Summary:

NtAddAtom(>) 1 NtUserGetThreadDesktop(>) 1 NtUserFindWindowEx(>) 4 NtUserRegisterWindowMessage(>) 19
NtAdjustPrivilegesToken(>) 1 NtAccessCheck(>) 2 NtWaitForSingleObject(>) 4 NtCreateSection(>) 21
NtCallbackReturn(>) 1 NtCreateIoCompletion(>) 2 NtDuplicateObject(>) 5 NtOpenProcessTokenEx(>) 25
NtCreateProcessEx(>) 1 NtCreateKey(>) 2 NtGdiGetStockObject(>) 5 NtOpenThreadTokenEx(>) 25
NtDuplicateToken(>) 1 NtCreateThread(>) 2 NtWriteFile(>) 5 NtOpenProcess(>) 26
NtEnumerateValueKey(>) 1 NtEnumerateKey(>) 2 NtFreeVirtualMemory(>) 6 NtQueryAttributesFile(>) 28
NtGdiCreateBitmap(>) 1 NtGdiCreateSolidBrush(>) 2 NtOpenProcessToken(>) 6 NtQuerySystemInformation(>) 30
NtGdiInit(>) 1 NtOpenDirectoryObject(>) 2 NtQueryVolumeInformationFile(>) 6 NtQueryInformationToken(>) 31
NtGdiQueryFontAssocInfo(>) 1 NtOpenEvent(>) 2 NtSetInformationProcess(>) 7 NtReadVirtualMemory(>) 31
NtGdiSelectBitmap(>) 1 NtOpenSymbolicLinkObject(>) 2 NtContinue(>) 8 NtOpenFile(>) 37
NtNotifyChangeKey(>) 1 NtQueryInstallUILanguage(>) 2 NtCreateFile(>) 8 NtQueryValueKey(>) 40
NtOpenKeyedEvent(>) 1 NtQuerySymbolicLinkObject(>) 2 NtQueryDefaultUILanguage(>) 8 NtUnmapViewOfSection(>) 41
NtQueryInformationJobObject(>) 1 NtRaiseException(>) 2 NtQuerySection(>) 8 NtUserUnregisterClass(>) 45
NtQueryObject(>) 1 NtResumeThread(>) 2 NtSetInformationFile(>) 8 NtOpenSection(>) 48
NtQueryPerformanceCounter(>) 1 NtTerminateProcess(>) 2 NtSetInformationThread(>) 8 NtUserFindExistingCursorIcon(>) 48
NtQuerySystemTime(>) 1 NtCreateSemaphore(>) 3 NtCreateEvent(>) 9 NtAllocateVirtualMemory(>) 56
NtReadFile(>) 1 NtGdiCreateCompatibleDC(>) 3 NtRequestWaitReplyPort(>) 9 NtUserRegisterClassExWOW(>) 63
NtRegisterThreadTerminatePort(>) 1 NtOpenMutant(>) 3 NtQueryDirectoryFile(>) 10 NtWriteVirtualMemory(>) 80
NtSecureConnectPort(>) 1 NtSetInformationObject(>) 3 NtUserSystemParametersInfo(>) 10 NtUserGetClassInfo(>) 82
NtSetSecurityObject(>) 1 NtFsControlFile(>) 4 NtFlushInstructionCache(>) 11 NtMapViewOfSection(>) 85
NtTestAlert(>) 1 NtOpenThreadToken(>) 4 NtQueryInformationProcess(>) 14 NtOpenKey(>) 108
NtUserCallNoParam(>) 1 NtQueryVirtualMemory(>) 4 NtQueryDebugFilterState(>) 15 NtProtectVirtualMemory(>) 118
NtUserCallOneParam(>) 1 NtReleaseMutant(>) 4 NtQueryDefaultLocale(>) 15 NtUserQueryWindow(>) 138
NtUserGetDC(>) 1 NtUserBuildHwndList(>) 4 NtQueryInformationFile(>) 15 NtClose(>) 205

Trace:

00001 428 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 428 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00003 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00004 428 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 1376256, 1048576, ) == 0x0 00005 428 NtAllocateVirtualMemory (-1, 1376256, 0, 4096, 4096, 4, ... 1376256, 4096, ) == 0x0 00006 428 NtAllocateVirtualMemory (-1, 1380352, 0, 8192, 4096, 4, ... 1380352, 8192, ) == 0x0 00007 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00008 428 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2424832, 65536, ) == 0x0 00009 428 NtAllocateVirtualMemory (-1, 2424832, 0, 24576, 4096, 4, ... 2424832, 24576, ) == 0x0 00010 428 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00011 428 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00012 428 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00013 428 NtClose (12, ... ) == 0x0 00014 428 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\U:\startupscripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00015 428 NtQueryVolumeInformationFile (12, 1243848, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00016 428 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... ) == STATUS_INVALID_PARAMETER 00017 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local"}, 1243832, ... ) }, 1243832, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00018 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00019 428 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e60000), 0x0, 937984, ) == 0x0 00020 428 NtClose (16, ... ) == 0x0 00021 428 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00022 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00023 428 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00024 428 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1385272, {12, 0, 0}, 1242016, 44, ... 24, {24, 16, 0, 65536, 2490368, 18415616}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1385272, {12, 0, 0}, 1242016, 44, ... 24, {24, 16, 0, 65536, 2490368, 18415616}, {0, 0, 0}, 200, 44, ) == 0x0 00025 428 NtClose (16, ... ) == 0x0 00026 428 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00027 428 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00028 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00029 428 NtQueryVirtualMemory (-1, 0x260000, Basic, 28, ... {BaseAddress=0x260000,AllocationBase=0x260000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00030 428 NtAllocateVirtualMemory (-1, 2490368, 0, 4096, 4096, 4, ... 2490368, 4096, ) == 0x0 00031 428 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 0, 0, 0, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 408, 428, 1489, 0} "\20>\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ... {28, 56, reply, 0, 408, 428, 1489, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 408, 428, 1489, 0} "\20>\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ) == 0x0 00032 428 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00033 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00034 428 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00035 428 NtClose (16, ... ) == 0x0 00036 428 NtAllocateVirtualMemory (-1, 1232896, 0, 4096, 4096, 260, ... 1232896, 4096, ) == 0x0 00037 428 NtOpenMutant (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\NlsCacheMutant"}, ... 16, ) }, ... 16, ) == 0x0 00038 428 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 28, ) }, ... 28, ) == 0x0 00039 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x270000), 0x0, 90112, ) == 0x0 00040 428 NtClose (28, ... ) == 0x0 00041 428 NtQueryDefaultLocale (0, 2012046252, ... ) == 0x0 00042 428 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 28, ) }, ... 28, ) == 0x0 00043 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x290000), 0x0, 212992, ) == 0x0 00044 428 NtClose (28, ... ) == 0x0 00045 428 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 28, ) }, ... 28, ) == 0x0 00046 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2d0000), 0x0, 266240, ) == 0x0 00047 428 NtQuerySection (28, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00048 428 NtClose (28, ... ) == 0x0 00049 428 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 28, ) }, ... 28, ) == 0x0 00050 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x320000), 0x0, 24576, ) == 0x0 00051 428 NtClose (28, ... ) == 0x0 00052 428 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00053 428 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00054 428 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00055 428 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 408, 428, 1532, 0} "(\261\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ... {28, 56, reply, 0, 408, 428, 1532, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 408, 428, 1532, 0} "(\261\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ) == 0x0 00056 428 NtProtectVirtualMemory (-1, (0x45d000), 204800, 4, ... (0x45d000), 204800, 128, ) == 0x0 00057 428 NtProtectVirtualMemory (-1, (0x45d000), 204800, 128, ... (0x45d000), 204800, 4, ) == 0x0 00058 428 NtFlushInstructionCache (-1, 4575232, 204800, ... ) == 0x0 00059 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "user32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00060 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77d40000), 0x0, 577536, ) == 0x0 00061 428 NtClose (28, ... ) == 0x0 00062 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00063 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c70000), 0x0, 262144, ) == 0x0 00064 428 NtClose (28, ... ) == 0x0 00065 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00066 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 569344, ) == 0x0 00067 428 NtClose (28, ... ) == 0x0 00068 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 28, ) }, ... 28, ) == 0x0 00069 428 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77cc0000), 0x0, 479232, ) == 0x0 00070 428 NtClose (28, ... ) == 0x0 00071 428 NtProtectVirtualMemory (-1, (0x45d000), 204800, 4, ... (0x45d000), 204800, 64, ) == 0x0 00072 428 NtProtectVirtualMemory (-1, (0x45d000), 204800, 64, ... (0x45d000), 204800, 4, ) == 0x0 00073 428 NtFlushInstructionCache (-1, 4575232, 204800, ... ) == 0x0 00074 428 NtOpenProcessToken (-1, 0x8, ... 28, ) == 0x0 00075 428 NtQueryInformationToken (28, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00076 428 NtClose (28, ... ) == 0x0 00077 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00078 428 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00079 428 NtClose (28, ... ) == 0x0 00080 428 NtAllocateVirtualMemory (-1, 1388544, 0, 4096, 4096, 4, ... 1388544, 4096, ) == 0x0 00081 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00082 428 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00083 428 NtQueryValueKey (28, (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00084 428 NtClose (28, ... ) == 0x0 00085 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 28, ) }, ... 28, ) == 0x0 00086 428 NtQueryValueKey (28, (28, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00087 428 NtClose (28, ... ) == 0x0 00088 428 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 28, ) }, ... 28, ) == 0x0 00089 428 NtSetInformationObject (28, Handle, {Inherit=0,ProtectFromClose=1,}, 2011365632, ... ) == 0x0 00090 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00091 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00092 428 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2, 2147347448, 1246412, 0} (24, {28, 56, new_msg, 0, 2, 2147347448, 1246412, 0} "\210\6\31\1\0\0\0\0\314\4\23\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 408, 428, 1555, 0} "XQ\26\0\0\0\0\0\0\0\0\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ) ... {28, 56, reply, 0, 408, 428, 1555, 0} (24, {28, 56, new_msg, 0, 2, 2147347448, 1246412, 0} "\210\6\31\1\0\0\0\0\314\4\23\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 408, 428, 1555, 0} "XQ\26\0\0\0\0\0\0\0\0\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ) ) == 0x0 00093 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00094 428 NtMapViewOfSection (32, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x4a0000), 0x0, 1060864, ) == 0x0 00095 428 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 36, ) == 0x0 00096 428 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00097 428 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482028, ) == 0x0 00098 428 NtQueryInformationToken (-2147482028, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00099 428 NtQueryInformationToken (-2147482028, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00100 428 NtClose (-2147482028, ... ) == 0x0 00101 428 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 5963776, 4096, ) == 0x0 00102 428 NtFreeVirtualMemory (-1, (0x5b0000), 4096, 32768, ... (0x5b0000), 4096, ) == 0x0 00103 428 NtDuplicateObject (-1, 40, -1, 0x0, 0, 2, ... 48, ) == 0x0 00104 428 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482028, ) }, ... -2147482028, ) == 0x0 00105 428 NtQueryValueKey (-2147482028, (-2147482028, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00106 428 NtClose (-2147482028, ... ) == 0x0 00107 428 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482028, ) }, ... -2147482028, ) == 0x0 00108 428 NtQueryValueKey (-2147482028, (-2147482028, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00109 428 NtClose (-2147482028, ... ) == 0x0 00110 428 NtQueryDefaultLocale (0, -136115700, ... ) == 0x0 00111 428 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00112 428 NtUserCallNoParam (24, ... ) == 0x0 00113 428 NtGdiCreateCompatibleDC (0, ... 00114 428 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 5963776, 4096, ) == 0x0 00113 428 NtGdiCreateCompatibleDC ... ) == 0x140103fc 00115 428 NtGdiGetStockObject (0, ... ) == 0x1900010 00116 428 NtGdiGetStockObject (4, ... ) == 0x1900011 00117 428 NtGdiCreateBitmap (8, 8, 1, 1, 2010393708, ... ) == 0x15050405 00118 428 NtGdiCreateSolidBrush (0, 0, ... 00119 428 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 9175040, 4096, ) == 0x0 00118 428 NtGdiCreateSolidBrush ... ) == 0x71003f7 00120 428 NtGdiGetStockObject (13, ... ) == 0x18a0021 00121 428 NtGdiCreateCompatibleDC (0, ... ) == 0xb0103f1 00122 428 NtGdiSelectBitmap (184615921, 352650245, ... ) == 0x185000f 00123 428 NtUserGetThreadDesktop (428, 0, ... ) == 0x2c 00124 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 52, ) }, ... 52, ) == 0x0 00125 428 NtQueryValueKey (52, (52, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (52, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00126 428 NtClose (52, ... ) == 0x0 00127 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00128 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 673, 128, 0, ... ) == 0x810dc017 00129 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00130 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 674, 128, 0, ... ) == 0x810dc01c 00131 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00132 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 675, 128, 0, ... ) == 0x810dc01e 00133 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00134 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 676, 128, 0, ... ) == 0x810d8002 00135 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10013 00136 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 677, 128, 0, ... ) == 0x810dc018 00137 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00138 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 678, 128, 0, ... ) == 0x810dc01a 00139 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00140 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 679, 128, 0, ... ) == 0x810dc01d 00141 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00142 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 681, 128, 0, ... ) == 0x810dc026 00143 428 NtUserFindExistingCursorIcon (1241204, 1241220, 1241788, ... ) == 0x10011 00144 428 NtUserRegisterClassExWOW (1241724, 1241804, 1241788, 1241820, 680, 128, 0, ... ) == 0x810dc019 00145 428 NtUserRegisterClassExWOW (1241676, 1241756, 1241740, 1241772, 0, 128, 0, ... 00146 428 NtAllocateVirtualMemory (-1, 6127616, 0, 4096, 4096, 32, ... 6127616, 4096, ) == 0x0 00145 428 NtUserRegisterClassExWOW ... ) == 0x810dc020 00147 428 NtUserRegisterClassExWOW (1241676, 1241752, 1241768, 1241740, 0, 130, 0, ... ) == 0x810dc022 00148 428 NtUserRegisterClassExWOW (1241676, 1241756, 1241740, 1241772, 0, 128, 0, ... ) == 0x810dc023 00149 428 NtUserRegisterClassExWOW (1241676, 1241752, 1241768, 1241740, 0, 130, 0, ... ) == 0x810dc024 00150 428 NtUserRegisterClassExWOW (1241676, 1241756, 1241740, 1241772, 0, 128, 0, ... ) == 0x810dc025 00151 428 NtCallbackReturn (0, 0, 0, ... 00152 428 NtGdiInit (... ) == 0x1 00153 428 NtGdiGetStockObject (18, ... ) == 0x290001c 00154 428 NtGdiGetStockObject (19, ... ) == 0x1b00019 00155 428 NtAllocateVirtualMemory (-1, 0, 0, 18086, 4096, 4, ... 9240576, 20480, ) == 0x0 00156 428 NtFreeVirtualMemory (-1, (0x8d0000), 0, 32768, ... (0x8d0000), 20480, ) == 0x0 00157 428 NtQueryVirtualMemory (-1, 0x401000, Basic, 52, ... {BaseAddress=0x401000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x23000,State=0x1000,Protect=0x80,Type=0x1000000,}, 28, ) == 0x0 00158 428 NtQueryVirtualMemory (-1, 0x45b2a7, Basic, 28, ... {BaseAddress=0x45b000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x2000,State=0x1000,Protect=0x4,Type=0x1000000,}, 28, ) == 0x0 00159 428 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 1392640, 4096, ) == 0x0 00160 428 NtProtectVirtualMemory (-1, (0x4001f0), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00161 428 NtProtectVirtualMemory (-1, (0x4001f0), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00162 428 NtProtectVirtualMemory (-1, (0x400218), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00163 428 NtProtectVirtualMemory (-1, (0x400218), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00164 428 NtProtectVirtualMemory (-1, (0x400240), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00165 428 NtProtectVirtualMemory (-1, (0x400240), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00166 428 NtProtectVirtualMemory (-1, (0x400268), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00167 428 NtProtectVirtualMemory (-1, (0x400268), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00168 428 NtProtectVirtualMemory (-1, (0x400290), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00169 428 NtProtectVirtualMemory (-1, (0x400290), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00170 428 NtProtectVirtualMemory (-1, (0x4002b8), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00171 428 NtProtectVirtualMemory (-1, (0x4002b8), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00172 428 NtProtectVirtualMemory (-1, (0x4002e0), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00173 428 NtProtectVirtualMemory (-1, (0x4002e0), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00174 428 NtProtectVirtualMemory (-1, (0x400308), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00175 428 NtProtectVirtualMemory (-1, (0x400308), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00176 428 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00177 428 NtUserFindWindowEx (0, 0, (0, 0, "WispWindowClass", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00178 428 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x50044, 0x20060, 0x20064, 0x20062, 0x100a2, 0x10082, 0x10076, 0x1006a, 0x30040, 0x10068, 0x10066, 0x30032, 0x1009a, 0x1008e, 0x1007e, 0x10026, 0x100c6, 0x100c2, 0x100c0, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b2, 0x100b0, 0x100ae, 0x100ac, 0x100a4, 0x1006e, 0x50042, 0x40048, 0x8002a, 0x10080, 0x10078, 0x1, ), 35, ) == 0x0 00179 428 NtUserQueryWindow (327748, 0, ... ) == 0xd0 00180 428 NtUserQueryWindow (327748, 1, ... ) == 0xd8 00181 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {208, 0}, ... 52, ) == 0x0 00182 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \1\0\0", 64, ) , 64, ) == 0x0 00183 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00184 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00185 428 NtClose (52, ... ) == 0x0 00186 428 NtUserQueryWindow (131168, 0, ... ) == 0xd0 00187 428 NtUserQueryWindow (131168, 1, ... ) == 0xd8 00188 428 NtUserQueryWindow (131172, 0, ... ) == 0xd0 00189 428 NtUserQueryWindow (131172, 1, ... ) == 0xd8 00190 428 NtUserQueryWindow (131170, 0, ... ) == 0xd0 00191 428 NtUserQueryWindow (131170, 1, ... ) == 0xd8 00192 428 NtUserQueryWindow (65698, 0, ... ) == 0x7e4 00193 428 NtUserQueryWindow (65698, 1, ... ) == 0x7fc 00194 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {2020, 0}, ... 52, ) == 0x0 00195 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00196 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... 00197 428 NtContinue (-136119140, 0, ... 00196 428 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00198 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... 00199 428 NtContinue (-136119140, 0, ... 00198 428 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00200 428 NtClose (52, ... ) == 0x0 00201 428 NtUserQueryWindow (65666, 0, ... ) == 0x7e4 00202 428 NtUserQueryWindow (65666, 1, ... ) == 0x7fc 00203 428 NtUserQueryWindow (65654, 0, ... ) == 0x7e4 00204 428 NtUserQueryWindow (65654, 1, ... ) == 0x7fc 00205 428 NtUserQueryWindow (65642, 0, ... ) == 0x7e4 00206 428 NtUserQueryWindow (65642, 1, ... ) == 0x7fc 00207 428 NtUserQueryWindow (196672, 0, ... ) == 0x7e4 00208 428 NtUserQueryWindow (196672, 1, ... ) == 0x7fc 00209 428 NtUserQueryWindow (65640, 0, ... ) == 0x7e4 00210 428 NtUserQueryWindow (65640, 1, ... ) == 0x7fc 00211 428 NtUserQueryWindow (65638, 0, ... ) == 0x7e4 00212 428 NtUserQueryWindow (65638, 1, ... ) == 0x7fc 00213 428 NtUserQueryWindow (196658, 0, ... ) == 0x7e4 00214 428 NtUserQueryWindow (196658, 1, ... ) == 0x7fc 00215 428 NtUserQueryWindow (65690, 0, ... ) == 0x7e4 00216 428 NtUserQueryWindow (65690, 1, ... ) == 0x7fc 00217 428 NtUserQueryWindow (65678, 0, ... ) == 0x7e4 00218 428 NtUserQueryWindow (65678, 1, ... ) == 0x7fc 00219 428 NtUserQueryWindow (65662, 0, ... ) == 0x7e4 00220 428 NtUserQueryWindow (65662, 1, ... ) == 0x7e8 00221 428 NtUserQueryWindow (65574, 0, ... ) == 0x268 00222 428 NtUserQueryWindow (65574, 1, ... ) == 0x2c4 00223 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {616, 0}, ... 52, ) == 0x0 00224 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00225 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00226 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00227 428 NtClose (52, ... ) == 0x0 00228 428 NtUserQueryWindow (65734, 0, ... ) == 0x1c8 00229 428 NtUserQueryWindow (65734, 1, ... ) == 0x1cc 00230 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {456, 0}, ... 52, ) == 0x0 00231 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00232 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00233 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00234 428 NtClose (52, ... ) == 0x0 00235 428 NtUserQueryWindow (65730, 0, ... ) == 0xf0 00236 428 NtUserQueryWindow (65730, 1, ... ) == 0xf4 00237 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {240, 0}, ... 52, ) == 0x0 00238 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0", 64, ) , 64, ) == 0x0 00239 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\377\0\377\377", 4, ) , 4, ) == 0x0 00240 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\210fvx\210x\206wfvGe$\306d\21\26\210ls\210\210\250g\207\210hhx\207xhvwdfF|d\21\27\210\206hx\250\252\206\210\207v\207\210x\207\207gfv4F\306G\21\21\210\206\207\210\212\250\250h\210\207x\210\210wvwgFD$d!\21\21x\250g\210\212\252\250\206\210\207w\210\207\207wvvgBGd\21\21\21\210\212\203\210\250\252\212\210x\210w\210\210xwgcd%F\1\21\21\21\27\212\250\210\212\252\252\210f\210\207x\210\207w7fR@`\21\21\21\21\21\210\2508\212\252\250\250\210gw\21088vvu$$!\21\21\21\21\21\30\210\210\210\212\252\210\206vgw\210\203wsb`\7\21\21\21\21\21\21\21\210\203\210\210\210\210\207vvwwwsf4\7\21\21\21\21\21\21\21\21\30\210\210\210\210\210wGwvwww5\2\21\21\21\21\21\21", 256, ) , 256, ) == 0x0 00241 428 NtClose (52, ... ) == 0x0 00242 428 NtUserQueryWindow (65728, 0, ... ) == 0xf0 00243 428 NtUserQueryWindow (65728, 1, ... ) == 0xf4 00244 428 NtUserQueryWindow (65726, 0, ... ) == 0xf0 00245 428 NtUserQueryWindow (65726, 1, ... ) == 0xf4 00246 428 NtUserQueryWindow (65724, 0, ... ) == 0xf0 00247 428 NtUserQueryWindow (65724, 1, ... ) == 0xf4 00248 428 NtUserQueryWindow (65722, 0, ... ) == 0xf0 00249 428 NtUserQueryWindow (65722, 1, ... ) == 0xf4 00250 428 NtUserQueryWindow (65720, 0, ... ) == 0xf0 00251 428 NtUserQueryWindow (65720, 1, ... ) == 0xf4 00252 428 NtUserQueryWindow (65714, 0, ... ) == 0xf0 00253 428 NtUserQueryWindow (65714, 1, ... ) == 0xf4 00254 428 NtUserQueryWindow (65712, 0, ... ) == 0xf0 00255 428 NtUserQueryWindow (65712, 1, ... ) == 0xf4 00256 428 NtUserQueryWindow (65710, 0, ... ) == 0x10c 00257 428 NtUserQueryWindow (65710, 1, ... ) == 0x110 00258 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {268, 0}, ... 52, ) == 0x0 00259 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\301\0\0\0\0\1\0\0\377\356\377\356\11\0\0\0\11\0\0\0\0\376\0\0\0\0\20\0\0 \0\0\0\2\0\0\0 \0\0q\0\0\0\377\357\375\177\0\0\10\6\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00260 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00261 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00262 428 NtClose (52, ... ) == 0x0 00263 428 NtUserQueryWindow (65708, 0, ... ) == 0xd0 00264 428 NtUserQueryWindow (65708, 1, ... ) == 0xd8 00265 428 NtUserQueryWindow (65700, 0, ... ) == 0xa0 00266 428 NtUserQueryWindow (65700, 1, ... ) == 0xb0 00267 428 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {160, 0}, ... 52, ) == 0x0 00268 428 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0", 64, ) , 64, ) == 0x0 00269 428 NtReadVirtualMemory (52, 0x4b1c86, 4, ... 00270 428 NtContinue (-136119140, 0, ... 00269 428 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00271 428 NtReadVirtualMemory (52, 0x4c91a0, 256, ... 00272 428 NtContinue (-136119140, 0, ... 00271 428 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00273 428 NtClose (52, ... ) == 0x0 00274 428 NtUserQueryWindow (65646, 0, ... ) == 0x7e4 00275 428 NtUserQueryWindow (65646, 1, ... ) == 0xa4 00276 428 NtUserQueryWindow (327746, 0, ... ) == 0x7e4 00277 428 NtUserQueryWindow (327746, 1, ... ) == 0x7e8 00278 428 NtUserQueryWindow (262216, 0, ... ) == 0x7e4 00279 428 NtUserQueryWindow (262216, 1, ... ) == 0x7e8 00280 428 NtUserQueryWindow (524330, 0, ... ) == 0x7e4 00281 428 NtUserQueryWindow (524330, 1, ... ) == 0x7e8 00282 428 NtUserQueryWindow (65664, 0, ... ) == 0x7e4 00283 428 NtUserQueryWindow (65664, 1, ... ) == 0x7e8 00284 428 NtUserQueryWindow (65656, 0, ... ) == 0x7e4 00285 428 NtUserQueryWindow (65656, 1, ... ) == 0x7e8 00286 428 NtRaiseException (1242696, 1241956, 1, ... 00287 428 NtContinue (1240752, 0, ... 00288 428 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 52, ) }, ... 52, ) == 0x0 00289 428 NtOpenMutant (0x120001, {24, 52, 0x2, 0, 0, (0x120001, {24, 52, 0x2, 0, 0, "DBWinMutex"}, ... 56, ) }, ... 56, ) == 0x0 00290 428 NtWaitForSingleObject (56, 0, 0x0, ... ) == 0x0 00291 428 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00292 428 NtReleaseMutant (56, ... 0x0, ) == 0x0 00293 428 NtDuplicateObject (-1, 2518, -1, 0x0, 0, 2, ... ) == STATUS_INVALID_HANDLE 00294 428 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00295 428 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00296 428 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x200b4, 0x50044, 0x20060, 0x20064, 0x20062, 0x100a2, 0x10082, 0x10076, 0x1006a, 0x30040, 0x10068, 0x10066, 0x30032, 0x1009a, 0x1008e, 0x1007e, 0x10026, 0x100c6, 0x100c2, 0x100c0, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b2, 0x100b0, 0x100ae, 0x100ac, 0x100a4, 0x1006e, 0x50042, 0x40048, 0x8002a, 0x10080, 0x10078, 0x1, ), 36, ) == 0x0 00297 428 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00298 428 NtUserFindWindowEx (0, 0, (0, 0, "WispWindowClass", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00299 428 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x200b4, 0x50044, 0x20060, 0x20064, 0x20062, 0x100a2, 0x10082, 0x10076, 0x1006a, 0x30040, 0x10068, 0x10066, 0x30032, 0x1009a, 0x1008e, 0x1007e, 0x10026, 0x100c6, 0x100c2, 0x100c0, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b2, 0x100b0, 0x100ae, 0x100ac, 0x100a4, 0x1006e, 0x50042, 0x40048, 0x8002a, 0x10080, 0x10078, 0x1, ), 36, ) == 0x0 00300 428 NtUserQueryWindow (131252, 0, ... ) == 0x1c8 00301 428 NtUserQueryWindow (131252, 1, ... ) == 0x230 00302 428 NtUserQueryWindow (327748, 0, ... ) == 0xd0 00303 428 NtUserQueryWindow (327748, 1, ... ) == 0xd8 00304 428 NtUserQueryWindow (131168, 0, ... ) == 0xd0 00305 428 NtUserQueryWindow (131168, 1, ... ) == 0xd8 00306 428 NtUserQueryWindow (131172, 0, ... ) == 0xd0 00307 428 NtUserQueryWindow (131172, 1, ... ) == 0xd8 00308 428 NtUserQueryWindow (131170, 0, ... ) == 0xd0 00309 428 NtUserQueryWindow (131170, 1, ... ) == 0xd8 00310 428 NtUserQueryWindow (65698, 0, ... ) == 0x7e4 00311 428 NtUserQueryWindow (65698, 1, ... ) == 0x7fc 00312 428 NtUserQueryWindow (65666, 0, ... ) == 0x7e4 00313 428 NtUserQueryWindow (65666, 1, ... ) == 0x7fc 00314 428 NtUserQueryWindow (65654, 0, ... ) == 0x7e4 00315 428 NtUserQueryWindow (65654, 1, ... ) == 0x7fc 00316 428 NtUserQueryWindow (65642, 0, ... ) == 0x7e4 00317 428 NtUserQueryWindow (65642, 1, ... ) == 0x7fc 00318 428 NtUserQueryWindow (196672, 0, ... ) == 0x7e4 00319 428 NtUserQueryWindow (196672, 1, ... ) == 0x7fc 00320 428 NtUserQueryWindow (65640, 0, ... ) == 0x7e4 00321 428 NtUserQueryWindow (65640, 1, ... ) == 0x7fc 00322 428 NtUserQueryWindow (65638, 0, ... ) == 0x7e4 00323 428 NtUserQueryWindow (65638, 1, ... ) == 0x7fc 00324 428 NtUserQueryWindow (196658, 0, ... ) == 0x7e4 00325 428 NtUserQueryWindow (196658, 1, ... ) == 0x7fc 00326 428 NtUserQueryWindow (65690, 0, ... ) == 0x7e4 00327 428 NtUserQueryWindow (65690, 1, ... ) == 0x7fc 00328 428 NtUserQueryWindow (65678, 0, ... ) == 0x7e4 00329 428 NtUserQueryWindow (65678, 1, ... ) == 0x7fc 00330 428 NtUserQueryWindow (65662, 0, ... ) == 0x7e4 00331 428 NtUserQueryWindow (65662, 1, ... ) == 0x7e8 00332 428 NtUserQueryWindow (65574, 0, ... ) == 0x268 00333 428 NtUserQueryWindow (65574, 1, ... ) == 0x2c4 00334 428 NtUserQueryWindow (65734, 0, ... ) == 0x1c8 00335 428 NtUserQueryWindow (65734, 1, ... ) == 0x1cc 00336 428 NtUserQueryWindow (65730, 0, ... ) == 0xf0 00337 428 NtUserQueryWindow (65730, 1, ... ) == 0xf4 00338 428 NtUserQueryWindow (65728, 0, ... ) == 0xf0 00339 428 NtUserQueryWindow (65728, 1, ... ) == 0xf4 00340 428 NtUserQueryWindow (65726, 0, ... ) == 0xf0 00341 428 NtUserQueryWindow (65726, 1, ... ) == 0xf4 00342 428 NtUserQueryWindow (65724, 0, ... ) == 0xf0 00343 428 NtUserQueryWindow (65724, 1, ... ) == 0xf4 00344 428 NtUserQueryWindow (65722, 0, ... ) == 0xf0 00345 428 NtUserQueryWindow (65722, 1, ... ) == 0xf4 00346 428 NtUserQueryWindow (65720, 0, ... ) == 0xf0 00347 428 NtUserQueryWindow (65720, 1, ... ) == 0xf4 00348 428 NtUserQueryWindow (65714, 0, ... ) == 0xf0 00349 428 NtUserQueryWindow (65714, 1, ... ) == 0xf4 00350 428 NtUserQueryWindow (65712, 0, ... ) == 0xf0 00351 428 NtUserQueryWindow (65712, 1, ... ) == 0xf4 00352 428 NtUserQueryWindow (65710, 0, ... ) == 0x10c 00353 428 NtUserQueryWindow (65710, 1, ... ) == 0x110 00354 428 NtUserQueryWindow (65708, 0, ... ) == 0xd0 00355 428 NtUserQueryWindow (65708, 1, ... ) == 0xd8 00356 428 NtUserQueryWindow (65700, 0, ... ) == 0xa0 00357 428 NtUserQueryWindow (65700, 1, ... ) == 0xb0 00358 428 NtUserQueryWindow (65646, 0, ... ) == 0x7e4 00359 428 NtUserQueryWindow (65646, 1, ... ) == 0xa4 00360 428 NtUserQueryWindow (327746, 0, ... ) == 0x7e4 00361 428 NtUserQueryWindow (327746, 1, ... ) == 0x7e8 00362 428 NtUserQueryWindow (262216, 0, ... ) == 0x7e4 00363 428 NtUserQueryWindow (262216, 1, ... ) == 0x7e8 00364 428 NtUserQueryWindow (524330, 0, ... ) == 0x7e4 00365 428 NtUserQueryWindow (524330, 1, ... ) == 0x7e8 00366 428 NtUserQueryWindow (65664, 0, ... ) == 0x7e4 00367 428 NtUserQueryWindow (65664, 1, ... ) == 0x7e8 00368 428 NtUserQueryWindow (65656, 0, ... ) == 0x7e4 00369 428 NtUserQueryWindow (65656, 1, ... ) == 0x7e8 00370 428 NtRaiseException (1242640, 1241900, 1, ... 00371 428 NtContinue (1240696, 0, ... 00372 428 NtWaitForSingleObject (56, 0, 0x0, ... ) == 0x0 00373 428 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00374 428 NtReleaseMutant (56, ... 0x0, ) == 0x0 00375 428 NtDuplicateObject (-1, 2221, -1, 0x0, 0, 2, ... ) == STATUS_INVALID_HANDLE 00376 428 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00377 428 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00378 428 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x200b4, 0x50044, 0x20060, 0x20064, 0x20062, 0x100a2, 0x10082, 0x10076, 0x1006a, 0x30040, 0x10068, 0x10066, 0x30032, 0x1009a, 0x1008e, 0x1007e, 0x10026, 0x100c6, 0x100c2, 0x100c0, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b2, 0x100b0, 0x100ae, 0x100ac, 0x100a4, 0x1006e, 0x50042, 0x40048, 0x8002a, 0x10080, 0x10078, 0x1, ), 36, ) == 0x0 00379 428 NtSetSecurityObject (-1, 4, {1, 0, 0x4, 0, 0, 0, 1242476}, ... ) == 0x0 00380 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 60, ) }, ... 60, ) == 0x0 00381 428 NtQueryValueKey (60, (60, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00382 428 NtClose (60, ... ) == 0x0 00383 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MPR.dll"}, ... 60, ) }, ... 60, ) == 0x0 00384 428 NtMapViewOfSection (60, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71b20000), 0x0, 69632, ) == 0x0 00385 428 NtClose (60, ... ) == 0x0 00386 428 NtCreateSemaphore (0x1f0003, 0x0, 1, 1, ... 60, ) == 0x0 00387 428 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 64, ) == 0x0 00388 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "system\CurrentControlSet\control\NetworkProvider\HwOrder"}, ... 68, ) }, ... 68, ) == 0x0 00389 428 NtNotifyChangeKey (68, 64, 0, 0, 2011390432, 4, 0, 0, 0, 1, ... ) == 0x103 00390 428 NtQueryInformationProcess (-1, 28, 4, ... {process info, class 28, size 4}, 0x0, ) == 0x0 00391 428 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 72, ) == 0x0 00392 428 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 76, ) == 0x0 00393 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ODBC32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00394 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ODBC32.dll"}, 1241484, ... ) }, 1241484, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00395 428 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "ODBC32.dll"}, 1241484, ... ) }, 1241484, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00396 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ODBC32.dll"}, 1241484, ... ) }, 1241484, ... ) == 0x0 00397 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ODBC32.dll"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00398 428 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 80, ... 84, ) == 0x0 00399 428 NtQuerySection (84, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00400 428 NtOpenProcessToken (-1, 0x8, ... 88, ) == 0x0 00401 428 NtQueryInformationToken (88, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00402 428 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00403 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 92, ) }, ... 92, ) == 0x0 00404 428 NtQueryValueKey (92, (92, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (92, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00405 428 NtClose (92, ... ) == 0x0 00406 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00407 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 92, ) == 0x0 00408 428 NtQueryInformationToken (92, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00409 428 NtClose (92, ... ) == 0x0 00410 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00411 428 NtClose (88, ... ) == 0x0 00412 428 NtClose (80, ... ) == 0x0 00413 428 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x1f7b0000), 0x0, 200704, ) == 0x0 00414 428 NtClose (84, ... ) == 0x0 00415 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMCTL32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00416 428 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77340000), 0x0, 569344, ) == 0x0 00417 428 NtClose (84, ... ) == 0x0 00418 428 NtProtectVirtualMemory (-1, (0x1f7b1000), 724, 4, ... (0x1f7b1000), 4096, 32, ) == 0x0 00419 428 NtProtectVirtualMemory (-1, (0x1f7b1000), 4096, 32, ... (0x1f7b1000), 4096, 4, ) == 0x0 00420 428 NtFlushInstructionCache (-1, 528158720, 724, ... ) == 0x0 00421 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "comdlg32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00422 428 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x763b0000), 0x0, 282624, ) == 0x0 00423 428 NtClose (84, ... ) == 0x0 00424 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHLWAPI.dll"}, ... 84, ) }, ... 84, ) == 0x0 00425 428 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x772d0000), 0x0, 405504, ) == 0x0 00426 428 NtClose (84, ... ) == 0x0 00427 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "msvcrt.dll"}, ... 84, ) }, ... 84, ) == 0x0 00428 428 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 339968, ) == 0x0 00429 428 NtClose (84, ... ) == 0x0 00430 428 NtProtectVirtualMemory (-1, (0x763b1000), 1536, 4, ... (0x763b1000), 4096, 32, ) == 0x0 00431 428 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 00432 428 NtFlushInstructionCache (-1, 1983582208, 1536, ... ) == 0x0 00433 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHELL32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00434 428 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x773d0000), 0x0, 8339456, ) == 0x0 00435 428 NtClose (84, ... ) == 0x0 00436 428 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {408, 0}, ... 84, ) == 0x0 00437 428 NtQueryInformationProcess (84, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 00438 428 NtClose (84, ... ) == 0x0 00439 428 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00440 428 NtUserSystemParametersInfo (104, 0, 2000318720, 0, ... ) == 0x1 00441 428 NtUserSystemParametersInfo (38, 4, 2000318708, 0, ... ) == 0x1 00442 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00443 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 84, ) == 0x0 00444 428 NtQueryInformationToken (84, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00445 428 NtClose (84, ... ) == 0x0 00446 428 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 84, ) }, ... 84, ) == 0x0 00447 428 NtSetInformationObject (84, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 00448 428 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Control Panel\Desktop"}, ... 80, ) }, ... 80, ) == 0x0 00449 428 NtQueryValueKey (80, (80, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00450 428 NtClose (80, ... ) == 0x0 00451 428 NtUserSystemParametersInfo (41, 500, 1241216, 0, ... ) == 0x1 00452 428 NtUserSystemParametersInfo (102, 0, 2000318732, 0, ... ) == 0x1 00453 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00454 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00455 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc03b 00456 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00457 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc03d 00458 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00459 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00460 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc03f 00461 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00462 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00463 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc041 00464 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00465 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00466 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc043 00467 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00468 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc045 00469 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00470 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00471 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc047 00472 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00473 428 NtUserFindExistingCursorIcon (1241004, 1241020, 1241588, ... ) == 0x10011 00474 428 NtUserRegisterClassExWOW (1241456, 1241536, 1241520, 1241552, 0, 384, 0, ... ) == 0x810dc049 00475 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00476 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00477 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc04b 00478 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00479 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00480 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc04d 00481 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00482 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00483 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc04f 00484 428 NtUserGetClassInfo (1999896576, 1241628, 1241580, 1241656, 0, ... ) == 0x0 00485 428 NtUserRegisterClassExWOW (1241464, 1241544, 1241528, 1241560, 0, 384, 0, ... ) == 0x810dc051 00486 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00487 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00488 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc053 00489 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00490 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00491 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc055 00492 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc057 00493 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00494 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00495 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc059 00496 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00497 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10013 00498 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc05b 00499 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00500 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00501 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc05d 00502 428 NtUserGetClassInfo (1999896576, 1241624, 1241576, 1241652, 0, ... ) == 0x0 00503 428 NtUserFindExistingCursorIcon (1241008, 1241024, 1241592, ... ) == 0x10011 00504 428 NtUserRegisterClassExWOW (1241460, 1241540, 1241524, 1241556, 0, 384, 0, ... ) == 0x810dc05f 00505 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00506 428 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 9240576, 65536, ) == 0x0 00507 428 NtAllocateVirtualMemory (-1, 9240576, 0, 4096, 4096, 4, ... 9240576, 4096, ) == 0x0 00508 428 NtAllocateVirtualMemory (-1, 9244672, 0, 8192, 4096, 4, ... 9244672, 8192, ) == 0x0 00509 428 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 80, ) }, ... 80, ) == 0x0 00510 428 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x8e0000), 0x0, 12288, ) == 0x0 00511 428 NtClose (80, ... ) == 0x0 00512 428 NtAllocateVirtualMemory (-1, 9252864, 0, 4096, 4096, 4, ... 9252864, 4096, ) == 0x0 00513 428 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00514 428 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 80, ) }, ... 80, ) == 0x0 00515 428 NtQueryValueKey (80, (80, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (80, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00516 428 NtClose (80, ... ) == 0x0 00517 428 NtQueryDefaultUILanguage (1239840, ... 00518 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00519 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00520 428 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00521 428 NtClose (-2147482020, ... ) == 0x0 00522 428 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00523 428 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00524 428 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00525 428 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00526 428 NtClose (-2147482032, ... ) == 0x0 00527 428 NtClose (-2147482020, ... ) == 0x0 00517 428 NtQueryDefaultUILanguage ... ) == 0x0 00528 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00529 428 NtQueryInstallUILanguage (2012047340, ... ) == 0x0 00530 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1, 96, ... 80, {status=0x0, info=1}, ) }, 1, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00531 428 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 80, ... 88, ) == 0x0 00532 428 NtMapViewOfSection (88, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x8f0000), 0x0, 8323072, ) == 0x0 00533 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00534 428 NtQueryDefaultUILanguage (2013024600, ... 00535 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00536 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00537 428 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00538 428 NtClose (-2147482020, ... ) == 0x0 00539 428 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00540 428 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00541 428 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00542 428 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00543 428 NtClose (-2147482032, ... ) == 0x0 00544 428 NtClose (-2147482020, ... ) == 0x0 00534 428 NtQueryDefaultUILanguage ... ) == 0x0 00545 428 NtAllocateVirtualMemory (-1, 1228800, 0, 4096, 4096, 260, ... 1228800, 4096, ) == 0x0 00546 428 NtQueryInstallUILanguage (2013024602, ... ) == 0x0 00547 428 NtQueryDefaultLocale (1, 1237876, ... ) == 0x0 00548 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00549 428 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1238732, 1, 96, 0} (24, {128, 156, new_msg, 0, 1238732, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\306\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355\22\0\0\0\0\0" ... {128, 156, reply, 0, 408, 428, 1589, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\306\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 408, 428, 1589, 0} (24, {128, 156, new_msg, 0, 1238732, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\306\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355\22\0\0\0\0\0" ... {128, 156, reply, 0, 408, 428, 1589, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\306\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355\22\0\0\0\0\0" ) ) == 0x0 00550 428 NtClose (80, ... ) == 0x0 00551 428 NtClose (88, ... ) == 0x0 00552 428 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 00553 428 NtUnmapViewOfSection (-1, 0x12edcc, ... ) == STATUS_NOT_MAPPED_VIEW 00554 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00555 428 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00556 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00557 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00558 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1236960, ... ) }, 1236960, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00559 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00560 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00561 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00562 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1237552, ... ) }, 1237552, ... ) == 0x0 00563 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 88, {status=0x0, info=1}, ) }, 3, 33, ... 88, {status=0x0, info=1}, ) == 0x0 00564 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00565 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00566 428 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 80, ... 92, ) == 0x0 00567 428 NtClose (80, ... ) == 0x0 00568 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x8f0000), 0x0, 921600, ) == 0x0 00569 428 NtClose (92, ... ) == 0x0 00570 428 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 00571 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00572 428 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 92, ... 80, ) == 0x0 00573 428 NtQuerySection (80, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00574 428 NtClose (92, ... ) == 0x0 00575 428 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71950000), 0x0, 933888, ) == 0x0 00576 428 NtClose (80, ... ) == 0x0 00577 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00578 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00579 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00580 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00581 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00582 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00583 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00584 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00585 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00586 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00587 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00588 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00589 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00590 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00591 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00592 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00593 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00594 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00595 428 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00596 428 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00597 428 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00598 428 NtAddAtom ( ("T\0h\0e\0m\0e\0P\0r\0o\0p\0S\0c\0r\0o\0l\0l\0B\0a\0r\0C\0t\0l\0", 42, 1238736, ... ) , 42, 1238736, ... ) == 0x0 00599 428 NtQueryDefaultUILanguage (1237452, ... 00600 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00601 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00602 428 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00603 428 NtClose (-2147482020, ... ) == 0x0 00604 428 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00605 428 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00606 428 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00607 428 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00608 428 NtClose (-2147482032, ... ) == 0x0 00609 428 NtClose (-2147482020, ... ) == 0x0 00599 428 NtQueryDefaultUILanguage ... ) == 0x0 00610 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00611 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1236304, ... ) }, 1236304, ... ) == 0x0 00612 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00613 428 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 80, ... 92, ) == 0x0 00614 428 NtClose (80, ... ) == 0x0 00615 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x8f0000), 0x0, 4096, ) == 0x0 00616 428 NtClose (92, ... ) == 0x0 00617 428 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 00618 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1235944, ... ) }, 1235944, ... ) == 0x0 00619 428 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1236644, (0x80100080, {24, 0, 0x40, 0, 1236644, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 0x0, 0, 5, 1, 96, 0, 0, ... 92, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 92, {status=0x0, info=1}, ) == 0x0 00620 428 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 92, ... 80, ) == 0x0 00621 428 NtClose (92, ... ) == 0x0 00622 428 NtMapViewOfSection (80, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x8f0000), {0, 0}, 4096, ) == 0x0 00623 428 NtClose (80, ... ) == 0x0 00624 428 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 00625 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1, 96, ... 80, {status=0x0, info=1}, ) }, 1, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00626 428 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 80, ... 92, ) == 0x0 00627 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x8f0000), 0x0, 4096, ) == 0x0 00628 428 NtQueryInformationFile (80, 1236264, 56, NetworkOpen, ... {status=0x0, info=56}, ) == 0x0 00629 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00630 428 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1236344, 1, 96, 0} (24, {128, 156, new_msg, 0, 1236344, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344\22\0\0\0\0\0" ... {128, 156, reply, 0, 408, 428, 1590, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 408, 428, 1590, 0} (24, {128, 156, new_msg, 0, 1236344, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344\22\0\0\0\0\0" ... {128, 156, reply, 0, 408, 428, 1590, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344\22\0\0\0\0\0" ) ) == 0x0 00631 428 NtClose (80, ... ) == 0x0 00632 428 NtClose (92, ... ) == 0x0 00633 428 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 00634 428 NtUnmapViewOfSection (-1, 0x12e478, ... ) == STATUS_NOT_MAPPED_VIEW 00635 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00636 428 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00637 428 NtUserSystemParametersInfo (104, 0, 1906151468, 0, ... ) == 0x1 00638 428 NtUserGetDC (0, ... ) == 0x1010053 00639 428 NtUserCallOneParam (16842835, 56, ... ) == 0x1 00640 428 NtUserSystemParametersInfo (38, 4, 1906153440, 0, ... ) == 0x1 00641 428 NtUserSystemParametersInfo (66, 12, 1238756, 0, ... ) == 0x1 00642 428 NtOpenProcessToken (-1, 0x8, ... 92, ) == 0x0 00643 428 NtAccessCheck (1393640, 92, 0x1, 1238160, 1238104, 56, 1238188, ... ) == STATUS_NO_IMPERSONATION_TOKEN 00644 428 NtClose (92, ... ) == 0x0 00645 428 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Control Panel\Desktop"}, ... 92, ) }, ... 92, ) == 0x0 00646 428 NtQueryValueKey (92, (92, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00647 428 NtClose (92, ... ) == 0x0 00648 428 NtUserSystemParametersInfo (41, 500, 1238256, 0, ... ) == 0x1 00649 428 NtAllocateVirtualMemory (-1, 1396736, 0, 4096, 4096, 4, ... 1396736, 4096, ) == 0x0 00650 428 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 92, ) }, ... 92, ) == 0x0 00651 428 NtQueryValueKey (92, (92, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00652 428 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 80, ) }, ... 80, ) == 0x0 00653 428 NtQueryValueKey (80, (80, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00654 428 NtClose (80, ... ) == 0x0 00655 428 NtClose (92, ... ) == 0x0 00656 428 NtUserSystemParametersInfo (102, 0, 1906153328, 0, ... ) == 0x1 00657 428 NtUserSystemParametersInfo (4130, 0, 1238780, 0, ... ) == 0x1 00658 428 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\LanguagePack"}, ... 92, ) }, ... 92, ) == 0x0 00659 428 NtEnumerateValueKey (92, 0, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 00660 428 NtClose (92, ... ) == 0x0 00661 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00662 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc03b 00663 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc03d 00664 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00665 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc03f 00666 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00667 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc041 00668 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00669 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc043 00670 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc045 00671 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00672 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc047 00673 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00674 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc049 00675 428 NtUserGetClassInfo (1905590272, 1238676, 1238628, 1238704, 0, ... ) == 0xc049 00676 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00677 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... 00678 428 NtAllocateVirtualMemory (-1, 6135808, 0, 4096, 4096, 32, ... 6135808, 4096, ) == 0x0 00677 428 NtUserRegisterClassExWOW ... ) == 0x810dc04b 00679 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00680 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc04d 00681 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00682 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc04f 00683 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc051 00684 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00685 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc053 00686 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00687 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc055 00688 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc057 00689 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00690 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc059 00691 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10013 00692 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc05b 00693 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00694 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc05d 00695 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00696 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc05f 00697 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00698 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc017 00699 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00700 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc019 00701 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10013 00702 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc018 00703 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00704 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc01a 00705 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00706 428 NtUserRegisterClassExWOW (1238512, 1238592, 1238576, 1238608, 0, 384, 0, ... ) == 0x810dc01c 00707 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00708 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc01e 00709 428 NtUserFindExistingCursorIcon (1238060, 1238076, 1238644, ... ) == 0x10011 00710 428 NtUserRegisterClassExWOW (1238572, 1238652, 1238636, 1238668, 0, 384, 0, ... ) == 0x810dc01b 00711 428 NtUserFindExistingCursorIcon (1238056, 1238072, 1238640, ... ) == 0x10011 00712 428 NtUserRegisterClassExWOW (1238568, 1238648, 1238632, 1238664, 0, 384, 0, ... ) == 0x810dc068 00713 428 NtUserFindExistingCursorIcon (1238064, 1238080, 1238648, ... ) == 0x10011 00714 428 NtUserRegisterClassExWOW (1238516, 1238596, 1238580, 1238612, 0, 384, 0, ... ) == 0x810dc06a 00715 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc03b 00716 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc03d 00717 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc03f 00718 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc041 00719 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc043 00720 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc045 00721 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc047 00722 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc049 00723 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc04b 00724 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc04d 00725 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc04f 00726 428 NtUserGetClassInfo (1999896576, 1241580, 1241532, 1241608, 0, ... ) == 0xc051 00727 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc053 00728 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc055 00729 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc059 00730 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc05b 00731 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc05d 00732 428 NtUserGetClassInfo (1999896576, 1241576, 1241528, 1241604, 0, ... ) == 0xc05f 00733 428 NtUserRegisterWindowMessage ( ("WOWLFChange", ... ) , ... ) == 0xc06b 00734 428 NtUserRegisterWindowMessage ( ("WOWDirChange", ... ) , ... ) == 0xc06c 00735 428 NtUserRegisterWindowMessage ( ("WOWCHOOSEFONT_GETLOGFONT", ... ) , ... ) == 0xc06d 00736 428 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 00737 428 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 00738 428 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 00739 428 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 00740 428 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 00741 428 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 00742 428 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 00743 428 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 00744 428 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 00745 428 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 00746 428 NtUserRegisterWindowMessage ( ("Shell IDList Array", ... ) , ... ) == 0xc073 00747 428 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 00748 428 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 00749 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\MDAC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00750 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00751 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00752 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00753 428 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 9502720, 262144, ) == 0x0 00754 428 NtAllocateVirtualMemory (-1, 9502720, 0, 4096, 4096, 4, ... 9502720, 4096, ) == 0x0 00755 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00756 428 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 9764864, 262144, ) == 0x0 00757 428 NtAllocateVirtualMemory (-1, 9764864, 0, 4096, 4096, 4, ... 9764864, 4096, ) == 0x0 00758 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00759 428 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 10027008, 262144, ) == 0x0 00760 428 NtAllocateVirtualMemory (-1, 10027008, 0, 4096, 4096, 4, ... 10027008, 4096, ) == 0x0 00761 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00762 428 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 10289152, 262144, ) == 0x0 00763 428 NtAllocateVirtualMemory (-1, 10289152, 0, 4096, 4096, 4, ... 10289152, 4096, ) == 0x0 00764 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00765 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00766 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00767 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00768 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 1237456, ... ) }, 1237456, ... ) == 0x0 00769 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00770 428 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 92, ... 80, ) == 0x0 00771 428 NtClose (92, ... ) == 0x0 00772 428 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa10000), 0x0, 90112, ) == 0x0 00773 428 NtClose (80, ... ) == 0x0 00774 428 NtUnmapViewOfSection (-1, 0xa10000, ... ) == 0x0 00775 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 1237772, ... ) }, 1237772, ... ) == 0x0 00776 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00777 428 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 80, ... 92, ) == 0x0 00778 428 NtQuerySection (92, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00779 428 NtClose (80, ... ) == 0x0 00780 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x1f850000), 0x0, 90112, ) == 0x0 00781 428 NtClose (92, ... ) == 0x0 00782 428 NtQueryDefaultLocale (1, 1239460, ... ) == 0x0 00783 428 NtAllocateVirtualMemory (-1, 9506816, 0, 4096, 4096, 4, ... 9506816, 4096, ) == 0x0 00784 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE"}, ... 92, ) }, ... 92, ) == 0x0 00785 428 NtClose (92, ... ) == 0x0 00786 428 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00787 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00788 428 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00789 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00790 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WININET.dll"}, ... 92, ) }, ... 92, ) == 0x0 00791 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76200000), 0x0, 618496, ) == 0x0 00792 428 NtClose (92, ... ) == 0x0 00793 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CRYPT32.dll"}, ... 92, ) }, ... 92, ) == 0x0 00794 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762c0000), 0x0, 565248, ) == 0x0 00795 428 NtClose (92, ... ) == 0x0 00796 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSASN1.dll"}, ... 92, ) }, ... 92, ) == 0x0 00797 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762a0000), 0x0, 61440, ) == 0x0 00798 428 NtClose (92, ... ) == 0x0 00799 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLEAUT32.dll"}, ... 92, ) }, ... 92, ) == 0x0 00800 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77120000), 0x0, 569344, ) == 0x0 00801 428 NtClose (92, ... ) == 0x0 00802 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLE32.DLL"}, ... 92, ) }, ... 92, ) == 0x0 00803 428 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x771b0000), 0x0, 1155072, ) == 0x0 00804 428 NtClose (92, ... ) == 0x0 00805 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\crypt32\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00806 428 NtAllocateVirtualMemory (-1, 1400832, 0, 4096, 4096, 4, ... 1400832, 4096, ) == 0x0 00807 428 NtAllocateVirtualMemory (-1, 1404928, 0, 4096, 4096, 4, ... 1404928, 4096, ) == 0x0 00808 428 NtAllocateVirtualMemory (-1, 1409024, 0, 4096, 4096, 4, ... 1409024, 4096, ) == 0x0 00809 428 NtCreateEvent (0x1f0003, {24, 52, 0x80, 1241616, 0, (0x1f0003, {24, 52, 0x80, 1241616, 0, "Global\crypt32LogoffEvent"}, 0, 0, ... ) }, 0, 0, ... ) == STATUS_ACCESS_DENIED 00810 428 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "Global\crypt32LogoffEvent"}, ... 92, ) }, ... 92, ) == 0x0 00811 428 NtAllocateVirtualMemory (-1, 1413120, 0, 4096, 4096, 4, ... 1413120, 4096, ) == 0x0 00812 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00813 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00814 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 80, ) }, ... 80, ) == 0x0 00815 428 NtQueryValueKey (80, (80, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (80, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 00816 428 NtClose (80, ... ) == 0x0 00817 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00818 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00819 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00820 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00821 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 80, ) }, ... 80, ) == 0x0 00822 428 NtQueryValueKey (80, (80, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00823 428 NtQueryValueKey (80, (80, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00824 428 NtQueryValueKey (80, (80, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00825 428 NtClose (80, ... ) == 0x0 00826 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 80, ) }, ... 80, ) == 0x0 00827 428 NtQueryValueKey (80, (80, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00828 428 NtQueryValueKey (80, (80, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00829 428 NtClose (80, ... ) == 0x0 00830 428 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00831 428 NtUserRegisterWindowMessage ( ("{FB8F0821-0164-101B-84ED-08002B2EC713}", ... ) , ... ) == 0xc07b 00832 428 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00833 428 NtOpenKey (0x9, {24, 28, 0x40, 0, 0, (0x9, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT\UserEra"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00834 428 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00835 428 NtAllocateVirtualMemory (-1, 1417216, 0, 8192, 4096, 4, ... 1417216, 8192, ) == 0x0 00836 428 NtCreateKey (0xf003f, {24, 84, 0x40, 0, 0, (0xf003f, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History"}, 0, 0x0, 0, ... 80, 2, ) }, 0, 0x0, 0, ... 80, 2, ) == 0x0 00837 428 NtQueryDefaultUILanguage (1239852, ... 00838 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00839 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00840 428 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00841 428 NtClose (-2147482020, ... ) == 0x0 00842 428 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00843 428 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00844 428 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00845 428 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00846 428 NtClose (-2147482032, ... ) == 0x0 00847 428 NtClose (-2147482020, ... ) == 0x0 00837 428 NtQueryDefaultUILanguage ... ) == 0x0 00848 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00849 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll"}, 1, 96, ... 96, {status=0x0, info=1}, ) }, 1, 96, ... 96, {status=0x0, info=1}, ) == 0x0 00850 428 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 96, ... 100, ) == 0x0 00851 428 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0xa10000), 0x0, 593920, ) == 0x0 00852 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00853 428 NtQueryDefaultLocale (1, 1237888, ... ) == 0x0 00854 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00855 428 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1238744, 1, 96, 0} (24, {128, 156, new_msg, 0, 1238744, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\250\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355\22\0\0\0\0\0" ... {128, 156, reply, 0, 408, 428, 1591, 0} " S\26\0\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\250\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 408, 428, 1591, 0} (24, {128, 156, new_msg, 0, 1238744, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\250\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355\22\0\0\0\0\0" ... {128, 156, reply, 0, 408, 428, 1591, 0} " S\26\0\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\250\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355\22\0\0\0\0\0" ) ) == 0x0 00856 428 NtClose (96, ... ) == 0x0 00857 428 NtClose (100, ... ) == 0x0 00858 428 NtUnmapViewOfSection (-1, 0xa10000, ... ) == 0x0 00859 428 NtUnmapViewOfSection (-1, 0x12edd8, ... ) == STATUS_NOT_MAPPED_VIEW 00860 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00861 428 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00862 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00863 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00864 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1236428, ... ) }, 1236428, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00865 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00866 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00867 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00868 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1237020, ... ) }, 1237020, ... ) == 0x0 00869 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 100, {status=0x0, info=1}, ) }, 3, 33, ... 100, {status=0x0, info=1}, ) == 0x0 00870 428 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00871 428 NtCreateKey (0x2001f, {24, 84, 0x40, 0, 0, (0x2001f, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, 0, 0x0, 0, ... 96, 2, ) }, 0, 0x0, 0, ... 96, 2, ) == 0x0 00872 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2_32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00873 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2_32.dll"}, 1241484, ... ) }, 1241484, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00874 428 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2_32.dll"}, 1241484, ... ) }, 1241484, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00875 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 1241484, ... ) }, 1241484, ... ) == 0x0 00876 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 00877 428 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 104, ... 108, ) == 0x0 00878 428 NtQuerySection (108, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00879 428 NtClose (104, ... ) == 0x0 00880 428 NtMapViewOfSection (108, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ab0000), 0x0, 86016, ) == 0x0 00881 428 NtClose (108, ... ) == 0x0 00882 428 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00883 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2HELP.dll"}, 1240680, ... ) }, 1240680, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00884 428 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2HELP.dll"}, 1240680, ... ) }, 1240680, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00885 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 1240680, ... ) }, 1240680, ... ) == 0x0 00886 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 5, 96, ... 108, {status=0x0, info=1}, ) }, 5, 96, ... 108, {status=0x0, info=1}, ) == 0x0 00887 428 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 108, ... 104, ) == 0x0 00888 428 NtQuerySection (104, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00889 428 NtClose (108, ... ) == 0x0 00890 428 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71aa0000), 0x0, 32768, ) == 0x0 00891 428 NtClose (104, ... ) == 0x0 00892 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00893 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00894 428 NtTestAlert (... ) == 0x0 00895 428 NtContinue (1244464, 1, ... 00896 428 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x490000,}, 4, ... ) == 0x0 00897 428 NtCreateEvent (0x1f0003, {24, 52, 0x80, 1245092, 0, (0x1f0003, {24, 52, 0x80, 1245092, 0, "VT_3"}, 1, 0, ... 104, ) }, 1, 0, ... 104, ) == 0x0 00898 428 NtCreateSection (0xe, {24, 0, 0x40, 1245092, 0, (0xe, {24, 0, 0x40, 1245092, 0, "\BaseNamedObjects\W32_Virtu"}, {27086, 0}, 64, 134217728, 0, ... 108, ) }, {27086, 0}, 64, 134217728, 0, ... 108, ) == 0x0 00899 428 NtMapViewOfSection (108, -1, (0x0), 0, 27086, 0x0, 27086, 2, 0, 64, ... (0xa10000), 0x0, 28672, ) == 0x0 00900 428 NtOpenProcessToken (-1, 0x20, ... 112, ) == 0x0 00901 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00902 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Rpc\PagedBuffers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00903 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Rpc"}, ... 116, ) }, ... 116, ) == 0x0 00904 428 NtQueryValueKey (116, (116, "MaxRpcSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00905 428 NtClose (116, ... ) == 0x0 00906 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe\RpcThreadPoolThrottle"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00907 428 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 116, ) == 0x0 00908 428 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 120, ) == 0x0 00909 428 NtQuerySystemTime (... {1086886150, 29873100}, ) == 0x0 00910 428 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 124, ) == 0x0 00911 428 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\Rpc"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00912 428 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 0x0, ) == 0x0 00913 428 NtQueryInformationProcess (-1, QuotaLimits, 32, ... {process info, class 1, size 32}, 0x0, ) == 0x0 00914 428 NtQueryInformationProcess (-1, VmCounters, 44, ... {process info, class 3, size 44}, 0x0, ) == 0x0 00915 428 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 128, ) == 0x0 00916 428 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 132, ) == 0x0 00917 428 NtAllocateVirtualMemory (-1, 1425408, 0, 4096, 4096, 4, ... 1425408, 4096, ) == 0x0 00918 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 136, ) }, ... 136, ) == 0x0 00919 428 NtOpenKey (0x20019, {24, 136, 0x40, 0, 0, (0x20019, {24, 136, 0x40, 0, 0, "ActiveComputerName"}, ... 140, ) }, ... 140, ) == 0x0 00920 428 NtQueryValueKey (140, (140, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (140, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (140, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 00921 428 NtClose (140, ... ) == 0x0 00922 428 NtClose (136, ... ) == 0x0 00923 428 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 136, ) == 0x0 00924 428 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 140, ) == 0x0 00925 428 NtDuplicateObject (-1, 136, -1, 0x0, 0, 2, ... 144, ) == 0x0 00926 428 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 00927 428 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 148, ) == 0x0 00928 428 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 00929 428 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 00930 428 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1243268, (0xc0100080, {24, 0, 0x40, 0, 1243268, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 152, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 152, {status=0x0, info=1}, ) == 0x0 00931 428 NtSetInformationFile (152, 1243324, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 00932 428 NtSetInformationFile (152, 1243316, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 00933 428 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 00934 428 NtWriteFile (152, 129, 0, 0, (152, 129, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 00935 428 NtAllocateVirtualMemory (-1, 1429504, 0, 4096, 4096, 4, ... 1429504, 4096, ) == 0x0 00936 428 NtReadFile (152, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (152, 129, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20' \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 00937 428 NtFsControlFile (152, 129, 0x0, 0x0, 0x11c017, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<\377\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20' \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<\377\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20' \0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 00938 428 NtFsControlFile (152, 129, 0x0, 0x0, 0x11c017, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0`\0\0\0\2\0\0\0H\0\0\0\0\0\37\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305 \0"\0(\262\25\0\21\0\0\0\0\0\0\0\20\0\0\0S\0e\0D\0e\0b\0u\0g\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 96, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \0(\262\25\0\21\0\0\0\0\0\0\0\20\0\0\0S\0e\0D\0e\0b\0u\0g\0P\0r\0i\0v\0i\0l\0e\0g\0e\0 (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0`\0\0\0\2\0\0\0H\0\0\0\0\0\37\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305 \0"\0(\262\25\0\21\0\0\0\0\0\0\0\20\0\0\0S\0e\0D\0e\0b\0u\0g\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 96, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) == 0x103 00939 428 NtFsControlFile (152, 129, 0x0, 0x0, 0x11c017, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=36}, (152, 129, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\317`\266}\277?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 00940 428 NtClose (148, ... ) == 0x0 00941 428 NtClose (152, ... ) == 0x0 00942 428 NtAdjustPrivilegesToken (112, 0, 1245096, 0, 0, 0, ... ) == 0x0 00943 428 NtClose (112, ... ) == 0x0 00944 428 NtAllocateVirtualMemory (-1, 0, 0, 65536, 4096, 4, ... 10616832, 65536, ) == 0x0 00945 428 NtQuerySystemInformation (ProcessesAndThreads, 65536, ... {system info, class 5, size 500}, 0x0, ) == 0x0 00946 428 NtCreateSection (0xf0007, 0x0, {12284, 0}, 4, 134217728, 0, ... 112, ) == 0x0 00947 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa30000), {0, 0}, 12288, ) == 0x0 00948 428 NtUnmapViewOfSection (-1, 0xa30000, ... ) == 0x0 00949 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa30000), {0, 0}, 12288, ) == 0x0 00950 428 NtFreeVirtualMemory (-1, (0xa20000), 0, 32768, ... (0xa20000), 65536, ) == 0x0 00951 428 NtUnmapViewOfSection (-1, 0xa30000, ... ) == 0x0 00952 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00953 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00954 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00955 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00956 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00957 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00958 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00959 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00960 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00961 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00962 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {616, 0}, ... 152, ) == 0x0 00963 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 148, ) }, ... 148, ) == 0x0 00964 428 NtMapViewOfSection (148, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ff90000), 0x0, 28672, ) == 0x0 00965 428 NtClose (148, ... ) == 0x0 00966 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 00967 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00968 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 00969 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00970 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 00971 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00972 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 00973 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00974 428 NtAllocateVirtualMemory (152, 0, 0, 1048576, 8192, 4, ... 21757952, 1048576, ) == 0x0 00975 428 NtAllocateVirtualMemory (152, 22798336, 0, 8192, 4096, 4, ... 22798336, 8192, ) == 0x0 00976 428 NtProtectVirtualMemory (152, (0x15be000), 4096, 260, ... (0x15be000), 4096, 4, ) == 0x0 00977 428 NtCreateThread (0x1f03ff, 0x0, 152, 1244008, 1244724, 1, ... 148, {616, 856}, ) == 0x0 00978 428 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1244852, 2012750850, 2012697848, -1} (24, {28, 56, new_msg, 0, 1244852, 2012750850, 2012697848, -1} "\0\0\0\0\1\0\1\0\0\0\25\0\0\0\0\0\224\0\0\0h\2\0\0X\3\0\0" ... {28, 56, reply, 0, 408, 428, 1592, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\224\0\0\0h\2\0\0X\3\0\0" ) ... {28, 56, reply, 0, 408, 428, 1592, 0} (24, {28, 56, new_msg, 0, 1244852, 2012750850, 2012697848, -1} "\0\0\0\0\1\0\1\0\0\0\25\0\0\0\0\0\224\0\0\0h\2\0\0X\3\0\0" ... {28, 56, reply, 0, 408, 428, 1592, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\224\0\0\0h\2\0\0X\3\0\0" ) ) == 0x0 00979 428 NtResumeThread (148, ... 1, ) == 0x0 00980 428 NtClose (152, ... ) == 0x0 00981 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00982 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00983 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {660, 0}, ... 152, ) == 0x0 00984 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 00985 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ff90000), 0x0, 28672, ) == 0x0 00986 428 NtClose (156, ... ) == 0x0 00987 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 00988 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00989 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 00990 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00991 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 00992 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00993 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 00994 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 00995 428 NtClose (152, ... ) == 0x0 00996 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 00997 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 00998 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {672, 0}, ... 152, ) == 0x0 00999 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01000 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ff90000), 0x0, 28672, ) == 0x0 01001 428 NtClose (156, ... ) == 0x0 01002 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01003 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01004 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01005 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01006 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01007 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01008 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01009 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\1\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01010 428 NtClose (152, ... ) == 0x0 01011 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01012 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01013 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {844, 0}, ... 152, ) == 0x0 01014 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01015 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01016 428 NtClose (156, ... ) == 0x0 01017 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01018 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01019 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01020 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01021 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01022 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01023 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01024 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01025 428 NtClose (152, ... ) == 0x0 01026 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01027 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01028 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {964, 0}, ... 152, ) == 0x0 01029 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01030 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ff70000), 0x0, 28672, ) == 0x0 01031 428 NtClose (156, ... ) == 0x0 01032 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01033 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\377\7", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01034 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01035 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\377\7", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01036 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01037 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\377\7", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01038 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01039 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\377\7", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01040 428 NtClose (152, ... ) == 0x0 01041 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01042 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01043 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {1060, 0}, ... 152, ) == 0x0 01044 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01045 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01046 428 NtClose (156, ... ) == 0x0 01047 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01048 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01049 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01050 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01051 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01052 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01053 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01054 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01055 428 NtClose (152, ... ) == 0x0 01056 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01057 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01058 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {1124, 0}, ... 152, ) == 0x0 01059 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01060 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01061 428 NtClose (156, ... ) == 0x0 01062 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01063 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01064 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01065 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01066 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01067 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01068 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01069 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01070 428 NtClose (152, ... ) == 0x0 01071 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01072 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01073 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {1368, 0}, ... 152, ) == 0x0 01074 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01075 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01076 428 NtClose (156, ... ) == 0x0 01077 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01078 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01079 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01080 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01081 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01082 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01083 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01084 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01085 428 NtClose (152, ... ) == 0x0 01086 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01087 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01088 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {1976, 0}, ... 152, ) == 0x0 01089 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01090 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01091 428 NtClose (156, ... ) == 0x0 01092 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01093 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01094 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01095 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01096 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01097 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01098 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01099 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01100 428 NtClose (152, ... ) == 0x0 01101 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01102 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01103 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {2020, 0}, ... 152, ) == 0x0 01104 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01105 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01106 428 NtClose (156, ... ) == 0x0 01107 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01108 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01109 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01110 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01111 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01112 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01113 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01114 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01115 428 NtClose (152, ... ) == 0x0 01116 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01117 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01118 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {160, 0}, ... 152, ) == 0x0 01119 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01120 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01121 428 NtClose (156, ... ) == 0x0 01122 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01123 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01124 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01125 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01126 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01127 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01128 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01129 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01130 428 NtClose (152, ... ) == 0x0 01131 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01132 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01133 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {208, 0}, ... 152, ) == 0x0 01134 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01135 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01136 428 NtClose (156, ... ) == 0x0 01137 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01138 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01139 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01140 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01141 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01142 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01143 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01144 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01145 428 NtClose (152, ... ) == 0x0 01146 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01147 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01148 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {240, 0}, ... 152, ) == 0x0 01149 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01150 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01151 428 NtClose (156, ... ) == 0x0 01152 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01153 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01154 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01155 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01156 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01157 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01158 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01159 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01160 428 NtClose (152, ... ) == 0x0 01161 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01162 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01163 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {256, 0}, ... 152, ) == 0x0 01164 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01165 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01166 428 NtClose (156, ... ) == 0x0 01167 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01168 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01169 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01170 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01171 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01172 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01173 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01174 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01175 428 NtClose (152, ... ) == 0x0 01176 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01177 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01178 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {268, 0}, ... 152, ) == 0x0 01179 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01180 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01181 428 NtClose (156, ... ) == 0x0 01182 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01183 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01184 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01185 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01186 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01187 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01188 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01189 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01190 428 NtClose (152, ... ) == 0x0 01191 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01192 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01193 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {296, 0}, ... 152, ) == 0x0 01194 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01195 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01196 428 NtClose (156, ... ) == 0x0 01197 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01198 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01199 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01200 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01201 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01202 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01203 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01204 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01205 428 NtClose (152, ... ) == 0x0 01206 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01207 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01208 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {408, 0}, ... 152, ) == 0x0 01209 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01210 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01211 428 NtClose (156, ... ) == 0x0 01212 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01213 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01214 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01215 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01216 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01217 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01218 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01219 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01220 428 NtClose (152, ... ) == 0x0 01221 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01222 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01223 428 NtOpenProcess (0x2a, {24, 0, 0x0, 0, 0, 0x0}, {456, 0}, ... 152, ) == 0x0 01224 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 156, ) }, ... 156, ) == 0x0 01225 428 NtMapViewOfSection (156, 152, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01226 428 NtClose (156, ... ) == 0x0 01227 428 NtProtectVirtualMemory (152, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01228 428 NtWriteVirtualMemory (152, 0x77f7e603, (152, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01229 428 NtProtectVirtualMemory (152, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01230 428 NtWriteVirtualMemory (152, 0x77f7eaf3, (152, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01231 428 NtProtectVirtualMemory (152, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01232 428 NtWriteVirtualMemory (152, 0x77f7e6a3, (152, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01233 428 NtProtectVirtualMemory (152, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01234 428 NtWriteVirtualMemory (152, 0x77f7e6b3, (152, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01235 428 NtClose (152, ... ) == 0x0 01236 428 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa20000), {0, 0}, 12288, ) == 0x0 01237 428 NtUnmapViewOfSection (-1, 0xa20000, ... ) == 0x0 01238 428 NtClose (112, ... ) == 0x0 01239 428 NtClose (104, ... ) == 0x0 01240 428 NtQueryPerformanceCounter (... {117166548, 0}, {3579545, 0}, ) == 0x0 01241 428 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01242 428 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 10616832, 65536, ) == 0x0 01243 428 NtAllocateVirtualMemory (-1, 10616832, 0, 4096, 4096, 4, ... 10616832, 4096, ) == 0x0 01244 428 NtAllocateVirtualMemory (-1, 10620928, 0, 8192, 4096, 4, ... 10620928, 8192, ) == 0x0 01245 428 NtAllocateVirtualMemory (-1, 10629120, 0, 4096, 4096, 4, ... 10629120, 4096, ) == 0x0 01246 428 NtAllocateVirtualMemory (-1, 10633216, 0, 4096, 4096, 4, ... 10633216, 4096, ) == 0x0 01247 428 NtAllocateVirtualMemory (-1, 0, 0, 6, 12288, 64, ... 10682368, 4096, ) == 0x0 01248 428 NtProtectVirtualMemory (-1, (0xa30000), 6, 64, ... 01249 428 NtContinue (-136118484, 0, ... 01248 428 NtProtectVirtualMemory ... ) == STATUS_ACCESS_VIOLATION 01250 428 NtFreeVirtualMemory (-1, (0xa30000), 0, 32768, ... (0xa30000), 4096, ) == 0x0 01251 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\U:\WORK\PACKED.EXE"}, 1241688, ... ) }, 1241688, ... ) == 0x0 01252 428 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\U:\WORK\PACKED.EXE"}, 7, 2113568, ... 104, {status=0x0, info=1}, ) }, 7, 2113568, ... 104, {status=0x0, info=1}, ) == 0x0 01253 428 NtSetInformationFile (104, 1241664, 40, Basic, ... ) == STATUS_ACCESS_DENIED 01254 428 NtClose (104, ... ) == 0x0 01255 428 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1241932, (0x80100080, {24, 0, 0x40, 0, 1241932, "\??\u:\work\packed.exe"}, 0x0, 0, 1, 1, 2097252, 0, 0, ... 104, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 2097252, 0, 0, ... 104, {status=0x0, info=1}, ) == 0x0 01256 428 NtQueryInformationFile (104, 1242868, 8, AttributeFlag, ... {status=0x0, info=8}, ) == 0x0 01257 428 NtQueryInformationFile (104, 1242840, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01258 428 NtQueryInformationFile (104, 1242792, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01259 428 NtAllocateVirtualMemory (-1, 1433600, 0, 8192, 4096, 4, ... 1433600, 8192, ) == 0x0 01260 428 NtQueryInformationFile (104, 1431152, 4094, Stream, ... {status=0x0, info=38}, ) == 0x0 01261 428 NtQueryInformationFile (104, 1241336, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01262 428 NtQueryInformationFile (104, 1241180, 4, Ea, ... {status=0x0, info=4}, ) == 0x0 01263 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\SYSTEM32\SZSVC.EXE"}, 1240072, ... ) }, 1240072, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01264 428 NtCreateFile (0x40110080, {24, 0, 0x40, 0, 1241188, (0x40110080, {24, 0, 0x40, 0, 1241188, "\??\C:\WINDOWS\System32\szsvc.exe"}, 0x0, 32, 0, 5, 100, 0, 0, ... }, 0x0, 32, 0, 5, 100, 0, 0, ... 01265 428 NtClose (-2147482020, ... ) == 0x0 01264 428 NtCreateFile ... 112, {status=0x0, info=2}, ) == 0x0 01266 428 NtQueryVolumeInformationFile (112, 1240560, 536, Attribute, ... {status=0x0, info=22}, ) == 0x0 01267 428 NtQueryInformationFile (112, 1240520, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01268 428 NtQueryVolumeInformationFile (104, 1240560, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 01269 428 NtQueryVolumeInformationFile (104, 1240244, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01270 428 NtSetInformationFile (112, 1240348, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 01271 428 NtCreateSection (0xf001f, 0x0, 0x0, 2, 134217728, 104, ... 152, ) == 0x0 01272 428 NtMapViewOfSection (152, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xa30000), {0, 0}, 221184, ) == 0x0 01273 428 NtClose (152, ... ) == 0x0 01274 428 NtWriteFile (112, 0, 0, 0, (112, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\211\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\370\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0V^\2517\22?\307d\22?\307d\22?\307d5\371\272d\11?\307d5\371\252d\234?\307d5\371\251d ?\307d\2217\232d\20?\307d\3210\232d\35?\307d\22?\306d\277?\307d5\371\265d\16?\307d5\371\277d\23?\307dRich\22?\307d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\221G\273`\327[]\6\204\315\264*\213I\15\22PE\0\0L\1\10\0\16e\340E\0\0\0\0\0\0\0\0\340\0\3\1\13\1\10\0\0\320\1\0\0\300\0\0\0\0\0\0\0\0\11\0\0\320\5\0\0\340\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0p\11\0\0\20\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\320\5\0\20\1\0\0\0\240\3\0\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\321\5\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.tex", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 01275 428 NtWriteFile (112, 0, 0, 0, (112, 0, 0, 0, "\17\314\313\221\310E\307t\256\202\354\213\241r(c\300\361\2Zs\31633\247\326\212iaWk\20|_\211Vw\251Q\243\225\13\270Hj\27\364\24L\2"\20\272\230\4\254\31\343\300\32\350\352T"\330Rw\214\312\2JD\211h\225rz\10$\302-i\211x;\305\2\215D$\270K\260G5 \221\10\356\311\310\7\307\24$"\264q\7 \226\253\373?X\22C\246Mqr%\223!b\276\252\365M\5\370\15*jq\300\255\253e\256:\247\204\217\2\374\240\276\274\6\243E\118_R\27\231\234\316VtUc\253\251\234\24\21[\10\246Z\10\246.M\6\34-\221\271V\17EE\12n\323\305\255\306m\312\267\370`\243\217\274\335E\35u\25?\242\205\320\333\330k\277\24zR\327\372\337]\27!\212\5\216\13L8\355;^\267\250\367\242\366\26\340q&\27*q\324\232\210\206P\236\37R \346"\265*\360\276\342W\254FW\261\214\257E\314V\272Q\251\37\260\242\353\214\210\223\4\12V2\212p\366\350\3515\276wQ\305(wqO\272\335C\340\337\363bTb>I7\342S\361\327$uq=0\31Z\22\272B\213\324\260\311\250`1piGY\33\347\356`!\34y]\237,\222\241A\234,\240\312B\371\241M\263\257\351\271\4\362D\267cl\322\324\261\233j\270\37[\35\217\231\313\210\214/UqNv.\342)0LqIKq.\12\33\264\36M\306\313\11=\345W\340B\233\13,! \271\2QF\33\21\306*\23\300\224\232\331\37\331Qt\332\320\244\16)J\313\255:_\30\355\332\302\7\3\253\17\230\324\260\214H!U<\34*\6\22\307\33\203\320\1\323\244\303\224\371a\36m\26X\276*\5\306b\276\337\5\212\251\224`\370Pg\314\332\253\224E\252\1\224\257\265e", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) \20\272\230\4\254\31\343\300\32\350\352T (112, 0, 0, 0, "\17\314\313\221\310E\307t\256\202\354\213\241r(c\300\361\2Zs\31633\247\326\212iaWk\20|_\211Vw\251Q\243\225\13\270Hj\27\364\24L\2"\20\272\230\4\254\31\343\300\32\350\352T"\330Rw\214\312\2JD\211h\225rz\10$\302-i\211x;\305\2\215D$\270K\260G5 \221\10\356\311\310\7\307\24$"\264q\7 \226\253\373?X\22C\246Mqr%\223!b\276\252\365M\5\370\15*jq\300\255\253e\256:\247\204\217\2\374\240\276\274\6\243E\118_R\27\231\234\316VtUc\253\251\234\24\21[\10\246Z\10\246.M\6\34-\221\271V\17EE\12n\323\305\255\306m\312\267\370`\243\217\274\335E\35u\25?\242\205\320\333\330k\277\24zR\327\372\337]\27!\212\5\216\13L8\355;^\267\250\367\242\366\26\340q&\27*q\324\232\210\206P\236\37R \346"\265*\360\276\342W\254FW\261\214\257E\314V\272Q\251\37\260\242\353\214\210\223\4\12V2\212p\366\350\3515\276wQ\305(wqO\272\335C\340\337\363bTb>I7\342S\361\327$uq=0\31Z\22\272B\213\324\260\311\250`1piGY\33\347\356`!\34y]\237,\222\241A\234,\240\312B\371\241M\263\257\351\271\4\362D\267cl\322\324\261\233j\270\37[\35\217\231\313\210\214/UqNv.\342)0LqIKq.\12\33\264\36M\306\313\11=\345W\340B\233\13,! \271\2QF\33\21\306*\23\300\224\232\331\37\331Qt\332\320\244\16)J\313\255:_\30\355\332\302\7\3\253\17\230\324\260\214H!U<\34*\6\22\307\33\203\320\1\323\244\303\224\371a\36m\26X\276*\5\306b\276\337\5\212\251\224`\370Pg\314\332\253\224E\252\1\224\257\265e", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) \264q\7 \226\253\373?X\22C\246Mqr%\223!b\276\252\365M\5\370\15*jq\300\255\253e\256:\247\204\217\2\374\240\276\274\6\243E\118_R\27\231\234\316VtUc\253\251\234\24\21[\10\246Z\10\246.M\6\34-\221\271V\17EE\12n\323\305\255\306m\312\267\370`\243\217\274\335E\35u\25?\242\205\320\333\330k\277\24zR\327\372\337]\27!\212\5\216\13L8\355;^\267\250\367\242\366\26\340q&\27*q\324\232\210\206P\236\37R \346 (112, 0, 0, 0, "\17\314\313\221\310E\307t\256\202\354\213\241r(c\300\361\2Zs\31633\247\326\212iaWk\20|_\211Vw\251Q\243\225\13\270Hj\27\364\24L\2"\20\272\230\4\254\31\343\300\32\350\352T"\330Rw\214\312\2JD\211h\225rz\10$\302-i\211x;\305\2\215D$\270K\260G5 \221\10\356\311\310\7\307\24$"\264q\7 \226\253\373?X\22C\246Mqr%\223!b\276\252\365M\5\370\15*jq\300\255\253e\256:\247\204\217\2\374\240\276\274\6\243E\118_R\27\231\234\316VtUc\253\251\234\24\21[\10\246Z\10\246.M\6\34-\221\271V\17EE\12n\323\305\255\306m\312\267\370`\243\217\274\335E\35u\25?\242\205\320\333\330k\277\24zR\327\372\337]\27!\212\5\216\13L8\355;^\267\250\367\242\366\26\340q&\27*q\324\232\210\206P\236\37R \346"\265*\360\276\342W\254FW\261\214\257E\314V\272Q\251\37\260\242\353\214\210\223\4\12V2\212p\366\350\3515\276wQ\305(wqO\272\335C\340\337\363bTb>I7\342S\361\327$uq=0\31Z\22\272B\213\324\260\311\250`1piGY\33\347\356`!\34y]\237,\222\241A\234,\240\312B\371\241M\263\257\351\271\4\362D\267cl\322\324\261\233j\270\37[\35\217\231\313\210\214/UqNv.\342)0LqIKq.\12\33\264\36M\306\313\11=\345W\340B\233\13,! \271\2QF\33\21\306*\23\300\224\232\331\37\331Qt\332\320\244\16)J\313\255:_\30\355\332\302\7\3\253\17\230\324\260\214H!U<\34*\6\22\307\33\203\320\1\323\244\303\224\371a\36m\26X\276*\5\306b\276\337\5\212\251\224`\370Pg\314\332\253\224E\252\1\224\257\265e", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 01276 428 NtWriteFile (112, 0, 0, 0, (112, 0, 0, 0, "\215\350\230\246\224;\310\37\355x\253T\326.(G\340\314\250\12\3756\4\227\273\360/\231\3273_~\320I\361\317\3332c\342G~\234\36\3\301\31~ES\365\346\276h'\230\11\250"^\364i\307I\253\301z[\242\241FJ\230-\242\5\23C%N*=6w\222\24\363C\207F\354\214\342\212\376f)X\243\312S\245\6n{\354\302\242\234BtU\363\265L\214\336\276V\203c\33\205\250\313\312\5\347\27+\345&2\304\263\162\201-\364\304\272\310\22\252\21+d\316\244}\321\213\352\276R\227\342\35\26>r\335FZA\265\277\221J\271\254&\322\346Y\27-\277u\242\13\223\357\201\244\300O\261B\236\303\344\324\372\32\322e\317\236\3376\274\225\31\202\240\314\25\361\347\22\372\320\221\34\240vo\330]\301)y6r\243\277X\325\364\313p[5f;\32\365\201\205\226=\363\27V\242\374\246\311\304\237\108\251\205\16\317\264V\360\242\33~\230\335\13m\375\247\370*\360L\210v\252\310E\325\317\366\231\332\2V\26O1\253\7\356\14i@\304\21\215\242\275\353\256\234\247\217\255\24$\354\213G\320X\1S\354\216+&\356\263\263\320\240V\315\214\7\307\313u\2513\376\246!\334A\223\15\204'\344j\224\16\305\203\373\227\351z\352e\301\337yBC\231\203\276\340x\245\20\371\4ecoA+U\273Tz$\205\203\363\222Z\27\224_\327\301\17\177\353&\264\2121c\307\231\367\22M\12\325\207\341\23P\3\302\276\201\317\214\251\361\376\242\210wY\31@\224\371\322\6\252\312\253\212X\1o%et\361lDs\5\31\342d\241\334\354\253+W\37\345\353\17\255\216\342\203>\361\276{\340te\316\257\350\377\244\32\31\5\367\243m\334y0q\33\211r\321\305'\233\264\211W\216\324\337\12\317\370\341xh\37", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) ^\364i\307I\253\301z[\242\241FJ\230-\242\5\23C%N*=6w\222\24\363C\207F\354\214\342\212\376f)X\243\312S\245\6n{\354\302\242\234BtU\363\265L\214\336\276V\203c\33\205\250\313\312\5\347\27+\345&2\304\263\162\201-\364\304\272\310\22\252\21+d\316\244}\321\213\352\276R\227\342\35\26>r\335FZA\265\277\221J\271\254&\322\346Y\27-\277u\242\13\223\357\201\244\300O\261B\236\303\344\324\372\32\322e\317\236\3376\274\225\31\202\240\314\25\361\347\22\372\320\221\34\240vo\330]\301)y6r\243\277X\325\364\313p[5f;\32\365\201\205\226=\363\27V\242\374\246\311\304\237\108\251\205\16\317\264V\360\242\33~\230\335\13m\375\247\370*\360L\210v\252\310E\325\317\366\231\332\2V\26O1\253\7\356\14i@\304\21\215\242\275\353\256\234\247\217\255\24$\354\213G\320X\1S\354\216+&\356\263\263\320\240V\315\214\7\307\313u\2513\376\246!\334A\223\15\204'\344j\224\16\305\203\373\227\351z\352e\301\337yBC\231\203\276\340x\245\20\371\4ecoA+U\273Tz$\205\203\363\222Z\27\224_\327\301\17\177\353&\264\2121c\307\231\367\22M\12\325\207\341\23P\3\302\276\201\317\214\251\361\376\242\210wY\31@\224\371\322\6\252\312\253\212X\1o%et\361lDs\5\31\342d\241\334\354\253+W\37\345\353\17\255\216\342\203>\361\276{\340te\316\257\350\377\244\32\31\5\367\243m\334y0q\33\211r\321\305'\233\264\211W\216\324\337\12\317\370\341xh\37", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 01277 428 NtWriteFile (112, 0, 0, 0, (112, 0, 0, 0, "k\224F\255\305/\2664\353SF\265\26f\312\346^d"g->\350J\341\364\324\312\326\304M \33e\221\213\277\21\255h\357q\215\233\361Y+\s\255\351\205MB\345\11/\372\374\233\301\201!\364\275=T\354\240yV%\177\333:|\223\222\236P\11\222\302F\12\352Y\273\6J\225y\317_Z\3\276\304\314\206\320\365a\300\236^?R[\27,\364;]\306\340\217Fk\265\23111,E\201C\202\352\213m?\17\216\25\252\20\17\26\2\253\361\265\253\333\316D\17\205\201\311\212\363\233W\272\37\257i\372J\314d\2469m\332\12\216\15\14\246E}\345\200\222\246gT?\366\24\364\20\370`I\4vGOz\211<\17\235\301\276S\206\277\351\317\364\23&\221\273\277\330*C\373\333sX\15\227a\337\307\252\207\233K\1\305\370\350!\23\276\231\33`\30\221\374P\371k\362\21D\263KZ\3744TT\6n\217\14\321+\10\351;#\336\333GS\333;T\362\13\260\365\363C\304\304\337I+MXq\224~\2146:bgW\202\201ooj\356\24MY\231\311\271G\247\233:\232E\337\216\203\260\3713m\24\211\303\30\1\3F\321\224\345{\326\204\342\216\207\327`\321\233\240m\217\357\377\247\3555\16\371\274-\204\271{/R\31"\317\14\247M\3229dZ\15\314*i\12V\344\213\372\334\247\1z6\374\20V\302\346\24j\26*\226\27\275\241\34)Uh\332\15\347\325\252K\301\251\273\mU\0*x\326\244\10\371W\200I+\350\24^\272J\347JC=\5\211\211\332\3769\204>\214\36BYqe\0%\25\22x;\230RL?\353b\32\342\12:\25\347\302\1K\240\321j\205\316t\324\273\21\35M\237U{\347\210F9\2674\226\353\355\204\222\343\367!\216H\332+b\3368\312B", 36352, 0x0, 0, ... {status=0x0, info=36352}, ) g->\350J\341\364\324\312\326\304M \33e\221\213\277\21\255h\357q\215\233\361Y+\s\255\351\205MB\345\11/\372\374\233\301\201!\364\275=T\354\240yV%\177\333:|\223\222\236P\11\222\302F\12\352Y\273\6J\225y\317_Z\3\276\304\314\206\320\365a\300\236^?R[\27,\364;]\306\340\217Fk\265\23111,E\201C\202\352\213m?\17\216\25\252\20\17\26\2\253\361\265\253\333\316D\17\205\201\311\212\363\233W\272\37\257i\372J\314d\2469m\332\12\216\15\14\246E}\345\200\222\246gT?\366\24\364\20\370`I\4vGOz\211<\17\235\301\276S\206\277\351\317\364\23&\221\273\277\330*C\373\333sX\15\227a\337\307\252\207\233K\1\305\370\350!\23\276\231\33`\30\221\374P\371k\362\21D\263KZ\3744TT\6n\217\14\321+\10\351;#\336\333GS\333;T\362\13\260\365\363C\304\304\337I+MXq\224~\2146:bgW\202\201ooj\356\24MY\231\311\271G\247\233:\232E\337\216\203\260\3713m\24\211\303\30\1\3F\321\224\345{\326\204\342\216\207\327`\321\233\240m\217\357\377\247\3555\16\371\274-\204\271{/R\31 (112, 0, 0, 0, "k\224F\255\305/\2664\353SF\265\26f\312\346^d"g->\350J\341\364\324\312\326\304M \33e\221\213\277\21\255h\357q\215\233\361Y+\s\255\351\205MB\345\11/\372\374\233\301\201!\364\275=T\354\240yV%\177\333:|\223\222\236P\11\222\302F\12\352Y\273\6J\225y\317_Z\3\276\304\314\206\320\365a\300\236^?R[\27,\364;]\306\340\217Fk\265\23111,E\201C\202\352\213m?\17\216\25\252\20\17\26\2\253\361\265\253\333\316D\17\205\201\311\212\363\233W\272\37\257i\372J\314d\2469m\332\12\216\15\14\246E}\345\200\222\246gT?\366\24\364\20\370`I\4vGOz\211<\17\235\301\276S\206\277\351\317\364\23&\221\273\277\330*C\373\333sX\15\227a\337\307\252\207\233K\1\305\370\350!\23\276\231\33`\30\221\374P\371k\362\21D\263KZ\3744TT\6n\217\14\321+\10\351;#\336\333GS\333;T\362\13\260\365\363C\304\304\337I+MXq\224~\2146:bgW\202\201ooj\356\24MY\231\311\271G\247\233:\232E\337\216\203\260\3713m\24\211\303\30\1\3F\321\224\345{\326\204\342\216\207\327`\321\233\240m\217\357\377\247\3555\16\371\274-\204\271{/R\31"\317\14\247M\3229dZ\15\314*i\12V\344\213\372\334\247\1z6\374\20V\302\346\24j\26*\226\27\275\241\34)Uh\332\15\347\325\252K\301\251\273\mU\0*x\326\244\10\371W\200I+\350\24^\272J\347JC=\5\211\211\332\3769\204>\214\36BYqe\0%\25\22x;\230RL?\353b\32\342\12:\25\347\302\1K\240\321j\205\316t\324\273\21\35M\237U{\347\210F9\2674\226\353\355\204\222\343\367!\216H\332+b\3368\312B", 36352, 0x0, 0, ... {status=0x0, info=36352}, ) , 36352, 0x0, 0, ... {status=0x0, info=36352}, ) == 0x0 01278 428 NtUnmapViewOfSection (-1, 0xa30000, ... ) == 0x0 01279 428 NtSetInformationFile (112, 1242792, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01280 428 NtClose (104, ... ) == 0x0 01281 428 NtClose (112, ... ) == 0x0 01282 428 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 01283 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe"}, 1239084, ... ) }, 1239084, ... ) == 0x0 01284 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe"}, 1239776, ... ) }, 1239776, ... ) == 0x0 01285 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\SYSTEM32\SZSVC.EXE"}, 1239696, ... ) }, 1239696, ... ) == 0x0 01286 428 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\SYSTEM32\SZSVC.EXE"}, 7, 2113568, ... 112, {status=0x0, info=1}, ) }, 7, 2113568, ... 112, {status=0x0, info=1}, ) == 0x0 01287 428 NtSetInformationFile (112, 1239672, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01288 428 NtClose (112, ... ) == 0x0 01289 428 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1239676, (0xc0100080, {24, 0, 0x40, 0, 1239676, "\??\C:\WINDOWS\SYSTEM32\SZSVC.EXE"}, 0x0, 0, 1, 1, 96, 0, 0, ... 112, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 96, 0, 0, ... 112, {status=0x0, info=1}, ) == 0x0 01290 428 NtQueryInformationFile (112, 1239728, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01291 428 NtQueryInformationFile (112, 1239728, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01292 428 NtCreateSection (0xf0007, 0x0, {220672, 0}, 4, 134217728, 112, ... 104, ) == 0x0 01293 428 NtMapViewOfSection (104, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa30000), {0, 0}, 221184, ) == 0x0 01294 428 NtUnmapViewOfSection (-1, 0xa30000, ... ) == 0x0 01295 428 NtClose (104, ... ) == 0x0 01296 428 NtSetInformationFile (112, 1239732, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01297 428 NtClose (112, ... ) == 0x0 01298 428 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\SYSTEM32\SZSVC.EXE"}, 7, 2113568, ... 112, {status=0x0, info=1}, ) }, 7, 2113568, ... 112, {status=0x0, info=1}, ) == 0x0 01299 428 NtSetInformationFile (112, 1239676, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01300 428 NtClose (112, ... ) == 0x0 01301 428 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe"}, 5, 96, ... 112, {status=0x0, info=1}, ) }, 5, 96, ... 112, {status=0x0, info=1}, ) == 0x0 01302 428 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 112, ... 104, ) == 0x0 01303 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01304 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 152, ) }, ... 152, ) == 0x0 01305 428 NtQueryValueKey (152, (152, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01306 428 NtClose (152, ... ) == 0x0 01307 428 NtQueryVolumeInformationFile (112, 1239084, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01308 428 NtOpenMutant (0x120001, {24, 52, 0x0, 0, 0, (0x120001, {24, 52, 0x0, 0, 0, "ShimCacheMutex"}, ... 152, ) }, ... 152, ) == 0x0 01309 428 NtWaitForSingleObject (152, 0, {-1000000, -1}, ... ) == 0x0 01310 428 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "ShimSharedMemory"}, ... 156, ) }, ... 156, ) == 0x0 01311 428 NtMapViewOfSection (156, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xa30000), {0, 0}, 57344, ) == 0x0 01312 428 NtReleaseMutant (152, ... 0x0, ) == 0x0 01313 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1237068, ... ) }, 1237068, ... ) == 0x0 01314 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 160, {status=0x0, info=1}, ) }, 5, 96, ... 160, {status=0x0, info=1}, ) == 0x0 01315 428 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 160, ... 164, ) == 0x0 01316 428 NtClose (160, ... ) == 0x0 01317 428 NtMapViewOfSection (164, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xa40000), 0x0, 106496, ) == 0x0 01318 428 NtClose (164, ... ) == 0x0 01319 428 NtUnmapViewOfSection (-1, 0xa40000, ... ) == 0x0 01320 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1237384, ... ) }, 1237384, ... ) == 0x0 01321 428 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 164, {status=0x0, info=1}, ) }, 5, 96, ... 164, {status=0x0, info=1}, ) == 0x0 01322 428 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 164, ... 160, ) == 0x0 01323 428 NtQuerySection (160, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01324 428 NtClose (164, ... ) == 0x0 01325 428 NtMapViewOfSection (160, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75f40000), 0x0, 118784, ) == 0x0 01326 428 NtClose (160, ... ) == 0x0 01327 428 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 160, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 160, {status=0x0, info=1}, ) == 0x0 01328 428 NtQueryInformationFile (160, 1237672, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01329 428 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 160, ... 164, ) == 0x0 01330 428 NtMapViewOfSection (164, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xa40000), 0x0, 1028096, ) == 0x0 01331 428 NtQueryInformationFile (160, 1237768, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01332 428 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01333 428 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01334 428 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 01335 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01336 428 NtQueryDirectoryFile (168, 0, 0, 0, 1235332, 616, BothDirectory, 1, (168, 0, 0, 0, 1235332, 616, BothDirectory, 1, "szsvc.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01337 428 NtClose (168, ... ) == 0x0 01338 428 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01339 428 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01340 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe"}, 1234720, ... ) }, 1234720, ... ) == 0x0 01341 428 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0 01342 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01343 428 NtQueryDirectoryFile (168, 0, 0, 0, 1234080, 616, BothDirectory, 1, (168, 0, 0, 0, 1234080, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01344 428 NtClose (168, ... ) == 0x0 01345 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01346 428 NtQueryDirectoryFile (168, 0, 0, 0, 1234080, 616, BothDirectory, 1, (168, 0, 0, 0, 1234080, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01347 428 NtClose (168, ... ) == 0x0 01348 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01349 428 NtQueryDirectoryFile (168, 0, 0, 0, 1234080, 616, BothDirectory, 1, (168, 0, 0, 0, 1234080, 616, BothDirectory, 1, "szsvc.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01350 428 NtClose (168, ... ) == 0x0 01351 428 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01352 428 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01353 428 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01354 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01355 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 168, ) == 0x0 01356 428 NtQueryInformationToken (168, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01357 428 NtClose (168, ... ) == 0x0 01358 428 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01359 428 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\szsvc.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01360 428 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01361 428 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01362 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe"}, 1237000, ... ) }, 1237000, ... ) == 0x0 01363 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01364 428 NtQueryDirectoryFile (168, 0, 0, 0, 1236360, 616, BothDirectory, 1, (168, 0, 0, 0, 1236360, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01365 428 NtClose (168, ... ) == 0x0 01366 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01367 428 NtQueryDirectoryFile (168, 0, 0, 0, 1236360, 616, BothDirectory, 1, (168, 0, 0, 0, 1236360, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01368 428 NtClose (168, ... ) == 0x0 01369 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01370 428 NtQueryDirectoryFile (168, 0, 0, 0, 1236360, 616, BothDirectory, 1, (168, 0, 0, 0, 1236360, 616, BothDirectory, 1, "szsvc.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01371 428 NtClose (168, ... ) == 0x0 01372 428 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01373 428 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01374 428 NtWaitForSingleObject (152, 0, {-1000000, -1}, ... ) == 0x0 01375 428 NtQueryVolumeInformationFile (112, 1237644, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01376 428 NtQueryInformationFile (112, 1237624, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01377 428 NtQueryInformationFile (112, 1237664, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01378 428 NtReleaseMutant (152, ... 0x0, ) == 0x0 01379 428 NtUnmapViewOfSection (-1, 0xa40000, ... ) == 0x0 01380 428 NtClose (164, ... ) == 0x0 01381 428 NtClose (160, ... ) == 0x0 01382 428 NtQuerySection (104, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01383 428 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\szsvc.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01384 428 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 01385 428 NtOpenProcessToken (-1, 0xa, ... 160, ) == 0x0 01386 428 NtQueryInformationToken (160, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 01387 428 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01388 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 164, ) }, ... 164, ) == 0x0 01389 428 NtQueryValueKey (164, (164, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (164, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01390 428 NtQueryValueKey (164, (164, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (164, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01391 428 NtClose (164, ... ) == 0x0 01392 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 164, ) }, ... 164, ) == 0x0 01393 428 NtQueryValueKey (164, (164, "ExecutableTypes", Partial, 0, ... ) , Partial, 0, ... ) == STATUS_BUFFER_TOO_SMALL 01394 428 NtQueryValueKey (164, (164, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) , Partial, 260, ... TitleIdx=0, Type=7, Data= (164, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) }, 260, ) == 0x0 01395 428 NtClose (164, ... ) == 0x0 01396 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01397 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 164, ) }, ... 164, ) == 0x0 01398 428 NtQueryValueKey (164, (164, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01399 428 NtClose (164, ... ) == 0x0 01400 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01401 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01402 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01403 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01404 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01405 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01406 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01407 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01408 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01409 428 NtQueryDefaultLocale (1, 1238456, ... ) == 0x0 01410 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 164, ) }, ... 164, ) == 0x0 01411 428 NtEnumerateKey (164, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name= (164, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 01412 428 NtOpenKey (0x20019, {24, 164, 0x40, 0, 0, (0x20019, {24, 164, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 168, ) }, ... 168, ) == 0x0 01413 428 NtQueryValueKey (168, (168, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (168, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 01414 428 NtQueryValueKey (168, (168, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (168, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01415 428 NtClose (168, ... ) == 0x0 01416 428 NtEnumerateKey (164, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 01417 428 NtClose (164, ... ) == 0x0 01418 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01419 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01420 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01421 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01422 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01423 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01424 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01425 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01426 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01427 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01428 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01429 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01430 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01431 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01432 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01433 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01434 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01435 428 NtClose (164, ... ) == 0x0 01436 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01437 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01438 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01439 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01440 428 NtClose (164, ... ) == 0x0 01441 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01442 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01443 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01444 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01445 428 NtClose (164, ... ) == 0x0 01446 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01447 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01448 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01449 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01450 428 NtClose (164, ... ) == 0x0 01451 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01452 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01453 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01454 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01455 428 NtClose (164, ... ) == 0x0 01456 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01457 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01458 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01459 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01460 428 NtClose (164, ... ) == 0x0 01461 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01462 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01463 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01464 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01465 428 NtClose (164, ... ) == 0x0 01466 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01467 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01468 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01469 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01470 428 NtClose (164, ... ) == 0x0 01471 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01472 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01473 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01474 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01475 428 NtClose (164, ... ) == 0x0 01476 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01477 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01478 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01479 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01480 428 NtClose (164, ... ) == 0x0 01481 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01482 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01483 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01484 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01485 428 NtClose (164, ... ) == 0x0 01486 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01487 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01488 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01489 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01490 428 NtClose (164, ... ) == 0x0 01491 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01492 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01493 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01494 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01495 428 NtClose (164, ... ) == 0x0 01496 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01497 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01498 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01499 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01500 428 NtClose (164, ... ) == 0x0 01501 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01502 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01503 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01504 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01505 428 NtClose (164, ... ) == 0x0 01506 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01507 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 164, ) }, ... 164, ) == 0x0 01508 428 NtQueryValueKey (164, (164, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (164, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (164, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 01509 428 NtClose (164, ... ) == 0x0 01510 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01511 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 164, ) == 0x0 01512 428 NtQueryInformationToken (164, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01513 428 NtClose (164, ... ) == 0x0 01514 428 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01515 428 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 01516 428 NtOpenProcessToken (-1, 0xa, ... 164, ) == 0x0 01517 428 NtDuplicateToken (164, 0xc, {24, 0, 0x0, 0, 1238976, 0x0}, 0, 2, ... 168, ) == 0x0 01518 428 NtClose (164, ... ) == 0x0 01519 428 NtAccessCheck (1438128, 168, 0x1, 1239104, 1239048, 56, 1239132, ... (0x1), ) == 0x0 01520 428 NtClose (168, ... ) == 0x0 01521 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 168, ) }, ... 168, ) == 0x0 01522 428 NtQueryValueKey (168, (168, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (168, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01523 428 NtClose (168, ... ) == 0x0 01524 428 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 168, ) }, ... 168, ) == 0x0 01525 428 NtQuerySymbolicLinkObject (168, ... (168, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 01526 428 NtClose (168, ... ) == 0x0 01527 428 NtQueryInformationFile (112, 1237436, 528, Name, ... {status=0x0, info=58}, ) == 0x0 01528 428 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01529 428 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01530 428 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe"}, 1236116, ... ) }, 1236116, ... ) == 0x0 01531 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01532 428 NtQueryDirectoryFile (168, 0, 0, 0, 1235476, 616, BothDirectory, 1, (168, 0, 0, 0, 1235476, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01533 428 NtClose (168, ... ) == 0x0 01534 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01535 428 NtQueryDirectoryFile (168, 0, 0, 0, 1235476, 616, BothDirectory, 1, (168, 0, 0, 0, 1235476, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01536 428 NtClose (168, ... ) == 0x0 01537 428 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 168, {status=0x0, info=1}, ) }, 3, 16417, ... 168, {status=0x0, info=1}, ) == 0x0 01538 428 NtQueryDirectoryFile (168, 0, 0, 0, 1235476, 616, BothDirectory, 1, (168, 0, 0, 0, 1235476, 616, BothDirectory, 1, "szsvc.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 01539 428 NtClose (168, ... ) == 0x0 01540 428 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01541 428 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01542 428 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01543 428 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 168, ) == 0x0 01544 428 NtQueryInformationToken (168, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01545 428 NtClose (168, ... ) == 0x0 01546 428 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 168, ) }, ... 168, ) == 0x0 01547 428 NtOpenKey (0x20019, {24, 168, 0x40, 0, 0, (0x20019, {24, 168, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 164, ) }, ... 164, ) == 0x0 01548 428 NtClose (168, ... ) == 0x0 01549 428 NtQueryValueKey (164, (164, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01550 428 NtQueryValueKey (164, (164, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=1, Data= (164, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) }, 162, ) == 0x0 01551 428 NtClose (164, ... ) == 0x0 01552 428 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 10747904, 4096, ) == 0x0 01553 428 NtAllocateVirtualMemory (-1, 10747904, 0, 4096, 4096, 4, ... 10747904, 4096, ) == 0x0 01554 428 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 164, ) }, ... 164, ) == 0x0 01555 428 NtQueryValueKey (164, (164, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01556 428 NtClose (164, ... ) == 0x0 01557 428 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01558 428 NtQueryInformationToken (160, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 01559 428 NtQueryInformationToken (160, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 01560 428 NtClose (160, ... ) == 0x0 01561 428 NtCreateProcessEx (1241712, 2035711, 0, -1, 0, 104, 0, 0, 0, ... ) == 0x0 01562 428 NtOpenSection (0xe, {24, 52, 0x0, 0, 0, (0xe, {24, 52, 0x0, 0, 0, "W32_Virtu"}, ... 164, ) }, ... 164, ) == 0x0 01563 428 NtMapViewOfSection (164, 160, (0x0), 0, 27086, 0x0, 27086, 2, 1048576, 64, ... (0x7ffa0000), 0x0, 28672, ) == 0x0 01564 428 NtClose (164, ... ) == 0x0 01565 428 NtProtectVirtualMemory (160, (0x77f7e603), 5, 64, ... (0x77f7e000), 4096, 32, ) == 0x0 01566 428 NtWriteVirtualMemory (160, 0x77f7e603, (160, 0x77f7e603, "\350\214=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01567 428 NtProtectVirtualMemory (160, (0x77f7eaf3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01568 428 NtWriteVirtualMemory (160, 0x77f7eaf3, (160, 0x77f7eaf3, "\350\3518\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01569 428 NtProtectVirtualMemory (160, (0x77f7e6a3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01570 428 NtWriteVirtualMemory (160, 0x77f7e6a3, (160, 0x77f7e6a3, "\350@=\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01571 428 NtProtectVirtualMemory (160, (0x77f7e6b3), 5, 64, ... (0x77f7e000), 4096, 64, ) == 0x0 01572 428 NtWriteVirtualMemory (160, 0x77f7e6b3, (160, 0x77f7e6b3, "\350==\2\10", 5, ... 0x0, ) , 5, ... 0x0, ) == 0x0 01573 428 NtSetInformationProcess (160, PriorityClass, {process info, class 18, size 2}, 512, ... ) == 0x0 01574 428 NtQueryInformationProcess (160, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=872,ParentPid=408,}, 0x0, ) == 0x0 01575 428 NtReadVirtualMemory (160, 0x7ffdf008, 4, ... (160, 0x7ffdf008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 01576 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01577 428 NtAllocateVirtualMemory (-1, 1441792, 0, 8192, 4096, 4, ... 1441792, 8192, ) == 0x0 01578 428 NtReadVirtualMemory (160, 0x400000, 4096, ... (160, 0x400000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\211\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\370\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0V^\2517\22?\307d\22?\307d\22?\307d5\371\272d\11?\307d5\371\252d\234?\307d5\371\251d ?\307d\2217\232d\20?\307d\3210\232d\35?\307d\22?\306d\277?\307d5\371\265d\16?\307d5\371\277d\23?\307dRich\22?\307d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\221G\273`\327[]\6\204\315\264*\213I\15\22PE\0\0L\1\10\0\16e\340E\0\0\0\0\0\0\0\0\340\0\3\1\13\1\10\0\0\320\1\0\0\300\0\0\0\0\0\0\0\0\11\0\0\320\5\0\0\340\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0p\11\0\0\20\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\320\5\0\20\1\0\0\0\240\3\0\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\321\5\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.tex", 4096, ) , 4096, ) == 0x0 01579 428 NtReadVirtualMemory (160, 0x43a000, 256, ... (160, 0x43a000, 256, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\30\0\0\0\30\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0X\240\3\0V\0\0\0\344\4\0\0\0\0\0\0\15\12PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING", 256, ) urn:schemas-microsoft-com:asm.v1 (160, 0x43a000, 256, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\30\0\0\0\30\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0X\240\3\0V\0\0\0\344\4\0\0\0\0\0\0\15\12PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING", 256, ) 1.0 (160, 0x43a000, 256, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\30\0\0\0\30\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0X\240\3\0V\0\0\0\344\4\0\0\0\0\0\0\15\12PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING", 256, ) , 256, ) == 0x0 01580 428 NtReadVirtualMemory (160, 0x43a018, 24, ... (160, 0x43a018, 24, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200", 24, ) , 24, ) == 0x0 01581 428 NtReadVirtualMemory (160, 0x43a030, 24, ... (160, 0x43a030, 24, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0", 24, ) , 24, ) == 0x0 01582 428 NtReadVirtualMemory (160, 0x43a048, 16, ... (160, 0x43a048, 16, ... "X\240\3\0V\0\0\0\344\4\0\0\0\0\0\0", 16, ) , 16, ) == 0x0 01583 428 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\szsvc.exe.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01584 428 NtQueryInformationProcess (160, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=872,ParentPid=408,}, 0x0, ) == 0x0 01585 428 NtAllocateVirtualMemory (-1, 0, 0, 1708, 4096, 4, ... 10813440, 4096, ) == 0x0 01586 428 NtAllocateVirtualMemory (160, 0, 0, 1910, 4096, 4, ... 65536, 4096, ) == 0x0 01587 428 NtWriteVirtualMemory (160, 0x10000, (160, 0x10000, "=\0:\0:\0=\0:\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0p\0o\0l\0y\0u\0n\0p\0a\0c\0k\0\0\0=\0E\0x\0i\0t\0C\0o\0d\0e\0=\00\00\00\00\00\00\00\02\0\0\0=\0U\0:\0=\0U\0:\0\\0s\0t\0a\0r\0t\0u\0p\0s\0c\0r\0i\0p\0t\0s\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0C\0L\0I\0E\0N\0T\0N\0A\0M\0E\0=\0C\0o\0n\0s\0o\0l\0e\0\0\0C\0o\0m\0m\0o\0n\0P\0r\0o\0g\0r\0a\0m\0F\0i\0l\0e\0s\0=\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0C\0O\0M\0", 1910, ... 0x0, ) , 1910, ... 0x0, ) == 0x0 01588 428 NtAllocateVirtualMemory (160, 0, 0, 1708, 4096, 4, ... 131072, 4096, ) == 0x0 01589 428 NtWriteVirtualMemory (160, 0x20000, (160, 0x20000, "\0\20\0\0\254\6\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0$\0\10\2\220\2\0\0\0\0\0\0\374\0\376\0\230\4\0\0:\0<\0\230\5\0\0t\0v\0\324\5\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0:\0<\0L\6\0\0\36\0 \0\210\6\0\0\0\0\2\0\250\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1708, ... 0x0, ) , 1708, ... 0x0, ) == 0x0 01590 428 NtWriteVirtualMemory (160, 0x7ffdf010, (160, 0x7ffdf010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 01591 428 NtWriteVirtualMemory (160, 0x7ffdf1e8, (160, 0x7ffdf1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 01592 428 NtFreeVirtualMemory (-1, (0xa50000), 0, 32768, ... (0xa50000), 4096, ) == 0x0 01593 428 NtAllocateVirtualMemory (160, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 01594 428 NtAllocateVirtualMemory (160, 1236992, 0, 8192, 4096, 4, ... 1236992, 8192, ) == 0x0 01595 428 NtProtectVirtualMemory (160, (0x12e000), 4096, 260, ... (0x12e000), 4096, 4, ) == 0x0 01596 428 NtCreateThread (0x1f03ff, 0x0, 160, 1239976, 1240696, 1, ... 164, {872, 876}, ) == 0x0 01597 428 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 1378696, 1376256, 1396744, 1241796} (24, {168, 196, new_msg, 0, 1378696, 1376256, 1396744, 1241796} "\210\6\31\1\0\0\1\0\2$\370w U\367w\243\0\0\0\244\0\0\0h\3\0\0l\3\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0:\0<\0\244\6\31\1p\0\0\0\240\0\0\0\0\0\0\0X\240C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0<\0\340\6\31\1\0\360\375\177\0\0\0\0\0\0\242\0\220\36\242\0" ... {168, 196, reply, 0, 408, 428, 1615, 0} "\250\232\26\0\0\0\1\0\0\0\0\0 U\367w\240\0\0\0\244\0\0\0h\3\0\0l\3\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0:\0<\0\244\6\31\1p\0\0\0\240\0\0\0\0\0\0\0X\240C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0<\0\340\6\31\1\0\360\375\177\0\0\0\0\0\0\242\0\220\36\242\0" ) ... {168, 196, reply, 0, 408, 428, 1615, 0} (24, {168, 196, new_msg, 0, 1378696, 1376256, 1396744, 1241796} "\210\6\31\1\0\0\1\0\2$\370w U\367w\243\0\0\0\244\0\0\0h\3\0\0l\3\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0:\0<\0\244\6\31\1p\0\0\0\240\0\0\0\0\0\0\0X\240C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0<\0\340\6\31\1\0\360\375\177\0\0\0\0\0\0\242\0\220\36\242\0" ... {168, 196, reply, 0, 408, 428, 1615, 0} "\250\232\26\0\0\0\1\0\0\0\0\0 U\367w\240\0\0\0\244\0\0\0h\3\0\0l\3\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0:\0<\0\244\6\31\1p\0\0\0\240\0\0\0\0\0\0\0X\240C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0<\0\340\6\31\1\0\360\375\177\0\0\0\0\0\0\242\0\220\36\242\0" ) ) == 0x0 01598 428 NtResumeThread (164, ... 1, ) == 0x0 01599 428 NtClose (112, ... ) == 0x0 01600 428 NtClose (104, ... ) == 0x0 01601 428 NtTerminateProcess (0, 0, ... ) == 0x0 01602 428 NtClose (96, ... ) == 0x0 01603 428 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 01604 428 NtClose (100, ... ) == 0x0 01605 428 NtClose (80, ... ) == 0x0 01606 428 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 01607 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc03b 01608 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01609 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc03d 01610 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01611 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc03f 01612 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01613 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc041 01614 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01615 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc043 01616 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01617 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc045 01618 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01619 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc047 01620 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01621 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc049 01622 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01623 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc04b 01624 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01625 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc04d 01626 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01627 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc04f 01628 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01629 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc051 01630 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01631 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc053 01632 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01633 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc057 01634 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01635 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc059 01636 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01637 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc05b 01638 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01639 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc05d 01640 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01641 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc05f 01642 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01643 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc017 01644 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01645 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc019 01646 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01647 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc018 01648 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01649 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc01a 01650 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01651 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc01c 01652 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01653 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc01e 01654 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01655 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc01b 01656 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01657 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc068 01658 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01659 428 NtUserGetClassInfo (1905590272, 1244380, 1244332, 1244408, 0, ... ) == 0xc06a 01660 428 NtUserUnregisterClass (1244384, 1905590272, 1244372, ... ) == 0x1 01661 428 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 01662 428 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 01663 428 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x1,}, 4, ... ) == 0x0 01664 428 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 01665 428 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 01666 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc03b 01667 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01668 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc03d 01669 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01670 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc03f 01671 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01672 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc041 01673 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01674 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc043 01675 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01676 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc045 01677 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01678 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc047 01679 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01680 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc049 01681 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01682 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc04b 01683 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01684 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc04d 01685 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01686 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc04f 01687 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01688 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc051 01689 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01690 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc053 01691 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01692 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc057 01693 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01694 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc059 01695 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01696 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc05b 01697 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01698 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc05d 01699 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01700 428 NtUserGetClassInfo (1999896576, 1244380, 1244332, 1244408, 0, ... ) == 0xc05f 01701 428 NtUserUnregisterClass (1244384, 1999896576, 1244372, ... ) == 0x1 01702 428 NtFreeVirtualMemory (-1, (0xa40000), 4096, 32768, ... (0xa40000), 4096, ) == 0x0 01703 428 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, -1, 4199054, 4310894, 4423228} (24, {20, 48, new_msg, 0, -1, 4199054, 4310894, 4423228} "\0\0\0\0\3\0\1\0\220~C\0C:\W\0\0\0\0" ... {20, 48, reply, 0, 408, 428, 1623, 0} "\0\0\0\0\3\0\1\0\0\0\0\0C:\W\0\0\0\0" ) ... {20, 48, reply, 0, 408, 428, 1623, 0} (24, {20, 48, new_msg, 0, -1, 4199054, 4310894, 4423228} "\0\0\0\0\3\0\1\0\220~C\0C:\W\0\0\0\0" ... {20, 48, reply, 0, 408, 428, 1623, 0} "\0\0\0\0\3\0\1\0\0\0\0\0C:\W\0\0\0\0" ) ) == 0x0 01704 428 NtTerminateProcess (-1, 0, ... 01705 428 NtClose (44, ... ) == 0x0