Summary:
NtAddAtom(>) | 1 | NtUserGetThreadDesktop(>) | 1 | NtQueryVirtualMemory(>) | 5 | NtQueryInformationProcess(>) | 18 |
NtCallbackReturn(>) | 1 | NtAdjustPrivilegesToken(>) | 2 | NtSetInformationProcess(>) | 5 | NtUserRegisterWindowMessage(>) | 18 |
NtClearEvent(>) | 1 | NtContinue(>) | 2 | NtSetInformationThread(>) | 5 | NtOpenSection(>) | 22 |
NtConnectPort(>) | 1 | NtCreateIoCompletion(>) | 2 | NtOpenThreadToken(>) | 6 | NtQueryAttributesFile(>) | 22 |
NtCreateSemaphore(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtQueryVolumeInformationFile(>) | 6 | NtOpenProcessTokenEx(>) | 27 |
NtEnumerateValueKey(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtFsControlFile(>) | 7 | NtOpenThreadTokenEx(>) | 27 |
NtFreeVirtualMemory(>) | 1 | NtOpenEvent(>) | 2 | NtQueryDefaultLocale(>) | 7 | NtQueryKey(>) | 28 |
NtGdiCreateBitmap(>) | 1 | NtReadFile(>) | 2 | NtQueryDirectoryFile(>) | 7 | NtMapViewOfSection(>) | 31 |
NtGdiInit(>) | 1 | NtSetEvent(>) | 2 | NtQuerySection(>) | 7 | NtQueryInformationToken(>) | 31 |
NtGdiQueryFontAssocInfo(>) | 1 | NtSetThreadExecutionState(>) | 2 | NtOpenProcessToken(>) | 8 | NtDeviceIoControlFile(>) | 42 |
NtGdiSelectBitmap(>) | 1 | NtUserGetDC(>) | 2 | NtQueryDefaultUILanguage(>) | 8 | NtAllocateVirtualMemory(>) | 45 |
NtOpenKeyedEvent(>) | 1 | NtUserQueryWindow(>) | 2 | NtQueryInformationFile(>) | 8 | NtOpenFile(>) | 47 |
NtOpenProcess(>) | 1 | NtWriteFile(>) | 2 | NtUnmapViewOfSection(>) | 8 | NtUserFindExistingCursorIcon(>) | 52 |
NtQueryInstallUILanguage(>) | 1 | NtAccessCheck(>) | 3 | NtCreateFile(>) | 9 | NtUserRegisterClassExWOW(>) | 61 |
NtQueryObject(>) | 1 | NtDuplicateObject(>) | 3 | NtQueryDebugFilterState(>) | 9 | NtQuerySystemInformation(>) | 73 |
NtQuerySystemTime(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtRequestWaitReplyPort(>) | 11 | NtFlushInstructionCache(>) | 78 |
NtRegisterThreadTerminatePort(>) | 1 | NtUserCallOneParam(>) | 3 | NtUserSystemParametersInfo(>) | 11 | NtDelayExecution(>) | 84 |
NtSecureConnectPort(>) | 1 | NtCreateMutant(>) | 4 | NtCreateEvent(>) | 13 | NtQueryValueKey(>) | 98 |
NtTestAlert(>) | 1 | NtSetInformationObject(>) | 4 | NtSetInformationFile(>) | 14 | NtOpenKey(>) | 147 |
NtUserCallNoParam(>) | 1 | NtGdiGetStockObject(>) | 5 | NtCreateKey(>) | 15 | NtProtectVirtualMemory(>) | 158 |
NtUserGetObjectInformation(>) | 1 | NtOpenSymbolicLinkObject(>) | 5 | NtCreateSection(>) | 15 | NtClose(>) | 213 |
NtUserGetProcessWindowStation(>) | 1 | NtQuerySymbolicLinkObject(>) | 5 | NtSetValueKey(>) | 17 |
, ) , ) == 0x0 01184 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\254\314\11=\246\323\211\250~\367\356\360\204\257\12\2011#V\342\326\325\205\263\377\22\257w(\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01185 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01186 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01187 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01188 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01189 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01190 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01191 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01192 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01193 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\264\177\370\226c\254'S<\267\315\237\363@\0\277\301\21bF\355\15\5\13g&\371vw\31\333et\356*\354\240\\232\275\261\247[\264\231M\14&\207a\207\277:\306\25\328\232@\233\245-GQ\274 WK\335\316v\204\2262/\5\277\17Z\23", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\264\177\370\226c\254'S<\267\315\237\363@\0\277\301\21bF\355\15\5\13g&\371vw\31\333et\356*\354\240\\232\275\261\247[\264\231M\14&\207a\207\277:\306\25\328\232@\233\245-GQ\274 WK\335\316v\204\2262/\5\277\17Z\23", 80, ... ) , 80, ... ) == 0x0 01194 1736 NtClose (-2147482128, ... ) == 0x0 01184 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\304U^\271]\13\250@\302\23\246^^\335\275\211H[\265\33\377\242\22\10\4V\274\12\27\26\336\5\1`f\225\27\376\247\256}\341J*By\216\241\362T\4@^\340\306n\256\275\232\6T\253\33\341\20\37\341\300y\204\35\275\253\(\362\377~O)\324\352N\341\343\362\345uf\262\10\3061.\226\32\3460\347n\310\32\21\15\217\246\33\5\312$\315\375\330a\34 ~\211\3713*\215\16B\2\323\11%\327\246\202z|\320\346/*\341\2012N\322\243.0Lp\324\340\347\305\240\263\213\367\247\336\10\317\263\374\376\37\355S\271\236\360\263F\25xpI\265\265<\266\25\357\205\30\5\336\205`\270\221\324\3626H\352\201\23M_\24\300\37\208Bg\330I\7E\33aU\227\356\325P\36_qn\20\4\305\337\273\15\304\322\21g\227G*\350!\310 H\334zG\375\10\322t\252\345\35q\37qC@*\277", ) , ) == 0x0 01195 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\254\314\11=\246\323\211\250~\367\356\360\204\257\12\2011#V\342\326lO1#V\342\326\325\205\263\377\22\257w(\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01196 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01197 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01198 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01199 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01200 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01201 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01202 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01203 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01204 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\251\353\367\266k9c\322\307l7\201\264z\215X\324UC\206\257\223\225$\264\300\12\36\263\331\314\220x\304\214\340\367D\23\374\340\16\205\352\232 \224%\365\202a\262l\315\222\232G\255\2003\267\272{#E\352_\201~\371\213\337\256-\233\5\7\201q", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\251\353\367\266k9c\322\307l7\201\264z\215X\324UC\206\257\223\225$\264\300\12\36\263\331\314\220x\304\214\340\367D\23\374\340\16\205\352\232 \224%\365\202a\262l\315\222\232G\255\2003\267\272{#E\352_\201~\371\213\337\256-\233\5\7\201q", 80, ... ) , 80, ... ) == 0x0 01205 1736 NtClose (-2147482128, ... ) == 0x0 01195 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\273Q\321\35^\207w:\226\374\264-\16\221*\224\371\221\247\350=\272\205\\303\36\312\213\275\217\275\32\350\11\250+\345\16\303\322\247\331\260,i\2727\234t\330&\32)\10i\227<\251\32\334-\371\326#\336\364\330^\363\360\240\200\351#\300^\13\325vP\250\312\244Z~QIX\374\36\310Xi\213(\211[\236\4%\373Dp\266\352\15\337o\371\315\223n\306)\242)\371\302&+\6"Z\2466\1\375"\320\217G\202\0,6\312\21\362\242\352\0\335\262\315\215J\312\33\13\352\267E#\321;\12\177\331\317\207\247F&\214\352\201\234\327?\16\360\265\337\357!M\34\301)s+k\222\254-\347+a\271\210\224`\335\222P""\225\247\21J\341b\231b\203t\260e, ) Z\2466\1\375 ... {status=0x0, info=256}, "\273Q\321\35^\207w:\226\374\264-\16\221*\224\371\221\247\350=\272\205\\303\36\312\213\275\217\275\32\350\11\250+\345\16\303\322\247\331\260,i\2727\234t\330&\32)\10i\227<\251\32\334-\371\326#\336\364\330^\363\360\240\200\351#\300^\13\325vP\250\312\244Z~QIX\374\36\310Xi\213(\211[\236\4%\373Dp\266\352\15\337o\371\315\223n\306)\242)\371\302&+\6"Z\2466\1\375"\320\217G\202\0,6\312\21\362\242\352\0\335\262\315\215J\312\33\13\352\267E#\321;\12\177\331\317\207\247F&\214\352\201\234\327?\16\360\265\337\357!M\34\301)s+k\222\254-\347+a\271\210\224`\335\222P""\225\247\21J\341b\231b\203t\260e, ) ... {status=0x0, info=256}, "\273Q\321\35^\207w:\226\374\264-\16\221*\224\371\221\247\350=\272\205\\303\36\312\213\275\217\275\32\350\11\250+\345\16\303\322\247\331\260,i\2727\234t\330&\32)\10i\227<\251\32\334-\371\326#\336\364\330^\363\360\240\200\351#\300^\13\325vP\250\312\244Z~QIX\374\36\310Xi\213(\211[\236\4%\373Dp\266\352\15\337o\371\315\223n\306)\242)\371\302&+\6"Z\2466\1\375"\320\217G\202\0,6\312\21\362\242\352\0\335\262\315\215J\312\33\13\352\267E#\321;\12\177\331\317\207\247F&\214\352\201\234\327?\16\360\265\337\357!M\34\301)s+k\222\254-\347+a\271\210\224`\335\222P""\225\247\21J\341b\231b\203t\260e, ) , ) == 0x0 01206 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\254\314\11=\246\323\211\250~\367\356\360\204\257\12\2011#V\342\326lO1#V\342\326lO1#V\342\326\325\205\263\377\22\257w(\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01207 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01208 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01209 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01210 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01211 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01212 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01213 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01214 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01215 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\34}\372\336\257\240\2\305&\2\363\341\361K\246\300\341\377F\376\241o,\253\2002\304-\326\220\25\24\232\36623\234\265X\214\251'\207\23*\253\275\350\22\335\272\242@LbW\304\330H\376\223\22M\305\315\317<"\2430\202\214r\365\2\312UP", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\34}\372\336\257\240\2\305&\2\363\341\361K\246\300\341\377F\376\241o,\253\2002\304-\326\220\25\24\232\36623\234\265X\214\251'\207\23*\253\275\350\22\335\272\242@LbW\304\330H\376\223\22M\305\315\317<"\2430\202\214r\365\2\312UP", 80, ... ) \2430\202\214r\365\2\312UP", 80, ... ) == 0x0 01216 1736 NtClose (-2147482128, ... ) == 0x0 01206 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\273\10\26B\236\327\367)\231\274(\311^\274\204<\217ZQ=\23\270=4\224w)\236\230\347\20(Kt\204\317l\355\206\227\T|B\372\221&\327\301+\215lY\375'\321\27\367\301,O\25,\327\276\356\23;\237\267\22\1i\314Q\14\202\224\366\225\347\220\314\330\327@\260\2407\355\220\17is\333\264\326\3043|\361\2575^O\270\240\251\37RJ\200s\257\370\354s\260[\273\246\21\267\254\256\336\23=\10\207\347\314Z\25\34E\2166u\332]RM1$D\227'\3>QWo\211o\340\322\33p\10\210\11#>\34H\274\252?@B\373\302\341\14Z\223j[\323a\17d\253\261E\215\16{\24\227i\303\37\237*\326\316\215P", ) == 0x0 01228 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\254\314\11=\246\323\211\250~\367\356\360\204\257\12\2011#V\342\326lO1#V\342\326lO1#V\342\326lO1#V\342\326lO1#V\342\326\325\205\263\377\22\257w(\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01229 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01230 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01231 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01232 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01233 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01234 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01235 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01236 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01237 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\344\260\252\17\214\306\327B\313\22\354#z\201M\366\263\4%V\3170\216k\214YQ\32\357M\210/\263>\272\14\226\326\213\272\365\300;\336;\332\257\264\322\216\353\366\321I\356\211^\364\301\30\226\207\371\253\267\37\14,#\215\244\355=\236\311\255\320\327\33i", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\344\260\252\17\214\306\327B\313\22\354#z\201M\366\263\4%V\3170\216k\214YQ\32\357M\210/\263>\272\14\226\326\213\272\365\300;\336;\332\257\264\322\216\353\366\321I\356\211^\364\301\30\226\207\371\253\267\37\14,#\215\244\355=\236\311\255\320\327\33i", 80, ... ) , 80, ... ) == 0x0 01238 1736 NtClose (-2147482128, ... ) == 0x0 01228 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\210\216f\334\211\221P_\230\314+\235\26{c\254\344X\325\34\204\376\321;\353\214Q\315/!\15\340j\25<\3312\220\12=a\355\316\326\227\211\24\230\352\11\212(\22T \26\346\35\22\22%Co\313a\240\201\324\213\307Z\317u\222\13l\351%\337\307\17\332\37\27zqX\252\331t\317\311\306\30\272)I\323\247\243\333r\264\337\227\212f&2M\227\35\211\206|\332\350f\304\32P\267&|\6\224XL\1\2352\206\271`w\13J!w\322\301\2425\13w\327\315)$F\342\15\235\314bcxEc\304H\322\363\2720\256\204\13^\307\326\34'\340E\220\16\215\365\36\275&\250q\5\256\377\213+\35\243^.\2\23\264\205\17\36\337\317]\224\11f{\367g\220m\254\314\31a\221o\212A\350\608z\346\24K\26e*\327F\35\245\274\346\356aI\263\2421dIKR\2\350\224\333\32j^\16\274\316\232", ) , ) == 0x0 01239 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\254\314\11=\246\323\211\250~\367\356\360\204\257\12\2011#V\342\326lO1#V\342\326lO1#V\342\326lO1#V\342\326lO1#V\342\326lO1#V\342\326\325\205\263\377\22\257w(\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01240 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01241 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01242 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01243 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01244 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01245 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01246 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01247 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01248 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\37\243\377\223\263L\223\346/\0\317\232\203\274r\20\316\3\273\332@\366\371\307\322Q\217/\252G\233\237G\344\3773X\224#\252h\221\36\314\263\300?t\326\306\206%\253|\273$U\255<'\364\27"\267\34\361l\345M\16\24\305>W\307\26\227\3476\24", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\37\243\377\223\263L\223\346/\0\317\232\203\274r\20\316\3\273\332@\366\371\307\322Q\217/\252G\233\237G\344\3773X\224#\252h\221\36\314\263\300?t\326\306\206%\253|\273$U\255<'\364\27"\267\34\361l\345M\16\24\305>W\307\26\227\3476\24", 80, ... ) \267\34\361l\345M\16\24\305>W\307\26\227\3476\24", 80, ... ) == 0x0 01249 1736 NtClose (-2147482128, ... ) == 0x0 01239 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "eo\357\232\275\21\367\5U\27\300^-/\325\33?\321\370\352\254OUu\310E\356T\3043z\315`\216\37\367\347&\307 Jc\37Y\356hjh\327\306\324\202.\212.\206`S[\300>\332\341\11\347\225\314\2456q\356"\274\364C\237\220\361\234\272\24\347\375;\247H\230^\216'Q\35\375w\213\324`g\305\177\263\35`\367\246\261\375\372e\320\346\214\224k\200"\367\32\255\217\365;\362ER\22\371g\201)b\340\243cl4/\275\37\323}\333\266!k\35\12\241\246\24H?\303\227#\24\241w\266\353\257\206\273\307\234\37\227w\231&\316?{\211\36\320\273\6\363c\6\221\242\26\265+O\257\247(I\345\357] \276\303;W>\302\3551\370\367\230\304\266\254\\304\240x\377d)\256t\232\326\251\275\31?r\216k]\11\305\330"E\24\317$\328\347\4\261h\234\345\351\207\36(\246\247\3561\21A", ) \274\364C\237\220\361\234\272\24\347\375;\247H\230^\216'Q\35\375w\213\324`g\305\177\263\35`\367\246\261\375\372e\320\346\214\224k\200 ... {status=0x0, info=256}, "eo\357\232\275\21\367\5U\27\300^-/\325\33?\321\370\352\254OUu\310E\356T\3043z\315`\216\37\367\347&\307 Jc\37Y\356hjh\327\306\324\202.\212.\206`S[\300>\332\341\11\347\225\314\2456q\356"\274\364C\237\220\361\234\272\24\347\375;\247H\230^\216'Q\35\375w\213\324`g\305\177\263\35`\367\246\261\375\372e\320\346\214\224k\200"\367\32\255\217\365;\362ER\22\371g\201)b\340\243cl4/\275\37\323}\333\266!k\35\12\241\246\24H?\303\227#\24\241w\266\353\257\206\273\307\234\37\227w\231&\316?{\211\36\320\273\6\363c\6\221\242\26\265+O\257\247(I\345\357] \276\303;W>\302\3551\370\367\230\304\266\254\\304\240x\377d)\256t\232\326\251\275\31?r\216k]\11\305\330"E\24\317$\328\347\4\261h\234\345\351\207\36(\246\247\3561\21A", ) E\24\317$\328\347\4\261h\234\345\351\207\36(\246\247\3561\21A", ) == 0x0 01250 1736 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 132, ) == 0x0 01251 1736 NtConnectPort ( ("\RPC Control\ntsvcs", {12, 2, 1, 1}, 0x0, 0x0, 1238540, 188, ... 136, 0x0, 0x0, 0x0, 188, ) , {12, 2, 1, 1}, 0x0, 0x0, 1238540, 188, ... 136, 0x0, 0x0, 0x0, 188, ) == 0x0 01252 1736 NtRequestWaitReplyPort (136, {200, 224, new_msg, 0, 1355632, 12, 2, 257} (136, {200, 224, new_msg, 0, 1355632, 12, 2, 257} "\0\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0`\2\24\0\4\0\0\0\2\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\351\26L\225\374\315\37\260`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\312\207e\207\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 1636, 1736, 75512, 0} "\7\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\2\0\0\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\351\26L\225\374\315\37\260`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\312\207e\207\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ... {200, 224, reply, 0, 1636, 1736, 75512, 0} (136, {200, 224, new_msg, 0, 1355632, 12, 2, 257} "\0\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0`\2\24\0\4\0\0\0\2\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\351\26L\225\374\315\37\260`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\312\207e\207\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ... {200, 224, reply, 0, 1636, 1736, 75512, 0} "\7\0\0\0\274\0\0\0\3443\24\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\2\0\0\0\377\377\377\377\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\2\0\0\0\351\26L\225\374\315\37\260`\227\24\0`\2\24\0\12\0\0\0\0\0\0\0\0\0\0 (\0\0\0h\227\24\0\312\207e\207\240\1\24\0\30\257\24\0\\1\24\0\0\0\0\0\0\0\0\0\30\257\24\0P\0\0\0 \257\24\0\360\6\221|`\2\24\0P\0\0\0\346\31\0\0\0\0\24\0\214\344\22\0\372\31\221| \354\22\0\30\356\220|\360\6\221|\0\0\0\0\0\0\0\0\0\0\0\0\6\0\0\0" ) ) == 0x0 01253 1736 NtRequestWaitReplyPort (136, {112, 136, new_msg, 0, 44, 3, 20, 0} (136, {112, 136, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\27\0\245}d@\240\5u8poe8"\0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {68, 92, reply, 0, 1636, 1736, 75513, 0} "\2\0\370\0\1\0\335\341<\0\370\0\226\245\335\341\264\311\275\201:\332R\200X{\266\367\]\222\201\306\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) \0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 (136, {112, 136, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\27\0\245}d@\240\5u8poe8"\0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {68, 92, reply, 0, 1636, 1736, 75513, 0} "\2\0\370\0\1\0\335\341<\0\370\0\226\245\335\341\264\311\275\201:\332R\200X{\266\367\]\222\201\306\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) \2\0\370\0\1\0\335\341<\0\370\0\226\245\335\341\264\311\275\201:\332R\200X{\266\367\]\222\201\306\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) == 0x0 01254 1736 NtAllocateVirtualMemory (-1, 1355776, 0, 4096, 4096, 4, ... 1355776, 4096, ) == 0x0 01255 1736 NtOpenThreadToken (-2, 0x20, 1, ... ) == STATUS_NO_TOKEN 01256 1736 NtOpenProcessToken (-1, 0x20, ... 140, ) == 0x0 01257 1736 NtAdjustPrivilegesToken (140, 0, 1352496, 0, 0, 0, ... ) == 0x0 01258 1736 NtClose (140, ... ) == 0x0 01259 1736 NtRequestWaitReplyPort (136, {140, 164, new_msg, 0, 1636, 1736, 75513, 0} (136, {140, 164, new_msg, 0, 1636, 1736, 75513, 0} "\1\0\0\0A\2\26\0<\0\370\0\226\245\335\341\264\311\275\201:\332R\200\377\377\377\377\]\222\201\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {40, 64, reply, 0, 1636, 1736, 75514, 0} "\2\314\274\201\4\0[\200\377\3\37\0\240\314\274\201\0\374\340\377H=\266\367U&\\200d=\266\367\274\1\0\0\360>\11\0" ) ... {40, 64, reply, 0, 1636, 1736, 75514, 0} (136, {140, 164, new_msg, 0, 1636, 1736, 75513, 0} "\1\0\0\0A\2\26\0<\0\370\0\226\245\335\341\264\311\275\201:\332R\200\377\377\377\377\]\222\201\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {40, 64, reply, 0, 1636, 1736, 75514, 0} "\2\314\274\201\4\0[\200\377\3\37\0\240\314\274\201\0\374\340\377H=\266\367U&\\200d=\266\367\274\1\0\0\360>\11\0" ) ) == 0x0 01260 1736 NtRequestWaitReplyPort (136, {64, 88, new_msg, 56, 1354664, 1239044, 1239144, 0} (136, {64, 88, new_msg, 56, 1354664, 1239044, 1239144, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ... {64, 88, reply, 56, 1636, 1736, 75515, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ) ... {64, 88, reply, 56, 1636, 1736, 75515, 0} (136, {64, 88, new_msg, 56, 1354664, 1239044, 1239144, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ... {64, 88, reply, 56, 1636, 1736, 75515, 0} "\10\350\22\0@\0\24\0\346\277\347wh\350\22\0\4\350\22\0\20\0\0\0\300j\222w\34\254\24\0\1\0\0\08\261\24\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\20\257\24\0" ) ) == 0x0 01261 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 140, {status=0x0, info=1}, ) }, 3, 96, ... 140, {status=0x0, info=1}, ) == 0x0 01262 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 144, ) }, ... 144, ) == 0x0 01263 1736 NtQuerySymbolicLinkObject (144, ... (144, ... "\Device\FloppyPDO0", 38, ) , 38, ) == 0x0 01264 1736 NtClose (144, ... ) == 0x0 01265 1736 NtQueryVolumeInformationFile (140, 1237816, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01266 1736 NtClose (140, ... ) == 0x0 01267 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 140, {status=0x0, info=1}, ) }, 3, 16, ... 140, {status=0x0, info=1}, ) == 0x0 01268 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, "\36\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", ) , ) == 0x0 01269 1736 NtClose (140, ... ) == 0x0 01270 1736 NtQueryInformationFile (-1, 1238868, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01271 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238820, (0x100080, {24, 0, 0x40, 0, 1238820, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01272 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 32, ... , 54, 32, ... 01273 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01274 1736 NtClose (-2147482128, ... ) == 0x0 01272 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01275 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 374, ... , 54, 374, ... 01276 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01277 1736 NtClose (-2147482128, ... ) == 0x0 01275 1736 NtDeviceIoControlFile ... {status=0x0, info=374}, ... {status=0x0, info=374}, "v\1\0\0\2\0\0\0\372\0\0\0`\0\0\08\0\0\0\244\0\0\0\334\0\0\0\36\0v\0Z\1\0\0\34\0\\08\0\0\0\244\0p\0\334\0\0\0\36\0\0\0\\0?\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0A\0:\0", ) , ) == 0x0 01278 1736 NtClose (140, ... ) == 0x0 01279 1736 NtAllocateVirtualMemory (-1, 1359872, 0, 4096, 4096, 4, ... 1359872, 4096, ) == 0x0 01280 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 140, ) }, ... 140, ) == 0x0 01281 1736 NtOpenKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, ... 144, ) }, ... 144, ) == 0x0 01282 1736 NtClose (140, ... ) == 0x0 01283 1736 NtQueryValueKey (144, (144, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01284 1736 NtQueryValueKey (144, (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\6\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) , Partial, 710, ... TitleIdx=0, Type=3, Data= (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0\5\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\6\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) }, 710, ) == 0x0 01285 1736 NtClose (144, ... ) == 0x0 01286 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 144, ) }, ... 144, ) == 0x0 01287 1736 NtOpenKey (0x2000000, {24, 144, 0x40, 0, 0, (0x2000000, {24, 144, 0x40, 0, 0, "{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, ... 140, ) }, ... 140, ) == 0x0 01288 1736 NtClose (144, ... ) == 0x0 01289 1736 NtQueryValueKey (140, (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01290 1736 NtClose (140, ... ) == 0x0 01291 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 140, {status=0x0, info=0}, ) }, 3, 96, ... 140, {status=0x0, info=0}, ) == 0x0 01292 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 144, ) }, ... 144, ) == 0x0 01293 1736 NtQuerySymbolicLinkObject (144, ... (144, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 01294 1736 NtClose (144, ... ) == 0x0 01295 1736 NtQueryVolumeInformationFile (140, 1237816, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01296 1736 NtClose (140, ... ) == 0x0 01297 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 140, {status=0x0, info=0}, ) }, 3, 16, ... 140, {status=0x0, info=0}, ) == 0x0 01298 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, (140, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, ".\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", ) , ) == 0x0 01299 1736 NtClose (140, ... ) == 0x0 01300 1736 NtQueryInformationFile (-1, 1238868, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01301 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1238820, (0x100080, {24, 0, 0x40, 0, 1238820, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01302 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 32, ... , 70, 32, ... 01303 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01304 1736 NtClose (-2147482128, ... ) == 0x0 01302 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01305 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0008, (140, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 238, ... , 70, 238, ... 01306 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01307 1736 NtClose (-2147482128, ... ) == 0x0 01305 1736 NtDeviceIoControlFile ... {status=0x0, info=238}, ... {status=0x0, info=238}, "\356\0\0\0\2\0\0\0r\0\0\0`\0\0\08\0\0\0\14\0\0\0D\0\0\0.\0v\0\322\0\0\0\34\0\\08\0\0\0\14\0d\0D\0\0\0.\0k\0\310\24\310\24\0~\0\0\0\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0C\0:\0", ) , ) == 0x0 01308 1736 NtClose (140, ... ) == 0x0 01309 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 140, ) }, ... 140, ) == 0x0 01310 1736 NtOpenKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 144, ) }, ... 144, ) == 0x0 01311 1736 NtClose (140, ... ) == 0x0 01312 1736 NtQueryValueKey (144, (144, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01313 1736 NtQueryValueKey (144, (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0#\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) , Partial, 710, ... TitleIdx=0, Type=3, Data= (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0#\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) \5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0 (144, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\220\0\0\0"\5\0\0d\6\0\0\310\6\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0#\5\0\0d\6\0\0\310\6\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0H\0\0\0P\347\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0\214\347\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) }, 710, ) == 0x0 01314 1736 NtClose (144, ... ) == 0x0 01315 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 144, ) }, ... 144, ) == 0x0 01316 1736 NtOpenKey (0x2000000, {24, 144, 0x40, 0, 0, (0x2000000, {24, 144, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 140, ) }, ... 140, ) == 0x0 01317 1736 NtClose (144, ... ) == 0x0 01318 1736 NtQueryValueKey (140, (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (140, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01319 1736 NtClose (140, ... ) == 0x0 01320 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01321 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01322 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01323 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01324 1736 NtClose (-2147482128, ... ) == 0x0 01322 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01325 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01326 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01327 1736 NtClose (-2147482128, ... ) == 0x0 01325 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 01328 1736 NtClose (140, ... ) == 0x0 01329 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01330 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01331 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01332 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01333 1736 NtClose (-2147482128, ... ) == 0x0 01331 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01334 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01335 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=0}, ) }, 0, 64, ... -2147482128, {status=0x0, info=0}, ) == 0x0 01336 1736 NtClose (-2147482128, ... ) == 0x0 01334 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 01337 1736 NtClose (140, ... ) == 0x0 01338 1736 NtCreateKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01339 1736 NtSetValueKey (140, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01340 1736 NtClose (140, ... ) == 0x0 01341 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01342 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01343 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01344 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01345 1736 NtClose (-2147482128, ... ) == 0x0 01343 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01346 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01347 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01348 1736 NtClose (-2147482128, ... ) == 0x0 01346 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 01349 1736 NtClose (140, ... ) == 0x0 01350 1736 NtQueryInformationFile (-1, 1240208, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 01351 1736 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1240160, (0x100080, {24, 0, 0x40, 0, 1240160, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 140, {status=0x0, info=0}, ) == 0x0 01352 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 01353 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01354 1736 NtClose (-2147482128, ... ) == 0x0 01352 1736 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 01355 1736 NtDeviceIoControlFile (140, 0, 0x0, 0x0, 0x6d0034, (140, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 01356 1736 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482128, {status=0x0, info=1}, ) }, 0, 64, ... -2147482128, {status=0x0, info=1}, ) == 0x0 01357 1736 NtClose (-2147482128, ... ) == 0x0 01355 1736 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 01358 1736 NtClose (140, ... ) == 0x0 01359 1736 NtCreateKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01360 1736 NtSetValueKey (140, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (140, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 01361 1736 NtClose (140, ... ) == 0x0 01362 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01363 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01364 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 140, {status=0x0, info=1}, ) }, 3, 96, ... 140, {status=0x0, info=1}, ) == 0x0 01365 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 144, ) }, ... 144, ) == 0x0 01366 1736 NtQuerySymbolicLinkObject (144, ... (144, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 01367 1736 NtClose (144, ... ) == 0x0 01368 1736 NtQueryVolumeInformationFile (140, 1239204, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01369 1736 NtClose (140, ... ) == 0x0 01370 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01371 1736 NtOpenKey (0x2000000, {24, 72, 0x40, 0, 0, (0x2000000, {24, 72, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 140, ) }, ... 140, ) == 0x0 01372 1736 NtOpenKey (0x2000000, {24, 140, 0x40, 0, 0, (0x2000000, {24, 140, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 144, ) }, ... 144, ) == 0x0 01373 1736 NtClose (140, ... ) == 0x0 01374 1736 NtQueryValueKey (144, (144, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (144, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01375 1736 NtClose (144, ... ) == 0x0 01376 1736 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, 1240336, ... ) }, 1240336, ... ) == 0x0 01377 1736 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 01378 1736 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 144, {status=0x0, info=1}, ) }, 3, 96, ... 144, {status=0x0, info=1}, ) == 0x0 01379 1736 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 140, ) }, ... 140, ) == 0x0 01380 1736 NtQuerySymbolicLinkObject (140, ... (140, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 01381 1736 NtClose (140, ... ) == 0x0 01382 1736 NtQueryVolumeInformationFile (144, 1241076, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01383 1736 NtClose (144, ... ) == 0x0 01384 1736 NtCreateEvent (0x1f0003, {24, 48, 0x80, 1339720, 0, (0x1f0003, {24, 48, 0x80, 1339720, 0, "ShellCopyEngineFinished"}, 0, 0, ... 144, ) }, 0, 0, ... 144, ) == 0x0 01385 1736 NtSetEvent (144, ... 0x0, ) == 0x0 01386 1736 NtClose (144, ... ) == 0x0 01387 1736 NtClearEvent (68, ... ) == 0x0 01388 1736 NtClose (68, ... ) == 0x0 01389 1736 NtSetThreadExecutionState (-2147483648, 1244004, ... ) == 0x0 01390 1736 NtDelayExecution (0, {-990000, -1}, ... ) == 0x0 01391 1736 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion"}, ... 68, ) }, ... 68, ) == 0x0 01392 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01393 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01394 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01395 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01396 1736 NtClose (68, ... ) == 0x0 01397 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01398 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01399 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01400 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01401 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01402 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01403 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01404 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01405 1736 NtClose (144, ... ) == 0x0 01406 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01407 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01408 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01409 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01410 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01411 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01412 1736 NtClose (144, ... ) == 0x0 01413 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01414 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01415 1736 NtClose (70, ... ) == 0x0 01416 1736 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion"}, ... 68, ) }, ... 68, ) == 0x0 01417 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01418 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01419 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01420 1736 NtQueryValueKey (68, (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (68, "ProgramFilesDir", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\0\0"}, 46, ) }, 46, ) == 0x0 01421 1736 NtClose (68, ... ) == 0x0 01422 1736 NtDelayExecution (0, {-420000, -1}, ... ) == 0x0 01423 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01424 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01425 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01426 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01427 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01428 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01429 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01430 1736 NtClose (144, ... ) == 0x0 01431 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01432 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01433 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01434 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01435 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01436 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01437 1736 NtClose (144, ... ) == 0x0 01438 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01439 1736 NtQueryValueKey (70, (70, "version", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01440 1736 NtClose (70, ... ) == 0x0 01441 1736 NtQueryKey (66, Name, 382, ... {Name= (66, Name, 382, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01442 1736 NtOpenKey (0x2000000, {24, 66, 0x40, 0, 0, (0x2000000, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01443 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes"}, ... 68, ) }, ... 68, ) == 0x0 01444 1736 NtCreateKey (0x20006, {24, 68, 0x40, 0, 0, (0x20006, {24, 68, 0x40, 0, 0, "WR"}, 0, "", 0, ... 144, 2, ) }, 0, "", 0, ... 144, 2, ) == 0x0 01445 1736 NtClose (68, ... ) == 0x0 01446 1736 NtQueryKey (146, Name, 392, ... {Name= (146, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01447 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01448 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 01449 1736 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01450 1736 NtClose (68, ... ) == 0x0 01451 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01452 1736 NtSetValueKey (146, (146, "version", 0, 1, "7\01\0\0\0", 6, ... , 0, 1, (146, "version", 0, 1, "7\01\0\0\0", 6, ... , 6, ... 01453 1736 NtSetInformationFile (-2147482448, -134732432, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 01452 1736 NtSetValueKey ... ) == 0x0 01454 1736 NtClose (146, ... ) == 0x0 01455 1736 NtDelayExecution (0, {-340000, -1}, ... ) == 0x0 01456 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01457 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01458 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01459 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01460 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01461 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01462 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 144, ) }, ... 144, ) == 0x0 01463 1736 NtQueryKey (146, Name, 392, ... {Name= (146, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01464 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01465 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 01466 1736 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01467 1736 NtClose (68, ... ) == 0x0 01468 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01469 1736 NtQueryValueKey (146, (146, "nextupdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01470 1736 NtClose (146, ... ) == 0x0 01471 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01472 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01473 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 144, ) }, ... 144, ) == 0x0 01474 1736 NtQueryKey (146, Name, 392, ... {Name= (146, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01475 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01476 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 68, ) == 0x0 01477 1736 NtQueryInformationToken (68, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01478 1736 NtClose (68, ... ) == 0x0 01479 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01480 1736 NtQueryValueKey (146, (146, "nextupdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01481 1736 NtClose (146, ... ) == 0x0 01482 1736 NtQueryKey (66, Name, 382, ... {Name= (66, Name, 382, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01483 1736 NtOpenKey (0x2000000, {24, 66, 0x40, 0, 0, (0x2000000, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01484 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes"}, ... 144, ) }, ... 144, ) == 0x0 01485 1736 NtCreateKey (0x20006, {24, 144, 0x40, 0, 0, (0x20006, {24, 144, 0x40, 0, 0, "WR"}, 0, "", 0, ... 68, 2, ) }, 0, "", 0, ... 68, 2, ) == 0x0 01486 1736 NtClose (144, ... ) == 0x0 01487 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01488 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01489 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01490 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01491 1736 NtClose (144, ... ) == 0x0 01492 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01493 1736 NtSetValueKey (70, (70, "nextupdate", 0, 4, ":\12\13H", 4, ... ) , 0, 4, (70, "nextupdate", 0, 4, ":\12\13H", 4, ... ) , 4, ... ) == 0x0 01494 1736 NtClose (70, ... ) == 0x0 01495 1736 NtDelayExecution (0, {-360000, -1}, ... ) == 0x0 01496 1736 NtDelayExecution (0, {-340000, -1}, ... ) == 0x0 01497 1736 NtDelayExecution (0, {-340000, -1}, ... ) == 0x0 01498 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01499 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01500 1736 NtDelayExecution (0, {-320000, -1}, ... ) == 0x0 01501 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01502 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01503 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01504 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01505 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01506 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01507 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01508 1736 NtClose (144, ... ) == 0x0 01509 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01510 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01511 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01512 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01513 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01514 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01515 1736 NtClose (144, ... ) == 0x0 01516 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01517 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01518 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01519 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01520 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01521 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01522 1736 NtClose (144, ... ) == 0x0 01523 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01524 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01525 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01526 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01527 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01528 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01529 1736 NtClose (144, ... ) == 0x0 01530 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01531 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01532 1736 NtClose (70, ... ) == 0x0 01533 1736 NtQueryKey (66, Name, 384, ... {Name= (66, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 01534 1736 NtOpenKey (0x20019, {24, 66, 0x40, 0, 0, (0x20019, {24, 66, 0x40, 0, 0, "WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01535 1736 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\WR"}, ... 68, ) }, ... 68, ) == 0x0 01536 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR\"}, 78, ) }, 78, ) == 0x0 01537 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01538 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01539 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01540 1736 NtClose (144, ... ) == 0x0 01541 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01542 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01543 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01544 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01545 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01546 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01547 1736 NtClose (144, ... ) == 0x0 01548 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01549 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01550 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01551 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01552 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01553 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01554 1736 NtClose (144, ... ) == 0x0 01555 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01556 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01557 1736 NtQueryKey (70, Name, 392, ... {Name= (70, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\WR1"}, 78, ) }, 78, ) == 0x0 01558 1736 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01559 1736 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 144, ) == 0x0 01560 1736 NtQueryInformationToken (144, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01561 1736 NtClose (144, ... ) == 0x0 01562 1736 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\WR"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01563 1736 NtQueryValueKey (70, (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (70, "cmd", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01564 1736 NtClose (70, ... ) == 0x0 01565 1736 NtDelayExecution (0, {-990000, -1}, ... ) == 0x0 01566 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01567 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01568 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01569 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01570 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01571 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01572 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01573 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01574 1736 NtDelayExecution (0, {-21370000, -1}, ... ) == 0x0 01575 1736 NtDelayExecution (0, {-21370000, -1}, ...\270)\24sKQ\205\307\251\242\22\13t\366\31jRw]b" , ) , ) == 0x0 01217 1736 NtDeviceIoControlFile (44, 0, 0x0, 0x0, 0x390008, (44, 0, 0x0, 0x0, 0x390008, "\254\314\11=\246\323\211\250~\367\356\360\204\257\12\2011#V\342\326lO1#V\342\326lO1#V\342\326lO1#V\342\326\325\205\263\377\22\257w(\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01218 1736 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01219 1736 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01220 1736 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01221 1736 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01222 1736 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01223 1736 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01224 1736 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01225 1736 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482128, 2, ) }, 0, 0x0, 0, ... -2147482128, 2, ) == 0x0 01226 1736 NtSetValueKey (-2147482128, (-2147482128, "Seed", 0, 3, "\177\16Vw\13\241\220P\316\37;Fc\30f\224\17\210\36\14\330<\264\322\271\341\36\343aX\237!\32\30\204\247\250D\277\360E\226H\231\215\256\337\211sI/\255\322\232H4#\36\212\235\273ZS\376j+\340'0\310\2g\2\362\221\370|\374\216\341", 80, ... ) , 0, 3, (-2147482128, "Seed", 0, 3, "\177\16Vw\13\241\220P\316\37;Fc\30f\224\17\210\36\14\330<\264\322\271\341\36\343aX\237!\32\30\204\247\250D\277\360E\226H\231\215\256\337\211sI/\255\322\232H4#\36\212\235\273ZS\376j+\340'0\310\2g\2\362\221\370|\374\216\341", 80, ... ) , 80, ... ) == 0x0 01227 1736 NtClose (-2147482128, ... ) == 0x0 01217 1736 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\275:\313~\327O\311\263\216}$qy*?\214\27o_\350f\203\22;\260\231@\30\264\253\250):\224Zh\235z\265\3269\312\212\343l\13v\333\304b8\212\353\221\206\262Z\35f\255\274[q\6\6hx2W>\335w\344\10\20;\20%\271\257\214\375e\341\2428\217W\364\376\304\320\30714\265\230"\245\211ss\7\342\353\\251\315a\263\12\363\365\365\252\6\31\11\365\12\275K(\214\333V[QWo\211o\340\322\33p\10\210\11#>\34H\274\252?@B\373\302\341\14Z\223j[\323a\17d\253\261E\215\16{\24\227i\303\37\237*\326\316\215P", ) \245\211ss\7\342\353\\251\315a\263\12\363\365\365\252\6\31\11\365\12\275K(\214\333V[ 371