0x2000000, {24, 366, 0x40, 0, 0, ""}, ... 348, ) == 0x0 03121 424 NtClose (366, ... ) == 0x0 03122 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03123 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03124 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 364, ) == 0x0 03125 424 NtQueryInformationToken (364, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03126 424 NtClose (364, ... ) == 0x0 03127 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\ShellEx\{C46CA590-3C3F-11D2-BEE6-0000F805CA57}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03128 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "ShellEx\{C46CA590-3C3F-11D2-BEE6-0000F805CA57}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03129 424 NtQueryKey (362, Name, 384, ... {Name= (362, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.batC"}, 82, ) }, 82, ) == 0x0 03130 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03131 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 364, ) == 0x0 03132 424 NtQueryInformationToken (364, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03133 424 NtClose (364, ... ) == 0x0 03134 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\.bat\ShellEx\{C46CA590-3C3F-11D2-BEE6-0000F805CA57}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03135 424 NtOpenKey (0x1, {24, 362, 0x40, 0, 0, (0x1, {24, 362, 0x40, 0, 0, "ShellEx\{C46CA590-3C3F-11D2-BEE6-0000F805CA57}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03136 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03137 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "SystemFileAssociations\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03138 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\SystemFileAssociations\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03139 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSESs"}, 138, ) }, 138, ) == 0x0 03140 424 NtOpenKey (0x1, {24, 162, 0x40, 0, 0, (0x1, {24, 162, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03141 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 364, ) }, ... 364, ) == 0x0 03142 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 03143 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03144 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03145 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03146 424 NtClose (368, ... ) == 0x0 03147 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03148 424 NtQueryValueKey (366, (366, "PerceivedType", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03149 424 NtClose (366, ... ) == 0x0 03150 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03151 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "*"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03152 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\*"}, ... 364, ) }, ... 364, ) == 0x0 03153 424 NtQueryKey (366, Name, 384, ... {Name= (366, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\*"}, 76, ) }, 76, ) == 0x0 03154 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03155 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03156 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03157 424 NtClose (368, ... ) == 0x0 03158 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\*\ShellEx\{C46CA590-3C3F-11D2-BEE6-0000F805CA57}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03159 424 NtOpenKey (0x1, {24, 366, 0x40, 0, 0, (0x1, {24, 366, 0x40, 0, 0, "ShellEx\{C46CA590-3C3F-11D2-BEE6-0000F805CA57}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03160 424 NtClose (362, ... ) == 0x0 03161 424 NtClose (350, ... ) == 0x0 03162 424 NtClose (366, ... ) == 0x0 03163 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03164 424 NtOpenKey (0x2000000, {24, 356, 0x40, 0, 0, (0x2000000, {24, 356, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03165 424 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03166 424 NtOpenKey (0x2000000, {24, 356, 0x40, 0, 0, (0x2000000, {24, 356, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03167 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03168 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03169 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 364, ) }, ... 364, ) == 0x0 03170 424 NtQueryKey (366, Name, 392, ... {Name= (366, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 03171 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03172 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 03173 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03174 424 NtClose (348, ... ) == 0x0 03175 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03176 424 NtQueryValueKey (366, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (366, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="b\0a\0t\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 03177 424 NtQueryKey (162, Name, 384, ... {Name= (162, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_CLASSES9"}, 138, ) }, 138, ) == 0x0 03178 424 NtOpenKey (0x2000000, {24, 162, 0x40, 0, 0, (0x2000000, {24, 162, 0x40, 0, 0, "batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03179 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\batfile"}, ... 348, ) }, ... 348, ) == 0x0 03180 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03181 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03182 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 03183 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03184 424 NtClose (360, ... ) == 0x0 03185 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03186 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03187 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03188 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03189 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 360, ) == 0x0 03190 424 NtQueryInformationToken (360, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03191 424 NtClose (360, ... ) == 0x0 03192 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03193 424 NtOpenKey (0x2000000, {24, 350, 0x40, 0, 0, ""}, ... 360, ) == 0x0 03194 424 NtClose (350, ... ) == 0x0 03195 424 NtQueryKey (362, Name, 384, ... {Name= (362, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03196 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03197 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 03198 424 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03199 424 NtClose (348, ... ) == 0x0 03200 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03201 424 NtOpenKey (0x2000000, {24, 362, 0x40, 0, 0, (0x2000000, {24, 362, 0x40, 0, 0, "shell\open"}, ... 348, ) }, ... 348, ) == 0x0 03202 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open3"}, 110, ) }, 110, ) == 0x0 03203 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03204 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03205 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03206 424 NtClose (368, ... ) == 0x0 03207 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03208 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "command"}, ... 368, ) }, ... 368, ) == 0x0 03209 424 NtQueryKey (370, Name, 392, ... {Name= (370, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command8"}, 126, ) }, 126, ) == 0x0 03210 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03211 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 372, ) == 0x0 03212 424 NtQueryInformationToken (372, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03213 424 NtClose (372, ... ) == 0x0 03214 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03215 424 NtQueryValueKey (370, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=" (370, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=""\0%\01\0"\0 \0%\0*\0\0\0"}, 28, ) \0 \0%\0*\0\0\0"}, 28, ) == 0x0 03216 424 NtClose (370, ... ) == 0x0 03217 424 NtOpenKey (0x2000000, {24, 64, 0x40, 0, 0, (0x2000000, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03218 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\opent"}, 110, ) }, 110, ) == 0x0 03219 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03220 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03221 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03222 424 NtClose (368, ... ) == 0x0 03223 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03224 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "command"}, ... 368, ) }, ... 368, ) == 0x0 03225 424 NtQueryKey (370, Name, 392, ... {Name= (370, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command8"}, 126, ) }, 126, ) == 0x0 03226 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03227 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 372, ) == 0x0 03228 424 NtQueryInformationToken (372, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03229 424 NtClose (372, ... ) == 0x0 03230 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03231 424 NtQueryValueKey (370, (370, "command", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03232 424 NtClose (370, ... ) == 0x0 03233 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\xeqfhcg.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03234 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\opent"}, 110, ) }, 110, ) == 0x0 03235 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03236 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03237 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03238 424 NtClose (368, ... ) == 0x0 03239 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03240 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "command"}, ... 368, ) }, ... 368, ) == 0x0 03241 424 NtQueryKey (370, Name, 392, ... {Name= (370, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command8"}, 126, ) }, 126, ) == 0x0 03242 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03243 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 372, ) == 0x0 03244 424 NtQueryInformationToken (372, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03245 424 NtClose (372, ... ) == 0x0 03246 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03247 424 NtQueryValueKey (370, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=" (370, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=""\0%\01\0"\0 \0%\0*\0\0\0"}, 28, ) \0 \0%\0*\0\0\0"}, 28, ) == 0x0 03248 424 NtClose (370, ... ) == 0x0 03249 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open3"}, 110, ) }, 110, ) == 0x0 03250 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03251 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03252 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03253 424 NtClose (368, ... ) == 0x0 03254 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\ddeexec"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03255 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "ddeexec"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03256 424 NtUserGetForegroundWindow (... ) == 0x20062 03257 424 NtQueryKey (350, Name, 384, ... {Name= (350, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open3"}, 110, ) }, 110, ) == 0x0 03258 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03259 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 368, ) == 0x0 03260 424 NtQueryInformationToken (368, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03261 424 NtClose (368, ... ) == 0x0 03262 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03263 424 NtOpenKey (0x1, {24, 350, 0x40, 0, 0, (0x1, {24, 350, 0x40, 0, 0, "command"}, ... 368, ) }, ... 368, ) == 0x0 03264 424 NtQueryKey (370, Name, 392, ... {Name= (370, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command8"}, 126, ) }, 126, ) == 0x0 03265 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03266 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 372, ) == 0x0 03267 424 NtQueryInformationToken (372, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03268 424 NtClose (372, ... ) == 0x0 03269 424 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03270 424 NtQueryValueKey (370, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=" (370, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=""\0%\01\0"\0 \0%\0*\0\0\0"}, 28, ) \0 \0%\0*\0\0\0"}, 28, ) == 0x0 03271 424 NtClose (370, ... ) == 0x0 03272 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 03273 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 03274 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03275 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 368, ) }, ... 368, ) == 0x0 03276 424 NtQueryValueKey (368, (368, "RestrictRun", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03277 424 NtClose (368, ... ) == 0x0 03278 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 03279 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 03280 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03281 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 368, ) }, ... 368, ) == 0x0 03282 424 NtQueryValueKey (368, (368, "DisallowRun", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03283 424 NtClose (368, ... ) == 0x0 03284 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Control\Session Manager\AppCompatibility\xeqfhcg.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03285 424 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Control\Session Manager\CheckBadApps"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03286 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\xeqfhcg.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03287 424 NtReleaseSemaphore (152, 1, ... 0, ) == 0x0 03288 424 NtWaitForSingleObject (152, 0, {0, 0}, ... ) == 0x0 03289 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03290 424 NtOpenKey (0x1, {24, 64, 0x40, 0, 0, (0x1, {24, 64, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 368, ) }, ... 368, ) == 0x0 03291 424 NtQueryValueKey (368, (368, "NoRunasInstallPrompt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03292 424 NtClose (368, ... ) == 0x0 03293 424 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\xeqfhcg.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03294 424 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 03295 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 1228780, ... ) }, 1228780, ... ) == 0x0 03296 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 1229472, ... ) }, 1229472, ... ) == 0x0 03297 424 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 5, 96, ... 368, {status=0x0, info=1}, ) }, 5, 96, ... 368, {status=0x0, info=1}, ) == 0x0 03298 424 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 368, ... ) == STATUS_INVALID_IMAGE_NOT_MZ 03299 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 372, ) }, ... 372, ) == 0x0 03300 424 NtQueryValueKey (372, (372, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03301 424 NtClose (372, ... ) == 0x0 03302 424 NtQueryVolumeInformationFile (368, 1228780, 8, Device, ... {status=0x0, info=8}, ) == 0x0 03303 424 NtWaitForSingleObject (164, 0, {-1000000, -1}, ... ) == 0x0 03304 424 NtReleaseMutant (164, ... 0x0, ) == 0x0 03305 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1226764, ... ) }, 1226764, ... ) == 0x0 03306 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 372, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 372, {status=0x0, info=1}, ) == 0x0 03307 424 NtQueryInformationFile (372, 1227368, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03308 424 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 372, ... 376, ) == 0x0 03309 424 NtMapViewOfSection (376, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x1070000), 0x0, 1028096, ) == 0x0 03310 424 NtQueryInformationFile (372, 1227464, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03311 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03312 424 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 03313 424 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 03314 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 380, {status=0x0, info=1}, ) }, 3, 16417, ... 380, {status=0x0, info=1}, ) == 0x0 03315 424 NtQueryDirectoryFile (380, 0, 0, 0, 1225028, 616, BothDirectory, 1, (380, 0, 0, 0, 1225028, 616, BothDirectory, 1, "xeqfhcg.bat", 0, ... {status=0x0, info=116}, ) , 0, ... {status=0x0, info=116}, ) == 0x0 03316 424 NtClose (380, ... ) == 0x0 03317 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03318 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03319 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 1224416, ... ) }, 1224416, ... ) == 0x0 03320 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\"}, 3, 16417, ... 380, {status=0x0, info=1}, ) }, 3, 16417, ... 380, {status=0x0, info=1}, ) == 0x0 03321 424 NtQueryDirectoryFile (380, 0, 0, 0, 1223776, 616, BothDirectory, 1, (380, 0, 0, 0, 1223776, 616, BothDirectory, 1, "work", 0, ... {status=0x0, info=104}, ) , 0, ... {status=0x0, info=104}, ) == 0x0 03322 424 NtClose (380, ... ) == 0x0 03323 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 380, {status=0x0, info=1}, ) }, 3, 16417, ... 380, {status=0x0, info=1}, ) == 0x0 03324 424 NtQueryDirectoryFile (380, 0, 0, 0, 1223776, 616, BothDirectory, 1, (380, 0, 0, 0, 1223776, 616, BothDirectory, 1, "xeqfhcg.bat", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 03325 424 NtClose (380, ... ) == 0x0 03326 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03327 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03328 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03329 424 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\u:"}, 3, 96, ... 380, {status=0x0, info=1}, ) }, 3, 96, ... 380, {status=0x0, info=1}, ) == 0x0 03330 424 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\u:"}, ... 384, ) }, ... 384, ) == 0x0 03331 424 NtQuerySymbolicLinkObject (384, ... (384, ... "\Device\WinDfs\U:00000000000092fa", 66, ) , 66, ) == 0x0 03332 424 NtClose (384, ... ) == 0x0 03333 424 NtQueryVolumeInformationFile (380, 1225168, 8, Device, ... {status=0x0, info=8}, ) == 0x0 03334 424 NtClose (380, ... ) == 0x0 03335 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03336 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 380, ) == 0x0 03337 424 NtQueryInformationToken (380, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03338 424 NtClose (380, ... ) == 0x0 03339 424 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03340 424 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\xeqfhcg.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03341 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03342 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03343 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\xeqfhcg.bat"}, 1226696, ... ) }, 1226696, ... ) == 0x0 03344 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\"}, 3, 16417, ... 380, {status=0x0, info=1}, ) }, 3, 16417, ... 380, {status=0x0, info=1}, ) == 0x0 03345 424 NtQueryDirectoryFile (380, 0, 0, 0, 1226056, 616, BothDirectory, 1, (380, 0, 0, 0, 1226056, 616, BothDirectory, 1, "work", 0, ... {status=0x0, info=104}, ) , 0, ... {status=0x0, info=104}, ) == 0x0 03346 424 NtClose (380, ... ) == 0x0 03347 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 380, {status=0x0, info=1}, ) }, 3, 16417, ... 380, {status=0x0, info=1}, ) == 0x0 03348 424 NtQueryDirectoryFile (380, 0, 0, 0, 1226056, 616, BothDirectory, 1, (380, 0, 0, 0, 1226056, 616, BothDirectory, 1, "xeqfhcg.bat", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 03349 424 NtClose (380, ... ) == 0x0 03350 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03351 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03352 424 NtWaitForSingleObject (164, 0, {-1000000, -1}, ... ) == 0x0 03353 424 NtQueryVolumeInformationFile (368, 1227340, 8, Device, ... {status=0x0, info=8}, ) == 0x0 03354 424 NtQueryInformationFile (368, 1227320, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 03355 424 NtQueryInformationFile (368, 1227360, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03356 424 NtReleaseMutant (164, ... 0x0, ) == 0x0 03357 424 NtUnmapViewOfSection (-1, 0x1070000, ... ) == 0x0 03358 424 NtClose (376, ... ) == 0x0 03359 424 NtClose (372, ... ) == 0x0 03360 424 NtClose (368, ... ) == 0x0 03361 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\cmd.exe"}, 1228756, ... ) }, 1228756, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03362 424 NtQueryAttributesFile ({24, 108, 0x40, 0, 0, ({24, 108, 0x40, 0, 0, "cmd.exe"}, 1228756, ... ) }, 1228756, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03363 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\cmd.exe"}, 1228756, ... ) }, 1228756, ... ) == 0x0 03364 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\cmd.exe"}, 1229472, ... ) }, 1229472, ... ) == 0x0 03365 424 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\cmd.exe"}, 5, 96, ... 368, {status=0x0, info=1}, ) }, 5, 96, ... 368, {status=0x0, info=1}, ) == 0x0 03366 424 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 368, ... 372, ) == 0x0 03367 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03368 424 NtQuerySection (372, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03369 424 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03370 424 NtCreateProcessEx (1231408, 2035711, 0, -1, 0, 372, 0, 0, 0, ... ) == 0x0 03371 424 NtSetInformationProcess (376, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03372 424 NtQueryInformationProcess (376, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=596,ParentPid=420,}, 0x0, ) == 0x0 03373 424 NtReadVirtualMemory (376, 0x7ffdf008, 4, ... (376, 0x7ffdf008, 4, ... "\0\0\320J", 0x0, ) , 0x0, ) == 0x0 03374 424 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\cmd.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03375 424 NtReadVirtualMemory (376, 0x4ad00000, 4096, ... (376, 0x4ad00000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0\13+S\231OJ=\312OJ=\312OJ=\312\265i}\312IJ=\312OJ<\312\235J=\312\265i$\312HJ=\312\224h \312MJ=\312\330ix\312NJ=\312\225i!\312\177J=\312\265i\0\312NJ=\312RichOJ=\312\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0&\343};\0\0\0\0\0\0\0\0\340\0\17\1\13\1\7\0\0\310\1\0\0\364\3\0\0\0\0\0\226\245\0\0\0\20\0\0\0\300\1\0\0\0\320J\0\20\0\0\0\2\0\0\5\0\1\0\5\0\1\0\4\0\0\0\0\0\0\0\0\340\5\0\0\4\0\0\374\313\5\0\3\0\0\200\0\0\20\0\0\0\20\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\300\310\1\0P\0\0\0\0\260\3\0\230(\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\200\327\1\08\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0P\2\0\0X\0\0\0\0\20\0\0\344\2\0\0d\305\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\270\307\1\0\0\20\0\0\0\310\1\0\0\4\0\0\0\0\0\0", 4096, ) , 4096, ) == 0x0 03376 424 NtReadVirtualMemory (376, 0x4ad3b000, 256, ... (376, 0x4ad3b000, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\3\0\0\00\0\0\200\13\0\0\0\200\0\0\200\16\0\0\0\230\0\0\200\20\0\0\0\260\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\1\0\0\0\310\0\0\200\2\0\0\0\340\0\0\200\3\0\0\0\370\0\0\200\4\0\0\0\20\1\0\200\5\0\0\0(\1\0\200\6\0\0\0@\1\0\200\7\0\0\0X\1\0\200\10\0\0\0p\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\1\0\0\0\210\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\200\2\0\200\240\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\1\0\0\0\270\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\320\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\340\1\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 03377 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03378 424 NtQueryInformationProcess (376, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=596,ParentPid=420,}, 0x0, ) == 0x0 03379 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work"}, 1229472, ... ) }, 1229472, ... ) == 0x0 03380 424 NtAllocateVirtualMemory (-1, 0, 0, 1644, 4096, 4, ... 17235968, 4096, ) == 0x0 03381 424 NtAllocateVirtualMemory (376, 0, 0, 1910, 4096, 4, ... 65536, 4096, ) == 0x0 03382 424 NtWriteVirtualMemory (376, 0x10000, (376, 0x10000, "=\0:\0:\0=\0:\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0p\0o\0l\0y\0u\0n\0p\0a\0c\0k\0\0\0=\0E\0x\0i\0t\0C\0o\0d\0e\0=\00\00\00\00\00\00\00\02\0\0\0=\0U\0:\0=\0U\0:\0\\0s\0t\0a\0r\0t\0u\0p\0s\0c\0r\0i\0p\0t\0s\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0C\0L\0I\0E\0N\0T\0N\0A\0M\0E\0=\0C\0o\0n\0s\0o\0l\0e\0\0\0C\0o\0m\0m\0o\0n\0P\0r\0o\0g\0r\0a\0m\0F\0i\0l\0e\0s\0=\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0C\0O\0M\0", 1910, ... 0x0, ) , 1910, ... 0x0, ) == 0x0 03383 424 NtAllocateVirtualMemory (376, 0, 0, 1644, 4096, 4, ... 131072, 4096, ) == 0x0 03384 424 NtWriteVirtualMemory (376, 0x20000, (376, 0x20000, "\0\20\0\0l\6\0\0\0\0\0\0\0\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\16\0\10\2\220\2\0\0\0\0\0\0\374\0\376\0\230\4\0\06\08\0\230\5\0\0>\0@\0\320\5\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\06\08\0\20\6\0\0\36\0 \0H\6\0\0\0\0\2\0h\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1644, ... 0x0, ) , 1644, ... 0x0, ) == 0x0 03385 424 NtWriteVirtualMemory (376, 0x7ffdf010, (376, 0x7ffdf010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 03386 424 NtWriteVirtualMemory (376, 0x7ffdf1e8, (376, 0x7ffdf1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 03387 424 NtFreeVirtualMemory (-1, (0x1070000), 0, 32768, ... (0x1070000), 4096, ) == 0x0 03388 424 NtAllocateVirtualMemory (376, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 03389 424 NtAllocateVirtualMemory (376, 196608, 0, 1048576, 4096, 4, ... 196608, 1048576, ) == 0x0 03390 424 NtCreateThread (0x1f03ff, 0x0, 376, 1229672, 1230392, 1, ... 380, {596, 636}, ) == 0x0 03391 424 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 0, 1231504, 0, 0} (24, {168, 196, new_msg, 0, 0, 1231504, 0, 0} "\0\0\0\0\0\0\1\0\24\0\0\0\1\0\0\0x\1\0\0|\1\0\0T\2\0\0|\2\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\0\0\0\0\34\315\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ... {168, 196, reply, 0, 420, 424, 1521, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\1\0\0\0x\1\0\0|\1\0\0T\2\0\0|\2\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\0\0\0\0\34\315\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {168, 196, reply, 0, 420, 424, 1521, 0} (24, {168, 196, new_msg, 0, 0, 1231504, 0, 0} "\0\0\0\0\0\0\1\0\24\0\0\0\1\0\0\0x\1\0\0|\1\0\0T\2\0\0|\2\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\0\0\0\0\34\315\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ... {168, 196, reply, 0, 420, 424, 1521, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\1\0\0\0x\1\0\0|\1\0\0T\2\0\0|\2\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\0\0\0\0\34\315\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 03392 424 NtResumeThread (380, ... 1, ) == 0x0 03393 424 NtClose (368, ... ) == 0x0 03394 424 NtClose (372, ... ) == 0x0 03395 424 NtClose (350, ... ) == 0x0 03396 424 NtClose (366, ... ) == 0x0 03397 424 NtClose (362, ... ) == 0x0 03398 424 NtClose (376, ... ) == 0x0 03399 424 NtClose (380, ... ) == 0x0 03400 424 NtGdiDeleteObjectApp (201851674, ... ) == 0x1 03401 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03402 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03403 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03404 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03405 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03406 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03407 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03408 424 NtUserGetClassInfo (1989935104, 1233712, 1233664, 1233740, 0, ... ) == 0x0 03409 424 NtUnmapViewOfSection (-1, 0xab0000, ... ) == 0x0 03410 424 NtClose (280, ... ) == 0x0 03411 424 NtUnmapViewOfSection (-1, 0x769c0000, ... ) == 0x0 03412 424 NtUserDestroyWindow (131250, ... 03413 424 NtUserRemoveProp (131250, 43288, ... ) == 0xffffffff 03414 424 NtUserRemoveProp (131250, 43282, ... ) == 0x0 03415 424 NtUserRemoveProp (131250, 43287, ... ) == 0x0 03412 424 NtUserDestroyWindow ... ) == 0x1 03416 424 NtUserUnregisterClass (1234852, 1998258176, 1234840, ... ) == 0x1 03417 424 NtFreeVirtualMemory (-1, (0x152000), 12288, 16384, ... (0x152000), 12288, ) == 0x0 03418 424 NtClose (184, ... ) == 0x0 03419 424 NtClose (176, ... ) == 0x0 03420 424 NtClose (180, ... ) == 0x0 03421 424 NtClose (156, ... ) == 0x0 03422 424 NtClose (172, ... ) == 0x0 03423 424 NtClose (204, ... ) == 0x0 03424 424 NtClose (208, ... ) == 0x0 03425 424 NtClose (200, ... ) == 0x0 03426 424 NtClose (192, ... ) == 0x0 03427 424 NtClose (196, ... ) == 0x0 03428 424 NtClose (220, ... ) == 0x0 03429 424 NtClose (224, ... ) == 0x0 03430 424 NtClose (212, ... ) == 0x0 03431 424 NtClose (216, ... ) == 0x0 03432 424 NtClose (244, ... ) == 0x0 03433 424 NtClose (236, ... ) == 0x0 03434 424 NtClose (240, ... ) == 0x0 03435 424 NtClose (228, ... ) == 0x0 03436 424 NtClose (232, ... ) == 0x0 03437 424 NtClose (248, ... ) == 0x0 03438 424 NtClose (252, ... ) == 0x0 03439 424 NtClose (264, ... ) == 0x0 03440 424 NtClose (268, ... ) == 0x0 03441 424 NtClose (256, ... ) == 0x0 03442 424 NtClose (260, ... ) == 0x0 03443 424 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 03444 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 1235728, ... ) }, 1235728, ... ) == 0x0 03445 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 1236420, ... ) }, 1236420, ... ) == 0x0 03446 424 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 5, 96, ... 260, {status=0x0, info=1}, ) }, 5, 96, ... 260, {status=0x0, info=1}, ) == 0x0 03447 424 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 260, ... 256, ) == 0x0 03448 424 NtQueryVolumeInformationFile (260, 1235728, 8, Device, ... {status=0x0, info=8}, ) == 0x0 03449 424 NtWaitForSingleObject (164, 0, {-1000000, -1}, ... ) == 0x0 03450 424 NtReleaseMutant (164, ... 0x0, ) == 0x0 03451 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 268, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 268, {status=0x0, info=1}, ) == 0x0 03452 424 NtQueryInformationFile (268, 1234316, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03453 424 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 268, ... 264, ) == 0x0 03454 424 NtMapViewOfSection (264, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x1070000), 0x0, 1028096, ) == 0x0 03455 424 NtQueryInformationFile (268, 1234412, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03456 424 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03457 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03458 424 NtQueryDirectoryFile (252, 0, 0, 0, 1231976, 616, BothDirectory, 1, (252, 0, 0, 0, 1231976, 616, BothDirectory, 1, "spoolsvc.exe", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 03459 424 NtClose (252, ... ) == 0x0 03460 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03461 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03462 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 1231364, ... ) }, 1231364, ... ) == 0x0 03463 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03464 424 NtQueryDirectoryFile (252, 0, 0, 0, 1230724, 616, BothDirectory, 1, (252, 0, 0, 0, 1230724, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 03465 424 NtClose (252, ... ) == 0x0 03466 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03467 424 NtQueryDirectoryFile (252, 0, 0, 0, 1230724, 616, BothDirectory, 1, (252, 0, 0, 0, 1230724, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 03468 424 NtClose (252, ... ) == 0x0 03469 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03470 424 NtQueryDirectoryFile (252, 0, 0, 0, 1230724, 616, BothDirectory, 1, (252, 0, 0, 0, 1230724, 616, BothDirectory, 1, "spoolsvc.exe", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 03471 424 NtClose (252, ... ) == 0x0 03472 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03473 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03474 424 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03475 424 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03476 424 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 252, ) == 0x0 03477 424 NtQueryInformationToken (252, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03478 424 NtClose (252, ... ) == 0x0 03479 424 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03480 424 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\spoolsvc.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03481 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03482 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03483 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 1233644, ... ) }, 1233644, ... ) == 0x0 03484 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03485 424 NtQueryDirectoryFile (252, 0, 0, 0, 1233004, 616, BothDirectory, 1, (252, 0, 0, 0, 1233004, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 03486 424 NtClose (252, ... ) == 0x0 03487 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03488 424 NtQueryDirectoryFile (252, 0, 0, 0, 1233004, 616, BothDirectory, 1, (252, 0, 0, 0, 1233004, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 03489 424 NtClose (252, ... ) == 0x0 03490 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 252, {status=0x0, info=1}, ) }, 3, 16417, ... 252, {status=0x0, info=1}, ) == 0x0 03491 424 NtQueryDirectoryFile (252, 0, 0, 0, 1233004, 616, BothDirectory, 1, (252, 0, 0, 0, 1233004, 616, BothDirectory, 1, "spoolsvc.exe", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 03492 424 NtClose (252, ... ) == 0x0 03493 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03494 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03495 424 NtWaitForSingleObject (164, 0, {-1000000, -1}, ... ) == 0x0 03496 424 NtQueryVolumeInformationFile (260, 1234288, 8, Device, ... {status=0x0, info=8}, ) == 0x0 03497 424 NtQueryInformationFile (260, 1234268, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 03498 424 NtQueryInformationFile (260, 1234308, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03499 424 NtReleaseMutant (164, ... 0x0, ) == 0x0 03500 424 NtUnmapViewOfSection (-1, 0x1070000, ... ) == 0x0 03501 424 NtClose (264, ... ) == 0x0 03502 424 NtClose (268, ... ) == 0x0 03503 424 NtQuerySection (256, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03504 424 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsvc.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03505 424 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 03506 424 NtOpenProcessToken (-1, 0xa, ... 268, ) == 0x0 03507 424 NtQueryInformationToken (268, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 03508 424 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03509 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 264, ) }, ... 264, ) == 0x0 03510 424 NtQueryValueKey (264, (264, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (264, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03511 424 NtQueryValueKey (264, (264, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (264, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 03512 424 NtClose (264, ... ) == 0x0 03513 424 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 264, ) }, ... 264, ) == 0x0 03514 424 NtQueryValueKey (264, (264, "ExecutableTypes", Partial, 0, ... ) , Partial, 0, ... ) == STATUS_BUFFER_TOO_SMALL 03515 424 NtQueryValueKey (264, (264, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) , Partial, 260, ... TitleIdx=0, Type=7, Data= (264, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) }, 260, ) == 0x0 03516 424 NtClose (264, ... ) == 0x0 03517 424 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 264, ) }, ... 264, ) == 0x0 03518 424 NtQuerySymbolicLinkObject (264, ... (264, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 03519 424 NtClose (264, ... ) == 0x0 03520 424 NtQueryInformationFile (260, 1234080, 528, Name, ... {status=0x0, info=64}, ) == 0x0 03521 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03522 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03523 424 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe"}, 1232760, ... ) }, 1232760, ... ) == 0x0 03524 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 03525 424 NtQueryDirectoryFile (264, 0, 0, 0, 1232120, 616, BothDirectory, 1, (264, 0, 0, 0, 1232120, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 03526 424 NtClose (264, ... ) == 0x0 03527 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 03528 424 NtQueryDirectoryFile (264, 0, 0, 0, 1232120, 616, BothDirectory, 1, (264, 0, 0, 0, 1232120, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 03529 424 NtClose (264, ... ) == 0x0 03530 424 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 03531 424 NtQueryDirectoryFile (264, 0, 0, 0, 1232120, 616, BothDirectory, 1, (264, 0, 0, 0, 1232120, 616, BothDirectory, 1, "spoolsvc.exe", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 03532 424 NtClose (264, ... ) == 0x0 03533 424 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03534 424 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03535 424 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 264, ) }, ... 264, ) == 0x0 03536 424 NtQueryValueKey (264, (264, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03537 424 NtClose (264, ... ) == 0x0 03538 424 NtQueryInformationToken (268, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 03539 424 NtQueryInformationToken (268, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 03540 424 NtClose (268, ... ) == 0x0 03541 424 NtCreateProcessEx (1238356, 2035711, 0, -1, 4, 256, 0, 0, 0, ... ) == 0x0 03542 424 NtSetInformationProcess (268, PriorityClass, {process info, class 18, size 2}, 83886592, ... ) == 0x0 03543 424 NtQueryInformationProcess (268, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=732,ParentPid=420,}, 0x0, ) == 0x0 03544 424 NtReadVirtualMemory (268, 0x7ffdf008, 4, ... (268, 0x7ffdf008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 03545 424 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\spoolsvc.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03546 424 NtReadVirtualMemory (268, 0x400000, 4096, ... (268, 0x400000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0V\323\325s\22\262\273 \22\262\273 \22\262\273 L\220\260 \20\262\273 i\256\267 \21\262\273 \221\272\346 \36\262\273 \221\256\265 \25\262\273 }\255\277 \21\262\273 }\255\260 \23\262\273 \22\262\272 \266\262\273 $\224\260 /\262\273 Rich\22\262\273 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0\340\253\231D\0\0\0\0\0\0\0\0\340\0\17\1\13\1\6\0\0\260\0\0\0\20\0\0\0\360\0\0\36\256\1\0\0\0\1\0\0\260\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\300\1\0\0\20\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\260\1\0\220\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0", 4096, ) , 4096, ) == 0x0 03547 424 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03548 424 NtQueryInformationProcess (268, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=732,ParentPid=420,}, 0x0, ) == 0x0 03549 424 NtAllocateVirtualMemory (-1, 0, 0, 1672, 4096, 4, ... 11206656, 4096, ) == 0x0 03550 424 NtAllocateVirtualMemory (268, 0, 0, 1910, 4096, 4, ... 65536, 4096, ) == 0x0 03551 424 NtWriteVirtualMemory (268, 0x10000, (268, 0x10000, "=\0:\0:\0=\0:\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0p\0o\0l\0y\0u\0n\0p\0a\0c\0k\0\0\0=\0E\0x\0i\0t\0C\0o\0d\0e\0=\00\00\00\00\00\00\00\02\0\0\0=\0U\0:\0=\0U\0:\0\\0s\0t\0a\0r\0t\0u\0p\0s\0c\0r\0i\0p\0t\0s\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0C\0L\0I\0E\0N\0T\0N\0A\0M\0E\0=\0C\0o\0n\0s\0o\0l\0e\0\0\0C\0o\0m\0m\0o\0n\0P\0r\0o\0g\0r\0a\0m\0F\0i\0l\0e\0s\0=\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0C\0O\0M\0", 1910, ... 0x0, ) , 1910, ... 0x0, ) == 0x0 03552 424 NtAllocateVirtualMemory (268, 0, 0, 1672, 4096, 4, ... 131072, 4096, ) == 0x0 03553 424 NtWriteVirtualMemory (268, 0x20000, (268, 0x20000, "\0\20\0\0\210\6\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\0\10\2\220\2\0\0o\0\0\0\374\0\376\0\230\4\0\0@\0B\0\230\5\0\0@\0B\0\334\5\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0@\0B\0 \6\0\0\36\0 \0d\6\0\0\0\0\2\0\204\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1672, ... 0x0, ) , 1672, ... 0x0, ) == 0x0 03554 424 NtWriteVirtualMemory (268, 0x7ffdf010, (268, 0x7ffdf010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 03555 424 NtWriteVirtualMemory (268, 0x7ffdf1e8, (268, 0x7ffdf1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 03556 424 NtFreeVirtualMemory (-1, (0xab0000), 0, 32768, ... (0xab0000), 4096, ) == 0x0 03557 424 NtAllocateVirtualMemory (268, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 03558 424 NtAllocateVirtualMemory (268, 1236992, 0, 8192, 4096, 4, ... 1236992, 8192, ) == 0x0 03559 424 NtProtectVirtualMemory (268, (0x12e000), 4096, 260, ... (0x12e000), 4096, 4, ) == 0x0 03560 424 NtCreateThread (0x1f03ff, 0x0, 268, 1236620, 1237340, 1, ... 264, {732, 744}, ) == 0x0 03561 424 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 1312872, 1310720, 1502552, 1238440} (24, {168, 196, new_msg, 0, 1312872, 1310720, 1502552, 1238440} "\0\0\0\0\0\0\1\0\2$\370w U\367w\17\1\0\0\10\1\0\0\334\2\0\0\350\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\\0w\0o\0r\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ... {168, 196, reply, 0, 420, 424, 1545, 0} "\0\0\0\0\0\0\1\0\0\0\0\0 U\367w\14\1\0\0\10\1\0\0\334\2\0\0\350\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\\0w\0o\0r\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {168, 196, reply, 0, 420, 424, 1545, 0} (24, {168, 196, new_msg, 0, 1312872, 1310720, 1502552, 1238440} "\0\0\0\0\0\0\1\0\2$\370w U\367w\17\1\0\0\10\1\0\0\334\2\0\0\350\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\\0w\0o\0r\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ... {168, 196, reply, 0, 420, 424, 1545, 0} "\0\0\0\0\0\0\1\0\0\0\0\0 U\367w\14\1\0\0\10\1\0\0\334\2\0\0\350\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\\0w\0o\0r\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 03562 424 NtResumeThread (264, ... 1, ) == 0x0 03563 424 NtClose (260, ... ) == 0x0 03564 424 NtClose (256, ... ) == 0x0 03565 424 NtTerminateProcess (0, 0, ... 02078 576 NtWaitForMultipleObjects ... ) == 0xc0 03565 424 NtTerminateProcess ... ) == 0x0 03566 424 NtRaiseException (1238104, 1237364, 1, ... 03567 424 NtContinue (1236160, 0, ... 03568 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 03569 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03570 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 03571 424 NtRaiseException (1228080, 1227340, 1, ... 03572 424 NtContinue (1226136, 0, ... 03573 424 NtWaitForSingleObject (316, 0, 0x0, ... ) == 0x0 03574 424 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03575 424 NtReleaseMutant (316, ... 0x0, ) == 0x0 03576 424 NtUnmapViewOfSection (-1, 0x1060000, ... ) == 0x0 03577 424 NtClose (344, ... ) == 0x0 03578 424 NtClose (340, ... ) == 0x0 03579 424 NtClose (328, ... ) == 0x0 03580 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x12,}, 4, ... ) == 0x0 03581 424 NtFreeVirtualMemory (-1, (0xfd0000), 0, 32768, ... (0xfd0000), 65536, ) == 0x0 03582 424 NtClose (320, ... ) == 0x0 03583 424 NtClose (324, ... ) == 0x0 03584 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x11,}, 4, ... ) == 0x0 03585 424 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\RDPNP\NetworkProvider"}, ... 324, ) }, ... 324, ) == 0x0 03586 424 NtQueryValueKey (324, (324, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (324, "Name", Partial, 144, ... TitleIdx=0, Type=1, Data="M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0T\0e\0r\0m\0i\0n\0a\0l\0 \0S\0e\0r\0v\0i\0c\0e\0s\0\0\0"}, 68, ) }, 68, ) == 0x0 03587 424 NtClose (324, ... ) == 0x0 03588 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xd,}, 4, ... ) == 0x0 03589 424 NtFreeVirtualMemory (-1, (0xaa0000), 0, 32768, ... (0xaa0000), 65536, ) == 0x0 03590 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xc,}, 4, ... ) == 0x0 03591 424 NtFreeVirtualMemory (-1, (0x960000), 0, 32768, ... (0x960000), 262144, ) == 0x0 03592 424 NtUnmapViewOfSection (-1, 0x3e0000, ... ) == 0x0 03593 424 NtClose (272, ... ) == 0x0 03594 424 NtFreeVirtualMemory (-1, (0x3f0000), 4096, 16384, ... (0x3f0000), 4096, ) == 0x0 03595 424 NtFreeVirtualMemory (-1, (0x3f0000), 0, 32768, ... (0x3f0000), 65536, ) == 0x0 03596 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xb,}, 4, ... ) == 0x0 03597 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 03598 424 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 03599 424 NtClose (104, ... ) == 0x0 03600 424 NtGdiDeleteObjectApp (118489986, ... ) == 0x1 03601 424 NtUserGetProcessWindowStation (... ) == 0x28 03602 424 NtUserBuildNameList (40, 256, 1329776, 1238744, ... ) == 0x0 03603 424 NtUserGetProcessWindowStation (... ) == 0x28 03604 424 NtUserOpenDesktop ({24, 40, 0x40, 0, 0, ({24, 40, 0x40, 0, 0, "Default"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x68 03605 424 NtUserBuildHwndList (104, 0, 0, 0, 64, ... (0x60036, 0x20060, 0x20064, 0x2005e, 0x100a0, 0x1007e, 0x10074, 0x10068, 0x3004a, 0x10066, 0x3004c, 0x3003c, 0x10098, 0x1008c, 0x1007c, 0x10026, 0x100c6, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b6, 0x100b4, 0x100b0, 0x100ae, 0x20062, 0x100ac, 0x100a2, 0x1006c, 0x50050, 0x40054, 0x5004e, 0x10082, 0x10076, 0x1, ), 35, ) == 0x0 03606 424 NtUserQueryWindow (393270, 0, ... ) == 0x7d4 03607 424 NtUserQueryWindow (393270, 1, ... ) == 0x7d8 03608 424 NtUserQueryWindow (131168, 0, ... ) == 0x7d4 03609 424 NtUserQueryWindow (131168, 1, ... ) == 0x7d8 03610 424 NtUserQueryWindow (131172, 0, ... ) == 0x7d4 03611 424 NtUserQueryWindow (131172, 1, ... ) == 0x7d8 03612 424 NtUserQueryWindow (131166, 0, ... ) == 0x7d4 03613 424 NtUserQueryWindow (131166, 1, ... ) == 0x7d8 03614 424 NtUserQueryWindow (65696, 0, ... ) == 0x774 03615 424 NtUserQueryWindow (65696, 1, ... ) == 0x780 03616 424 NtUserQueryWindow (65662, 0, ... ) == 0x774 03617 424 NtUserQueryWindow (65662, 1, ... ) == 0x780 03618 424 NtUserBuildHwndList (0, 65662, 1, 0, 64, ... (0x10080, 0x10086, 0x10088, 0x1008a, 0x1008e, 0x10090, 0x10092, 0x10094, 0x10096, 0x1009a, 0x1009c, 0x1009e, 0x1, ), 13, ) == 0x0 03619 424 NtUserQueryWindow (65664, 0, ... ) == 0x774 03620 424 NtUserQueryWindow (65664, 1, ... ) == 0x780 03621 424 NtUserQueryWindow (65670, 0, ... ) == 0x774 03622 424 NtUserQueryWindow (65670, 1, ... ) == 0x780 03623 424 NtUserQueryWindow (65672, 0, ... ) == 0x774 03624 424 NtUserQueryWindow (65672, 1, ... ) == 0x780 03625 424 NtUserQueryWindow (65674, 0, ... ) == 0x774 03626 424 NtUserQueryWindow (65674, 1, ... ) == 0x780 03627 424 NtUserQueryWindow (65678, 0, ... ) == 0x774 03628 424 NtUserQueryWindow (65678, 1, ... ) == 0x780 03629 424 NtUserQueryWindow (65680, 0, ... ) == 0x774 03630 424 NtUserQueryWindow (65680, 1, ... ) == 0x780 03631 424 NtUserQueryWindow (65682, 0, ... ) == 0x774 03632 424 NtUserQueryWindow (65682, 1, ... ) == 0x780 03633 424 NtUserQueryWindow (65684, 0, ... ) == 0x774 03634 424 NtUserQueryWindow (65684, 1, ... ) == 0x780 03635 424 NtUserQueryWindow (65686, 0, ... ) == 0x774 03636 424 NtUserQueryWindow (65686, 1, ... ) == 0x780 03637 424 NtUserQueryWindow (65690, 0, ... ) == 0x774 03638 424 NtUserQueryWindow (65690, 1, ... ) == 0x780 03639 424 NtUserQueryWindow (65692, 0, ... ) == 0x774 03640 424 NtUserQueryWindow (65692, 1, ... ) == 0x780 03641 424 NtUserQueryWindow (65694, 0, ... ) == 0x774 03642 424 NtUserQueryWindow (65694, 1, ... ) == 0x780 03643 424 NtUserQueryWindow (65652, 0, ... ) == 0x774 03644 424 NtUserQueryWindow (65652, 1, ... ) == 0x780 03645 424 NtUserQueryWindow (65640, 0, ... ) == 0x774 03646 424 NtUserQueryWindow (65640, 1, ... ) == 0x780 03647 424 NtUserQueryWindow (196682, 0, ... ) == 0x774 03648 424 NtUserQueryWindow (196682, 1, ... ) == 0x780 03649 424 NtUserQueryWindow (65638, 0, ... ) == 0x774 03650 424 NtUserQueryWindow (65638, 1, ... ) == 0x780 03651 424 NtUserQueryWindow (196684, 0, ... ) == 0x774 03652 424 NtUserQueryWindow (196684, 1, ... ) == 0x780 03653 424 NtUserQueryWindow (196668, 0, ... ) == 0x774 03654 424 NtUserQueryWindow (196668, 1, ... ) == 0x780 03655 424 NtUserBuildHwndList (0, 196668, 1, 0, 64, ... (0x3003e, 0x30042, 0x30040, 0x30044, 0x30046, 0x30048, 0x1006a, 0x1006e, 0x10072, 0x1, ), 10, ) == 0x0 03656 424 NtUserQueryWindow (196670, 0, ... ) == 0x774 03657 424 NtUserQueryWindow (196670, 1, ... ) == 0x780 03658 424 NtUserQueryWindow (196674, 0, ... ) == 0x774 03659 424 NtUserQueryWindow (196674, 1, ... ) == 0x780 03660 424 NtUserQueryWindow (196672, 0, ... ) == 0x774 03661 424 NtUserQueryWindow (196672, 1, ... ) == 0x780 03662 424 NtUserQueryWindow (196676, 0, ... ) == 0x774 03663 424 NtUserQueryWindow (196676, 1, ... ) == 0x780 03664 424 NtUserQueryWindow (196678, 0, ... ) == 0x774 03665 424 NtUserQueryWindow (196678, 1, ... ) == 0x780 03666 424 NtUserQueryWindow (196680, 0, ... ) == 0x774 03667 424 NtUserQueryWindow (196680, 1, ... ) == 0x780 03668 424 NtUserQueryWindow (65642, 0, ... ) == 0x774 03669 424 NtUserQueryWindow (65642, 1, ... ) == 0x780 03670 424 NtUserQueryWindow (65646, 0, ... ) == 0x774 03671 424 NtUserQueryWindow (65646, 1, ... ) == 0x780 03672 424 NtUserQueryWindow (65650, 0, ... ) == 0x774 03673 424 NtUserQueryWindow (65650, 1, ... ) == 0x780 03674 424 NtUserQueryWindow (65688, 0, ... ) == 0x774 03675 424 NtUserQueryWindow (65688, 1, ... ) == 0x780 03676 424 NtUserQueryWindow (65676, 0, ... ) == 0x774 03677 424 NtUserQueryWindow (65676, 1, ... ) == 0x780 03678 424 NtUserQueryWindow (65660, 0, ... ) == 0x774 03679 424 NtUserQueryWindow (65660, 1, ... ) == 0x778 03680 424 NtUserQueryWindow (65574, 0, ... ) == 0x268 03681 424 NtUserQueryWindow (65574, 1, ... ) == 0x2c4 03682 424 NtUserQueryWindow (65734, 0, ... ) == 0x254 03683 424 NtUserQueryWindow (65734, 1, ... ) == 0x27c 03684 424 NtUserQueryWindow (65726, 0, ... ) == 0x7e0 03685 424 NtUserQueryWindow (65726, 1, ... ) == 0x7e4 03686 424 NtUserQueryWindow (65724, 0, ... ) == 0x7e0 03687 424 NtUserQueryWindow (65724, 1, ... ) == 0x7e4 03688 424 NtUserQueryWindow (65722, 0, ... ) == 0x7e0 03689 424 NtUserQueryWindow (65722, 1, ... ) == 0x7e4 03690 424 NtUserQueryWindow (65720, 0, ... ) == 0x7e0 03691 424 NtUserQueryWindow (65720, 1, ... ) == 0x7e4 03692 424 NtUserQueryWindow (65718, 0, ... ) == 0x7e0 03693 424 NtUserQueryWindow (65718, 1, ... ) == 0x7e4 03694 424 NtUserQueryWindow (65716, 0, ... ) == 0x7e0 03695 424 NtUserQueryWindow (65716, 1, ... ) == 0x7e4 03696 424 NtUserQueryWindow (65712, 0, ... ) == 0x7e0 03697 424 NtUserQueryWindow (65712, 1, ... ) == 0x7e4 03698 424 NtUserQueryWindow (65710, 0, ... ) == 0x7e0 03699 424 NtUserQueryWindow (65710, 1, ... ) == 0x7e4 03700 424 NtUserQueryWindow (131170, 0, ... ) == 0x7f4 03701 424 NtUserQueryWindow (131170, 1, ... ) == 0x7f8 03702 424 NtUserQueryWindow (65708, 0, ... ) == 0x7d4 03703 424 NtUserQueryWindow (65708, 1, ... ) == 0x7d8 03704 424 NtUserQueryWindow (65698, 0, ... ) == 0x7c8 03705 424 NtUserQueryWindow (65698, 1, ... ) == 0x7cc 03706 424 NtUserQueryWindow (65644, 0, ... ) == 0x774 03707 424 NtUserQueryWindow (65644, 1, ... ) == 0x79c 03708 424 NtUserQueryWindow (327760, 0, ... ) == 0x774 03709 424 NtUserQueryWindow (327760, 1, ... ) == 0x778 03710 424 NtUserQueryWindow (262228, 0, ... ) == 0x774 03711 424 NtUserQueryWindow (262228, 1, ... ) == 0x778 03712 424 NtUserQueryWindow (327758, 0, ... ) == 0x774 03713 424 NtUserQueryWindow (327758, 1, ... ) == 0x778 03714 424 NtUserQueryWindow (65666, 0, ... ) == 0x774 03715 424 NtUserQueryWindow (65666, 1, ... ) == 0x778 03716 424 NtUserQueryWindow (65654, 0, ... ) == 0x774 03717 424 NtUserQueryWindow (65654, 1, ... ) == 0x778 03718 424 NtUserBuildHwndList (0, 65654, 1, 0, 64, ... (0x10078, 0x1007a, 0x1, ), 3, ) == 0x0 03719 424 NtUserQueryWindow (65656, 0, ... ) == 0x774 03720 424 NtUserQueryWindow (65656, 1, ... ) == 0x778 03721 424 NtUserQueryWindow (65658, 0, ... ) == 0x774 03722 424 NtUserQueryWindow (65658, 1, ... ) == 0x778 03723 424 NtUserCloseDesktop (104, ... 03724 424 NtClose (104, ... ) == 0x0 03723 424 NtUserCloseDesktop ... ) == 0x1 03725 424 NtUserGetProcessWindowStation (... ) == 0x28 03726 424 NtUserOpenDesktop ({24, 40, 0x40, 0, 0, ({24, 40, 0x40, 0, 0, "Disconnect"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 03727 424 NtUserGetProcessWindowStation (... ) == 0x28 03728 424 NtUserOpenDesktop ({24, 40, 0x40, 0, 0, ({24, 40, 0x40, 0, 0, "Winlogon"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0 03729 424 NtGdiDeleteObjectApp (940180426, ... ) == 0x1 03730 424 NtGdiDeleteObjectApp (369755065, ... ) == 0x1 03731 424 NtClose (12, ... ) == 0x0 03732 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x9,}, 4, ... ) == 0x0 03733 424 NtFreeVirtualMemory (-1, (0x14c000), 16384, 16384, ... (0x14c000), 16384, ) == 0x0 03734 424 NtClose (96, ... ) == 0x0 03735 424 NtUnmapViewOfSection (-1, 0x370000, ... ) == 0x0 03736 424 NtClose (100, ... ) == 0x0 03737 424 NtClose (92, ... ) == 0x0 03738 424 NtFreeVirtualMemory (-1, (0x390000), 0, 32768, ... (0x390000), 262144, ) == 0x0 03739 424 NtUserUnregisterClass (1238704, 1991376896, 1238692, ... ) == 0x0 03740 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc03b 03741 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03742 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc03d 03743 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03744 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc03f 03745 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03746 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc041 03747 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03748 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc043 03749 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03750 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc045 03751 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03752 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc047 03753 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03754 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc049 03755 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03756 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc04b 03757 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03758 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc04d 03759 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03760 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc04f 03761 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03762 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc051 03763 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03764 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc053 03765 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03766 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc057 03767 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03768 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc059 03769 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03770 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc05b 03771 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03772 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc05d 03773 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03774 424 NtUserGetClassInfo (1999896576, 1238792, 1238744, 1238820, 0, ... ) == 0xc05f 03775 424 NtUserUnregisterClass (1238796, 1999896576, 1238784, ... ) == 0x1 03776 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc03b 03777 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03778 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc03d 03779 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03780 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc03f 03781 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03782 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc041 03783 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03784 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc043 03785 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03786 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc045 03787 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03788 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc047 03789 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03790 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc049 03791 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03792 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc04b 03793 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03794 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc04d 03795 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03796 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc04f 03797 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03798 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc051 03799 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03800 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc053 03801 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03802 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc057 03803 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03804 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc059 03805 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03806 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc05b 03807 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03808 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc05d 03809 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03810 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc05f 03811 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03812 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc017 03813 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03814 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc019 03815 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03816 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc018 03817 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03818 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc01a 03819 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03820 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc01c 03821 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03822 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc01e 03823 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03824 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc01b 03825 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03826 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc068 03827 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03828 424 NtUserGetClassInfo (1905590272, 1238792, 1238744, 1238820, 0, ... ) == 0xc06a 03829 424 NtUserUnregisterClass (1238796, 1905590272, 1238784, ... ) == 0x1 03830 424 NtUnmapViewOfSection (-1, 0x380000, ... ) == 0x0 03831 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 03832 424 NtClose (336, ... ) == 0x0 03833 424 NtClose (152, ... ) == 0x0 03834 424 NtClose (352, ... ) == 0x0 03835 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 03836 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 03837 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 03838 424 NtClose (148, ... ) == 0x0 03839 424 NtClose (356, ... ) == 0x0 03840 424 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x1,}, 4, ... ) == 0x0 03841 424 NtUnmapViewOfSection (-1, 0xbc0000, ... ) == 0x0 03842 424 NtClose (312, ... ) == 0x0 03843 424 NtClose (112, ... ) == 0x0 03844 424 NtFreeVirtualMemory (-1, (0xfc0000), 4096, 32768, ... (0xfc0000), 4096, ) == 0x0 03845 424 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 68, 0, 1310720, 1238928} (24, {20, 48, new_msg, 0, 68, 0, 1310720, 1238928} "\0\0\0\0\3\0\1\0\2$\370w\370T\367w\0\0\0\0" ... {20, 48, reply, 0, 420, 424, 1563, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\370T\367w\0\0\0\0" ) ... {20, 48, reply, 0, 420, 424, 1563, 0} (24, {20, 48, new_msg, 0, 68, 0, 1310720, 1238928} "\0\0\0\0\3\0\1\0\2$\370w\370T\367w\0\0\0\0" ... {20, 48, reply, 0, 420, 424, 1563, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\370T\367w\0\0\0\0" ) ) == 0x0 03846 424 NtTerminateProcess (-1, 0, ... 03847 424 NtClose (44, ... ) == 0x0