Summary:

NtCallbackReturn(>) 1 NtDuplicateObject(>) 2 NtGdiSaveDC(>) 7 NtQueryDebugFilterState(>) 23
NtConnectPort(>) 1 NtGdiCreateSolidBrush(>) 2 NtGdiSetDIBitsToDeviceInternal(>) 7 NtWriteFile(>) 23
NtCreateProcessEx(>) 1 NtOpenDirectoryObject(>) 2 NtQueryDirectoryFile(>) 7 NtCreateEvent(>) 24
NtCreateThread(>) 1 NtOpenProcess(>) 2 NtUserDestroyCursor(>) 7 NtCreateFile(>) 24
NtDuplicateToken(>) 1 NtOpenSymbolicLinkObject(>) 2 NtUserSetCursorIconData(>) 7 NtReadFile(>) 24
NtEnumerateValueKey(>) 1 NtQueryInstallUILanguage(>) 2 NtGdiCreateBitmap(>) 8 NtOpenProcessTokenEx(>) 26
NtFsControlFile(>) 1 NtQuerySymbolicLinkObject(>) 2 NtSetInformationProcess(>) 8 NtOpenThreadTokenEx(>) 26
NtGdiCreatePaletteInternal(>) 1 NtReadVirtualMemory(>) 2 NtCreateKey(>) 9 NtFreeVirtualMemory(>) 31
NtGdiInit(>) 1 NtTerminateProcess(>) 2 NtCreateSemaphore(>) 10 NtQuerySection(>) 32
NtGdiQueryFontAssocInfo(>) 1 NtAddAtom(>) 3 NtGdiCreateCompatibleDC(>) 10 NtQueryInformationToken(>) 33
NtOpenKeyedEvent(>) 1 NtClearEvent(>) 3 NtGdiExtGetObjectW(>) 10 NtQuerySystemInformation(>) 35
NtQueryEvent(>) 1 NtGdiHfontCreate(>) 3 NtQueryDefaultUILanguage(>) 10 NtWaitForSingleObject(>) 37
NtQueryInformationJobObject(>) 1 NtNotifyChangeKey(>) 3 NtOpenMutant(>) 11 NtProtectVirtualMemory(>) 41
NtQueryObject(>) 1 NtOpenEvent(>) 3 NtRequestWaitReplyPort(>) 11 NtCreateSection(>) 43
NtQueryPerformanceCounter(>) 1 NtReleaseSemaphore(>) 3 NtUserGetDC(>) 11 NtUserUnregisterClass(>) 46
NtQueryTimerResolution(>) 1 NtSetInformationObject(>) 3 NtQueryVolumeInformationFile(>) 12 NtReleaseMutant(>) 48
NtRegisterThreadTerminatePort(>) 1 NtWaitForMultipleObjects(>) 3 NtSetValueKey(>) 13 NtOpenSection(>) 54
NtResumeThread(>) 1 NtWriteVirtualMemory(>) 4 NtUserSystemParametersInfo(>) 13 NtQueryVirtualMemory(>) 56
NtSecureConnectPort(>) 1 NtOpenThreadToken(>) 5 NtQueryInformationProcess(>) 14 NtGdiSelectBitmap(>) 57
NtTestAlert(>) 1 NtDeviceIoControlFile(>) 6 NtSetInformationThread(>) 14 NtUserRegisterClassExWOW(>) 63
NtUserCallNoParam(>) 1 NtEnumerateKey(>) 6 NtUserSelectPalette(>) 14 NtMapViewOfSection(>) 69
NtUserEnumDisplayMonitors(>) 1 NtOpenProcessToken(>) 6 NtSetInformationFile(>) 15 NtUserFindExistingCursorIcon(>) 72
NtUserGetKeyboardLayoutList(>) 1 NtSetEvent(>) 6 NtGdiDeleteObjectApp(>) 18 NtOpenFile(>) 73
NtUserGetObjectInformation(>) 1 NtCreateMutant(>) 7 NtUnmapViewOfSection(>) 18 NtUserGetClassInfo(>) 82
NtUserGetProcessWindowStation(>) 1 NtGdiBitBlt(>) 7 NtQueryDefaultLocale(>) 19 NtAllocateVirtualMemory(>) 120
NtUserGetThreadDesktop(>) 1 NtGdiCreateDIBitmapInternal(>) 7 NtContinue(>) 20 NtQueryAttributesFile(>) 129
NtUserSetWindowsHookEx(>) 1 NtGdiGetDCObject(>) 7 NtFlushInstructionCache(>) 20 NtOpenKey(>) 195
NtAccessCheck(>) 2 NtGdiGetDCforBitmap(>) 7 NtUserCallOneParam(>) 20 NtClose(>) 336
NtDelayExecution(>) 2 NtGdiGetStockObject(>) 7 NtQueryInformationFile(>) 21 NtQueryValueKey(>) 340
NtDeleteAtom(>) 2 NtGdiRestoreDC(>) 7 NtUserRegisterWindowMessage(>) 22

Trace:

00001 400 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 400 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00003 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00004 400 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 1310720, 1048576, ) == 0x0 00005 400 NtAllocateVirtualMemory (-1, 1310720, 0, 4096, 4096, 4, ... 1310720, 4096, ) == 0x0 00006 400 NtAllocateVirtualMemory (-1, 1314816, 0, 8192, 4096, 4, ... 1314816, 8192, ) == 0x0 00007 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00008 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2359296, 65536, ) == 0x0 00009 400 NtAllocateVirtualMemory (-1, 2359296, 0, 24576, 4096, 4, ... 2359296, 24576, ) == 0x0 00010 400 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00011 400 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00012 400 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00013 400 NtClose (12, ... ) == 0x0 00014 400 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\U:\startupscripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00015 400 NtQueryVolumeInformationFile (12, 1243848, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00016 400 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... ) == STATUS_INVALID_PARAMETER 00017 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local"}, 1243832, ... ) }, 1243832, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00018 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00019 400 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e60000), 0x0, 937984, ) == 0x0 00020 400 NtClose (16, ... ) == 0x0 00021 400 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00022 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00023 400 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00024 400 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1242016, 44, ... 24, {24, 16, 0, 65536, 2424832, 18415616}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1319736, {12, 0, 0}, 1242016, 44, ... 24, {24, 16, 0, 65536, 2424832, 18415616}, {0, 0, 0}, 200, 44, ) == 0x0 00025 400 NtClose (16, ... ) == 0x0 00026 400 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00027 400 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00028 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00029 400 NtQueryVirtualMemory (-1, 0x250000, Basic, 28, ... {BaseAddress=0x250000,AllocationBase=0x250000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00030 400 NtAllocateVirtualMemory (-1, 2424832, 0, 4096, 4096, 4, ... 2424832, 4096, ) == 0x0 00031 400 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 0, 0, 0, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 396, 400, 1490, 0} "\360L\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ... {28, 56, reply, 0, 396, 400, 1490, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 396, 400, 1490, 0} "\360L\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ) == 0x0 00032 400 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00033 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00034 400 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00035 400 NtClose (16, ... ) == 0x0 00036 400 NtAllocateVirtualMemory (-1, 1232896, 0, 4096, 4096, 260, ... 1232896, 4096, ) == 0x0 00037 400 NtOpenMutant (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\NlsCacheMutant"}, ... 16, ) }, ... 16, ) == 0x0 00038 400 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 28, ) }, ... 28, ) == 0x0 00039 400 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x260000), 0x0, 90112, ) == 0x0 00040 400 NtClose (28, ... ) == 0x0 00041 400 NtQueryDefaultLocale (0, 2012046252, ... ) == 0x0 00042 400 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 28, ) }, ... 28, ) == 0x0 00043 400 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x280000), 0x0, 212992, ) == 0x0 00044 400 NtClose (28, ... ) == 0x0 00045 400 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 28, ) }, ... 28, ) == 0x0 00046 400 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2c0000), 0x0, 266240, ) == 0x0 00047 400 NtQuerySection (28, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00048 400 NtClose (28, ... ) == 0x0 00049 400 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 28, ) }, ... 28, ) == 0x0 00050 400 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x310000), 0x0, 24576, ) == 0x0 00051 400 NtClose (28, ... ) == 0x0 00052 400 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00053 400 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00054 400 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00055 400 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 396, 400, 1493, 0} "\230\243\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ... {28, 56, reply, 0, 396, 400, 1493, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 396, 400, 1493, 0} "\230\243\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ) == 0x0 00056 400 NtProtectVirtualMemory (-1, (0x47c000), 8192, 4, ... (0x47c000), 8192, 128, ) == 0x0 00057 400 NtProtectVirtualMemory (-1, (0x47c000), 8192, 128, ... (0x47c000), 8192, 4, ) == 0x0 00058 400 NtFlushInstructionCache (-1, 4702208, 8192, ... ) == 0x0 00059 400 NtOpenProcessToken (-1, 0x8, ... 28, ) == 0x0 00060 400 NtQueryInformationToken (28, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00061 400 NtClose (28, ... ) == 0x0 00062 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00063 400 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00064 400 NtClose (28, ... ) == 0x0 00065 400 NtTestAlert (... ) == 0x0 00066 400 NtContinue (1244464, 1, ... 00067 400 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x47e000,}, 4, ... ) == 0x0 00068 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 28, ) }, ... 28, ) == 0x0 00069 400 NtQueryValueKey (28, (28, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00070 400 NtClose (28, ... ) == 0x0 00071 400 NtAllocateVirtualMemory (-1, 1323008, 0, 4096, 4096, 4, ... 1323008, 4096, ) == 0x0 00072 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00073 400 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 569344, ) == 0x0 00074 400 NtClose (28, ... ) == 0x0 00075 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 28, ) }, ... 28, ) == 0x0 00076 400 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77cc0000), 0x0, 479232, ) == 0x0 00077 400 NtClose (28, ... ) == 0x0 00078 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00079 400 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00080 400 NtQueryValueKey (28, (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00081 400 NtClose (28, ... ) == 0x0 00082 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 28, ) }, ... 28, ) == 0x0 00083 400 NtQueryValueKey (28, (28, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00084 400 NtClose (28, ... ) == 0x0 00085 400 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 28, ) }, ... 28, ) == 0x0 00086 400 NtSetInformationObject (28, Handle, {Inherit=0,ProtectFromClose=1,}, 2011365632, ... ) == 0x0 00087 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00088 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00089 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 32, ) == 0x0 00090 400 NtQueryInformationToken (32, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00091 400 NtClose (32, ... ) == 0x0 00092 400 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 32, ) }, ... 32, ) == 0x0 00093 400 NtSetInformationObject (32, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 00094 400 NtOpenKey (0x20019, {24, 32, 0x40, 0, 0, (0x20019, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 36, ) }, ... 36, ) == 0x0 00095 400 NtQueryValueKey (36, (36, "PINF", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00096 400 NtClose (36, ... ) == 0x0 00097 400 NtAllocateVirtualMemory (-1, 1228800, 0, 4096, 4096, 260, ... 1228800, 4096, ) == 0x0 00098 400 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0 00099 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1234112, (0x80100080, {24, 0, 0x40, 0, 1234112, "\??\u:\work\packed.exe"}, 0x0, 1, 1, 1, 96, 0, 0, ... 36, {status=0x0, info=1}, ) }, 0x0, 1, 1, 1, 96, 0, 0, ... 36, {status=0x0, info=1}, ) == 0x0 00100 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp"}, 1233828, ... ) }, 1233828, ... ) == 0x0 00101 400 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 3, 2, 11, 1311808} (24, {20, 48, new_msg, 0, 3, 2, 11, 1311808} "\0\0\0\0\2\0\1\0d\1\24\0\0\0\0\0\215\26\365w" ... {20, 48, reply, 0, 396, 400, 1496, 0} "\0\0\0\0\2\0\1\0\1\0\0\0\0\0\0\0\1\0\0\0" ) ... {20, 48, reply, 0, 396, 400, 1496, 0} (24, {20, 48, new_msg, 0, 3, 2, 11, 1311808} "\0\0\0\0\2\0\1\0d\1\24\0\0\0\0\0\215\26\365w" ... {20, 48, reply, 0, 396, 400, 1496, 0} "\0\0\0\0\2\0\1\0\1\0\0\0\0\0\0\0\1\0\0\0" ) ) == 0x0 00102 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1233836, (0x80100080, {24, 0, 0x40, 0, 1233836, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 0x0, 128, 0, 2, 96, 0, 0, ... 40, {status=0x0, info=2}, ) }, 0x0, 128, 0, 2, 96, 0, 0, ... 40, {status=0x0, info=2}, ) == 0x0 00103 400 NtClose (40, ... ) == 0x0 00104 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234112, (0xc0100080, {24, 0, 0x40, 0, 1234112, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 0x0, 128, 1, 5, 96, 0, 0, ... }, 0x0, 128, 1, 5, 96, 0, 0, ... 00105 400 NtClose (-2147482032, ... ) == 0x0 00104 400 NtCreateFile ... 40, {status=0x0, info=3}, ) == 0x0 00106 400 NtSetInformationFile (36, 1234204, 8, Position, ... {status=0x0, info=0}, ) == 0x0 00107 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\2\201\202\0M\333\322\0K\333\335\0\260$\322\0\367\333\322\0O\333\322\0\17\333\310\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\331\322\0\365\313\322\16Po\333\315nc\323L\202\372B\220\33\263\273so\253\240o(\251\263mo\266\247s;\373\260eo\251\247no\256\274d*\251\362W&\265\3412B\321\3667O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0O\333\322\0", ) , ) == 0x0 00108 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "MZP\0\2\0\0\0\4\0\17\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\32\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\272\20\0\16\37\264\11\315!\270\1L\315!\220\220This program must be run under Win32\15\12$7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00109 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\32\323\344\34 \347\237E \251\253,\357\266\263\10\177\330S\7\207\23\264\331-\33\223\304\207\230\32f\237'f3I\303\15~Y*4\221\267\220\266\37\277"Xq\355\0 \213\351\225W\207_\32\257\3\365\243P\246\237\322(N\7R\24\314\341\370\12?\336\327\34$p\4\12\247\213\0\10\211\333\265)\314\342*\251\264\377\30\232\15\230\353RU\233\205\344\337\355\343\15\304\232\346\324\346r\37\\6\316\327-\203\377J\365\17\326\200\314\37HR\221\342I<\334\326\12\366\370\352\246\207u\217P\217\304\204\202D\357\303\30z\306\343kfF\37\3253\224w\23\201\1\321s\345\225i\17\372\217\374h\27\223\271\341\365\250\356\333lm \343Qx\27\266\342\213\373P\230Xb\377\325\2200\23\362^V8\371\227[$-\12c\243\356\231n\303\266\360\233J\252]r\365q\261\233\2765\354N\0\336pE\5!P(\270\32\266Q\231\361\35063\3315&m6&\253\203\335\11\222\6\342\2M\273\222\3\335\223z\211\15\203\3512k\2005\324\233\210q\17\313\312`\1\243\304c\22+\223\32\324H\37\210\274*r5$D\320\311a\311\27T[\343+\17\17", ) f\237'f3I\303\15~Y*4\221\267\220\266\37\277 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\32\323\344\34 \347\237E \251\253,\357\266\263\10\177\330S\7\207\23\264\331-\33\223\304\207\230\32f\237'f3I\303\15~Y*4\221\267\220\266\37\277"Xq\355\0 \213\351\225W\207_\32\257\3\365\243P\246\237\322(N\7R\24\314\341\370\12?\336\327\34$p\4\12\247\213\0\10\211\333\265)\314\342*\251\264\377\30\232\15\230\353RU\233\205\344\337\355\343\15\304\232\346\324\346r\37\\6\316\327-\203\377J\365\17\326\200\314\37HR\221\342I<\334\326\12\366\370\352\246\207u\217P\217\304\204\202D\357\303\30z\306\343kfF\37\3253\224w\23\201\1\321s\345\225i\17\372\217\374h\27\223\271\341\365\250\356\333lm \343Qx\27\266\342\213\373P\230Xb\377\325\2200\23\362^V8\371\227[$-\12c\243\356\231n\303\266\360\233J\252]r\365q\261\233\2765\354N\0\336pE\5!P(\270\32\266Q\231\361\35063\3315&m6&\253\203\335\11\222\6\342\2M\273\222\3\335\223z\211\15\203\3512k\2005\324\233\210q\17\313\312`\1\243\304c\22+\223\32\324H\37\210\274*r5$D\320\311a\311\27T[\343+\17\17", ) , ) == 0x0 00110 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "U\106\34o\301\21\0\12^]|\168M\221\3311]\33\26\31\220\220\330\225\273\262P\12\254\27\213QO\10d\203\220\4\10#\314\322,\2100\306{\22A\16\341\311\370F(I\3446\33\37\4\317\360f\320\374\2643\6\303\341\151\202\3704\336lB\266Pd\360X>6\322 \3042GW\310\204\310\257L.qP\351D\0(\1\334\200\24\203:*\12p\5\5\34k\253\326\12\350P\322<&p\256\10Vtu\310E\206\25\212\335\315\354\10\306\0g)\2039\370\251\373$\312\232BC9R\32@W\344\22061\15\213A4\324\251\251\315\I\25\5-\314$\230\365@\15R\314P\223\200\221\255\222\356\334\231\321$\370\245}Uu\300\213]\304\313Y\226\357\214\303\250\306\254\260\264FP\16\341\2248\310S\1\236\2507\225&\324(\217\263\263\305\223\366:'\250\241\0\276mo8\203xXm0\213\264\213JX-$\7\220\177\310 ^\31\343+\227\24\377\377\12,x<\231!\30d\360\324\221x]=.\243\261\324e\347\354\1\333\14p\12\336\363Pgc\310\266\36B#\350y\350\135i\266\344&\344X\17\11\335\3350\2\2`@\3\222H\250\211BX;2$[\347\324\324S\243\17\204\21\262\1\354\37\261\22dH\310\324\7\304Z\274e\251\347$\13\13\33a\206\314\206[\254\360\335\17", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \301\21\0\12^]|\168M\221\3311]\33\26\31\220\220\330\225\273\262P\12\254\27\213QO\10d\203\220\4\10#\314\322,\2100\306{\22A\16\341\311\370F(I\3446\33\37\4\317\360f\320\374\2643\6\303\341\151\202\3704\336lB\266Pd\360X>6\322 \3042GW\310\204\310\257L.qP\351D\0(\1\334\200\24\203:*\12p\5\5\34k\253\326\12\350P\322<&p\256\10Vtu\310E\206\25\212\335\315\354\10\306\0g)\2039\370\251\373$\312\232BC9R\32@W\344\22061\15\213A4\324\251\251\315\I\25\5-\314$\230\365@\15R\314P\223\200\221\255\222\356\334\231\321$\370\245}Uu\300\213]\304\313Y\226\357\214\303\250\306\254\260\264FP\16\341\2248\310S\1\236\2507\225&\324(\217\263\263\305\223\366:'\250\241\0\276mo8\203xXm0\213\264\213JX-$\7\220\177\310 ^\31\343+\227\24\377\377\12,x<\231!\30d\360\324\221x]=.\243\261\324e\347\354\1\333\14p\12\336\363Pgc\310\266\36B#\350y\350\135i\266\344&\344X\17\11\335\3350\2\2`@\3\222H\250\211BX;2$[\347\324\324S\243\17\204\21\262\1\354\37\261\22dH\310\324\7\304Z\274e\251\347$\13\13\33a\206\314\206[\254\360\335\17", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00111 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\230\31\331X\367\311\307w~\321\336H\234\226\21\30\5M\236\340\32~`HOp@\345\377^e}W\237\222\221\252K\267Z+\207\212YA\200H\0\35\220\261T\37\277\353dT\271\3066+\273C\345\337\276\270!#\263\203\226\14M\240\14;\253\376\35\206\273\31z3\356\252@eZJC_\247\310\3010^F\235\324\273\265\20\341\253i\363vp\204%]S\3369d_\302\274HPT9\325\232^\14\307\264\222\323\260,\370\276gQ\225\10u\13\2469\271\235i3\345\222\7\256\327\7\205\4\266\267\227]\370\337\2244\274\235\315\306\371\231\306\270\3417\306\5C\225\327>KL\230V\177\255p\310\245]\357\366J\320RK\17\203\21\13\335\\207?D\253\21k\340\3669\221\363?\32\257{\23\323\367N\365*\27\253\235\263l<\\274\31\253X\201T=\256\267\1a\330Z\4 .\343\322\305\213\304D_\331\345\304\312\245Ywt\352\33\212\7\230\226\10\263$\220\267\20\333\332\215:\324Y|G\334\343\300\305\325\351J\263\256e~\356\200\\E)\316\16\271\30\15\237\6\2560o\24p#\371X\233\366\16N\342*~\222~\265\5b\37\351\200w\374\335MK\200)\302=?W\257 lm\202;t[\321F\272\331\212\10Q\370\201\277\211<\356\256$\15\177\224Q\212c\333Q\214\12\312\200\201o#\247\314\13Y\303]\36B\342&\355B%\212\32\317<\159\204'e\0\0\312\312\33:7?\355y\331c \3300\32?\317>\15:\371\33?\355U00\35\305\267\310\221#\303\220\305\335$\20\11\267<\231u\277Tq:\304\344a\4\317\344\327\266\22x\325\203\236\224\323\267@)-\255\345l\230\205\334,\261=\320\245\15@d\33\3\5\7x\5s\34-\321\301\1-B\252U\353\1", ) , ) == 0x0 00112 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\327\302\13X\270\22\25w1\12\14H\323M\303\30J\226L\340U\245\262H\0\253\222\345\260\205\267}\30D@\221\345\220eZd\XY\16[\232\0RKcTPd9d\33b\246d`\221\345\220ej!lhQ\226C\226r\14tp,\35\311`\313z|5x@*\201\230C\20|\32\301\177\205\224\235\233`g\20\256p\273\3639\253V%\22\210\149+\204\20\274\7\213\2069\232A\214\14\210o@\323\377\367*\276(\212G\10:\320t9\366F\2733\252I\325\256\230\334W\4\371lE]\267\4F4\363F\37\306\266B\24\270\256\354\24\5\14N\5>\4\227JV0v\242\310\352\206=\366\5\13\200K@X\303\13\222\207U?\13p\303k\257-\353\221\274\344\310\2574\310\1\367\1.\370\27\344Fals\207n\31\344\203STrue\1.\3\210\4o\3651\322\212P\26D\20\27\304\205~\213w;1\311\212HCD\10\374\377B\267_\0\10\215u\17\213|\10\71\300\212\16;J\374u\267~\241[\216\\12\362\34\16\366\303\337\237Iu\342o[\253\361\371\27@$\16\19\370~\335\245g\5-\304;\2008'\17M\4[\373\302r\344\205\257o\267\277\202t\257\211\321\11a\13\212G\212*\201\360R\356\356\341\377\337\177\333\212Xc\224\212^\12\205[Sol|\36\13\26\30\217\36\159\364\355\15\376X\32\200\347\3379\313\374\267\0O\21\30\33u\354\355\3556\2\261 \227\353\310?\200\345\337:\266\300\355\355\32\353\342\35\212l\32\221l\30B\305\222\377\302\11\370\347Ku\360\217\243:\213?\263\4\200?\5\266]\243\7\203\321O\1\267\17\362\377\255\252\267J\20z\7\376\261r\13w\15\17\277\311\3J\334\252\5<\307\377\321\216\332\377B\345\2169\1", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00113 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\3310/\265\317\14~f\34RW\6Y[X\2658\35W\2270\325\245\21)df\22\32\327\267\211F{\213\6\374\34\263\35\177g\316\210\373\240M\240\305VG>E\333f\274(\365\225\263>\361\220V\202I4N\34\320\316\313y\215\271\306L\346tG\201\326\310\322_D\244d\5#t,\200\201\364\32\211\366\361\32\323\200"\10[\245\307W\227\13\7Yy\200\341Q\336&f[\343\254r?9\12R\320\245\266\271]/\13\0Q\207\373X\212\227vz\275\23i\177Z61\210\207\244\214j\243\376\2E\233P\32\313\320*B\350\315R{zm\302\31\201E\242\353H\377\6\350|[Dt\314\231\365!'\202\222{\334\331_\5[=\21\377b\366>N)zE\360)|\362\364Z]r\266\233\321&\364\237\21\302\240m\213b\326b\2\325C\263\226\275\0t\213\356/c\372\361\207_\254\3568T\251\32\310s\343\3568f\372\364\205\350<\235\210H\0\351w\24\325F\341N\327r\346\216F\322\233G\241\324\243T\331\374,\212\34\204\272\345\352\304z\271\31\302\360\36V@`\314\315\306\310\253\207@\246\357h\235X\2770\316\30\23{ya\207h\302\35|\22\206\17\330Q\311\0\3107\312\1\215\253\13\22\355\325\21^p\332 \204\24\\371\271\32%&\15\372-\326\3222-\227\3768\215\12\353e\312\376\332M\235.\26\221\246\341:s\246\331`\333\302\230\33AA\272O\336\237\217\25G\377\360\16N\307\223\340/L\260\364\14Q\300\20\273\201t\266I\322\275\21\267+~\0W;\326Ua\322\373*F\337u\26G\213\276\253\363/\301\4\204S\365\247\15\335\370H\247C!9\226\225gj\272\335"\354\241\260\200\321\234\233*\234\215\331\346\0\34\254\254\3500\253\271\330\343\313\315\322\267\216\2178", ) \10[\245\307W\227\13\7Yy\200\341Q\336&f[\343\254r?9\12R\320\245\266\271]/\13\0Q\207\373X\212\227vz\275\23i\177Z61\210\207\244\214j\243\376\2E\233P\32\313\320*B\350\315R{zm\302\31\201E\242\353H\377\6\350|[Dt\314\231\365!'\202\222{\334\331_\5[=\21\377b\366>N)zE\360)|\362\364Z]r\266\233\321&\364\237\21\302\240m\213b\326b\2\325C\263\226\275\0t\213\356/c\372\361\207_\254\3568T\251\32\310s\343\3568f\372\364\205\350<\235\210H\0\351w\24\325F\341N\327r\346\216F\322\233G\241\324\243T\331\374,\212\34\204\272\345\352\304z\271\31\302\360\36V@`\314\315\306\310\253\207@\246\357h\235X\2770\316\30\23{ya\207h\302\35|\22\206\17\330Q\311\0\3107\312\1\215\253\13\22\355\325\21^p\332 \204\24\\371\271\32%&\15\372-\326\3222-\227\3768\215\12\353e\312\376\332M\235.\26\221\246\341:s\246\331`\333\302\230\33AA\272O\336\237\217\25G\377\360\16N\307\223\340/L\260\364\14Q\300\20\273\201t\266I\322\275\21\267+~\0W;\326Ua\322\373*F\337u\26G\213\276\253\363/\301\4\204S\365\247\15\335\370H\247C!9\226\225gj\272\335 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\3310/\265\317\14~f\34RW\6Y[X\2658\35W\2270\325\245\21)df\22\32\327\267\211F{\213\6\374\34\263\35\177g\316\210\373\240M\240\305VG>E\333f\274(\365\225\263>\361\220V\202I4N\34\320\316\313y\215\271\306L\346tG\201\326\310\322_D\244d\5#t,\200\201\364\32\211\366\361\32\323\200"\10[\245\307W\227\13\7Yy\200\341Q\336&f[\343\254r?9\12R\320\245\266\271]/\13\0Q\207\373X\212\227vz\275\23i\177Z61\210\207\244\214j\243\376\2E\233P\32\313\320*B\350\315R{zm\302\31\201E\242\353H\377\6\350|[Dt\314\231\365!'\202\222{\334\331_\5[=\21\377b\366>N)zE\360)|\362\364Z]r\266\233\321&\364\237\21\302\240m\213b\326b\2\325C\263\226\275\0t\213\356/c\372\361\207_\254\3568T\251\32\310s\343\3568f\372\364\205\350<\235\210H\0\351w\24\325F\341N\327r\346\216F\322\233G\241\324\243T\331\374,\212\34\204\272\345\352\304z\271\31\302\360\36V@`\314\315\306\310\253\207@\246\357h\235X\2770\316\30\23{ya\207h\302\35|\22\206\17\330Q\311\0\3107\312\1\215\253\13\22\355\325\21^p\332 \204\24\\371\271\32%&\15\372-\326\3222-\227\3768\215\12\353e\312\376\332M\235.\26\221\246\341:s\246\331`\333\302\230\33AA\272O\336\237\217\25G\377\360\16N\307\223\340/L\260\364\14Q\300\20\273\201t\266I\322\275\21\267+~\0W;\326Ua\322\373*F\337u\26G\213\276\253\363/\301\4\204S\365\247\15\335\370H\247C!9\226\225gj\272\335"\354\241\260\200\321\234\233*\234\215\331\346\0\34\254\254\3500\253\271\330\343\313\315\322\267\216\2178", ) , ) == 0x0 00114 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\226\353\375\265\200\327\254fS\211\205\6\26\200\212\265w\306\205\227\177\16w\21f\277\264\22U\14e\211\11\240Y\6\263\307a\350\274\34\210\264{\237\240\212\215\225>\12\0\264\274g.G\263q*\3000\31Y\2334\1\307\2\316\204\242_\271\211\2274t\10Z\4\310\235\204\226\244+\336\361tc[S\364UR$\361U\10R"G\200\3065\210\214E\13H\202\253\200\256\212\14&)\2001\254=\344\353\12\35\13w\266\366\206\375\13O\212U\373\27QEv5f\301i0\201\3441\307\v\214%x,\2\12@\202\32\204\13\370B\247\26\200{5\266\20\31\316\236p\353\7$\324\3503\200\226t\203B'!hY@{\223\2\215\5\24\346\303\377--\354Nf\241\227\360f\247 \364\25\206\240\266\324\12\364\364\320\312\20\240"P\260\326-\331\7C\374Mo\0;P\16\1\34A\340`\227b\364C\212\22\20\364Z\246\266\6\11o\21\370\360\254\0\30\340\4U.\11)*\11\4\247\26\10Pl\253\274\364\23\4\313\210'\247B\6*H\350\230\3639\331N\265j\365\6\360\354\356kR\321\323@\370\234\302\24\0Sw~\350\177pk\330\254\20\37\322\370U]8", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) G\200\3065\210\214E\13H\202\253\200\256\212\14&)\2001\254=\344\353\12\35\13w\266\366\206\375\13O\212U\373\27QEv5f\301i0\201\3441\307\v\214%x,\2\12@\202\32\204\13\370B\247\26\200{5\266\20\31\316\236p\353\7$\324\3503\200\226t\203B'!hY@{\223\2\215\5\24\346\303\377--\354Nf\241\227\360f\247 \364\25\206\240\266\324\12\364\364\320\312\20\240 (40, 0, 0, 0, "\226\353\375\265\200\327\254fS\211\205\6\26\200\212\265w\306\205\227\177\16w\21f\277\264\22U\14e\211\11\240Y\6\263\307a\350\274\34\210\264{\237\240\212\215\225>\12\0\264\274g.G\263q*\3000\31Y\2334\1\307\2\316\204\242_\271\211\2274t\10Z\4\310\235\204\226\244+\336\361tc[S\364UR$\361U\10R"G\200\3065\210\214E\13H\202\253\200\256\212\14&)\2001\254=\344\353\12\35\13w\266\366\206\375\13O\212U\373\27QEv5f\301i0\201\3441\307\v\214%x,\2\12@\202\32\204\13\370B\247\26\200{5\266\20\31\316\236p\353\7$\324\3503\200\226t\203B'!hY@{\223\2\215\5\24\346\303\377--\354Nf\241\227\360f\247 \364\25\206\240\266\324\12\364\364\320\312\20\240"P\260\326-\331\7C\374Mo\0;P\16\1\34A\340`\227b\364C\212\22\20\364Z\246\266\6\11o\21\370\360\254\0\30\340\4U.\11)*\11\4\247\26\10Pl\253\274\364\23\4\313\210'\247B\6*H\350\230\3639\331N\265j\365\6\360\354\356kR\321\323@\370\234\302\24\0Sw~\350\177pk\330\254\20\37\322\370U]8", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \16\1\34A\340`\227b\364C\212\22\20\364Z\246\266\6\11o\21\370\360\254\0\30\340\4U.\11)*\11\4\247\26\10Pl\253\274\364\23\4\313\210'\247B\6*H\350\230\3639\331N\265j\365\6\360\354\356kR\321\323@\370\234\302\24\0Sw~\350\177pk\330\254\20\37\322\370U]8", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00115 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "P\264\20#n\313\22\11\367\367\0\345+\324{y)\31S\307\17\271\311\341Q\371P|N\323P.\27\315\307&lp:{\16i\21\270A\327j%\16g\3\273\306\203\364w\231V\242\30Xcc\263\210\321[\34\206\311\257\314\11a\331 G\215I\301\331s\10\233"\3264{\303\333\2718\227\252\353rjh\370_\257\333F\223\303\274\303G}\365\25\223\305\332D0C?\242,\373g\347\217\233k\14|\232\7\2223\332lv\307\372U0\373\25\242\302V\22\233q\30\210\351\370\374\204\306\237:\222v;\12[\247>+\266\12C\33\255\346J\33\30Z=O\3218\4\377\341\362mu\262i\303)\22\272*y\302\7\241\277T\372\30zky\366}\3\266$\321\262\337Xx\31\365h\303\350\11\265T[>0x\22&\246V\320Z5\345|\344\31y\365\243\265G\315\302\214\245\314[\342c\26\17q'sb$\13n\233\4O\316Z\367E\205\202\345w@\276\362]\253\227\344\37c\313F\325W\331\254\312\273[\24\231[V\35%\237\346=I\273\361F\224VtH\341d^\2\11e9 '\271E\213\303\332\323X\367YwIC\2025\362];\261\2\235K6iC\2652\14\275\336\327\333N\3012\262@\O\330ES\351t}%ljEB2\340\35w\351\205\362\254t\21\363\372b\177\377\22D\30CM\201|\31y\223\357\317j\232i\\301\305\217\30\11\211\370&\346\304\311}\3@\215Y\27\373\343D\221\232\7", ) \3264{\303\333225\261\316\334\223\363\325\361:\16\177\210M\337\25]Oe\363\264\2513\303xu\275\315a\377\23\262\315\273\306.\252\32I\370\262\345\333\207\3151L\352\322z\255\367_;\304\205\307A\320\320Cj\363H8\244\332=\305\355\370\274\5\377\22\244Y\243\266\337Pa\206>\2718\227\252\353rjh\370_\257\333F\223\303\274\303G}\365\25\223\305\332D0C?\242,\373g\347\217\233k\14|\232\7\2223\332lv\307\372U0\373\25\242\302V\22\233q\30\210\351\370\374\204\306\237:\222v;\12[\247>+\266\12C\33\255\346J\33\30Z=O\3218\4\377\341\362mu\262i\303)\22\272*y\302\7\241\277T\372\30zky\366}\3\266$\321\262\337Xx\31\365h\303\350\11\265T[>0x\22&\246V\320Z5\345|\344\31y\365\243\265G\315\302\214\245\314[\342c\26\17q'sb$\13n\233\4O\316Z\367E\205\202\345w@\276\362]\253\227\344\37c\313F\325W\331\254\312\273[\24\231[V\35%\237\346=I\273\361F\224VtH\341d^\2\11e9 '\271E\213\303\332\323X\367YwIC\2025\362];\261\2\235K6iC\2652\14\275\336\327\333N\3012\262@\O\330ES\351t}%ljEB2\340\35w\351\205\362\254t\21\363\372b\177\377\22D\30CM\201|\31y\223\357\317j\232i\\301\305\217\30\11\211\370&\346\304\311}\3@\215Y\27\373\343D\221\232\7", ) == 0x0 00116 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\37o\302#!\20\300\11\270,\322\345d\17\251yf\302\201\307@b\33\341\36"\202|\1\10\202.X\26\25&#\253\350{A\262\303\270\16\14\270%A\274\321\273\211X&w\326\215p\30\27\270\261\263\307\12\211\34\311\22}\314F\272\13 \10V\233\301\226\250\332\233m\15\346{\214\0\356Y\332j\34\334\334(\7\361u\325\255\210\2\4\307]\0\276!\264\346\350\21x:f\37a\260\310`\315\364\35\374\252U\222*\262\252\0U\315~\2278\3225v%_t\37W\307\16\13\2C%(\2328\353\1\357\305\242#n\5\260\311vY\354m\15P.]\354\271wLx\353=\261\272\370\20t\11F\334\30n\303\10\246'\25\334\36\10D\177\230\355\242c \265\347\300@\271\143A\325\222|\1\276v\210!\2070\264\316p\302\31\311IqWS;\370\263_\24\237uI\244;E\200u>dm\330CTv4JT\303\210=\0\12\352\4\260: m:i\273\303f\311h*6\31\325\241\360\217(\305\260\253\3662\330d$\236i\15X7\302'h\2143\333\265\33\200\35407\311\364\246\31\13\2105\252\2476\316.q\265\10\26\20\214\352\27\211\342,\315\335qh\250\260$D\265I\4\0\25\210\367\12^P\3458\233l\362\22pE\344P\270\31F\232\214\13\254\205`\211\24\326\200\204\35jD4=\6`#F\333\215\246H\256\277\214\2F\276\353 hb\227\213\214\1\1X\270\202\245I\14Y\347\362\22\340c\2\322\220\344i\14n\340\14\362\5\5\333\1\32\340\262\17\207\235\330\12\210;t2\376\276j\12\231\340\340R\254;\205\275w\246\21\274!\260\177\260\311\226\30\14\226S|V\242A\357\200\261Hi\23\32\27\217W\322[\370i=\26\3112\330\222\215\26\314)\343\13JH\7", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \202|\1\10\202.X\26\25&#\253\350{A\262\303\270\16\14\270%A\274\321\273\211X&w\326\215p\30\27\270\261\263\307\12\211\34\311\22}\314F\272\13 \10V\233\301\226\250\332\233m\15\346{\214\0\356Y\332j\34\334\334(\7\361u\325\255\210\2\4\307]\0\276!\264\346\350\21x:f\37a\260\310`\315\364\35\374\252U\222*\262\252\0U\315~\2278\3225v%_t\37W\307\16\13\2C%(\2328\353\1\357\305\242#n\5\260\311vY\354m\15P.]\354\271wLx\353=\261\272\370\20t\11F\334\30n\303\10\246'\25\334\36\10D\177\230\355\242c \265\347\300@\271\143A\325\222|\1\276v\210!\2070\264\316p\302\31\311IqWS;\370\263_\24\237uI\244;E\200u>dm\330CTv4JT\303\210=\0\12\352\4\260: m:i\273\303f\311h*6\31\325\241\360\217(\305\260\253\3662\330d$\236i\15X7\302'h\2143\333\265\33\200\35407\311\364\246\31\13\2105\252\2476\316.q\265\10\26\20\214\352\27\211\342,\315\335qh\250\260$D\265I\4\0\25\210\367\12^P\3458\233l\362\22pE\344P\270\31F\232\214\13\254\205`\211\24\326\200\204\35jD4=\6`#F\333\215\246H\256\277\214\2F\276\353 hb\227\213\214\1\1X\270\202\245I\14Y\347\362\22\340c\2\322\220\344i\14n\340\14\362\5\5\333\1\32\340\262\17\207\235\330\12\210;t2\376\276j\12\231\340\340R\254;\205\275w\246\21\274!\260\177\260\311\226\30\14\226S|V\242A\357\200\261Hi\23\32\27\217W\322[\370i=\26\3112\330\222\215\26\314)\343\13JH\7", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00117 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "}E\202\20\210\373\222\12\375\223\356\350\221\320\204\34G\366\367\14{\11\323\324\204\374&\377\317\206kAmUI\275\220\223\331\250\220\375 +\210\205\200 S\20,\342\15n\2R\323\305Y\373\337\2649\22\24\314\334\332)$\304-K\274oK\240\3409J$A\371U;\203\345Wy\373\265\22L\377\367\21\274\357\363%\340OR\341\12\13\217N\325T\267\377\253\374\253\336]\251\\252\312\312\246%y\23\263\267\255\234T\312\241\271"\330\5\335\276\25L\360\202j\311\233?u\21lH[Z\37\366\1\312B\33\325\325}ktL.\30\21b\225\275\11\374}\273\237\227?\236\223v\267\267\206\6\263\311\3\200\333\202\13,\313\362k^\305L\212\351\373:\134\204\310\3\5\206Sx[\37\210\357a\343\254\23\32\375s'\3m\271'8\277\206\317\35\335\302S\23\277\231c\304\306+Jw\360\276\260\230J\310\304D\325\0 \32\356\276\24@\304|\32[\245\12;\34\377z\345\211zp]JL\221\30\301\37?\200\272\227~#\237R\360\306\14\334W\373\204\350;\1\236\37\370eO\232V\12\31\177\271\3371$\301\211K\35\222,O\330\367@"\357\320\324\334\367\264\210\322\263\266\242K\12\251~o;\303\3600\3475:\25s\250\237\271\236\246\371C\0\237\21T\301\36-{\13\254\4 0\376\215\13 \324\205\235\246\320\300d\337\301\353\204\215pj\32\306\314\14;\325\326\217\366\226\377\27_\360\20\263z\254\245\41\335\12\344\207\360\30\15y\271\376>\304\324\217\20;\306f\205\337\232h\0\226cR3\264\20\342\261\214\223\36{^\277\200\224\340\273tV+\336PR\351\333'\201\343\33;\177[\216\310Oo\342\366n{\2410\374\324Z\4\363\366^\204x\210\352\27\306\213\352\221\316qC&\375\330\306\275", ) \330\5\335\276\25L\360\202j\311\233?u\21lH[Z\37\366\1\312B\33\325\325}ktL.\30\21b\225\275\11\374}\273\237\227?\236\223v\267\267\206\6\263\311\3\200\333\202\13,\313\362k^\305L\212\351\373:\134\204\310\3\5\206Sx[\37\210\357a\343\254\23\32\375s'\3m\271'8\277\206\317\35\335\302S\23\277\231c\304\306+Jw\360\276\260\230J\310\304D\325\0 \32\356\276\24@\304|\32[\245\12;\34\377z\345\211zp]JL\221\30\301\37?\200\272\227~#\237R\360\306\14\334W\373\204\350;\1\236\37\370eO\232V\12\31\177\271\3371$\301\211K\35\222,O\330\367@ (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "}E\202\20\210\373\222\12\375\223\356\350\221\320\204\34G\366\367\14{\11\323\324\204\374&\377\317\206kAmUI\275\220\223\331\250\220\375 +\210\205\200 S\20,\342\15n\2R\323\305Y\373\337\2649\22\24\314\334\332)$\304-K\274oK\240\3409J$A\371U;\203\345Wy\373\265\22L\377\367\21\274\357\363%\340OR\341\12\13\217N\325T\267\377\253\374\253\336]\251\\252\312\312\246%y\23\263\267\255\234T\312\241\271"\330\5\335\276\25L\360\202j\311\233?u\21lH[Z\37\366\1\312B\33\325\325}ktL.\30\21b\225\275\11\374}\273\237\227?\236\223v\267\267\206\6\263\311\3\200\333\202\13,\313\362k^\305L\212\351\373:\134\204\310\3\5\206Sx[\37\210\357a\343\254\23\32\375s'\3m\271'8\277\206\317\35\335\302S\23\277\231c\304\306+Jw\360\276\260\230J\310\304D\325\0 \32\356\276\24@\304|\32[\245\12;\34\377z\345\211zp]JL\221\30\301\37?\200\272\227~#\237R\360\306\14\334W\373\204\350;\1\236\37\370eO\232V\12\31\177\271\3371$\301\211K\35\222,O\330\367@"\357\320\324\334\367\264\210\322\263\266\242K\12\251~o;\303\3600\3475:\25s\250\237\271\236\246\371C\0\237\21T\301\36-{\13\254\4 0\376\215\13 \324\205\235\246\320\300d\337\301\353\204\215pj\32\306\314\14;\325\326\217\366\226\377\27_\360\20\263z\254\245\41\335\12\344\207\360\30\15y\271\376>\304\324\217\20;\306f\205\337\232h\0\226cR3\264\20\342\261\214\223\36{^\277\200\224\340\273tV+\336PR\351\333'\201\343\33;\177[\216\310Oo\342\366n{\2410\374\324Z\4\363\366^\204x\210\352\27\306\213\352\221\316qC&\375\330\306\275", ) , ) == 0x0 00118 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "2\236P\20\307 @\12\262H<\350\336\13V\34\10-%\144\322\1\324\313'\364\377\200]\271A"\216\233\275\337H\13\250\337&\362+\307^R \34\313\376\342B\265\320R\234\36\213\373\220o\353\22[\27\16\332f\377\26-\4g\275K\357;\353Jk\232+UtX7W6 g\22\3$%\21\3634!%\257\224\200\341E\320]N\232\217e\377\344'y\336\22r\216\252\205\21t%6\310a\267\342G\206\312\356b\360\330J\6l\25\3+Pj\206@\355u^\267\232[\25\304$\1\205\231\311\325\232\246\271t\3\365\312\21-No\11\263\246i\237\330\344L\2239le\206Ih\33\3\317\0P\13c\20 k\21\36\236\212\246 \350\13{_\32\3J]\201x\24\304Z\357.8~\23U&\241'L\266k'wdT\317R\6\20S\dKc\213\35\371J8+l\260\327\221\32\304\13\16\322 U5l\24\17\37\256\32\24~\330;S$\250\345\306\241\242]\5\227C\30\216\304\355\200\365L\254#\320\211"\306C\7\205\373\3133\351\1\321\304*e\0A\204\12V\244k\337~\377\23\211\4\306@,\0\3%@m4\2\324\223,f\210\235hd\242\4\321{~ \340\21\360\177<\347:Z\250z\237\366Et\371\14\333M\21\33\32\314-4\320~\4o\353,\215D\373\6\205\322}\2\300+\4\23\353\313V\242jU\35\36\14t\16\4\217\271M-\27\20+\302\2635ww\4~\6\330\344\310+\312\156b,>\213\17]\20t\35\264\205\220A\272\0\331\270\2003Y\357\302\342\376WA\364\205m\200\333;it\31\360\14P\352\11'\3168\311;0\200\\310\0\2640\366!\240s0\263\17\210\4\274-\214\2047S8\27\211P8\221\201\252\221&\262\3\24\275", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \216\233\275\337H\13\250\337&\362+\307^R \34\313\376\342B\265\320R\234\36\213\373\220o\353\22[\27\16\332f\377\26-\4g\275K\357;\353Jk\232+UtX7W6 g\22\3$%\21\3634!%\257\224\200\341E\320]N\232\217e\377\344'y\336\22r\216\252\205\21t%6\310a\267\342G\206\312\356b\360\330J\6l\25\3+Pj\206@\355u^\267\232[\25\304$\1\205\231\311\325\232\246\271t\3\365\312\21-No\11\263\246i\237\330\344L\2239le\206Ih\33\3\317\0P\13c\20 k\21\36\236\212\246 \350\13{_\32\3J]\201x\24\304Z\357.8~\23U&\241'L\266k'wdT\317R\6\20S\dKc\213\35\371J8+l\260\327\221\32\304\13\16\322 U5l\24\17\37\256\32\24~\330;S$\250\345\306\241\242]\5\227C\30\216\304\355\200\365L\254#\320\211 (40, 0, 0, 0, "2\236P\20\307 @\12\262H<\350\336\13V\34\10-%\144\322\1\324\313'\364\377\200]\271A"\216\233\275\337H\13\250\337&\362+\307^R \34\313\376\342B\265\320R\234\36\213\373\220o\353\22[\27\16\332f\377\26-\4g\275K\357;\353Jk\232+UtX7W6 g\22\3$%\21\3634!%\257\224\200\341E\320]N\232\217e\377\344'y\336\22r\216\252\205\21t%6\310a\267\342G\206\312\356b\360\330J\6l\25\3+Pj\206@\355u^\267\232[\25\304$\1\205\231\311\325\232\246\271t\3\365\312\21-No\11\263\246i\237\330\344L\2239le\206Ih\33\3\317\0P\13c\20 k\21\36\236\212\246 \350\13{_\32\3J]\201x\24\304Z\357.8~\23U&\241'L\266k'wdT\317R\6\20S\dKc\213\35\371J8+l\260\327\221\32\304\13\16\322 U5l\24\17\37\256\32\24~\330;S$\250\345\306\241\242]\5\227C\30\216\304\355\200\365L\254#\320\211"\306C\7\205\373\3133\351\1\321\304*e\0A\204\12V\244k\337~\377\23\211\4\306@,\0\3%@m4\2\324\223,f\210\235hd\242\4\321{~ \340\21\360\177<\347:Z\250z\237\366Et\371\14\333M\21\33\32\314-4\320~\4o\353,\215D\373\6\205\322}\2\300+\4\23\353\313V\242jU\35\36\14t\16\4\217\271M-\27\20+\302\2635ww\4~\6\330\344\310+\312\156b,>\213\17]\20t\35\264\205\220A\272\0\331\270\2003Y\357\302\342\376WA\364\205m\200\333;it\31\360\14P\352\11'\3168\311;0\200\\310\0\2640\366!\240s0\263\17\210\4\274-\214\2047S8\27\211P8\221\201\252\221&\262\3\24\275", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00119 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "M(\12H:qx\277\207\232\360\210\222X_\327\34\204b\337X\33\32d]\202\372`\31\336faT\311o\377Y\131'\367\201\353\212\3\332-\200\246\321\\375\225\201j\4LD\230\215i\277\346?H._I\17\221\247\336\20\251y\14\223\264\320\25?\327 L\254\322\250\4\210\245s\4\345x dN\376\245\2l'\202m\231i\31\11>\2345\275\230\34WG\311\246h\3058ZNu\276\273\325\342#\201=uP\355\355\227\371\10\370\273m\353\325Sm\4Y:\12\317;c\371A\335\307;\252\0\277q\200*B\210&-\335\370`\2152#wv%Z\100;\30Z\05\322\336\254\254\, oy\303\3\255\6\14\201U:\241\36\245E\35\223Nx\321};\257\274\243\1\355\366]#\245\200\16\233,j"P\206\232\354G9\220nDi\323\12\245\22\334Ix\355\21\3MS\33\26\277\305j6\23\13\35303/\344\213\363\340M\220\305\302\201\32\13\226/\372\353/A\307\300\311\300D]\226\361<\317\210\306CNaBj\337\274A&\306\10\223"1\310'CG\273\336tT\366-\257KY\275\272]Z\221\4\305\213\225\351\6\365\21\35\244\252\335\270\267\\356\344\337#*CK#\32\0=\376*\370*\331M\267\251kkk\336W\344iKa<8\327X\343\271c\26\224/\233\23p\224P\23 3\233\26\30\253\375\37k\342y\362W@XS\10\\334\16O\177\336\353v)\307HJh\320(GX\200\362J\331\365\350SQ\215R\16kkh;\255\32\246\315\32Zm\337b\272\214\211\361\223\24\7\10AT\277\36:0$\331\322\311\\22\365\357M\363\335aI\313ooO\224\212a\36\12\260H_\374y\360\177O\266\24s\333\224`\214\363\232`h\303\343\30", ) P\206\232\354G9\220nDi\323\12\245\22\334Ix\355\21\3MS\33\26\277\305j6\23\13\35303/\344\213\363\340M\220\305\302\201\32\13\226/\372\353/A\307\300\311\300D]\226\361<\317\210\306CNaBj\337\274A&\306\10\223 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "M(\12H:qx\277\207\232\360\210\222X_\327\34\204b\337X\33\32d]\202\372`\31\336faT\311o\377Y\131'\367\201\353\212\3\332-\200\246\321\\375\225\201j\4LD\230\215i\277\346?H._I\17\221\247\336\20\251y\14\223\264\320\25?\327 L\254\322\250\4\210\245s\4\345x dN\376\245\2l'\202m\231i\31\11>\2345\275\230\34WG\311\246h\3058ZNu\276\273\325\342#\201=uP\355\355\227\371\10\370\273m\353\325Sm\4Y:\12\317;c\371A\335\307;\252\0\277q\200*B\210&-\335\370`\2152#wv%Z\100;\30Z\05\322\336\254\254\, oy\303\3\255\6\14\201U:\241\36\245E\35\223Nx\321};\257\274\243\1\355\366]#\245\200\16\233,j"P\206\232\354G9\220nDi\323\12\245\22\334Ix\355\21\3MS\33\26\277\305j6\23\13\35303/\344\213\363\340M\220\305\302\201\32\13\226/\372\353/A\307\300\311\300D]\226\361<\317\210\306CNaBj\337\274A&\306\10\223"1\310'CG\273\336tT\366-\257KY\275\272]Z\221\4\305\213\225\351\6\365\21\35\244\252\335\270\267\\356\344\337#*CK#\32\0=\376*\370*\331M\267\251kkk\336W\344iKa<8\327X\343\271c\26\224/\233\23p\224P\23 3\233\26\30\253\375\37k\342y\362W@XS\10\\334\16O\177\336\353v)\307HJh\320(GX\200\362J\331\365\350SQ\215R\16kkh;\255\32\246\315\32Zm\337b\272\214\211\361\223\24\7\10AT\277\36:0$\331\322\311\\22\365\357M\363\335aI\313ooO\224\212a\36\12\260H_\374y\360\177O\266\24s\333\224`\214\363\232`h\303\343\30", ) , ) == 0x0 00120 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\2\363\330Hu\252\252\277\310A"\210\335\203\215\327S_\260\337\27\300\310d\22Y(`V\5\264a\33\22\275\377\26\320\343'\270Z9\212L\1\377\200\351\12\216\375\332Z\270\4\3\237J\215&d4?\7\365\215I@Ju\336_r\253\14\334o\2\25p\14\362L\343\11z\4\307~\241\4\252\243\362d\1%w\2#\374\3022"B\273\31F\345N5\362C\316W\10\22th\212\343\210N:ei\325\255\370S=:\213?\355\330"\332\370\364\2669\325\34\266\326Yu\321\35;,"\223\335\210\340x\0\360\252R*\15S\364-\222#\262\215}\370\245vj\201\3320t\303\210\0z\11\14\254\343\207\376 \242\21\3\342\335\336\201\32\341s\36\352\236\317\223\1\243\3}ttn\243N6$]l~R\16\324\367\270"\37]H\354\10\342Bn\13\262\1\12\352\311\16I76\303\3\2\210\311\26\360\36\2706\\32090|\3646\213\274;\237\220\212\31S\32DM\375\372\244\364\223\307\217\22\22D\22M#<\200S\24C\1\272\220j\220g\223&\211\323A"~\23\365C\10`\14t\33-\377\257\4\202o\272\22\201C\4\212PG\351I.\303\35\353q\17\270\370\207<\344\220\370\370C\4\370\310\0r%\370\370e\300\343M\370r\271k$\5\205\344&\220\263, 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \210\335\203\215\327S_\260\337\27\300\310d\22Y(`V\5\264a\33\22\275\377\26\320\343'\270Z9\212L\1\377\200\351\12\216\375\332Z\270\4\3\237J\215&d4?\7\365\215I@Ju\336_r\253\14\334o\2\25p\14\362L\343\11z\4\307~\241\4\252\243\362d\1%w\2#\374\3022 (40, 0, 0, 0, "\2\363\330Hu\252\252\277\310A"\210\335\203\215\327S_\260\337\27\300\310d\22Y(`V\5\264a\33\22\275\377\26\320\343'\270Z9\212L\1\377\200\351\12\216\375\332Z\270\4\3\237J\215&d4?\7\365\215I@Ju\336_r\253\14\334o\2\25p\14\362L\343\11z\4\307~\241\4\252\243\362d\1%w\2#\374\3022"B\273\31F\345N5\362C\316W\10\22th\212\343\210N:ei\325\255\370S=:\213?\355\330"\332\370\364\2669\325\34\266\326Yu\321\35;,"\223\335\210\340x\0\360\252R*\15S\364-\222#\262\215}\370\245vj\201\3320t\303\210\0z\11\14\254\343\207\376 \242\21\3\342\335\336\201\32\341s\36\352\236\317\223\1\243\3}ttn\243N6$]l~R\16\324\367\270"\37]H\354\10\342Bn\13\262\1\12\352\311\16I76\303\3\2\210\311\26\360\36\2706\\32090|\3646\213\274;\237\220\212\31S\32DM\375\372\244\364\223\307\217\22\22D\22M#<\200S\24C\1\272\220j\220g\223&\211\323A"~\23\365C\10`\14t\33-\377\257\4\202o\272\22\201C\4\212PG\351I.\303\35\353q\17\270\370\207<\344\220\370\370C\4\370\310\0r%\370\370e\300\343M\370r\271k$\5\205\344&\220\263, 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \332\370\364\2669\325\34\266\326Yu\321\35;, (40, 0, 0, 0, "\2\363\330Hu\252\252\277\310A"\210\335\203\215\327S_\260\337\27\300\310d\22Y(`V\5\264a\33\22\275\377\26\320\343'\270Z9\212L\1\377\200\351\12\216\375\332Z\270\4\3\237J\215&d4?\7\365\215I@Ju\336_r\253\14\334o\2\25p\14\362L\343\11z\4\307~\241\4\252\243\362d\1%w\2#\374\3022"B\273\31F\345N5\362C\316W\10\22th\212\343\210N:ei\325\255\370S=:\213?\355\330"\332\370\364\2669\325\34\266\326Yu\321\35;,"\223\335\210\340x\0\360\252R*\15S\364-\222#\262\215}\370\245vj\201\3320t\303\210\0z\11\14\254\343\207\376 \242\21\3\342\335\336\201\32\341s\36\352\236\317\223\1\243\3}ttn\243N6$]l~R\16\324\367\270"\37]H\354\10\342Bn\13\262\1\12\352\311\16I76\303\3\2\210\311\26\360\36\2706\\32090|\3646\213\274;\237\220\212\31S\32DM\375\372\244\364\223\307\217\22\22D\22M#<\200S\24C\1\272\220j\220g\223&\211\323A"~\23\365C\10`\14t\33-\377\257\4\202o\272\22\201C\4\212PG\351I.\303\35\353q\17\270\370\207<\344\220\370\370C\4\370\310\0r%\370\370e\300\343M\370r\271k$\5\205\344&\220\263, 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \37]H\354\10\342Bn\13\262\1\12\352\311\16I76\303\3\2\210\311\26\360\36\2706\\32090|\3646\213\274;\237\220\212\31S\32DM\375\372\244\364\223\307\217\22\22D\22M#<\200S\24C\1\272\220j\220g\223&\211\323A (40, 0, 0, 0, "\2\363\330Hu\252\252\277\310A"\210\335\203\215\327S_\260\337\27\300\310d\22Y(`V\5\264a\33\22\275\377\26\320\343'\270Z9\212L\1\377\200\351\12\216\375\332Z\270\4\3\237J\215&d4?\7\365\215I@Ju\336_r\253\14\334o\2\25p\14\362L\343\11z\4\307~\241\4\252\243\362d\1%w\2#\374\3022"B\273\31F\345N5\362C\316W\10\22th\212\343\210N:ei\325\255\370S=:\213?\355\330"\332\370\364\2669\325\34\266\326Yu\321\35;,"\223\335\210\340x\0\360\252R*\15S\364-\222#\262\215}\370\245vj\201\3320t\303\210\0z\11\14\254\343\207\376 \242\21\3\342\335\336\201\32\341s\36\352\236\317\223\1\243\3}ttn\243N6$]l~R\16\324\367\270"\37]H\354\10\342Bn\13\262\1\12\352\311\16I76\303\3\2\210\311\26\360\36\2706\\32090|\3646\213\274;\237\220\212\31S\32DM\375\372\244\364\223\307\217\22\22D\22M#<\200S\24C\1\272\220j\220g\223&\211\323A"~\23\365C\10`\14t\33-\377\257\4\202o\272\22\201C\4\212PG\351I.\303\35\353q\17\270\370\207<\344\220\370\370C\4\370\310\0r%\370\370e\300\343M\370r\271k$\5\205\344&\220\263, 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00121 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "7\273\374\230\4\225\275\374X)\375{\4\310\232S?\267\273t\31w3,n\204\237\4&\213+b0\202US\36\227\205ag\270\326\205\317^\327\323\373\374\320\366_\226\322\227K\334\346 .`\36\327\24\323\345\260\24,I\0x\271\371zL\310\341\25\375\377\345\12\324\226b\17L\364\361\340O\214Y\326\6\317\356\0'\244\232S\6\237\323\340B\243\13\220\3159?\353_\372\31I\365#\212\305N9\261\262|\323K\260}\247\221\214[\31\214}\302\210\323\271N\230\223\202\305\310\360|:\333\351\200VY\234`\225\316Z\267L;\332*Jz\333\12w\336\353\327\345\353P\2169\264\335\271b\276\355\242\355o\357\215YR{(_g\317 \334\332F<\372\332\26u\260[\306\6Z\346RX_<\353\242\32\345\320\201S\333\265\307m{\325\25\255\325\372h\206h~\221@\212\331\5\217\310\250r \300p\362\273\340\252\4c$\321\24t\215\332I\33\310X|\204\334\316\325\343\271g\252K\17^\325J\301\246\364\337\364z\110 *\207%\322\203-WQZ;\347\330E\200\333\202P'\13\264\2\4\302\226*\346\317\273\23\11\247\372\332\313l\324y\252X\240Fq\327\320\360XK\222\335\244\354[\334\10z\301\227\22m\354d\24\33h\261\3322\306q\203c\320\0\323\313\335\377\203\313o\2q\226\232uB\216W"\271&\2138\244\346l\16\213\347a O\379&\347J\315*'\316'\205KK\322|\12\254\370\12%\331e\252\370vpG\223%\247G\210\201\323\3M\271\266\236c\20`lJ\327\336\20_\317`,\204i\306\30W\373\362\313\375\367\31$k\363\372,c\317I\0-\14#\202\37\232^\355\33\333yS@.Zf\36d\231\242l\201\320\213\236\3308\11\233xwv/7\336\3", ) \271&\2138\244\346l\16\213\347a O\379&\347J\315*'\316'\205KK\322|\12\254\370\12%\331e\252\370vpG\223%\247G\210\201\323\3M\271\266\236c\20`lJ\327\336\20_\317`,\204i\306\30W\373\362\313\375\367\31$k\363\372,c\317I\0-\14#\202\37\232^\355\33\333yS@.Zf\36d\231\242l\201\320\213\236\3308\11\233xwv/7\336\3", ) == 0x0 00122 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "x`.\230KNo\374\27\362/{K\23HSplitV\254\341,!_M\4iP\371b\177Y\207SQLWa(c\4\205\200\205\5\323\264'\2\366\20M\0\227\4\74 a\273\314\327[\107\260[\367\233\07b+z\3\233\25\262$7\12\233M\260\17\3/#\340\0W\213\326I\24<\0h\177HSID\1\340\15x\331\220\202\342\355\353\20!\313I\272\370X\305\1\342c\2623\10\231\2602|C\214\24\302^}\215S\1\271\1CA\202\212\23"|u\0;\200\31\202N`\332\25\210\267\3\340\10*\5\241\11\128\59\327\2520\202\216vo\17\271-e?\242\242\264=\215\26\211\251(\20\274\35 \223\1\224<\265\1\304u\377\200\24\6\25=\200X\20\3479\242U>\2\201\34\0g\307"\240\7\25\342\16(h\311\263\254\221\17Q\13\5\300\23zro\33\242\362\364;x\4,\377\3\24;V\10IT\23\212|\313\7\34\325\254b\265\252\4\324\214\325\5\32t\364\220/\250\11\177\373\370\207j\11Q-\30\212\210;\250\3\227\200\224Y\202'Do\320\4\215M\370\346\200`\301\11\350!\10\313#\17\253\252\27{\224q\230\13"X\4I\17\244\243\200\16\105\32E\22"7\266\24T\263c\33}\351\24q\314\270\2\0\234\20\17\377\314\20\275\2>MHu\15U\205"\366\375Y8\353=\276\16\304<\263 \0\304\353&\250\221\37*h\25\365\205\4\220\0|Ew*\12j\2\267\252\267\255\242G\334\376uG\307Z\1\3\2bd\236,\313\262l\5\14\14\20\20\24\262,\313\262\24\30\30 \313\262,\313$$((,,\24\233\0b\327\361\202PA\214\355T\0\253S\17\365\210fQ\277K\242#Z\2\213\321\3\352\11\324\243\245v`\354\14\3", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) |u\0;\200\31\202N`\332\25\210\267\3\340\10*\5\241\11\128\59\327\2520\202\216vo\17\271-e?\242\242\264=\215\26\211\251(\20\274\35 \223\1\224<\265\1\304u\377\200\24\6\25=\200X\20\3479\242U>\2\201\34\0g\307 (40, 0, 0, 0, "x`.\230KNo\374\27\362/{K\23HSplitV\254\341,!_M\4iP\371b\177Y\207SQLWa(c\4\205\200\205\5\323\264'\2\366\20M\0\227\4\74 a\273\314\327[\107\260[\367\233\07b+z\3\233\25\262$7\12\233M\260\17\3/#\340\0W\213\326I\24<\0h\177HSID\1\340\15x\331\220\202\342\355\353\20!\313I\272\370X\305\1\342c\2623\10\231\2602|C\214\24\302^}\215S\1\271\1CA\202\212\23"|u\0;\200\31\202N`\332\25\210\267\3\340\10*\5\241\11\128\59\327\2520\202\216vo\17\271-e?\242\242\264=\215\26\211\251(\20\274\35 \223\1\224<\265\1\304u\377\200\24\6\25=\200X\20\3479\242U>\2\201\34\0g\307"\240\7\25\342\16(h\311\263\254\221\17Q\13\5\300\23zro\33\242\362\364;x\4,\377\3\24;V\10IT\23\212|\313\7\34\325\254b\265\252\4\324\214\325\5\32t\364\220/\250\11\177\373\370\207j\11Q-\30\212\210;\250\3\227\200\224Y\202'Do\320\4\215M\370\346\200`\301\11\350!\10\313#\17\253\252\27{\224q\230\13"X\4I\17\244\243\200\16\105\32E\22"7\266\24T\263c\33}\351\24q\314\270\2\0\234\20\17\377\314\20\275\2>MHu\15U\205"\366\375Y8\353=\276\16\304<\263 \0\304\353&\250\221\37*h\25\365\205\4\220\0|Ew*\12j\2\267\252\267\255\242G\334\376uG\307Z\1\3\2bd\236,\313\262l\5\14\14\20\20\24\262,\313\262\24\30\30 \313\262,\313$$((,,\24\233\0b\327\361\202PA\214\355T\0\253S\17\365\210fQ\277K\242#Z\2\213\321\3\352\11\324\243\245v`\354\14\3", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) X\4I\17\244\243\200\16\105\32E\22 (40, 0, 0, 0, "x`.\230KNo\374\27\362/{K\23HSplitV\254\341,!_M\4iP\371b\177Y\207SQLWa(c\4\205\200\205\5\323\264'\2\366\20M\0\227\4\74 a\273\314\327[\107\260[\367\233\07b+z\3\233\25\262$7\12\233M\260\17\3/#\340\0W\213\326I\24<\0h\177HSID\1\340\15x\331\220\202\342\355\353\20!\313I\272\370X\305\1\342c\2623\10\231\2602|C\214\24\302^}\215S\1\271\1CA\202\212\23"|u\0;\200\31\202N`\332\25\210\267\3\340\10*\5\241\11\128\59\327\2520\202\216vo\17\271-e?\242\242\264=\215\26\211\251(\20\274\35 \223\1\224<\265\1\304u\377\200\24\6\25=\200X\20\3479\242U>\2\201\34\0g\307"\240\7\25\342\16(h\311\263\254\221\17Q\13\5\300\23zro\33\242\362\364;x\4,\377\3\24;V\10IT\23\212|\313\7\34\325\254b\265\252\4\324\214\325\5\32t\364\220/\250\11\177\373\370\207j\11Q-\30\212\210;\250\3\227\200\224Y\202'Do\320\4\215M\370\346\200`\301\11\350!\10\313#\17\253\252\27{\224q\230\13"X\4I\17\244\243\200\16\105\32E\22"7\266\24T\263c\33}\351\24q\314\270\2\0\234\20\17\377\314\20\275\2>MHu\15U\205"\366\375Y8\353=\276\16\304<\263 \0\304\353&\250\221\37*h\25\365\205\4\220\0|Ew*\12j\2\267\252\267\255\242G\334\376uG\307Z\1\3\2bd\236,\313\262l\5\14\14\20\20\24\262,\313\262\24\30\30 \313\262,\313$$((,,\24\233\0b\327\361\202PA\214\355T\0\253S\17\365\210fQ\277K\242#Z\2\213\321\3\352\11\324\243\245v`\354\14\3", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \366\375Y8\353=\276\16\304<\263 \0\304\353&\250\221\37*h\25\365\205\4\220\0|Ew*\12j\2\267\252\267\255\242G\334\376uG\307Z\1\3\2bd\236,\313\262l\5\14\14\20\20\24\262,\313\262\24\30\30 \313\262,\313$$((,,\24\233\0b\327\361\202PA\214\355T\0\253S\17\365\210fQ\277K\242#Z\2\213\321\3\352\11\324\243\245v`\354\14\3", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00123 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "Z<\35o\312\371\3031\2240\322\314S\217\301\32 \255\263'\234\366vPSs"\354`\241\206\36\200\203\213>:\5\300\234\255\322\276\1Kd\236 \371\217\336\360~\334(\17\5\227x~o\300Il\26\243;P\4\307\334\212\220\21\233\25\263G\350P\36\250\5\16^\332\320\216\300\222\307\4\354\370\252\203Z\333u\322\323\363\3210l\270\331|S]\3358\201\334\302\213\12+R\0cE\2716_\246\6H1\36\317 \32+\10\25\336\351hd4\233\314\325)\11&YG\331BCA\342\321\4J\220x`=\350\22\303)7\311\311\232\266bh\353\327\307<\335\216\14\222\255\313\312I\224\25\244\11\317\32\370\336"yw_\377\303\362\206C\223\226\3\307\22\331\211\31\342\4\23\14\241\2001\337R\237\354\204\243>\205\237HZ\\231\301\225`\134\3231TI\200\350\333\353>E!\0\362\1H\245\251\321\3\332\274z\367\3526\27>\271\226K8\16ZLV\337\342\37\273\373\362\200\263\331\5\25\7\320\262\235\231\206\27A\313\306h\32\362\222\0\204\355'$YuY\1\235+&z\216\300\331\200\10\337w9]\3232%b+6\200;\312v\344\230\307\3661.V\371\364\210\251s\322\377u\370{V\332\203E]\211_H\36\367+\332\227\320\351\203\32\330\251.\108\245\24\331\323\312`\220\274\7#F\243X\206\210\4\34#\14\12\22\260\10\230\333\27\330\331\372g\236(\232\356\304}\300n\255`\3G\320\332$a\227\252\248\301\313\177\211\203\336\11\2146%\336\351sV\\227\237}5\36\367I\220\275\316\3125\313\365\0\251\365m\34?\313\360\316E2\312\220P\242\235\245u\272\334\351\271\361\331\220\242FqR\200\363\217=\2N\263\305\13f\201#=\267\6`\375\305\212T\246\310NJ\14", ) \354`\241\206\36\200\203\213>:\5\300\234\255\322\276\1Kd\236 \371\217\336\360~\334(\17\5\227x~o\300Il\26\243;P\4\307\334\212\220\21\233\25\263G\350P\36\250\5\16^\332\320\216\300\222\307\4\354\370\252\203Z\333u\322\323\363\3210l\270\331|S]\3358\201\334\302\213\12+R\0cE\2716_\246\6H1\36\317 \32+\10\25\336\351hd4\233\314\325)\11&YG\331BCA\342\321\4J\220x`=\350\22\303)7\311\311\232\266bh\353\327\307<\335\216\14\222\255\313\312I\224\25\244\11\317\32\370\336 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "Z<\35o\312\371\3031\2240\322\314S\217\301\32 \255\263'\234\366vPSs"\354`\241\206\36\200\203\213>:\5\300\234\255\322\276\1Kd\236 \371\217\336\360~\334(\17\5\227x~o\300Il\26\243;P\4\307\334\212\220\21\233\25\263G\350P\36\250\5\16^\332\320\216\300\222\307\4\354\370\252\203Z\333u\322\323\363\3210l\270\331|S]\3358\201\334\302\213\12+R\0cE\2716_\246\6H1\36\317 \32+\10\25\336\351hd4\233\314\325)\11&YG\331BCA\342\321\4J\220x`=\350\22\303)7\311\311\232\266bh\353\327\307<\335\216\14\222\255\313\312I\224\25\244\11\317\32\370\336"yw_\377\303\362\206C\223\226\3\307\22\331\211\31\342\4\23\14\241\2001\337R\237\354\204\243>\205\237HZ\\231\301\225`\134\3231TI\200\350\333\353>E!\0\362\1H\245\251\321\3\332\274z\367\3526\27>\271\226K8\16ZLV\337\342\37\273\373\362\200\263\331\5\25\7\320\262\235\231\206\27A\313\306h\32\362\222\0\204\355'$YuY\1\235+&z\216\300\331\200\10\337w9]\3232%b+6\200;\312v\344\230\307\3661.V\371\364\210\251s\322\377u\370{V\332\203E]\211_H\36\367+\332\227\320\351\203\32\330\251.\108\245\24\331\323\312`\220\274\7#F\243X\206\210\4\34#\14\12\22\260\10\230\333\27\330\331\372g\236(\232\356\304}\300n\255`\3G\320\332$a\227\252\248\301\313\177\211\203\336\11\2146%\336\351sV\\227\237}5\36\367I\220\275\316\3125\313\365\0\251\365m\34?\313\360\316E2\312\220P\242\235\245u\272\334\351\271\361\331\220\242FqR\200\363\217=\2N\263\305\13f\201#=\267\6`\375\305\212T\246\310NJ\14", ) , ) == 0x0 00124 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\25\347\317o\205"\211\333\353\0\314\34T\23\32ova'\323-\244P\34\250\360\354/zT\36\317XY>u\336\22\234\342\11l\1\4\277L \266T\14\3601\7\372\17JL\252~ \33\233lYx\351PK\34\16\212\337\312I\25\374\234:PQs\327\16\21\1\2\216\217I\25\4\243#x\203\25\0\247\322\234(\30#c\13|\34\206\178\316\7\20\213E\360\200\0,\236k6\20}\324H~\305\35 U\360\332\25\2212\272d{@\36\325f\322\364Y\10\2\220C\169\3\4\5K\252`r3\300\303f\354\33\311\325m\260h\244\14\25<\222U\336\222\342\20\30I\333\316v\11\200\301*\336m\242\245_\260\30 \206\14HD\3\210\311\13\211V9\326\23CzR1\220\211M\354\313x\354\205\320\223\210\\326\32G`D\357\11\33\222R\350\2240\354En\333 \1\7~{\321L\1nz\2701\344\27qbDKw\325\210L\31\40\37\364 \200\374\2\327\25H\301\342\262\322BT\27\16\20\24hU)@\0\3136\365$\26\256\213\1\322\360\364z\301\33\13\200G\4\2459\22\10\340%-\360\344\200t\21\244\344\327\34$1a\215+\364\307r\241\322\260\256*{\31\1QE\22R\215HQ,\371\332\330\13;\203U\3{.G\343w\24\226\10\30`\337g\325#\11x\212\206\307\337\3214l\327\330\22\377\323J\333X\3\13\372(E\372\232\241\37\257\300!v\262\3\10\13\10$.Lx\24w\32\31\177\306X\14\11\303\355\367\336\246\250\204\\330D\2575Q,\233\220\362\25\305\204.\322\251\272\266\316?\204+\34E}\21BP\355Fwu\365\7;\271\276\2B\242\11\252\200\200\274T\357\2\1h\27\13)Z\361=\370\335\262\375\212Q\206\246\207\225\230\14", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \211\333\353\0\314\34T\23\32ova'\323-\244P\34\250\360\354/zT\36\317XY>u\336\22\234\342\11l\1\4\277L \266T\14\3601\7\372\17JL\252~ \33\233lYx\351PK\34\16\212\337\312I\25\374\234:PQs\327\16\21\1\2\216\217I\25\4\243#x\203\25\0\247\322\234(\30#c\13|\34\206\178\316\7\20\213E\360\200\0,\236k6\20}\324H~\305\35 U\360\332\25\2212\272d{@\36\325f\322\364Y\10\2\220C\169\3\4\5K\252`r3\300\303f\354\33\311\325m\260h\244\14\25<\222U\336\222\342\20\30I\333\316v\11\200\301*\336m\242\245_\260\30 \206\14HD\3\210\311\13\211V9\326\23CzR1\220\211M\354\313x\354\205\320\223\210\\326\32G`D\357\11\33\222R\350\2240\354En\333 \1\7~{\321L\1nz\2701\344\27qbDKw\325\210L\31\40\37\364 \200\374\2\327\25H\301\342\262\322BT\27\16\20\24hU)@\0\3136\365$\26\256\213\1\322\360\364z\301\33\13\200G\4\2459\22\10\340%-\360\344\200t\21\244\344\327\34$1a\215+\364\307r\241\322\260\256*{\31\1QE\22R\215HQ,\371\332\330\13;\203U\3{.G\343w\24\226\10\30`\337g\325#\11x\212\206\307\337\3214l\327\330\22\377\323J\333X\3\13\372(E\372\232\241\37\257\300!v\262\3\10\13\10$.Lx\24w\32\31\177\306X\14\11\303\355\367\336\246\250\204\\330D\2575Q,\233\220\362\25\305\204.\322\251\272\266\316?\204+\34E}\21BP\355Fwu\365\7;\271\276\2B\242\11\252\200\200\274T\357\2\1h\27\13)Z\361=\370\335\262\375\212Q\206\246\207\225\230\14", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00125 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "Nz-N\353\16\332\22\20\306\266\262\223_\371qd\232\313\367\307\354\3274\355VP:\300\225`C!\267\213\2051\373\341\31j\221\376\13\344\335R\1\326\233l&h\332\320\20\37\265\263\315\213\250\2356\307\\332\370\244\335\350\7\364.\202\201"\3303\367u\331I\315\33\252\247\32&i@\254\35\201\316\254\16\\5/\333\367\242x\316\6\305\367\35\306\374\14\375\237f\254\3\335\341\204\376\261\233\23\207\25\211\251\221s\364\330\241S\221\20\271\343#E?^\35\300'"X\276\371\332\370 \306\320\316FLc/\118\233\25F\13\3052?\323G'm\241\350\362&G\336\212sC\241Y\300G\343\312*\255\205\266V\324\305\3\352\215\345\221\270R\2739Fa\27\307\32}\303\336\320c[\236\204nd\277\2\243[\236\37\16\247~\360T\320\231 m\231J\33;\367I[w\266r \201\336\306\24\257\236\26\262W\303\241Kh\20\4\257C\327\336\30M\317\261\7\244M\351uE\323__[<\304\212\302\256\177\211('\225\327\10q$\276/\354\266\353X\21\301\30Q\303P\220\322\257\336\301\277_H\20Z\222>O\17cD\252\340\316YDWQ\210\31\27v\247\346\24\354\32\213\16\327\334\33E\247\11Y\252\343\316\15\331\2479O\232\36\326\346\217\371\204|\330y1\377;\\341O\212\25Z\16\347*\200\362/\262\366eU\222 }\324]\370\260\317'\222A\33\26\3=\303\351\306\217\267EmV\5\3728B\13\33N", ) \3303\367u\331I\315\33\252\247\32&i@\254\35\201\316\254\16\\5/\333\367\242x\316\6\305\367\35\306\374\14\375\237f\254\3\335\341\204\376\261\233\23\207\25\211\251\221s\364\330\241S\221\20\271\343#E?^\35\300' (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "Nz-N\353\16\332\22\20\306\266\262\223_\371qd\232\313\367\307\354\3274\355VP:\300\225`C!\267\213\2051\373\341\31j\221\376\13\344\335R\1\326\233l&h\332\320\20\37\265\263\315\213\250\2356\307\\332\370\244\335\350\7\364.\202\201"\3303\367u\331I\315\33\252\247\32&i@\254\35\201\316\254\16\\5/\333\367\242x\316\6\305\367\35\306\374\14\375\237f\254\3\335\341\204\376\261\233\23\207\25\211\251\221s\364\330\241S\221\20\271\343#E?^\35\300'"X\276\371\332\370 \306\320\316FLc/\118\233\25F\13\3052?\323G'm\241\350\362&G\336\212sC\241Y\300G\343\312*\255\205\266V\324\305\3\352\215\345\221\270R\2739Fa\27\307\32}\303\336\320c[\236\204nd\277\2\243[\236\37\16\247~\360T\320\231 m\231J\33;\367I[w\266r \201\336\306\24\257\236\26\262W\303\241Kh\20\4\257C\327\336\30M\317\261\7\244M\351uE\323__[<\304\212\302\256\177\211('\225\327\10q$\276/\354\266\353X\21\301\30Q\303P\220\322\257\336\301\277_H\20Z\222>O\17cD\252\340\316YDWQ\210\31\27v\247\346\24\354\32\213\16\327\334\33E\247\11Y\252\343\316\15\331\2479O\232\36\326\346\217\371\204|\330y1\377;\\341O\212\25Z\16\347*\200\362/\262\366eU\222 }\324]\370\260\317'\222A\33\26\3=\303\351\306\217\267EmV\5\3728B\13\33N", ) \252\343\316\15\331\2479O\232\36\326\346\217\371\204|\330y1\377;\\341O\212\25Z\16\347*\200\362/\262\366eU\222 }\324]\370\260\317'\222A\33\26\3=\303\351\306\217\267EmV\5\3728B\13\33N", ) == 0x0 00126 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\1\241\377N\244\325\10\22_\35d\262\334\204+q+A\31\367\2107\54\242\215\202:\217N\262CnlY\205~ 3\31%J,\13\253\6\200\1\231@\276&'\1\2\20Pna\315\304sO6\210\207\10\370\353\6:\7\273\365P\201m\3\341\367:\2\233\315Tqu\32i\262\222\254RZ\34\254A\207\327/\224,px\201\335\27\367R\35.\14\262D\264\254L\63\204\261jI\23\310\316[\251\336\250&\330\356\210C\20\3668\361Ep\205\317\300h\371\212\276\266\1* \211\13\34F\3\270\375\11w@\307FD\36\340?\234\234\365m\3563 &\10\5Xs\14z\213\300\108\30*\342^dV\233\36\321\352\302>C\270\35`\353F.\314\25\322\30\14\320,\200L\204!\277m\2\354\200L\37A|\254\360\33\13K "B\230\33t,\233[8m\240 \316\5\24\24\340E\304\262\30\30sK'\313\326\257\14\14\14\30\2\24c\7\353\226;u\12\10\215_\24\347\26\212\215u\255\211g\374G\327G\252\366\276`7d\353\27\312\23\30\36\30\202\220\235t\14\301\360\204\232\20\25I\354O@\270\226\252\257\25\213D\30\212Z\31X\255u\346[7\310\213A\14\16\33\12|\333Ys\267B\2J\30\23\10\240P\267Q\262,\333\22k!\24\14\30\30}\266\330r\14\30-\273HP\10D,a\314\15\200[\367U\315\22#ZK\270y:\356\12\32B\267\232\302\177*[;\266\3~I\374\5\370+b\22|z\340\361\261\27"\364\307\0\22\13\222\360\330 \237mq1\316B\2u9\0A\314\326\251T+\2043\3\2531\260\340\216\341\0Q\307ZA<\370\200\275\364`\366*\216@ 2\17\217\370\377\24\365\222\16\300\304\3r\30;\306\300l\227m\31\336(8\15\320\311N", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) B\230\33t,\233[8m\240 \316\5\24\24\340E\304\262\30\30sK'\313\326\257\14\14\14\30\2\24c\7\353\226;u\12\10\215_\24\347\26\212\215u\255\211g\374G\327G\252\366\276`7d\353\27\312\23\30\36\30\202\220\235t\14\301\360\204\232\20\25I\354O@\270\226\252\257\25\213D\30\212Z\31X\255u\346[7\310\213A\14\16\33\12|\333Ys\267B\2J\30\23\10\240P\267Q\262,\333\22k!\24\14\30\30}\266\330r\14\30-\273HP\10D,a\314\15\200[\367U\315\22#ZK\270y:\356\12\32B\267\232\302\177*[;\266\3~I\374\5\370+b\22|z\340\361\261\27 (40, 0, 0, 0, "\1\241\377N\244\325\10\22_\35d\262\334\204+q+A\31\367\2107\54\242\215\202:\217N\262CnlY\205~ 3\31%J,\13\253\6\200\1\231@\276&'\1\2\20Pna\315\304sO6\210\207\10\370\353\6:\7\273\365P\201m\3\341\367:\2\233\315Tqu\32i\262\222\254RZ\34\254A\207\327/\224,px\201\335\27\367R\35.\14\262D\264\254L\63\204\261jI\23\310\316[\251\336\250&\330\356\210C\20\3668\361Ep\205\317\300h\371\212\276\266\1* \211\13\34F\3\270\375\11w@\307FD\36\340?\234\234\365m\3563 &\10\5Xs\14z\213\300\108\30*\342^dV\233\36\321\352\302>C\270\35`\353F.\314\25\322\30\14\320,\200L\204!\277m\2\354\200L\37A|\254\360\33\13K "B\230\33t,\233[8m\240 \316\5\24\24\340E\304\262\30\30sK'\313\326\257\14\14\14\30\2\24c\7\353\226;u\12\10\215_\24\347\26\212\215u\255\211g\374G\327G\252\366\276`7d\353\27\312\23\30\36\30\202\220\235t\14\301\360\204\232\20\25I\354O@\270\226\252\257\25\213D\30\212Z\31X\255u\346[7\310\213A\14\16\33\12|\333Ys\267B\2J\30\23\10\240P\267Q\262,\333\22k!\24\14\30\30}\266\330r\14\30-\273HP\10D,a\314\15\200[\367U\315\22#ZK\270y:\356\12\32B\267\232\302\177*[;\266\3~I\374\5\370+b\22|z\340\361\261\27"\364\307\0\22\13\222\360\330 \237mq1\316B\2u9\0A\314\326\251T+\2043\3\2531\260\340\216\341\0Q\307ZA<\370\200\275\364`\366*\216@ 2\17\217\370\377\24\365\222\16\300\304\3r\30;\306\300l\227m\31\336(8\15\320\311N", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00127 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "%\337 \3015Q\332\16{\6|\307\324a\237\201\271\267\204\247;\21{\304\327\227\332%C\310\311\12\353\35^L2D\T\36]\317\14\266DgL\254"\357\240\247\15=\332\254\34\31E\233\217\351v*\226Z\366Uf\22\27\26\353?\301K\14_\322\331\25\203\336f8P\32\266\333\1\3\255\360A\331\206\5\214V\375\370b\14\321\11\345\222\241\267\345\26\206\23P\375\221\271\211[\210Q\277\315\261\275\336\247P\233\306?\350\234\3\251V7G3^\341\2YB\343r S3[\352\211\244\206Q\320\216\361K\346\262aSj\1\215Z)WE\325\215\3431\322\25\20G0\10M\343Sm\373\3164\216a)C\217\310\366\320~JP\327\340\371\207C\311\243Mc\30\4\315F\13\263/R\3]\6\371\336;\10\373\221\331\217\327Dm#\343!\317Z\311\234^\16\232\26 \337i\235\316\325C\35\226\277ZK\331\247>\2507\312\333E\336+\316\330\264I\240\263\223\270%\31\2\202\207\211\263,\370*\261q\363\3\262G\23L[\2721|@\337\326\373\337\23\335\267\206\311Z!\3739\341\5\255\11\324\32d\361\315bP\307\211\30F\216\217\364\306\253\257\254\305^\257\10)Z\30\265\215\200R\16\211\226\306\243\355\363\344\25\247\246\217dk\271\230\365\277\235\372D4mO\353x\\58wR\252\344\253\21\244y2\377\352\364\313\236\200\24\373\314h\222o[y\4\207\271\221`\276\17,\0\21\321\226\211\255K\347\375K\375\27430\13\251\14m\332&\256Yt\333sG\360%a\214\211o8X\340\34\302\276\302\321\307\276\217\306\217\17\367\323sC\335r\350nZ\21f\327\7\216\276\262\322\246\14)$\33\4\244\313[PD\332\324\3\37\361\223=\36\324\222S\7\372U\214\374HjDN\374\363\353", ) \357\240\247\15=\332\254\34\31E\233\217\351v*\226Z\366Uf\22\27\26\353?\301K\14_\322\331\25\203\336f8P\32\266\333\1\3\255\360A\331\206\5\214V\375\370b\14\321\11\345\222\241\267\345\26\206\23P\375\221\271\211[\210Q\277\315\261\275\336\247P\233\306?\350\234\3\251V7G3^\341\2YB\343r S3[\352\211\244\206Q\320\216\361K\346\262aSj\1\215Z)WE\325\215\3431\322\25\20G0\10M\343Sm\373\3164\216a)C\217\310\366\320~JP\327\340\371\207C\311\243Mc\30\4\315F\13\263/R\3]\6\371\336;\10\373\221\331\217\327Dm#\343!\317Z\311\234^\16\232\26 \337i\235\316\325C\35\226\277ZK\331\247>\2507\312\333E\336+\316\330\264I\240\263\223\270%\31\2\202\207\211\263,\370*\261q\363\3\262G\23L[\2721|@\337\326\373\337\23\335\267\206\311Z!\3739\341\5\255\11\324\32d\361\315bP\307\211\30F\216\217\364\306\253\257\254\305^\257\10)Z\30\265\215\200R\16\211\226\306\243\355\363\344\25\247\246\217dk\271\230\365\277\235\372D4mO\353x\\58wR\252\344\253\21\244y2\377\352\364\313\236\200\24\373\314h\222o[y\4\207\271\221`\276\17,\0\21\321\226\211\255K\347\375K\375\27430\13\251\14m\332&\256Yt\333sG\360%a\214\211o8X\340\34\302\276\302\321\307\276\217\306\217\17\367\323sC\335r\350nZ\21f\327\7\216\276\262\322\246\14)$\33\4\244\313[PD\332\324\3\37\361\223=\36\324\222S\7\372U\214\374HjDN\374\363\353", ) == 0x0 00128 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "j\4\362\30~\356\203\332A\240\324|\210\17\263\237\316be\204\350\340\303{\213\14E\332j\230\3130\206\3219\35\21\227\340D\23\217\314]\200\327dD(\227~"\240{u\15r\1~\34V\236I\217\246\255\370\226\25-\207f]\314\304\353p\32\231\14\20\11\13\25\314\5\2648\37\301d\333N\330\177\360\16\2T\5\303\215/\370-\327\3\11\252Is\267\252\315T\23\37&C\271\306\200ZQ\360\26c\275\221|\202\233\211\344:\234Lr\2047\10\350\214\341M\202\220\343=\373\2013\241[\244\311\212\2\216\276\2204\262.\210\270\1\302\201\373W\12\16_\343~\11\307\20\10\353\3230\28\201m\264\25\346\216.\362\221\217\207-\2~\5\213\5\340\266\\221\311\354\226\261\30K\26\224\13\374\364\200\3\22\335+\336t\323)\221\226T\5D"\3701!\200\201\33\234\21\325H\26o\4\273\235\201\16\221\35\331d\210K\226|\354\250x\21\11E\221\360\34\330\373\222r\263\334c\367\31MYU\211\374\367**\376\252!\3\375\234\301L\24a\343|\17\4\4\373\220\310\17\267\311\22\210!\264\3423\5\342\322\6\32+*\37b\37\34[\30\11U]\364\211p}\254\212\205}\10f\201\312\265\302[\200\16\306M\24\243\242(6\25\350}]d$bJ\365\360F(D{\266\235\3537\207\32788\211x\344\344\312vy}$8\364\204ER\24\264\27\272\222 \200\253\4\310bC`\361\324\376\0^\12D\211\342\2205\375\4&n3\177\320{\14"\1\364\256\26\257\11s\10+\367a\303R\2758\27;\316\302\361\31\3\307\361T\24\217@,\1s\14\6\240\350!\201\303f\230\334\\276\375\11t\14f\377\311\4\353\20\211P\13\1\6\3P*A=Q\17@SH!\207\214\263\223\270D\1'!\353", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \240{u\15r\1~\34V\236I\217\246\255\370\226\25-\207f]\314\304\353p\32\231\14\20\11\13\25\314\5\2648\37\301d\333N\330\177\360\16\2T\5\303\215/\370-\327\3\11\252Is\267\252\315T\23\37&C\271\306\200ZQ\360\26c\275\221|\202\233\211\344:\234Lr\2047\10\350\214\341M\202\220\343=\373\2013\241[\244\311\212\2\216\276\2204\262.\210\270\1\302\201\373W\12\16_\343~\11\307\20\10\353\3230\28\201m\264\25\346\216.\362\221\217\207-\2~\5\213\5\340\266\\221\311\354\226\261\30K\26\224\13\374\364\200\3\22\335+\336t\323)\221\226T\5D (40, 0, 0, 0, "j\4\362\30~\356\203\332A\240\324|\210\17\263\237\316be\204\350\340\303{\213\14E\332j\230\3130\206\3219\35\21\227\340D\23\217\314]\200\327dD(\227~"\240{u\15r\1~\34V\236I\217\246\255\370\226\25-\207f]\314\304\353p\32\231\14\20\11\13\25\314\5\2648\37\301d\333N\330\177\360\16\2T\5\303\215/\370-\327\3\11\252Is\267\252\315T\23\37&C\271\306\200ZQ\360\26c\275\221|\202\233\211\344:\234Lr\2047\10\350\214\341M\202\220\343=\373\2013\241[\244\311\212\2\216\276\2204\262.\210\270\1\302\201\373W\12\16_\343~\11\307\20\10\353\3230\28\201m\264\25\346\216.\362\221\217\207-\2~\5\213\5\340\266\\221\311\354\226\261\30K\26\224\13\374\364\200\3\22\335+\336t\323)\221\226T\5D"\3701!\200\201\33\234\21\325H\26o\4\273\235\201\16\221\35\331d\210K\226|\354\250x\21\11E\221\360\34\330\373\222r\263\334c\367\31MYU\211\374\367**\376\252!\3\375\234\301L\24a\343|\17\4\4\373\220\310\17\267\311\22\210!\264\3423\5\342\322\6\32+*\37b\37\34[\30\11U]\364\211p}\254\212\205}\10f\201\312\265\302[\200\16\306M\24\243\242(6\25\350}]d$bJ\365\360F(D{\266\235\3537\207\32788\211x\344\344\312vy}$8\364\204ER\24\264\27\272\222 \200\253\4\310bC`\361\324\376\0^\12D\211\342\2205\375\4&n3\177\320{\14"\1\364\256\26\257\11s\10+\367a\303R\2758\27;\316\302\361\31\3\307\361T\24\217@,\1s\14\6\240\350!\201\303f\230\334\\276\375\11t\14f\377\311\4\353\20\211P\13\1\6\3P*A=Q\17@SH!\207\214\263\223\270D\1'!\353", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \1\364\256\26\257\11s\10+\367a\303R\2758\27;\316\302\361\31\3\307\361T\24\217@,\1s\14\6\240\350!\201\303f\230\334\\276\375\11t\14f\377\311\4\353\20\211P\13\1\6\3P*A=Q\17@SH!\207\214\263\223\270D\1'!\353", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00129 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\\374\301\2234\362\216\15\2653\255\3@\232w\240"\266\22+v\377\16?\6a\377\335\341+\260\215\22\365\20\10\264\323\247\323{\26\245\367\202\374\361\363\240\230\14\2\305\310$o\210\362w\271\30\224O\355\17\216\273\244\26d\306[#\211\373\4\341&\212i[.+1\337\377u\223\3516\271\322m\4.\347\232\2240\36"\36\232\372\270\203^\34Q\244\214\211\241Y-\24\315-[\244Sq\303\260\245Z\12\211\300\256\14\26\7-M\227\245\271\245\265\256$\353B$\337\261\214?\254\22\244\232\0cTM\372CQ\320\231\21\257\245\343}\375\305r\212\373\320\271\271Iq\247\353QF\330\27n\200\10\25\378\335\262\207)^M%\313\207.\361\323\341F\346\217\232\322U\23\364\303\31\210\311\371c\267?O\340q\324\343\243\223\377\10\371$\304\16T~\367\364M\346\324um\275%\240\205\216\25FIE\303\35;:\264\226J\245\337\3\17\262\24C\361\367\242\267\2432\227@\224\365`?&\33\302M\311P\320\336J\32*\2022'\227\247\366\15\370\226:\301\7\2.\333bP\270\13\220}\242\330\226@\17\202\324\210 \350\220\271\257A;\322\10\273\241#\15u\251V\251\3\2606\315\202k@XDZ>\16\300\247\337R\344@\275\327\360\242l\100\177:\263\353}\33x\213\253\330\257\106z4\340\22)P;2\327\351\4\267\245)\275\311\241'y\340\3215=\376\24DI\333\235xB%3n\260<\325\22v\254?\353P\275\25\245~\333\263\13 ke^\360I\366\31o{#\333t{\272\360T#\264\301\245\261[\7_;*\3\307\210\320\303\16\22\320\340\342\331\353\310D\21\257\201\24J\306\3736\334\244\367\227X\10\12\317v\342\12)\320\237|\267-\351zK\247\315\277A\232\377!", ) \266\22+v\377\16?\6a\377\335\341+\260\215\22\365\20\10\264\323\247\323{\26\245\367\202\374\361\363\240\230\14\2\305\310$o\210\362w\271\30\224O\355\17\216\273\244\26d\306[#\211\373\4\341&\212i[.+1\337\377u\223\3516\271\322m\4.\347\232\2240\36 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\\374\301\2234\362\216\15\2653\255\3@\232w\240"\266\22+v\377\16?\6a\377\335\341+\260\215\22\365\20\10\264\323\247\323{\26\245\367\202\374\361\363\240\230\14\2\305\310$o\210\362w\271\30\224O\355\17\216\273\244\26d\306[#\211\373\4\341&\212i[.+1\337\377u\223\3516\271\322m\4.\347\232\2240\36"\36\232\372\270\203^\34Q\244\214\211\241Y-\24\315-[\244Sq\303\260\245Z\12\211\300\256\14\26\7-M\227\245\271\245\265\256$\353B$\337\261\214?\254\22\244\232\0cTM\372CQ\320\231\21\257\245\343}\375\305r\212\373\320\271\271Iq\247\353QF\330\27n\200\10\25\378\335\262\207)^M%\313\207.\361\323\341F\346\217\232\322U\23\364\303\31\210\311\371c\267?O\340q\324\343\243\223\377\10\371$\304\16T~\367\364M\346\324um\275%\240\205\216\25FIE\303\35;:\264\226J\245\337\3\17\262\24C\361\367\242\267\2432\227@\224\365`?&\33\302M\311P\320\336J\32*\2022'\227\247\366\15\370\226:\301\7\2.\333bP\270\13\220}\242\330\226@\17\202\324\210 \350\220\271\257A;\322\10\273\241#\15u\251V\251\3\2606\315\202k@XDZ>\16\300\247\337R\344@\275\327\360\242l\100\177:\263\353}\33x\213\253\330\257\106z4\340\22)P;2\327\351\4\267\245)\275\311\241'y\340\3215=\376\24DI\333\235xB%3n\260<\325\22v\254?\353P\275\25\245~\333\263\13 ke^\360I\366\31o{#\333t{\272\360T#\264\301\245\261[\7_;*\3\307\210\320\303\16\22\320\340\342\331\353\310D\21\257\201\24J\306\3736\334\244\367\227X\10\12\317v\342\12)\320\237|\267-\351zK\247\315\277A\232\377!", ) , ) == 0x0 00130 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\23'\23\223{)\\15\372\350\177\3\17A\245\240mm\300+9$\334?I\272-\335\256\360b\215].\302\10\373\10u\3234\315w\367\315'#\363\357C\3234M\36\32$ S w\366\303FO\242\324\\273\353\315\266\306\24\370[\373K:\364\212&\200\374+~\4-u\3342\344\271\235\266\326.\250AF0Q\371\314\232\265cQ^S\212v\214\306z\213-[\26\377[\353\210\243\303\377~\210\12\306\33|\14Y\334\377M\330~k\245\372u\366\353\15\377\15\261\303\344~\22\353A\322c\33\226(C\36\13K\21\340~1}\262\36\240\212\264\13k\271\6\252u\353\36\235\12\27![\332\25P\343\17\262\310\362\214Mj\20U.\276\103F\251TH\322\32\310&\303VS\33\371,l\355O\257\252\6\343\354H-\10\266\377\26\16\33\245%\364\2=\6u"f\367\240\312U\307F\6\236\21\35t\341f\226\5~\15\3@i\306C\276,p\267\354\351E@\333.\262?i\300\20M\206\213\2\336\5\301\370\20}\351\365\227\350-\337\370\331\341\3121H\331\374\333-\213j\13\337\246p\330\331\233\335\202\233S\362\350\337b}At\11\332\273\356\370\337u\346\215{\3\377\355\37\202$\233\212D\25\345\334\300\350\4\200\344\17f\5\360\355\267\33200\341a\3532\300\252\213\344\3}\10y\241\346\340]\362\202;}\14;\4\370~\373\27z\22s'6;\35r%\306D\6\0Ox\15\376\341n\377\347\7\229w\355\353\37f\307\2451\0a\13o\260\267^\277\222$\31 \240\361\333;\240h\360\33\370f\301\352j\211\7\20\340\370\3\210S\2\303A\311\2\340\255\29\310\13\312}\201[\221\24\373y\7v\367\330\203\332\12\200\2550\12f\13M|\370\366;z\4|\37\277\16A-!", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) f\367\240\312U\307F\6\236\21\35t\341f\226\5~\15\3@i\306C\276,p\267\354\351E@\333.\262?i\300\20M\206\213\2\336\5\301\370\20}\351\365\227\350-\337\370\331\341\3121H\331\374\333-\213j\13\337\246p\330\331\233\335\202\233S\362\350\337b}At\11\332\273\356\370\337u\346\215{\3\377\355\37\202$\233\212D\25\345\334\300\350\4\200\344\17f\5\360\355\267\33200\341a\3532\300\252\213\344\3}\10y\241\346\340]\362\202;}\14;\4\370~\373\27z\22s'6;\35r%\306D\6\0Ox\15\376\341n\377\347\7\229w\355\353\37f\307\2451\0a\13o\260\267^\277\222$\31 \240\361\333;\240h\360\33\370f\301\352j\211\7\20\340\370\3\210S\2\303A\311\2\340\255\29\310\13\312}\201[\221\24\373y\7v\367\330\203\332\12\200\2550\12f\13M|\370\366;z\4|\37\277\16A-!", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00131 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\177\372\372\336\331\3279'Y\330\204\15\311%E\254B\307\305\213\220\3409u\215N\304\13ee\27\237\243\375\3467E\202\22Z\24\13)\213 /\371\240}@\240l\1\330\230\44\350\323\4p\260\37w\21\312k\255\13\216\212\273N\245\12\31\17k\327)\367\237\266\20>8\344\353\331\321Y\377L\25\223\3049\360\340\27t\24/)Y\333k\266\322\375\306A\365\256\3(\355^\34\213\244[\204\24]s\64\31\361\352\331\3130\336n\34\233bF\263\300\351\373:^\6\221\346\215}Yl\206[\30\322\345\17\236I\362S\306{Z4\248\255\110\226[\360\243\243S\332R\13\337\351\270\256W\217\350\241\330\27\211\272P\317TX\301\254N\244\212 s\3005\245\14\223\366\376\200L\255\351\318\340\351c\347\241J\333\311R\327\24C\255\351b\314f\376t\31\251W\12\210\16\263\234\365\336\227\250\327\324\15\251\255\37}\252\27\256uQv\236\275k\216~m\31A\322\322\360N\237\302\344Y\332\357\334G\326|[\360Kr\10\24\13Y\352\316Y\274[\236>\322\376L\327S\302z@\251\233BZ0\16\211\342\226(\243\273\215T\336\36\227\213z\25[\216m\273\356\3161gd\335%\270)\2179\321\17;4\323k/@\314\16\213J$\244\36\30\313\371\373\30j\317v\361\210\22B\3520\3336j\322X\317Abn\210\275\302\344&dn!\241\316=\33\20\253\355\346\235\244\330\235\310\206\272\17F\271\360\324A\313\343\4m \344\316$<\330Y\4t4\241\214", ) , ) == 0x0 00132 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "0!(\336\226\14\353'\26\3V\15\206\376\227\254\15\34\27\213\337;\353u\302\225\26\13*\276\305\237\354&47\12Y\300Z[\320\373\213o\364+\2402\233rlN\3J\4{3\1\4?k\315w^\21\271\255DUX\273\1~\330\31@\260\5)\270Dd\20q\3436\353\226\12\213\377\3\316A\304v+2\27;\317\375)\26\0\271\266\235&\24A\272u\321(\242\205\316\213\353\200V\24\22\250\3244V*8\331\204\353\14nS@\260F\374\33;\373u\205\324\221\251V\257Y#]\211\30\235>\335\236\6)\201\3064\201\346<9\0\32\10\37\30U\301\22QVL\341WQ=\370\211;\27\323\270G>b;\254\314c\23$\2009\3\350\0\356\241\272H\367\373_\1\236\216_U\350\343`jv\300\276\261\4Oh\13URu\37x\5\315&G\4$Y\2\354\24wv\3330\331\200"\243\354\210\10RD\4;\270\341\214]\350\356\3\305\211\365\213\35T\27\32~N\353Q\362s\217\356w\14\334-,\200\3v;\31w;;c\250z\230\333\206\211\5\24\14v;b\203\275,tVr\205\12\307\325a\234\272\5E\250\230\17\337\251\342\304\257\252Xu\247Q9Eok\301\245\277\31\16\11\0\360\1D\20\344\26\1=\334\10\15\256[\277\220\240\10[\320\213\352\201\202n[\321\345\0\376\3\14\201\3025\233{\233\15\201\342\16\3069D(\354`_T\221\305E\2135\316\211\216"`<\316~\274\266\335jc\373\217v\12\335;{\10\271/\17\27\334\213\5\377v\36W\20+\373W\261\35v\276S\300B\245\353\116%\11\212\317\16\271\274\210\362\316&+\265\363\241\201\346\311\20\34464\235\353\3O\310\311a\335F\366+\6A\2048\326mo?\34$s\3\213\4;\357s\214", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \243\354\210\10RD\4;\270\341\214]\350\356\3\305\211\365\213\35T\27\32~N\353Q\362s\217\356w\14\334-,\200\3v;\31w;;c\250z\230\333\206\211\5\24\14v;b\203\275,tVr\205\12\307\325a\234\272\5E\250\230\17\337\251\342\304\257\252Xu\247Q9Eok\301\245\277\31\16\11\0\360\1D\20\344\26\1=\334\10\15\256[\277\220\240\10[\320\213\352\201\202n[\321\345\0\376\3\14\201\3025\233{\233\15\201\342\16\3069D(\354`_T\221\305E\2135\316\211\216 (40, 0, 0, 0, "0!(\336\226\14\353'\26\3V\15\206\376\227\254\15\34\27\213\337;\353u\302\225\26\13*\276\305\237\354&47\12Y\300Z[\320\373\213o\364+\2402\233rlN\3J\4{3\1\4?k\315w^\21\271\255DUX\273\1~\330\31@\260\5)\270Dd\20q\3436\353\226\12\213\377\3\316A\304v+2\27;\317\375)\26\0\271\266\235&\24A\272u\321(\242\205\316\213\353\200V\24\22\250\3244V*8\331\204\353\14nS@\260F\374\33;\373u\205\324\221\251V\257Y#]\211\30\235>\335\236\6)\201\3064\201\346<9\0\32\10\37\30U\301\22QVL\341WQ=\370\211;\27\323\270G>b;\254\314c\23$\2009\3\350\0\356\241\272H\367\373_\1\236\216_U\350\343`jv\300\276\261\4Oh\13URu\37x\5\315&G\4$Y\2\354\24wv\3330\331\200"\243\354\210\10RD\4;\270\341\214]\350\356\3\305\211\365\213\35T\27\32~N\353Q\362s\217\356w\14\334-,\200\3v;\31w;;c\250z\230\333\206\211\5\24\14v;b\203\275,tVr\205\12\307\325a\234\272\5E\250\230\17\337\251\342\304\257\252Xu\247Q9Eok\301\245\277\31\16\11\0\360\1D\20\344\26\1=\334\10\15\256[\277\220\240\10[\320\213\352\201\202n[\321\345\0\376\3\14\201\3025\233{\233\15\201\342\16\3069D(\354`_T\221\305E\2135\316\211\216"`<\316~\274\266\335jc\373\217v\12\335;{\10\271/\17\27\334\213\5\377v\36W\20+\373W\261\35v\276S\300B\245\353\116%\11\212\317\16\271\274\210\362\316&+\265\363\241\201\346\311\20\34464\235\353\3O\310\311a\335F\366+\6A\2048\326mo?\34$s\3\213\4;\357s\214", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00133 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\\366Y\274\314\341\354\334\262\356\237\15ER\323\241I\7\24\0A\242\256\364)\20\370\263\360T\205\2\230\336G\32\210\322\26\231\325\372\332\17\313H\365\353d\2366\35\37\360\326\202\266A\317\257\372\257\217G\213\3030\335\302\244\11GUFc\20\370\362 \360\24\206p\327i\34\207\314\0\216\223\207|\344\343\326\270\270\230\377\17+\217\220\0o\30=T~\315\315\20\233\310|\265\5\335u~E\324\211\25\3\272\315tr\262\205P\217\315\265\34\0~y\255\335'~DV\357\252\353\35\214\201\246\2\256\246_\30\333\306\360W\343l\240\177V\242\30\270\177\201\300\17\232\27\261\225\253\337\211EY9.VI\231+\363Kz\222F\342\230\320\347\202\323d+Kz\33\323\342\3425\\34\261\227\37\317\22\3\324\200\207P\345[\320\22\350]i\2207\305\342\310+\254\331\230\266{[\312\36\266\212L\216\21D\320E\334eS\342\331"ZG`\255\331osG\202K\332\13\233\16\6\341\213\205LM#d[-\260n\340,rn\257\377\375V\331\252\255b\374\3747\243\266\277\261Q\347.\261\263\324\224\257,\347E\177\6T\205\212\277k\361\340\364\313\202\212\257,\20\374\2\206\264\253\267l\275\231\302\227\305\374I\234\320\213H\328\3]\276\11\332"\334\331\4\5\4\327\10G\327De\26M\365\20[\305\312\34\26M\267YZ\373\366\14g\220\327\277\12\321\2550\5\256\32\350\16\323\264\255\362'\274mE\334\13[\3544\335\13\307\334,\312\375\273\226\27\260\316\274\257:hY\205)\324\5\363)pM\2\27-\313\357\321\351\22$\263K-\374\275u_w\260P\257\14d"U\367g+\237\21#:\227\250L\256\377\213\222\215\37\1C\301\32\1OZ\214\340\370\260\200", ) ZG`\255\331osG\202K\332\13\233\16\6\341\213\205LM#d[-\260n\340,rn\257\377\375V\331\252\255b\374\3747\243\266\277\261Q\347.\261\263\324\224\257,\347E\177\6T\205\212\277k\361\340\364\313\202\212\257,\20\374\2\206\264\253\267l\275\231\302\227\305\374I\234\320\213H\328\3]\276\11\332 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\\366Y\274\314\341\354\334\262\356\237\15ER\323\241I\7\24\0A\242\256\364)\20\370\263\360T\205\2\230\336G\32\210\322\26\231\325\372\332\17\313H\365\353d\2366\35\37\360\326\202\266A\317\257\372\257\217G\213\3030\335\302\244\11GUFc\20\370\362 \360\24\206p\327i\34\207\314\0\216\223\207|\344\343\326\270\270\230\377\17+\217\220\0o\30=T~\315\315\20\233\310|\265\5\335u~E\324\211\25\3\272\315tr\262\205P\217\315\265\34\0~y\255\335'~DV\357\252\353\35\214\201\246\2\256\246_\30\333\306\360W\343l\240\177V\242\30\270\177\201\300\17\232\27\261\225\253\337\211EY9.VI\231+\363Kz\222F\342\230\320\347\202\323d+Kz\33\323\342\3425\\34\261\227\37\317\22\3\324\200\207P\345[\320\22\350]i\2207\305\342\310+\254\331\230\266{[\312\36\266\212L\216\21D\320E\334eS\342\331"ZG`\255\331osG\202K\332\13\233\16\6\341\213\205LM#d[-\260n\340,rn\257\377\375V\331\252\255b\374\3747\243\266\277\261Q\347.\261\263\324\224\257,\347E\177\6T\205\212\277k\361\340\364\313\202\212\257,\20\374\2\206\264\253\267l\275\231\302\227\305\374I\234\320\213H\328\3]\276\11\332"\334\331\4\5\4\327\10G\327De\26M\365\20[\305\312\34\26M\267YZ\373\366\14g\220\327\277\12\321\2550\5\256\32\350\16\323\264\255\362'\274mE\334\13[\3544\335\13\307\334,\312\375\273\226\27\260\316\274\257:hY\205)\324\5\363)pM\2\27-\313\357\321\351\22$\263K-\374\275u_w\260P\257\14d"U\367g+\237\21#:\227\250L\256\377\213\222\215\37\1C\301\32\1OZ\214\340\370\260\200", ) U\367g+\237\21#:\227\250L\256\377\213\222\215\37\1C\301\32\1OZ\214\340\370\260\200", ) == 0x0 00134 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\23-\213\274\203:>\334\3755M\15\12\211\1\241\6\334\306\0\16y|\364f\313*\263\277\217W\2\327\5\225\32\307\11\304\231\232!\10\17\204\223'\353+E\344\35P+\4\202\371\232\35\257P\351}\217\10P\210\222\31v\11\10\216\224c_# \277\317Tp\230\262\316\207s\226d\177\226|\314-\210\\266;\204\345\36\0\301HU|\2538\4\270\367C-\17dTB\0 \303\357T1\26\37\20\324\23\256\265J\6\247~\12\17[\25La\37t=iWP\300\26g\34O\245\253\255\222\374\254D\314x\353RWS\246Mut_W\0\24\360\308\276\2400\215p\30\367\244S\300@A\305\261\332p\15\211\12\202\353.\31\222K+\274\220\250\222\119J\320\250Y\1dd\220\250\33\234905\23\307c\227P\24\300\3\233[UP\252\200\2\22\247\206\273\220x\360\310dw\13\230\371\240\211\312QmXL\301\312\226\320\12\7\267S\255\2\360Z\10\273\177\331 \250\225\202\4\1\331\233A\3353\213\312\227\237#+\200\377\260!;\376r!t-\375\31\2x\255-'.7\354mm\261\36<\374\261\374\17F\257c<\227\177I\217W\212\360\260#\340\273\20P\212\340\367\302\374M]f\253\370\267o\231\215L\27\374\6G\2\213\7\301\352\3\22e\333\332m\7\13\4J\337\5\10\10\14\226eY\226'\20\24\36\30\34Y\226eY\25 $\14(K\5\277E\12\1770Ju\310\350A\10f\255\275\374nm\12\7\331[\243\357\17\13\210\7\376\312\262`D\27\377\25n\257u\263\213\205f\17\327\363f\253\237\2X\366\31\357\2362\300$\374\220\377\374\362\256\215w\377\213}\14+\371\207\367(\360M\21l\341E\250\3u-\213\335V\315\1\14\32\310\1\0\201^\340\267\315\342\200", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00135 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "l.\307\205)\235.\6T\257Y\22J\0\332s`\0L\242!\357\350C\321\3310\6^4\3222\373\251\302\1\205\211\223\301\261\27{"/\312*\273\313\272\322,\307H\321\370:\352 \243\22\213\203\351\344\273\21\202\\277\352\213\205a\312OG\303\323\346\26\203\2062\317r\34\370\33i\2\262]c\0\22X\357\305(X\360"\323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\", ) \302\1\205\211\223\301\261\27{ (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "l.\307\205)\235.\6T\257Y\22J\0\332s`\0L\242!\357\350C\321\3310\6^4\3222\373\251\302\1\205\211\223\301\261\27{"/\312*\273\313\272\322,\307H\321\370:\352 \243\22\213\203\351\344\273\21\202\\277\352\213\205a\312OG\303\323\346\26\203\2062\317r\34\370\33i\2\262]c\0\22X\357\305(X\360"\323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\", ) \323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\", ) == 0x0 00136 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "#\365\25\205fF\374\6\33t\213\22\5\333\10s/\333\236\242n4:C\236\2\342\6\21\357\02\264r\356/\255\372;\373w\242}\31\260\21\35\353\373v\357\377l\377\7\16 \242\225\12;M\370\177\220\38\0\0\261u\213\264R\373x\311X\3150\334gA`\353\361\336\5\10\267-\227\344\206\234\231\245\350\320\16\304\30\266\375\370\7\350\13t(\31W\25]\253\200\27D\215_\4N\272\24\3406*\32\312U\30\24\311\31\270?2;7|\352o\257\330\347\201\200\14\330\20\340\202`\321\222\330\373j\6\304\14\264\346o\341m\227\267\203\377\355hA}\5\5\270Z\6\15\372Y\245\32\370\351\22\17\2133^ND\202\231\350Y\361\370\226\221\200\264\36\260\344\260\17*\200w\30\23\203|\223\317Vc\201B\177\351tF\0\35\247(\200\201\21\243\325\13\14{-\333\213\30QW\341>E\37\237V\307\323\364?1\253w\267\221W\3$\377\15~\325\305\30_3+T\224\274=>\301\226\17\203%\274b\236\360&\204A\13\1J\231\3\22\0\3116\24\370Qn\247\250\221\12Jo\375\336G\263\2\316\23\275\15\22\20\30:\237\276-#\367u\313\357\363\245Jo\370H\272\225\34\243\17\361k\35\242\21m\234\364Q\303o\2\5\346\34PSaO\360\200np\375)\376\242\371\20\1\312RA\301\376\314\251"`\21\370\273\204a\0,\210\223\3\370u1\362\243]PQ\351\253`\303\202\23d8\213\312\272\30O\10\30\1\346YXT2\200\251\316\370T\262\320\262\22\270\322\22\274\27(\27+\360\323\344Y\300cV\4c\17\63\227D\303\264\13\260\250\206XxS\25P\376\333\1\201{\227\215\34\224E\7\1\1}\26\235|$,\350\0t\2132]j\34F\354\21\364*\361\333C\307k\357v\3\", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) `\21\370\273\204a\0,\210\223\3\370u1\362\243]PQ\351\253`\303\202\23d8\213\312\272\30O\10\30\1\346YXT2\200\251\316\370T\262\320\262\22\270\322\22\274\27(\27+\360\323\344Y\300cV\4c\17\63\227D\303\264\13\260\250\206XxS\25P\376\333\1\201{\227\215\34\224E\7\1\1}\26\235|$,\350\0t\2132]j\34F\354\21\364*\361\333C\307k\357v\3\", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00137 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, ",\225\312!c\340\361\264\325\330\244B\16\217\331D[\332\261t\17\225\266t[\274\223\14\207\276\37\4[\343\361\220\343\220E<\314\377\216\310p\223;^.GZ\233\15\203\361\364\14\22\267(3\222\336\240\347\205\206\5<\304\32\3Np\230DJ\230\312\316H\22\31HN\330\267\30O\345\366\313\355\361\12\7\237\11XAe[B\204\13!\326\231\317\20\333:o\236\204\7\2260\374Mc\254\326\306D?\236\201\14\233\345\3\271\23\210+\14W\331|'\233\234\232[\332N\254\337L#JH\224t\357\36\206\4*4\364\203\274\274L\321%\377\267\322O\360\224\363\233/\4\226\24\13\357\332KI7\267\13\13\313\3618\374\314\33\215\313\230\300\24\13?\1\147\337\300S\12\323i\11vNNSz\236\352\35\215\213\12SS\264\2523CL\357\204\333\204\31E\347\204\206a\363\23\244/\32\323!E\227\264\3\267\203\257\207\303\300\324\346t`\342C_\12'\224\30 O\230\232bJ\361H\367\R\220T\267\321w\241a\237p\324\214\225\30L\274\325\246/\373k\1\315\374\323\271'\330+ \266\333\3014O\214\352\217\262\3356\0\36;\320i\375\213\240\3\32\277\264T[\24\242TO\373P*\367\2|\27\35\343\302\3448\215\33&H\303\304P^\254\204\1\372\25\303\27\264\250\22\354\343\321\357\347p\210\262\20_I\323E\177O\202T\257%\355S\207\312\275\351\3657V\346D\217\200\2\220\207\31\30ojD\334\224\330\pN\3119\2\204\234n\367e"\256\4O\234\12H[\370\230.\14\222j8\26\23\324\244E\303\216\242K \336\2\2\256\302\257\7\330\266\2\355}\212h$>\265pT\3026\3\340\367\33\360v,\326\4\K\320\3\235\326\326\266C\333\322\10S\330\30\226{\330\222 \fWM", ) \256\4O\234\12H[\370\230.\14\222j8\26\23\324\244E\303\216\242K \336\2\2\256\302\257\7\330\266\2\355}\212h$>\265pT\3026\3\340\367\33\360v,\326\4\K\320\3\235\326\326\266C\333\322\10S\330\30\226{\330\222 \fWM", ) == 0x0 00138 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "cN\30!,;#\264\232\3vBAT\13D\24\1ct@Ndt\24gA\14\310e\315\4\248#\220\254K\227<\203$\\310?H\351^a\234\210\233BX#\364C\311e(|I\14\240\250^T\5s\37\310\3\1\253JD\5C\30\316\7\311\313H\1\3e\30\0>$\313\242*\330\7\320\322\212A*\200\220\204D\372\4\231\200\313\11: EV\7\331\353.M,w\4\306\13\344L\201C@7\3\366\310Z+C\214\13|h@N\232\24\1\234\254\220\227\361J\7O\246\357Q]\326*{/Q\274\363\227\3%\260l\0O\277O!\233`\337D\24D4\10K\6\354e\13D\20#8\263\27\311\215\204C\22\24D\344\323\14x\4\22SE\10\273\119\225\234S5E8\35\302P\330S\34ox3\14\227=\204\224_\313E\250_Ta\274\310v/U\10\363E\330o\321\267\314tU\303\217\174t/9\221_E\374F\30o\224J\232-\221#H\270\207\200\220\33l\3w\356\272Mp\233WG\30\3g\7\246` \271\1\202'\1\271h\3\371 \371\0\234\0W8\217\375\6\344\0Q\340\2i\262Pr\3UdfT\24\317pT\0 \202*\270\331\256\27R8\20\344wV\311&\7\30\26P\21wV\1\265\316\21\27\373s\300\354\254\12=\347?S`\20\20\222\1E0\224PT\340\376?S\310\21o\351\272\354\204\346\13TR\2\337\\313\30 \261\226\334\333\3\216p\1\22\353\2\313G\274\367*\371|\4\0G\330H\24#J.CI\2708Y\310\6\244\12\30\\242\4\373\14\2Mu\20\257H\3d\2\242\246Xhk\345gp\33\31\344\3\257,\311\3609\367\4\4\23\220\2\3\322\15\4\266\14\0\0\10\34\3\312\2264\3@ \23\275\205M", 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00139 400 NtReadFile (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\325\233\302\214M\307\302\205\304\212\311\27\217\340\2368\36\3727R"|\204\210\277e\321|\205\267L\11o\205B\346T\33\27h\271\324\377\330_\352bF\244'\236\15+\320\251\301C\333\12\17s\321\224\21\213\315\216k\265\373\264AR\332\6k\7H\330\345\254=Za \3\331+D\267d\214me\302\201My9\301\360\332\264@\363\2\371v\301\325\12\262o\233\335\21\377\353J\315\5\351\237\263\243\376I@7\325T\14\206\26\300\226g\223\334\13k\233\21@_\236X\261\26\300S|+\321\333\221x@\327\20\350\312\201\360\362\30`\11\6\320\216B\210\330\314\357\370\327\24\217\261\231\202\261\313\361\216\203.\32\220\20\305 \364\364GYx\211uj\276\26\353U\300\14i\250\343\353\330\331I\11!\377\302s\216\365\250\266v\206\374Y\303\351\265\20\224\257\202\5\374\321\373\370\375\322\31\352Xo\35:C\377\311B\37\321\206\20G\315\326MI\212\376\2K\37\255dJ\260\306\6\11\177B\11Y\320P\242$\375\314#\26\306\320=\247\27J\5\256N18_\300\313\263J\224\246\242\245\311D\260\\362\347\26t\303\324\234\31\276\351;\213\271\236\20\303\310q\10/h\352$\343\374\303I\7C\271\4A\353\242\232b\240\303nB3\262\300\314\272\342\211`\367\13\214\226\253\306\2\263\325\361\250W\31\212\337\23\22L-@\256\260\236\12\215\203\21K\305\335\22\15\327\224@0\211`C\205\321`\14\222e\332\322\377y\201\344"\337\276Y\214p\224\16\315\302a%\322\324p\336|\257\31F\236\267\3326C\273M)m&hAC\203\22\340.\347\223\315cLo\2-\212\356s[\337#N\267\211$h\4A\212\237^\342 \1g\271o\11\250\354A\226\202\7\336\224F\206\12\222\216i\266\20\270\313\210x\371!\304\4", ) |\204\210\277e\321|\205\267L\11o\205B\346T\33\27h\271\324\377\330_\352bF\244'\236\15+\320\251\301C\333\12\17s\321\224\21\213\315\216k\265\373\264AR\332\6k\7H\330\345\254=Za \3\331+D\267d\214me\302\201My9\301\360\332\264@\363\2\371v\301\325\12\262o\233\335\21\377\353J\315\5\351\237\263\243\376I@7\325T\14\206\26\300\226g\223\334\13k\233\21@_\236X\261\26\300S|+\321\333\221x@\327\20\350\312\201\360\362\30`\11\6\320\216B\210\330\314\357\370\327\24\217\261\231\202\261\313\361\216\203.\32\220\20\305 \364\364GYx\211uj\276\26\353U\300\14i\250\343\353\330\331I\11!\377\302s\216\365\250\266v\206\374Y\303\351\265\20\224\257\202\5\374\321\373\370\375\322\31\352Xo\35:C\377\311B\37\321\206\20G\315\326MI\212\376\2K\37\255dJ\260\306\6\11\177B\11Y\320P\242$\375\314#\26\306\320=\247\27J\5\256N18_\300\313\263J\224\246\242\245\311D\260\\362\347\26t\303\324\234\31\276\351;\213\271\236\20\303\310q\10/h\352$\343\374\303I\7C\271\4A\353\242\232b\240\303nB3\262\300\314\272\342\211`\367\13\214\226\253\306\2\263\325\361\250W\31\212\337\23\22L-@\256\260\236\12\215\203\21K\305\335\22\15\327\224@0\211`C\205\321`\14\222e\332\322\377y\201\344 (36, 0, 0, 0, 10240, 0x0, 0, ... {status=0x0, info=10240}, "\325\233\302\214M\307\302\205\304\212\311\27\217\340\2368\36\3727R"|\204\210\277e\321|\205\267L\11o\205B\346T\33\27h\271\324\377\330_\352bF\244'\236\15+\320\251\301C\333\12\17s\321\224\21\213\315\216k\265\373\264AR\332\6k\7H\330\345\254=Za \3\331+D\267d\214me\302\201My9\301\360\332\264@\363\2\371v\301\325\12\262o\233\335\21\377\353J\315\5\351\237\263\243\376I@7\325T\14\206\26\300\226g\223\334\13k\233\21@_\236X\261\26\300S|+\321\333\221x@\327\20\350\312\201\360\362\30`\11\6\320\216B\210\330\314\357\370\327\24\217\261\231\202\261\313\361\216\203.\32\220\20\305 \364\364GYx\211uj\276\26\353U\300\14i\250\343\353\330\331I\11!\377\302s\216\365\250\266v\206\374Y\303\351\265\20\224\257\202\5\374\321\373\370\375\322\31\352Xo\35:C\377\311B\37\321\206\20G\315\326MI\212\376\2K\37\255dJ\260\306\6\11\177B\11Y\320P\242$\375\314#\26\306\320=\247\27J\5\256N18_\300\313\263J\224\246\242\245\311D\260\\362\347\26t\303\324\234\31\276\351;\213\271\236\20\303\310q\10/h\352$\343\374\303I\7C\271\4A\353\242\232b\240\303nB3\262\300\314\272\342\211`\367\13\214\226\253\306\2\263\325\361\250W\31\212\337\23\22L-@\256\260\236\12\215\203\21K\305\335\22\15\327\224@0\211`C\205\321`\14\222e\332\322\377y\201\344"\337\276Y\214p\224\16\315\302a%\322\324p\336|\257\31F\236\267\3326C\273M)m&hAC\203\22\340.\347\223\315cLo\2-\212\356s[\337#N\267\211$h\4A\212\237^\342 \1g\271o\11\250\354A\226\202\7\336\224F\206\12\222\216i\266\20\270\313\210x\371!\304\4", ) , ) == 0x0 00140 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "\232@\20\214\2\34\20\205\213Q\33\27\300;L8Q!\345Rm\247V\210\360\276\3|\312l\236\11 ^\220\346\33\300\305h\366\17-\330\201\260F\353\374L\15d\13{\301\14\0\330\17<\12F\21\304\26\k\372 fA\35\1\324kH\223\12\345\343\346\210ao\330\13+\13l\266\214"\276\20\201\2\242\353\301\277\1f@\274\331+v\216\16\330\262 @\17\21\2600\230\315J2M\263\354%\233@x\16\206\14\311\315\22\226(H\16\13$@\303@\20E\212\261Y\33\201|d\12\11\2217\233\5\20\247\21S\360\275\303\262\11I\13\B\307\3\36\357\267\14\306\217\376BP\261\204*\\203a\301B\20\212\373&\364\10\202\252\211:\261l\26\244\216\22\14&s1\353\227\2\233\11n$\20s\301.z\2669].Y\2142g\20\333tP\5\263\12)\370\262\11\313\352\27\264\317:\14$\33BP\12T\20\10\26\4M\6Q,\2\4\304\177d\5k\24\6F\244\220\11\26\13\202\242k&\36#Y\35\2=\350\314\230\5\341\225\3438\20\33\31\263\5Ot\242\352\22\226\260\23)5\26;\30\6\234Ve;;\304bL\20\214\23\243\10`\2638$\254'\21IH\230k\4\160p\232-{\21n\15\350`\300\203a0\211/,\331\214\331p\24\2\374\16#\250\30\302X\337\\311\236-\17ub\236EVQ\21\4\36\17\22B\14F@\177R\262C\312\12\262\14\335\276\10\322\260\242S\344m\4lY\303\253F\16\202\31\263%\235\17\242\3363t\313F\321l\106\14`\237)"\375\272A\14X\300\340a, 10240, 0x0, 0, ... {status=0x0, info=10240}, ) \276\20\201\2\242\353\301\277\1f@\274\331+v\216\16\330\262 @\17\21\2600\230\315J2M\263\354%\233@x\16\206\14\311\315\22\226(H\16\13$@\303@\20E\212\261Y\33\201|d\12\11\2217\233\5\20\247\21S\360\275\303\262\11I\13\B\307\3\36\357\267\14\306\217\376BP\261\204*\\203a\301B\20\212\373&\364\10\202\252\211:\261l\26\244\216\22\14&s1\353\227\2\233\11n$\20s\301.z\2669].Y\2142g\20\333tP\5\263\12)\370\262\11\313\352\27\264\317:\14$\33BP\12T\20\10\26\4M\6Q,\2\4\304\177d\5k\24\6F\244\220\11\26\13\202\242k&\36#Y\35\2=\350\314\230\5\341\225\3438\20\33\31\263\5Ot\242\352\22\226\260\23)5\26;\30\6\234Ve;;\304bL\20\214\23\243\10`\2638$\254'\21IH\230k\4\160p\232-{\21n\15\350`\300\203a0\211/,\331\214\331p\24\2\374\16#\250\30\302X\337\\311\236-\17ub\236EVQ\21\4\36\17\22B\14F@\177R\262C\312\12\262\14\335\276\10\322\260\242S\344m\4lY\303\253F\16\202\31\263%\235\17\242\3363t\313F\321l\106\14`\237) (40, 0, 0, 0, "\232@\20\214\2\34\20\205\213Q\33\27\300;L8Q!\345Rm\247V\210\360\276\3|\312l\236\11 ^\220\346\33\300\305h\366\17-\330\201\260F\353\374L\15d\13{\301\14\0\330\17<\12F\21\304\26\k\372 fA\35\1\324kH\223\12\345\343\346\210ao\330\13+\13l\266\214"\276\20\201\2\242\353\301\277\1f@\274\331+v\216\16\330\262 @\17\21\2600\230\315J2M\263\354%\233@x\16\206\14\311\315\22\226(H\16\13$@\303@\20E\212\261Y\33\201|d\12\11\2217\233\5\20\247\21S\360\275\303\262\11I\13\B\307\3\36\357\267\14\306\217\376BP\261\204*\\203a\301B\20\212\373&\364\10\202\252\211:\261l\26\244\216\22\14&s1\353\227\2\233\11n$\20s\301.z\2669].Y\2142g\20\333tP\5\263\12)\370\262\11\313\352\27\264\317:\14$\33BP\12T\20\10\26\4M\6Q,\2\4\304\177d\5k\24\6F\244\220\11\26\13\202\242k&\36#Y\35\2=\350\314\230\5\341\225\3438\20\33\31\263\5Ot\242\352\22\226\260\23)5\26;\30\6\234Ve;;\304bL\20\214\23\243\10`\2638$\254'\21IH\230k\4\160p\232-{\21n\15\350`\300\203a0\211/,\331\214\331p\24\2\374\16#\250\30\302X\337\\311\236-\17ub\236EVQ\21\4\36\17\22B\14F@\177R\262C\312\12\262\14\335\276\10\322\260\242S\344m\4lY\303\253F\16\202\31\263%\235\17\242\3363t\313F\321l\106\14`\237)"\375\272A\14X\300\340a, 10240, 0x0, 0, ... {status=0x0, info=10240}, ) , 10240, 0x0, 0, ... {status=0x0, info=10240}, ) == 0x0 00141 400 NtReadFile (36, 0, 0, 0, 2048, 0x0, 0, ... {status=0x0, info=2048}, (36, 0, 0, 0, 2048, 0x0, 0, ... {status=0x0, info=2048}, "\17\220\322\0\37\220\322\0+\200\322\0;\200\322\0\253\262\322\0\273\262\322\0K\261\322\0C\261\322\0[\261\322\0S\261\322\0k\261\322\0c\261\322\0{\261\322\0s\261\322\0\13\261\322\0\3\261\322\0\357\261\322\0\373\261\322\0\227\261\322\0S\260\322\0\37\260\322\0\347\260\322\0\237\260\322\0_\267\322\0\337\267\322\0\247\267\322\0\313\265\322\0\277\264\322\0\177\253\322\0[\252\322\0\357\252\322\0;\250\322\03\256\322\0\13\254\322\0g\243\322\0\207\243\322\0\7\242\322\0\307\242\322\03\241\322\0\323\241\322\0\217\241\322\0\277\241\322\0\327\230\327\0\257\230\327\0\230\362\325\0\244\362\325\0M\361\325\0U\361\325\0{\361\325\0\1\361\325\0&\361\325\0\313\361\325\0\357\361\325\0\366\361\325\0\233\361\325\0\247\361\325\0\261\361\325\0]\360\325\0g\360\325\0\16\360\325\0\37\360\325\02\360\325\0\331\360\325\0\370\360\325\0\236\360\325\0\267\360\325\0T\367\325\0\5\367\325\0 \367\325\0\335\367\325\0\216\367\325\0\256\367\325\0K\366\325\0v\366\325\0(\366\325\03\366\325\0\335\366\325\0\345\366\325\0\217\366\325\0\231\366\325\0\243\366\325\0N\365\325\0U\365\325\0`\365\325\0\13\365\325\0\21\365\325\06\365\325\0\313\365\325\0\305\365\325\0\334\365\325\0\320\365\325\0S\333\304\0X\333\313\0[\333\312\0Z\333\310\0K\333\321\0G\333\325\0I\333\327\0d\333\311\0R\333\314\0k\333\362\0g\333\370\0f\333\363\0l\333\360\0P\333\367\0i\333\365\0\\333\303\0]\333\336\0_\333\334\0@\333\337\0D\333\330\0F\333\376\0O\333\320\0N\333\374\0b\333\322\0O\333\322\0O\333\322\0O\333\322@k\243\242$~\351\234m:\277\242@\33\225\237U\13\213\322@k\243\242$~\356\234m", ) , ) == 0x0 00142 400 NtWriteFile (40, 0, 0, 0, (40, 0, 0, 0, "@K\0\0PK\0\0d[\0\0t[\0\0\344i\0\0\364i\0\0\4j\0\0\14j\0\0\24j\0\0\34j\0\0$j\0\0,j\0\04j\0\0\0\37\0%\0&\0'\0\23\0\21\0\22\0\14\0\20\0\16\0\17\0\15\0\13\0\12\0\11\0,\0\0\0\2\0\1\0.\0-\0\0\0\0\0\0\0\0\0\0\0\0\0\0@$xp$12Nmudp@TNMUDP\0@$xp$15Nm", 2048, 0x0, 0, ... {status=0x0, info=2048}, ) \0\37\0%\0&\0'\0\23\0\21\0\22\0\14\0\20\0\16\0\17\0\15\0\13\0\12\0\11\0,\0\0\0\2\0\1\0.\0-\0\0\0\0\0\0\0\0\0\0\0\0\0\0@$xp$12Nmudp@TNMUDP\0@$xp$15Nm", 2048, 0x0, 0, ... {status=0x0, info=2048}, ) == 0x0 00143 400 NtClose (40, ... ) == 0x0 00144 400 NtClose (36, ... ) == 0x0 00145 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 1242420, ... ) }, 1242420, ... ) == 0x0 00146 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 5, 96, ... 36, {status=0x0, info=1}, ) }, 5, 96, ... 36, {status=0x0, info=1}, ) == 0x0 00147 400 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 36, ... 40, ) == 0x0 00148 400 NtClose (36, ... ) == 0x0 00149 400 NtMapViewOfSection (40, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x320000), 0x0, 176128, ) == 0x0 00150 400 NtClose (40, ... ) == 0x0 00151 400 NtUnmapViewOfSection (-1, 0x320000, ... ) == 0x0 00152 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 1242736, ... ) }, 1242736, ... ) == 0x0 00153 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 1242736, ... ) }, 1242736, ... ) == 0x0 00154 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.tmp"}, 5, 96, ... 40, {status=0x0, info=1}, ) }, 5, 96, ... 40, {status=0x0, info=1}, ) == 0x0 00155 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 40, ... 36, ) == 0x0 00156 400 NtQuerySection (36, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00157 400 NtOpenProcessToken (-1, 0x8, ... 44, ) == 0x0 00158 400 NtQueryInformationToken (44, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00159 400 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00160 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 48, ) }, ... 48, ) == 0x0 00161 400 NtQueryValueKey (48, (48, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (48, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00162 400 NtClose (48, ... ) == 0x0 00163 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00164 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 48, ) == 0x0 00165 400 NtQueryInformationToken (48, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00166 400 NtClose (48, ... ) == 0x0 00167 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00168 400 NtClose (44, ... ) == 0x0 00169 400 NtClose (40, ... ) == 0x0 00170 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x320000), 0x0, 471040, ) == STATUS_IMAGE_NOT_AT_BASE 00171 400 NtMapViewOfSection (36, -1, (0x320000), 0, 0, 0x0, 471040, 1, 0, 4, ... ) == STATUS_CONFLICTING_ADDRESSES 00172 400 NtFlushInstructionCache (-1, 0, 0, ... ) == 0x0 00173 400 NtClose (36, ... ) == 0x0 00174 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 8, ) == 0x0 00175 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 8, ... (0x392000), 4096, 4, ) == 0x0 00176 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00177 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00178 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00179 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00180 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMCTL32.DLL"}, ... 36, ) }, ... 36, ) == 0x0 00181 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77340000), 0x0, 569344, ) == 0x0 00182 400 NtClose (36, ... ) == 0x0 00183 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 36, ) }, ... 36, ) == 0x0 00184 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c70000), 0x0, 262144, ) == 0x0 00185 400 NtClose (36, ... ) == 0x0 00186 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "USER32.dll"}, ... 36, ) }, ... 36, ) == 0x0 00187 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77d40000), 0x0, 577536, ) == 0x0 00188 400 NtClose (36, ... ) == 0x0 00189 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00190 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00191 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00192 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00193 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00194 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00195 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MPR.DLL"}, ... 36, ) }, ... 36, ) == 0x0 00196 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71b20000), 0x0, 69632, ) == 0x0 00197 400 NtClose (36, ... ) == 0x0 00198 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00199 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00200 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00201 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLE32.DLL"}, ... 36, ) }, ... 36, ) == 0x0 00202 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x771b0000), 0x0, 1155072, ) == 0x0 00203 400 NtClose (36, ... ) == 0x0 00204 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00205 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00206 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00207 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLEAUT32.DLL"}, ... 36, ) }, ... 36, ) == 0x0 00208 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77120000), 0x0, 569344, ) == 0x0 00209 400 NtClose (36, ... ) == 0x0 00210 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSVCRT.DLL"}, ... 36, ) }, ... 36, ) == 0x0 00211 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 339968, ) == 0x0 00212 400 NtClose (36, ... ) == 0x0 00213 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00214 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00215 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00216 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00217 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00218 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00219 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WSOCK32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00220 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WSOCK32.DLL"}, 1241952, ... ) }, 1241952, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00221 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WSOCK32.DLL"}, 1241952, ... ) }, 1241952, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00222 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WSOCK32.DLL"}, 1241952, ... ) }, 1241952, ... ) == 0x0 00223 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WSOCK32.DLL"}, 5, 96, ... 36, {status=0x0, info=1}, ) }, 5, 96, ... 36, {status=0x0, info=1}, ) == 0x0 00224 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 36, ... 40, ) == 0x0 00225 400 NtQuerySection (40, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00226 400 NtClose (36, ... ) == 0x0 00227 400 NtMapViewOfSection (40, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ad0000), 0x0, 32768, ) == 0x0 00228 400 NtClose (40, ... ) == 0x0 00229 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2_32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00230 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2_32.dll"}, 1241148, ... ) }, 1241148, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00231 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2_32.dll"}, 1241148, ... ) }, 1241148, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00232 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 1241148, ... ) }, 1241148, ... ) == 0x0 00233 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 5, 96, ... 40, {status=0x0, info=1}, ) }, 5, 96, ... 40, {status=0x0, info=1}, ) == 0x0 00234 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 40, ... 36, ) == 0x0 00235 400 NtQuerySection (36, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00236 400 NtClose (40, ... ) == 0x0 00237 400 NtMapViewOfSection (36, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ab0000), 0x0, 86016, ) == 0x0 00238 400 NtClose (36, ... ) == 0x0 00239 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00240 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2HELP.dll"}, 1240344, ... ) }, 1240344, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00241 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2HELP.dll"}, 1240344, ... ) }, 1240344, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00242 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 1240344, ... ) }, 1240344, ... ) == 0x0 00243 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 5, 96, ... 36, {status=0x0, info=1}, ) }, 5, 96, ... 36, {status=0x0, info=1}, ) == 0x0 00244 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 36, ... 40, ) == 0x0 00245 400 NtQuerySection (40, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00246 400 NtClose (36, ... ) == 0x0 00247 400 NtMapViewOfSection (40, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71aa0000), 0x0, 32768, ) == 0x0 00248 400 NtClose (40, ... ) == 0x0 00249 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00250 400 NtProtectVirtualMemory (-1, (0x392000), 4096, 4, ... (0x392000), 4096, 4, ) == 0x0 00251 400 NtFlushInstructionCache (-1, 3743744, 4096, ... ) == 0x0 00252 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00253 400 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1246456, 1, 24, 2012568566} (24, {28, 56, new_msg, 0, 1246456, 1, 24, 2012568566} "\210\6\31\1\0\0\0\0\314\4\23\0\324Wh\364\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 396, 400, 1506, 0} "XQ\26\0\0\0\0\0\0\0\0\0\324Wh\364\3\0\0\0\234\6\31\1$\1\0\0" ) ... {28, 56, reply, 0, 396, 400, 1506, 0} (24, {28, 56, new_msg, 0, 1246456, 1, 24, 2012568566} "\210\6\31\1\0\0\0\0\314\4\23\0\324Wh\364\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 396, 400, 1506, 0} "XQ\26\0\0\0\0\0\0\0\0\0\324Wh\364\3\0\0\0\234\6\31\1$\1\0\0" ) ) == 0x0 00254 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00255 400 NtMapViewOfSection (40, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x550000), 0x0, 1060864, ) == 0x0 00256 400 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 36, ) == 0x0 00257 400 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00258 400 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482032, ) == 0x0 00259 400 NtQueryInformationToken (-2147482032, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00260 400 NtQueryInformationToken (-2147482032, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00261 400 NtClose (-2147482032, ... ) == 0x0 00262 400 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 3801088, 4096, ) == 0x0 00263 400 NtFreeVirtualMemory (-1, (0x3a0000), 4096, 32768, ... (0x3a0000), 4096, ) == 0x0 00264 400 NtDuplicateObject (-1, 44, -1, 0x0, 0, 2, ... 52, ) == 0x0 00265 400 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00266 400 NtQueryValueKey (-2147482032, (-2147482032, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00267 400 NtClose (-2147482032, ... ) == 0x0 00268 400 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00269 400 NtQueryValueKey (-2147482032, (-2147482032, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00270 400 NtClose (-2147482032, ... ) == 0x0 00271 400 NtQueryDefaultLocale (0, -130577908, ... ) == 0x0 00272 400 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00273 400 NtUserCallNoParam (24, ... ) == 0x0 00274 400 NtGdiCreateCompatibleDC (0, ... 00275 400 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 3801088, 4096, ) == 0x0 00274 400 NtGdiCreateCompatibleDC ... ) == 0x110103d0 00276 400 NtGdiGetStockObject (0, ... ) == 0x1900010 00277 400 NtGdiGetStockObject (4, ... ) == 0x1900011 00278 400 NtGdiCreateBitmap (8, 8, 1, 1, 2010393708, ... ) == 0x90503df 00279 400 NtGdiCreateSolidBrush (0, 0, ... 00280 400 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 3866624, 4096, ) == 0x0 00279 400 NtGdiCreateSolidBrush ... ) == 0xb1003e2 00281 400 NtGdiGetStockObject (13, ... ) == 0x18a0021 00282 400 NtGdiCreateCompatibleDC (0, ... ) == 0x80103dd 00283 400 NtGdiSelectBitmap (134284253, 151323615, ... ) == 0x185000f 00284 400 NtUserGetThreadDesktop (400, 0, ... ) == 0x30 00285 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 56, ) }, ... 56, ) == 0x0 00286 400 NtQueryValueKey (56, (56, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (56, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00287 400 NtClose (56, ... ) == 0x0 00288 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00289 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 673, 128, 0, ... ) == 0x810dc017 00290 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00291 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 674, 128, 0, ... ) == 0x810dc01c 00292 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00293 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 675, 128, 0, ... ) == 0x810dc01e 00294 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00295 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 676, 128, 0, ... ) == 0x810d8002 00296 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10013 00297 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 677, 128, 0, ... ) == 0x810dc018 00298 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00299 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 678, 128, 0, ... ) == 0x810dc01a 00300 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00301 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 679, 128, 0, ... ) == 0x810dc01d 00302 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00303 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 681, 128, 0, ... ) == 0x810dc026 00304 400 NtUserFindExistingCursorIcon (1240532, 1240548, 1241116, ... ) == 0x10011 00305 400 NtUserRegisterClassExWOW (1241052, 1241132, 1241116, 1241148, 680, 128, 0, ... ) == 0x810dc019 00306 400 NtUserRegisterClassExWOW (1241004, 1241084, 1241068, 1241100, 0, 128, 0, ... 00307 400 NtAllocateVirtualMemory (-1, 6778880, 0, 4096, 4096, 32, ... 6778880, 4096, ) == 0x0 00306 400 NtUserRegisterClassExWOW ... ) == 0x810dc020 00308 400 NtUserRegisterClassExWOW (1241004, 1241080, 1241096, 1241068, 0, 130, 0, ... ) == 0x810dc022 00309 400 NtUserRegisterClassExWOW (1241004, 1241084, 1241068, 1241100, 0, 128, 0, ... ) == 0x810dc023 00310 400 NtUserRegisterClassExWOW (1241004, 1241080, 1241096, 1241068, 0, 130, 0, ... ) == 0x810dc024 00311 400 NtUserRegisterClassExWOW (1241004, 1241084, 1241068, 1241100, 0, 128, 0, ... ) == 0x810dc025 00312 400 NtCallbackReturn (0, 0, 0, ... 00313 400 NtGdiInit (... ) == 0x1 00314 400 NtGdiGetStockObject (18, ... ) == 0x290001c 00315 400 NtGdiGetStockObject (19, ... ) == 0x1b00019 00316 400 NtAllocateVirtualMemory (-1, 1327104, 0, 4096, 4096, 4, ... 1327104, 4096, ) == 0x0 00317 400 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {396, 0}, ... 56, ) == 0x0 00318 400 NtQueryInformationProcess (56, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 00319 400 NtClose (56, ... ) == 0x0 00320 400 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00321 400 NtUserSystemParametersInfo (104, 0, 2000318720, 0, ... ) == 0x1 00322 400 NtUserSystemParametersInfo (38, 4, 2000318708, 0, ... ) == 0x1 00323 400 NtOpenKey (0x20019, {24, 32, 0x40, 0, 0, (0x20019, {24, 32, 0x40, 0, 0, "Control Panel\Desktop"}, ... 56, ) }, ... 56, ) == 0x0 00324 400 NtQueryValueKey (56, (56, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00325 400 NtClose (56, ... ) == 0x0 00326 400 NtUserSystemParametersInfo (41, 500, 1242460, 0, ... ) == 0x1 00327 400 NtUserSystemParametersInfo (102, 0, 2000318732, 0, ... ) == 0x1 00328 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00329 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00330 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc03b 00331 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00332 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc03d 00333 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00334 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00335 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc03f 00336 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00337 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00338 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc041 00339 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00340 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00341 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc043 00342 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00343 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc045 00344 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00345 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00346 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc047 00347 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00348 400 NtUserFindExistingCursorIcon (1242248, 1242264, 1242832, ... ) == 0x10011 00349 400 NtUserRegisterClassExWOW (1242700, 1242780, 1242764, 1242796, 0, 384, 0, ... ) == 0x810dc049 00350 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00351 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00352 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc04b 00353 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00354 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00355 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc04d 00356 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00357 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00358 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc04f 00359 400 NtUserGetClassInfo (1999896576, 1242872, 1242824, 1242900, 0, ... ) == 0x0 00360 400 NtUserRegisterClassExWOW (1242708, 1242788, 1242772, 1242804, 0, 384, 0, ... ) == 0x810dc051 00361 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00362 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00363 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc053 00364 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00365 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00366 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc055 00367 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc057 00368 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00369 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00370 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc059 00371 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00372 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10013 00373 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc05b 00374 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00375 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00376 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc05d 00377 400 NtUserGetClassInfo (1999896576, 1242868, 1242820, 1242896, 0, ... ) == 0x0 00378 400 NtUserFindExistingCursorIcon (1242252, 1242268, 1242836, ... ) == 0x10011 00379 400 NtUserRegisterClassExWOW (1242704, 1242784, 1242768, 1242800, 0, 384, 0, ... ) == 0x810dc05f 00380 400 NtCreateSemaphore (0x1f0003, 0x0, 1, 1, ... 56, ) == 0x0 00381 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 60, ) == 0x0 00382 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "system\CurrentControlSet\control\NetworkProvider\HwOrder"}, ... 64, ) }, ... 64, ) == 0x0 00383 400 NtNotifyChangeKey (64, 60, 0, 0, 2011390432, 4, 0, 0, 0, 1, ... ) == 0x103 00384 400 NtQueryInformationProcess (-1, 28, 4, ... {process info, class 28, size 4}, 0x0, ) == 0x0 00385 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 68, ) == 0x0 00386 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 72, ) == 0x0 00387 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00388 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00389 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 76, ) }, ... 76, ) == 0x0 00390 400 NtQueryValueKey (76, (76, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (76, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 00391 400 NtClose (76, ... ) == 0x0 00392 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00393 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00394 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00395 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00396 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 76, ) }, ... 76, ) == 0x0 00397 400 NtQueryValueKey (76, (76, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00398 400 NtQueryValueKey (76, (76, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00399 400 NtQueryValueKey (76, (76, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00400 400 NtClose (76, ... ) == 0x0 00401 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 76, ) }, ... 76, ) == 0x0 00402 400 NtQueryValueKey (76, (76, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00403 400 NtQueryValueKey (76, (76, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00404 400 NtClose (76, ... ) == 0x0 00405 400 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 76, ) }, ... 76, ) == 0x0 00406 400 NtOpenEvent (0x1f0003, {24, 76, 0x0, 0, 0, (0x1f0003, {24, 76, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00407 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00408 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 3932160, 65536, ) == 0x0 00409 400 NtAllocateVirtualMemory (-1, 3932160, 0, 4096, 4096, 4, ... 3932160, 4096, ) == 0x0 00410 400 NtAllocateVirtualMemory (-1, 3936256, 0, 8192, 4096, 4, ... 3936256, 8192, ) == 0x0 00411 400 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 80, ) }, ... 80, ) == 0x0 00412 400 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x3d0000), 0x0, 12288, ) == 0x0 00413 400 NtClose (80, ... ) == 0x0 00414 400 NtAllocateVirtualMemory (-1, 3944448, 0, 4096, 4096, 4, ... 3944448, 4096, ) == 0x0 00415 400 NtUserRegisterWindowMessage ( ("{FB8F0821-0164-101B-84ED-08002B2EC713}", ... ) , ... ) == 0xc07b 00416 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00417 400 NtOpenKey (0x9, {24, 28, 0x40, 0, 0, (0x9, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT\UserEra"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00418 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00419 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00420 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00421 400 NtUserCallOneParam (0, 40, ... ) == 0x4 00422 400 NtAllocateVirtualMemory (-1, 1331200, 0, 4096, 4096, 4, ... 1331200, 4096, ) == 0x0 00423 400 NtQueryVirtualMemory (-1, 0x12f674, Basic, 28, ... {BaseAddress=0x12f000,AllocationBase=0x30000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 00424 400 NtAllocateVirtualMemory (-1, 1335296, 0, 4096, 4096, 4, ... 1335296, 4096, ) == 0x0 00425 400 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 1, ... 9830400, 1048576, ) == 0x0 00426 400 NtAllocateVirtualMemory (-1, 9830400, 0, 16384, 4096, 4, ... 9830400, 16384, ) == 0x0 00427 400 NtQuerySystemInformation (TimeZone, 172, ... {system info, class 44, size 172}, 0x0, ) == 0x0 00428 400 NtQuerySystemInformation (TimeZone, 172, ... {system info, class 44, size 172}, 0x0, ) == 0x0 00429 400 NtOpenKey (0xf003f, {24, 32, 0x40, 0, 0, (0xf003f, {24, 32, 0x40, 0, 0, "Software\Borland\Locales"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00430 400 NtOpenKey (0xf003f, {24, 32, 0x40, 0, 0, (0xf003f, {24, 32, 0x40, 0, 0, "Software\Borland\Delphi\Locales"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00431 400 NtOpenProcessToken (-1, 0x8, ... 80, ) == 0x0 00432 400 NtQueryInformationToken (80, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00433 400 NtClose (80, ... ) == 0x0 00434 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00435 400 NtReleaseMutant (16, ... 00436 400 NtContinue (-130580344, 0, ... 00435 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00437 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.ENU"}, 1241184, ... ) }, 1241184, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00438 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.ENU"}, 1240824, ... ) }, 1240824, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00439 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.ENU.DLL"}, 1240824, ... ) }, 1240824, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00440 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.EN"}, 1241184, ... ) }, 1241184, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00441 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.EN"}, 1240824, ... ) }, 1240824, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00442 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\DOCUME~1\SRI-user\LOCALS~1\Temp\eka1.EN.DLL"}, 1240824, ... ) }, 1240824, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00443 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00444 400 NtReleaseMutant (16, ... 00445 400 NtContinue (-130580344, 0, ... 00444 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00446 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00447 400 NtReleaseMutant (16, ... 00448 400 NtContinue (-130580344, 0, ... 00447 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00449 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00450 400 NtReleaseMutant (16, ... 00451 400 NtContinue (-130580344, 0, ... 00450 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00452 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00453 400 NtReleaseMutant (16, ... 00454 400 NtContinue (-130580344, 0, ... 00453 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00455 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00456 400 NtReleaseMutant (16, ... 00457 400 NtContinue (-130580344, 0, ... 00456 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00458 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00459 400 NtReleaseMutant (16, ... 00460 400 NtContinue (-130580344, 0, ... 00459 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00461 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00462 400 NtReleaseMutant (16, ... 00463 400 NtContinue (-130580344, 0, ... 00462 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00464 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00465 400 NtReleaseMutant (16, ... 00466 400 NtContinue (-130580344, 0, ... 00465 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00467 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00468 400 NtReleaseMutant (16, ... 00469 400 NtContinue (-130580344, 0, ... 00468 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00470 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00471 400 NtReleaseMutant (16, ... 00472 400 NtContinue (-130580344, 0, ... 00471 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00473 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00474 400 NtReleaseMutant (16, ... 00475 400 NtContinue (-130580344, 0, ... 00474 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00476 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00477 400 NtReleaseMutant (16, ... 00478 400 NtContinue (-130580344, 0, ... 00477 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00479 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00480 400 NtReleaseMutant (16, ... 00481 400 NtContinue (-130580344, 0, ... 00480 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00482 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00483 400 NtReleaseMutant (16, ... 00484 400 NtContinue (-130580344, 0, ... 00483 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00485 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00486 400 NtReleaseMutant (16, ... 00487 400 NtContinue (-130580344, 0, ... 00486 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00488 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00489 400 NtReleaseMutant (16, ... 00490 400 NtContinue (-130580344, 0, ... 00489 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00491 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00492 400 NtReleaseMutant (16, ... 00493 400 NtContinue (-130580344, 0, ... 00492 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00494 400 NtWaitForSingleObject (16, 0, 0x0, ... ) == STATUS_ACCESS_DENIED 00495 400 NtReleaseMutant (16, ... 00496 400 NtContinue (-130580344, 0, ... 00495 400 NtReleaseMutant ... ) == STATUS_MUTANT_NOT_OWNED 00497 400 NtCreateEvent (0x1f0003, 0x0, 0, -1, ... 80, ) == 0x0 00498 400 NtUserGetDC (0, ... ) == 0x1010052 00499 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00500 400 NtUserGetDC (0, ... ) == 0x1010052 00501 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00502 400 NtGdiCreatePaletteInternal (1241872, 16, ... ) == 0x70803de 00503 400 NtGdiGetStockObject (7, ... ) == 0x1b00017 00504 400 NtGdiGetStockObject (5, ... ) == 0x1900015 00505 400 NtUserFindExistingCursorIcon (1242268, 1242284, 1242852, ... ) == 0x10003 00506 400 NtAddAtom ( ("D\0e\0l\0p\0h\0i\00\00\00\00\00\01\08\0C\0", 28, 1242804, ... ) , 28, 1242804, ... ) == 0x0 00507 400 NtAddAtom ( ("C\0o\0n\0t\0r\0o\0l\0O\0f\0s\00\00\03\02\00\00\00\00\00\00\00\00\00\01\09\00\0", 52, 1242804, ... ) , 52, 1242804, ... ) == 0x0 00508 400 NtUserSystemParametersInfo (104, 0, 9835644, 0, ... ) == 0x1 00509 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10011 00510 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10023 00511 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00512 400 NtUserGetDC (0, ... ) == 0x1010052 00513 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x140503e5 00514 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00515 400 NtGdiSelectBitmap (285279184, 335872997, ... ) == 0x185000f 00516 400 NtGdiGetDCforBitmap (335872997, ... ) == 0x110103d0 00517 400 NtGdiSaveDC (285279184, ... ) == 0x1 00518 400 NtGdiSelectBitmap (285279184, 335872997, ... ) == 0x140503e5 00519 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00520 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00521 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3683852, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00522 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00523 400 NtGdiSelectBitmap (285279184, 335872997, ... ) == 0x140503e5 00524 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00525 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x140503e5 00526 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x350103e4 00527 400 NtGdiExtGetObjectW (335872997, 24, 1241324, ... ) == 0x18 00528 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0xd0503e6 00529 400 NtGdiSelectBitmap (285279184, 335872997, ... ) == 0x185000f 00530 400 NtGdiSelectBitmap (889258980, 218432486, ... ) == 0x185000f 00531 400 NtGdiBitBlt (889258980, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00532 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x140503e5 00533 400 NtGdiSelectBitmap (889258980, 25493519, ... ) == 0xd0503e6 00534 400 NtGdiDeleteObjectApp (335872997, ... ) == 0x1 00535 400 NtGdiDeleteObjectApp (889258980, ... ) == 0x1 00536 400 NtUserCallOneParam (0, 33, ... ) == 0x20093 00537 400 NtUserSetCursorIconData (131219, 1241432, 1241448, 1242028, ... ) == 0x1 00538 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10029 00539 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10027 00540 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10025 00541 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00542 400 NtUserGetDC (0, ... ) == 0x1010052 00543 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x320503e0 00544 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00545 400 NtGdiSelectBitmap (285279184, 839189472, ... ) == 0x185000f 00546 400 NtGdiGetDCforBitmap (839189472, ... ) == 0x110103d0 00547 400 NtGdiSaveDC (285279184, ... ) == 0x1 00548 400 NtGdiSelectBitmap (285279184, 839189472, ... ) == 0x320503e0 00549 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00550 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00551 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3684160, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00552 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00553 400 NtGdiSelectBitmap (285279184, 839189472, ... ) == 0x320503e0 00554 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00555 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x320503e0 00556 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x160103e5 00557 400 NtGdiExtGetObjectW (839189472, 24, 1241324, ... ) == 0x18 00558 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0x40503e7 00559 400 NtGdiSelectBitmap (285279184, 839189472, ... ) == 0x185000f 00560 400 NtGdiSelectBitmap (369165285, 67437543, ... ) == 0x185000f 00561 400 NtGdiBitBlt (369165285, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00562 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x320503e0 00563 400 NtGdiSelectBitmap (369165285, 25493519, ... ) == 0x40503e7 00564 400 NtGdiDeleteObjectApp (839189472, ... ) == 0x1 00565 400 NtGdiDeleteObjectApp (369165285, ... ) == 0x1 00566 400 NtUserCallOneParam (0, 33, ... ) == 0x3006d 00567 400 NtUserSetCursorIconData (196717, 1241432, 1241448, 1242028, ... ) == 0x1 00568 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00569 400 NtUserGetDC (0, ... ) == 0x1010052 00570 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x370503e4 00571 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00572 400 NtGdiSelectBitmap (285279184, 923075556, ... ) == 0x185000f 00573 400 NtGdiGetDCforBitmap (923075556, ... ) == 0x110103d0 00574 400 NtGdiSaveDC (285279184, ... ) == 0x1 00575 400 NtGdiSelectBitmap (285279184, 923075556, ... ) == 0x370503e4 00576 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00577 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00578 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3684468, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00579 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00580 400 NtGdiSelectBitmap (285279184, 923075556, ... ) == 0x370503e4 00581 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00582 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x370503e4 00583 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x340103e0 00584 400 NtGdiExtGetObjectW (923075556, 24, 1241324, ... ) == 0x18 00585 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0x40503e8 00586 400 NtGdiSelectBitmap (285279184, 923075556, ... ) == 0x185000f 00587 400 NtGdiSelectBitmap (872481760, 67437544, ... ) == 0x185000f 00588 400 NtGdiBitBlt (872481760, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00589 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x370503e4 00590 400 NtGdiSelectBitmap (872481760, 25493519, ... ) == 0x40503e8 00591 400 NtGdiDeleteObjectApp (923075556, ... ) == 0x1 00592 400 NtGdiDeleteObjectApp (872481760, ... ) == 0x1 00593 400 NtUserCallOneParam (0, 33, ... ) == 0x3006b 00594 400 NtUserSetCursorIconData (196715, 1241432, 1241448, 1242028, ... ) == 0x1 00595 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00596 400 NtUserGetDC (0, ... ) == 0x1010052 00597 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x180503e5 00598 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00599 400 NtGdiSelectBitmap (285279184, 402981861, ... ) == 0x185000f 00600 400 NtGdiGetDCforBitmap (402981861, ... ) == 0x110103d0 00601 400 NtGdiSaveDC (285279184, ... ) == 0x1 00602 400 NtGdiSelectBitmap (285279184, 402981861, ... ) == 0x180503e5 00603 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00604 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00605 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3684776, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00606 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00607 400 NtGdiSelectBitmap (285279184, 402981861, ... ) == 0x180503e5 00608 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00609 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x180503e5 00610 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x390103e4 00611 400 NtGdiExtGetObjectW (402981861, 24, 1241324, ... ) == 0x18 00612 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0x140503e3 00613 400 NtGdiSelectBitmap (285279184, 402981861, ... ) == 0x185000f 00614 400 NtGdiSelectBitmap (956367844, 335872995, ... ) == 0x185000f 00615 400 NtGdiBitBlt (956367844, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00616 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x180503e5 00617 400 NtGdiSelectBitmap (956367844, 25493519, ... ) == 0x140503e3 00618 400 NtGdiDeleteObjectApp (402981861, ... ) == 0x1 00619 400 NtGdiDeleteObjectApp (956367844, ... ) == 0x1 00620 400 NtUserCallOneParam (0, 33, ... ) == 0x30085 00621 400 NtUserSetCursorIconData (196741, 1241432, 1241448, 1242028, ... ) == 0x1 00622 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00623 400 NtUserGetDC (0, ... ) == 0x1010052 00624 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x360503e0 00625 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00626 400 NtGdiSelectBitmap (285279184, 906298336, ... ) == 0x185000f 00627 400 NtGdiGetDCforBitmap (906298336, ... ) == 0x110103d0 00628 400 NtGdiSaveDC (285279184, ... ) == 0x1 00629 400 NtGdiSelectBitmap (285279184, 906298336, ... ) == 0x360503e0 00630 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00631 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00632 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3685084, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00633 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00634 400 NtGdiSelectBitmap (285279184, 906298336, ... ) == 0x360503e0 00635 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00636 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x360503e0 00637 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x1a0103e5 00638 400 NtGdiExtGetObjectW (906298336, 24, 1241324, ... ) == 0x18 00639 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0x30503e9 00640 400 NtGdiSelectBitmap (285279184, 906298336, ... ) == 0x185000f 00641 400 NtGdiSelectBitmap (436274149, 50660329, ... ) == 0x185000f 00642 400 NtGdiBitBlt (436274149, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00643 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x360503e0 00644 400 NtGdiSelectBitmap (436274149, 25493519, ... ) == 0x30503e9 00645 400 NtGdiDeleteObjectApp (906298336, ... ) == 0x1 00646 400 NtGdiDeleteObjectApp (436274149, ... ) == 0x1 00647 400 NtUserCallOneParam (0, 33, ... ) == 0x5005d 00648 400 NtUserSetCursorIconData (327773, 1241432, 1241448, 1242028, ... ) == 0x1 00649 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00650 400 NtUserGetDC (0, ... ) == 0x1010052 00651 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x3b0503e4 00652 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00653 400 NtGdiSelectBitmap (285279184, 990184420, ... ) == 0x185000f 00654 400 NtGdiGetDCforBitmap (990184420, ... ) == 0x110103d0 00655 400 NtGdiSaveDC (285279184, ... ) == 0x1 00656 400 NtGdiSelectBitmap (285279184, 990184420, ... ) == 0x3b0503e4 00657 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00658 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00659 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3685700, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00660 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00661 400 NtGdiSelectBitmap (285279184, 990184420, ... ) == 0x3b0503e4 00662 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00663 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x3b0503e4 00664 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x380103e0 00665 400 NtGdiExtGetObjectW (990184420, 24, 1241324, ... ) == 0x18 00666 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0x30503ea 00667 400 NtGdiSelectBitmap (285279184, 990184420, ... ) == 0x185000f 00668 400 NtGdiSelectBitmap (939590624, 50660330, ... ) == 0x185000f 00669 400 NtGdiBitBlt (939590624, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00670 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x3b0503e4 00671 400 NtGdiSelectBitmap (939590624, 25493519, ... ) == 0x30503ea 00672 400 NtGdiDeleteObjectApp (990184420, ... ) == 0x1 00673 400 NtGdiDeleteObjectApp (939590624, ... ) == 0x1 00674 400 NtUserCallOneParam (0, 33, ... ) == 0x10095 00675 400 NtUserSetCursorIconData (65685, 1241432, 1241448, 1242028, ... ) == 0x1 00676 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x0 00677 400 NtUserGetDC (0, ... ) == 0x1010052 00678 400 NtGdiCreateDIBitmapInternal (16842834, 32, 64, 2, 0, 2010764464, 0, 48, 0, 0, 0, ... ) == 0x1c0503e5 00679 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00680 400 NtGdiSelectBitmap (285279184, 470090725, ... ) == 0x185000f 00681 400 NtGdiGetDCforBitmap (470090725, ... ) == 0x110103d0 00682 400 NtGdiSaveDC (285279184, ... ) == 0x1 00683 400 NtGdiSelectBitmap (285279184, 470090725, ... ) == 0x1c0503e5 00684 400 NtGdiGetDCObject (285279184, 524288, ... ) == 0x188000b 00685 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00686 400 NtGdiSetDIBitsToDeviceInternal (285279184, 0, 0, 32, 64, 0, 0, 0, 64, 3685392, 1319624, 0, 256, 48, 1, 0, ... ) == 0x40 00687 400 NtUserSelectPalette (285279184, 25690123, 0, ... ) == 0x188000b 00688 400 NtGdiSelectBitmap (285279184, 470090725, ... ) == 0x1c0503e5 00689 400 NtGdiRestoreDC (285279184, -1, ... ) == 0x1 00690 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x1c0503e5 00691 400 NtGdiCreateCompatibleDC (285279184, ... ) == 0x3d0103e4 00692 400 NtGdiExtGetObjectW (470090725, 24, 1241324, ... ) == 0x18 00693 400 NtGdiCreateBitmap (32, 64, 1, 1, 0, ... ) == 0x30503eb 00694 400 NtGdiSelectBitmap (285279184, 470090725, ... ) == 0x185000f 00695 400 NtGdiSelectBitmap (1023476708, 50660331, ... ) == 0x185000f 00696 400 NtGdiBitBlt (1023476708, 0, 0, 32, 64, 285279184, 0, 0, 13369376, -1, 0, ... ) == 0x1 00697 400 NtGdiSelectBitmap (285279184, 25493519, ... ) == 0x1c0503e5 00698 400 NtGdiSelectBitmap (1023476708, 25493519, ... ) == 0x30503eb 00699 400 NtGdiDeleteObjectApp (470090725, ... ) == 0x1 00700 400 NtGdiDeleteObjectApp (1023476708, ... ) == 0x1 00701 400 NtUserCallOneParam (0, 33, ... ) == 0x10097 00702 400 NtUserSetCursorIconData (65687, 1241432, 1241448, 1242028, ... ) == 0x1 00703 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10015 00704 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10019 00705 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x1001f 00706 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x1001b 00707 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10021 00708 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x1001d 00709 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10013 00710 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10017 00711 400 NtUserFindExistingCursorIcon (1242152, 1242168, 1242736, ... ) == 0x10011 00712 400 NtUserCallOneParam (0, 39, ... ) == 0x4090409 00713 400 NtUserGetDC (0, ... ) == 0x1010052 00714 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00715 400 NtUserEnumDisplayMonitors (0, 0, 3408484, 9836224, ... ) == 0x1 00716 400 NtUserSystemParametersInfo (31, 60, 1241588, 0, ... ) == 0x1 00717 400 NtGdiHfontCreate (1241984, 356, 0, 0, 1329296, ... ) == 0x3e0a03e4 00718 400 NtGdiExtGetObjectW (1040843748, 420, 1241808, ... ) == 0x164 00719 400 NtUserSystemParametersInfo (41, 0, 1241788, 0, ... ) == 0x1 00720 400 NtGdiHfontCreate (1241984, 356, 0, 0, 1329288, ... ) == 0x3a0a03e0 00721 400 NtGdiExtGetObjectW (973734880, 420, 1241808, ... ) == 0x164 00722 400 NtGdiHfontCreate (1241984, 356, 0, 0, 1329280, ... ) == 0x1d0a03e5 00723 400 NtGdiExtGetObjectW (487195621, 420, 1241808, ... ) == 0x164 00724 400 NtUserFindExistingCursorIcon (1241896, 1241912, 1242480, ... ) == 0x0 00725 400 NtAllocateVirtualMemory (-1, 0, 0, 4096, 4096, 64, ... 4063232, 4096, ) == 0x0 00726 400 NtUserGetKeyboardLayoutList (64, 1242468, ... ) == 0x1 00727 400 NtUserRegisterWindowMessage ( ("Delphi Picture", ... ) , ... ) == 0xc0cc 00728 400 NtUserRegisterWindowMessage ( ("Delphi Component", ... ) , ... ) == 0xc0cd 00729 400 NtOpenMutant (0x1f0001, {24, 76, 0x0, 0, 0, (0x1f0001, {24, 76, 0x0, 0, 0, "Residented"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00730 400 NtUserSetWindowsHookEx (3276800, 1243796, 0, 4, 3284668, 2, ... ) == 0x10099 00731 400 NtProtectVirtualMemory (-1, (0x4000e0), 4096, 4, ... (0x400000), 8192, 2, ) == 0x0 00732 400 NtProtectVirtualMemory (-1, (0x4000e0), 4096, 4, ... (0x400000), 8192, 4, ) == 0x0 00733 400 NtAllocateVirtualMemory (-1, 0, 0, 16777216, 4096, 64, ... 10878976, 16777216, ) == 0x0 00734 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00735 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 4128768, 65536, ) == 0x0 00736 400 NtAllocateVirtualMemory (-1, 4128768, 0, 4096, 4096, 4, ... 4128768, 4096, ) == 0x0 00737 400 NtAllocateVirtualMemory (-1, 4132864, 0, 8192, 4096, 4, ... 4132864, 8192, ) == 0x0 00738 400 NtAllocateVirtualMemory (-1, 4141056, 0, 4096, 4096, 4, ... 4141056, 4096, ) == 0x0 00739 400 NtQueryPerformanceCounter (... {90849572, 0}, {3579545, 0}, ) == 0x0 00740 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "wininet.dll"}, ... 84, ) }, ... 84, ) == 0x0 00741 400 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76200000), 0x0, 618496, ) == 0x0 00742 400 NtClose (84, ... ) == 0x0 00743 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHLWAPI.dll"}, ... 84, ) }, ... 84, ) == 0x0 00744 400 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x772d0000), 0x0, 405504, ) == 0x0 00745 400 NtClose (84, ... ) == 0x0 00746 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CRYPT32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00747 400 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762c0000), 0x0, 565248, ) == 0x0 00748 400 NtClose (84, ... ) == 0x0 00749 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSASN1.dll"}, ... 84, ) }, ... 84, ) == 0x0 00750 400 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762a0000), 0x0, 61440, ) == 0x0 00751 400 NtClose (84, ... ) == 0x0 00752 400 NtAllocateVirtualMemory (-1, 1339392, 0, 4096, 4096, 4, ... 1339392, 4096, ) == 0x0 00753 400 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00754 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\crypt32\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00755 400 NtAllocateVirtualMemory (-1, 1343488, 0, 4096, 4096, 4, ... 1343488, 4096, ) == 0x0 00756 400 NtAllocateVirtualMemory (-1, 1347584, 0, 4096, 4096, 4, ... 1347584, 4096, ) == 0x0 00757 400 NtAllocateVirtualMemory (-1, 1351680, 0, 4096, 4096, 4, ... 1351680, 4096, ) == 0x0 00758 400 NtCreateEvent (0x1f0003, {24, 76, 0x80, 1240440, 0, (0x1f0003, {24, 76, 0x80, 1240440, 0, "Global\crypt32LogoffEvent"}, 0, 0, ... ) }, 0, 0, ... ) == STATUS_ACCESS_DENIED 00759 400 NtOpenEvent (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "Global\crypt32LogoffEvent"}, ... 84, ) }, ... 84, ) == 0x0 00760 400 NtAllocateVirtualMemory (-1, 1355776, 0, 4096, 4096, 4, ... 1355776, 4096, ) == 0x0 00761 400 NtAllocateVirtualMemory (-1, 1359872, 0, 8192, 4096, 4, ... 1359872, 8192, ) == 0x0 00762 400 NtCreateKey (0xf003f, {24, 32, 0x40, 0, 0, (0xf003f, {24, 32, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History"}, 0, 0x0, 0, ... 88, 2, ) }, 0, 0x0, 0, ... 88, 2, ) == 0x0 00763 400 NtQueryDefaultUILanguage (1238676, ... 00764 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00765 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00766 400 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00767 400 NtClose (-2147482032, ... ) == 0x0 00768 400 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00769 400 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00770 400 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 00771 400 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00772 400 NtClose (-2147482044, ... ) == 0x0 00773 400 NtClose (-2147482032, ... ) == 0x0 00763 400 NtQueryDefaultUILanguage ... ) == 0x0 00774 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00775 400 NtQueryInstallUILanguage (2012047340, ... ) == 0x0 00776 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wininet.dll"}, 1, 96, ... 92, {status=0x0, info=1}, ) }, 1, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00777 400 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 92, ... 96, ) == 0x0 00778 400 NtMapViewOfSection (96, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x1a60000), 0x0, 593920, ) == 0x0 00779 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wininet.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00780 400 NtQueryDefaultUILanguage (2013024600, ... 00781 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00782 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00783 400 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00784 400 NtClose (-2147482032, ... ) == 0x0 00785 400 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00786 400 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00787 400 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 00788 400 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00789 400 NtClose (-2147482044, ... ) == 0x0 00790 400 NtClose (-2147482032, ... ) == 0x0 00780 400 NtQueryDefaultUILanguage ... ) == 0x0 00791 400 NtQueryInstallUILanguage (2013024602, ... ) == 0x0 00792 400 NtQueryDefaultLocale (1, 1236712, ... ) == 0x0 00793 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\wininet.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00794 400 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1237568, 1, 96, 0} (24, {128, 156, new_msg, 0, 1237568, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\345\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\\0\0\0\377\377\377\377\0\0\0\0P\275\255\1\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0@\351\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1507, 0} "(\350\26\0\33\0\1\0\0\0\0\0\1\345\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\\0\0\0\377\377\377\377\0\0\0\0P\275\255\1\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0@\351\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 396, 400, 1507, 0} (24, {128, 156, new_msg, 0, 1237568, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\345\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\\0\0\0\377\377\377\377\0\0\0\0P\275\255\1\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0@\351\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1507, 0} "(\350\26\0\33\0\1\0\0\0\0\0\1\345\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\\0\0\0\377\377\377\377\0\0\0\0P\275\255\1\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0@\351\22\0\0\0\0\0" ) ) == 0x0 00795 400 NtClose (92, ... ) == 0x0 00796 400 NtClose (96, ... ) == 0x0 00797 400 NtUnmapViewOfSection (-1, 0x1a60000, ... ) == 0x0 00798 400 NtUnmapViewOfSection (-1, 0x12e940, ... ) == STATUS_NOT_MAPPED_VIEW 00799 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00800 400 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00801 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00802 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00803 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1235252, ... ) }, 1235252, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00804 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00805 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00806 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00807 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1235844, ... ) }, 1235844, ... ) == 0x0 00808 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 96, {status=0x0, info=1}, ) }, 3, 33, ... 96, {status=0x0, info=1}, ) == 0x0 00809 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00810 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00811 400 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 92, ... 100, ) == 0x0 00812 400 NtClose (92, ... ) == 0x0 00813 400 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x1b10000), 0x0, 921600, ) == 0x0 00814 400 NtClose (100, ... ) == 0x0 00815 400 NtUnmapViewOfSection (-1, 0x1b10000, ... ) == 0x0 00816 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 100, {status=0x0, info=1}, ) }, 5, 96, ... 100, {status=0x0, info=1}, ) == 0x0 00817 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 100, ... 92, ) == 0x0 00818 400 NtQuerySection (92, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00819 400 NtClose (100, ... ) == 0x0 00820 400 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71950000), 0x0, 933888, ) == 0x0 00821 400 NtClose (92, ... ) == 0x0 00822 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00823 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00824 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00825 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00826 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00827 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00828 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00829 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00830 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00831 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00832 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00833 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00834 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00835 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00836 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00837 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00838 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00839 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00840 400 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00841 400 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00842 400 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00843 400 NtAddAtom ( ("T\0h\0e\0m\0e\0P\0r\0o\0p\0S\0c\0r\0o\0l\0l\0B\0a\0r\0C\0t\0l\0", 42, 1237028, ... ) , 42, 1237028, ... ) == 0x0 00844 400 NtQueryDefaultUILanguage (1235744, ... 00845 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00846 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 00847 400 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00848 400 NtClose (-2147482032, ... ) == 0x0 00849 400 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00850 400 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00851 400 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 00852 400 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00853 400 NtClose (-2147482044, ... ) == 0x0 00854 400 NtClose (-2147482032, ... ) == 0x0 00844 400 NtQueryDefaultUILanguage ... ) == 0x0 00855 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00856 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1234596, ... ) }, 1234596, ... ) == 0x0 00857 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00858 400 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 92, ... 100, ) == 0x0 00859 400 NtClose (92, ... ) == 0x0 00860 400 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x1a60000), 0x0, 4096, ) == 0x0 00861 400 NtClose (100, ... ) == 0x0 00862 400 NtUnmapViewOfSection (-1, 0x1a60000, ... ) == 0x0 00863 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1234236, ... ) }, 1234236, ... ) == 0x0 00864 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1234936, (0x80100080, {24, 0, 0x40, 0, 1234936, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 0x0, 0, 5, 1, 96, 0, 0, ... 100, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 100, {status=0x0, info=1}, ) == 0x0 00865 400 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 100, ... 92, ) == 0x0 00866 400 NtClose (100, ... ) == 0x0 00867 400 NtMapViewOfSection (92, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x1a60000), {0, 0}, 4096, ) == 0x0 00868 400 NtClose (92, ... ) == 0x0 00869 400 NtUnmapViewOfSection (-1, 0x1a60000, ... ) == 0x0 00870 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1, 96, ... 92, {status=0x0, info=1}, ) }, 1, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00871 400 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 92, ... 100, ) == 0x0 00872 400 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x1a60000), 0x0, 4096, ) == 0x0 00873 400 NtQueryInformationFile (92, 1234556, 56, NetworkOpen, ... {status=0x0, info=56}, ) == 0x0 00874 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00875 400 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1234636, 1, 96, 0} (24, {128, 156, new_msg, 0, 1234636, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1\\0\0\0d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\314\335\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1508, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1\\0\0\0d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\314\335\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 396, 400, 1508, 0} (24, {128, 156, new_msg, 0, 1234636, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1\\0\0\0d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\314\335\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1508, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1\\0\0\0d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0\314\335\22\0\0\0\0\0" ) ) == 0x0 00876 400 NtClose (92, ... ) == 0x0 00877 400 NtClose (100, ... ) == 0x0 00878 400 NtUnmapViewOfSection (-1, 0x1a60000, ... ) == 0x0 00879 400 NtUnmapViewOfSection (-1, 0x12ddcc, ... ) == STATUS_NOT_MAPPED_VIEW 00880 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00881 400 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00882 400 NtUserSystemParametersInfo (104, 0, 1906151468, 0, ... ) == 0x1 00883 400 NtUserGetDC (0, ... ) == 0x1010052 00884 400 NtUserCallOneParam (16842834, 56, ... ) == 0x1 00885 400 NtUserSystemParametersInfo (38, 4, 1906153440, 0, ... ) == 0x1 00886 400 NtUserSystemParametersInfo (66, 12, 1237048, 0, ... ) == 0x1 00887 400 NtOpenProcessToken (-1, 0x8, ... 100, ) == 0x0 00888 400 NtAccessCheck (1364096, 100, 0x1, 1236452, 1236396, 56, 1236480, ... ) == STATUS_NO_IMPERSONATION_TOKEN 00889 400 NtClose (100, ... ) == 0x0 00890 400 NtOpenKey (0x20019, {24, 32, 0x40, 0, 0, (0x20019, {24, 32, 0x40, 0, 0, "Control Panel\Desktop"}, ... 100, ) }, ... 100, ) == 0x0 00891 400 NtQueryValueKey (100, (100, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00892 400 NtClose (100, ... ) == 0x0 00893 400 NtUserSystemParametersInfo (41, 500, 1236548, 0, ... ) == 0x1 00894 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 100, ) }, ... 100, ) == 0x0 00895 400 NtQueryValueKey (100, (100, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00896 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 92, ) }, ... 92, ) == 0x0 00897 400 NtQueryValueKey (92, (92, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00898 400 NtClose (92, ... ) == 0x0 00899 400 NtClose (100, ... ) == 0x0 00900 400 NtUserSystemParametersInfo (102, 0, 1906153328, 0, ... ) == 0x1 00901 400 NtUserSystemParametersInfo (4130, 0, 1237072, 0, ... ) == 0x1 00902 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\LanguagePack"}, ... 100, ) }, ... 100, ) == 0x0 00903 400 NtEnumerateValueKey (100, 0, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 00904 400 NtClose (100, ... ) == 0x0 00905 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00906 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc03b 00907 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc03d 00908 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00909 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc03f 00910 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00911 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc041 00912 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00913 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... 00914 400 NtAllocateVirtualMemory (-1, 6782976, 0, 4096, 4096, 32, ... 6782976, 4096, ) == 0x0 00913 400 NtUserRegisterClassExWOW ... ) == 0x810dc043 00915 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc045 00916 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00917 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc047 00918 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00919 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc049 00920 400 NtUserGetClassInfo (1905590272, 1236968, 1236920, 1236996, 0, ... ) == 0xc049 00921 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00922 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc04b 00923 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00924 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc04d 00925 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00926 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc04f 00927 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc051 00928 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00929 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc053 00930 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00931 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc055 00932 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc057 00933 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00934 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc059 00935 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10013 00936 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc05b 00937 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00938 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc05d 00939 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00940 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc05f 00941 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00942 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc017 00943 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00944 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc019 00945 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10013 00946 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc018 00947 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00948 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc01a 00949 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00950 400 NtUserRegisterClassExWOW (1236804, 1236884, 1236868, 1236900, 0, 384, 0, ... ) == 0x810dc01c 00951 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00952 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc01e 00953 400 NtUserFindExistingCursorIcon (1236352, 1236368, 1236936, ... ) == 0x10011 00954 400 NtUserRegisterClassExWOW (1236864, 1236944, 1236928, 1236960, 0, 384, 0, ... ) == 0x810dc01b 00955 400 NtUserFindExistingCursorIcon (1236348, 1236364, 1236932, ... ) == 0x10011 00956 400 NtUserRegisterClassExWOW (1236860, 1236940, 1236924, 1236956, 0, 384, 0, ... ) == 0x810dc068 00957 400 NtUserFindExistingCursorIcon (1236356, 1236372, 1236940, ... ) == 0x10011 00958 400 NtUserRegisterClassExWOW (1236808, 1236888, 1236872, 1236904, 0, 384, 0, ... ) == 0x810dc06a 00959 400 NtCreateKey (0x2001f, {24, 32, 0x40, 0, 0, (0x2001f, {24, 32, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, 0, 0x0, 0, ... 100, 2, ) }, 0, 0x0, 0, ... 100, 2, ) == 0x0 00960 400 NtQueryValueKey (100, (100, "FromCacheTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00961 400 NtQueryValueKey (100, (100, "SecureProtocols", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00962 400 NtQueryValueKey (100, (100, "CertificateRevocation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00963 400 NtQueryValueKey (100, (100, "DisableKeepAlive", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00964 400 NtQueryValueKey (100, (100, "DisablePassport", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00965 400 NtQueryValueKey (100, (100, "CacheMode", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00966 400 NtQueryValueKey (100, (100, "EnableHttp1_1", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (100, "EnableHttp1_1", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00967 400 NtQueryValueKey (100, (100, "ProxyHttp1.1", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00968 400 NtQueryValueKey (100, (100, "EnableNegotiate", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (100, "EnableNegotiate", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00969 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "Secur32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00970 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\Secur32.dll"}, 1239780, ... ) }, 1239780, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00971 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "Secur32.dll"}, 1239780, ... ) }, 1239780, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00972 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Secur32.dll"}, 1239780, ... ) }, 1239780, ... ) == 0x0 00973 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\Secur32.dll"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00974 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 92, ... 104, ) == 0x0 00975 400 NtQuerySection (104, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00976 400 NtClose (92, ... ) == 0x0 00977 400 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f90000), 0x0, 65536, ) == 0x0 00978 400 NtClose (104, ... ) == 0x0 00979 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 104, ) == 0x0 00980 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 92, ) == 0x0 00981 400 NtOpenEvent (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\SECURITY\LSA_AUTHENTICATION_INITIALIZED"}, ... 108, ) }, ... 108, ) == 0x0 00982 400 NtQueryEvent (108, Basic, 8, ... {EventType=0,SignalState=1,}, 0x0, ) == 0x0 00983 400 NtClose (108, ... ) == 0x0 00984 400 NtConnectPort ( ("\LsaAuthenticationPort", {12, 2, 1, 0}, 0x0, 0x0, 1241264, 140, ... 108, 0x0, 0x0, 256, 140, ) , {12, 2, 1, 0}, 0x0, 0x0, 1241264, 140, ... 108, 0x0, 0x0, 256, 140, ) == 0x0 00985 400 NtRequestWaitReplyPort (108, {28, 52, new_msg, 0, 0, 0, 0, 0} (108, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\13\30\10\2\220\36\24\0" ... {176, 200, reply, 0, 396, 400, 1510, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\20\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0R\0I\0-\0u\0s\0e\0r\0" ) ... {176, 200, reply, 0, 396, 400, 1510, 0} (108, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\13\30\10\2\220\36\24\0" ... {176, 200, reply, 0, 396, 400, 1510, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\20\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0S\0R\0I\0-\0u\0s\0e\0r\0" ) ) == 0x0 00986 400 NtQueryValueKey (100, (100, "SyncMode5", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00987 400 NtOpenKey (0xf, {24, 28, 0x40, 0, 0, (0xf, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache"}, ... 112, ) }, ... 112, ) == 0x0 00988 400 NtQueryValueKey (112, (112, "FixupKey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00989 400 NtClose (112, ... ) == 0x0 00990 400 NtOpenKey (0xf, {24, 28, 0x40, 0, 0, (0xf, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 112, ) }, ... 112, ) == 0x0 00991 400 NtQueryValueKey (112, (112, "SessionStartTimeDefaultDeltaSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00992 400 NtClose (112, ... ) == 0x0 00993 400 NtOpenKey (0xf, {24, 28, 0x40, 0, 0, (0xf, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 112, ) }, ... 112, ) == 0x0 00994 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\Setup"}, ... 116, ) }, ... 116, ) == 0x0 00995 400 NtQueryValueKey (116, (116, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (116, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00996 400 NtClose (116, ... ) == 0x0 00997 400 NtOpenKey (0xf, {24, 32, 0x40, 0, 0, (0xf, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 116, ) }, ... 116, ) == 0x0 00998 400 NtOpenKey (0xf, {24, 32, 0x40, 0, 0, (0xf, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 120, ) }, ... 120, ) == 0x0 00999 400 NtOpenKey (0xf, {24, 32, 0x40, 0, 0, (0xf, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, ... 124, ) }, ... 124, ) == 0x0 01000 400 NtOpenKey (0xf, {24, 32, 0x40, 0, 0, (0xf, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 128, ) }, ... 128, ) == 0x0 01001 400 NtQueryValueKey (128, (128, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) }, 68, ) == 0x0 01002 400 NtQueryValueKey (128, (128, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "Signature", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0l\0i\0e\0n\0t\0 \0U\0r\0l\0C\0a\0c\0h\0e\0 \0M\0M\0F\0 \0V\0e\0r\0 \05\0.\02\0\0\0"}, 68, ) }, 68, ) == 0x0 01003 400 NtClose (128, ... ) == 0x0 01004 400 NtOpenKey (0xf, {24, 32, 0x40, 0, 0, (0xf, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, ... 128, ) }, ... 128, ) == 0x0 01005 400 NtQueryValueKey (128, (128, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (128, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 01006 400 NtQueryValueKey (128, (128, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (128, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 01007 400 NtQueryValueKey (128, (128, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (128, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 01008 400 NtQueryValueKey (128, (128, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (128, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 01009 400 NtQueryValueKey (128, (128, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (128, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 01010 400 NtQueryValueKey (128, (128, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (128, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 01011 400 NtClose (128, ... ) == 0x0 01012 400 NtOpenKey (0xf, {24, 120, 0x40, 0, 0, (0xf, {24, 120, 0x40, 0, 0, "Content"}, ... 128, ) }, ... 128, ) == 0x0 01013 400 NtQueryValueKey (128, (128, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (128, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01014 400 NtClose (128, ... ) == 0x0 01015 400 NtOpenKey (0xf, {24, 120, 0x40, 0, 0, (0xf, {24, 120, 0x40, 0, 0, "Content"}, ... 128, ) }, ... 128, ) == 0x0 01016 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "shell32.dll"}, ... 132, ) }, ... 132, ) == 0x0 01017 400 NtMapViewOfSection (132, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x773d0000), 0x0, 8339456, ) == 0x0 01018 400 NtClose (132, ... ) == 0x0 01019 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 132, ) }, ... 132, ) == 0x0 01020 400 NtQueryValueKey (132, (132, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (132, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01021 400 NtClose (132, ... ) == 0x0 01022 400 NtQueryDefaultUILanguage (1236232, ... 01023 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01024 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 01025 400 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01026 400 NtClose (-2147482032, ... ) == 0x0 01027 400 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 01028 400 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01029 400 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 01030 400 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01031 400 NtClose (-2147482044, ... ) == 0x0 01032 400 NtClose (-2147482032, ... ) == 0x0 01022 400 NtQueryDefaultUILanguage ... ) == 0x0 01033 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01034 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\shell32.dll"}, 1, 96, ... 132, {status=0x0, info=1}, ) }, 1, 96, ... 132, {status=0x0, info=1}, ) == 0x0 01035 400 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 132, ... 136, ) == 0x0 01036 400 NtMapViewOfSection (136, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x1b10000), 0x0, 8323072, ) == 0x0 01037 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\shell32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01038 400 NtQueryDefaultLocale (1, 1234268, ... ) == 0x0 01039 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\shell32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01040 400 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1235124, 1, 96, 0} (24, {128, 156, new_msg, 0, 1235124, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\334\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\204\0\0\0\377\377\377\377\0\0\0\0\20\311\350\1\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\264\337\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1511, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\334\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\204\0\0\0\377\377\377\377\0\0\0\0\20\311\350\1\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\264\337\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 396, 400, 1511, 0} (24, {128, 156, new_msg, 0, 1235124, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\334\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\204\0\0\0\377\377\377\377\0\0\0\0\20\311\350\1\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\264\337\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1511, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\334\22\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\204\0\0\0\377\377\377\377\0\0\0\0\20\311\350\1\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\264\337\22\0\0\0\0\0" ) ) == 0x0 01041 400 NtClose (132, ... ) == 0x0 01042 400 NtClose (136, ... ) == 0x0 01043 400 NtUnmapViewOfSection (-1, 0x1b10000, ... ) == 0x0 01044 400 NtUnmapViewOfSection (-1, 0x12dfb4, ... ) == STATUS_NOT_MAPPED_VIEW 01045 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01046 400 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01047 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01048 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01049 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1233352, ... ) }, 1233352, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01050 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01051 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01052 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01053 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1233944, ... ) }, 1233944, ... ) == 0x0 01054 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 136, {status=0x0, info=1}, ) }, 3, 33, ... 136, {status=0x0, info=1}, ) == 0x0 01055 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01056 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc03b 01057 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc03d 01058 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc03f 01059 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc041 01060 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc043 01061 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc045 01062 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc047 01063 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc049 01064 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc04b 01065 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc04d 01066 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc04f 01067 400 NtUserGetClassInfo (1999896576, 1237972, 1237924, 1238000, 0, ... ) == 0xc051 01068 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc053 01069 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc055 01070 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc059 01071 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc05b 01072 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc05d 01073 400 NtUserGetClassInfo (1999896576, 1237968, 1237920, 1237996, 0, ... ) == 0xc05f 01074 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01075 400 NtCreateSemaphore (0x1f0003, {24, 76, 0x80, 1367176, 0, (0x1f0003, {24, 76, 0x80, 1367176, 0, "shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}"}, 0, 2147483647, ... 132, ) }, 0, 2147483647, ... 132, ) == STATUS_OBJECT_NAME_EXISTS 01076 400 NtReleaseSemaphore (132, 1, ... 0, ) == 0x0 01077 400 NtWaitForSingleObject (132, 0, {0, 0}, ... ) == 0x0 01078 400 NtCreateKey (0x2000000, {24, 32, 0x40, 0, 0, (0x2000000, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01079 400 NtQueryValueKey (140, (140, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (140, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 01080 400 NtClose (140, ... ) == 0x0 01081 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 1238492, ... ) }, 1238492, ... ) == 0x0 01082 400 NtCreateKey (0x2000000, {24, 32, 0x40, 0, 0, (0x2000000, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01083 400 NtSetValueKey (140, (140, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 150, ... ) , 0, 1, (140, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 150, ... ) , 150, ... ) == 0x0 01084 400 NtClose (140, ... ) == 0x0 01085 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 1239824, ... ) }, 1239824, ... ) == 0x0 01086 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 1239556, ... ) }, 1239556, ... ) == 0x0 01087 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files"}, 7, 2113568, ... 140, {status=0x0, info=1}, ) }, 7, 2113568, ... 140, {status=0x0, info=1}, ) == 0x0 01088 400 NtSetInformationFile (140, 1239532, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01089 400 NtClose (140, ... ) == 0x0 01090 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\desktop.ini"}, 1239556, ... ) }, 1239556, ... ) == 0x0 01091 400 NtQueryValueKey (128, (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01092 400 NtQueryValueKey (128, (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 01093 400 NtQueryValueKey (128, (128, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\251~\1\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (128, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\251~\1\0"}, 16, ) }, 16, ) == 0x0 01094 400 NtOpenKey (0xf, {24, 28, 0x40, 0, 0, (0xf, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache"}, ... 140, ) }, ... 140, ) == 0x0 01095 400 NtOpenKey (0xf, {24, 140, 0x40, 0, 0, (0xf, {24, 140, 0x40, 0, 0, "Paths"}, ... 144, ) }, ... 144, ) == 0x0 01096 400 NtOpenKey (0xf, {24, 144, 0x40, 0, 0, (0xf, {24, 144, 0x40, 0, 0, "Path1"}, ... 148, ) }, ... 148, ) == 0x0 01097 400 NtOpenKey (0xf, {24, 144, 0x40, 0, 0, (0xf, {24, 144, 0x40, 0, 0, "Path2"}, ... 152, ) }, ... 152, ) == 0x0 01098 400 NtOpenKey (0xf, {24, 144, 0x40, 0, 0, (0xf, {24, 144, 0x40, 0, 0, "Path3"}, ... 156, ) }, ... 156, ) == 0x0 01099 400 NtOpenKey (0xf, {24, 144, 0x40, 0, 0, (0xf, {24, 144, 0x40, 0, 0, "Path4"}, ... 160, ) }, ... 160, ) == 0x0 01100 400 NtOpenKey (0xf, {24, 140, 0x40, 0, 0, (0xf, {24, 140, 0x40, 0, 0, "Special Paths"}, ... 164, ) }, ... 164, ) == 0x0 01101 400 NtSetValueKey (144, (144, "Directory", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\0\0", 174, ... ) , 0, 1, (144, "Directory", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\0\0", 174, ... ) , 174, ... ) == 0x0 01102 400 NtSetValueKey (144, (144, "Paths", 0, 4, "\4\0\0\0", 4, ... ) , 0, 4, (144, "Paths", 0, 4, "\4\0\0\0", 4, ... ) , 4, ... ) == 0x0 01103 400 NtSetValueKey (148, (148, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\01\0\0\0", 188, ... ) , 0, 1, (148, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\01\0\0\0", 188, ... ) , 188, ... ) == 0x0 01104 400 NtSetValueKey (152, (152, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\02\0\0\0", 188, ... ) , 0, 1, (152, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\02\0\0\0", 188, ... ) , 188, ... ) == 0x0 01105 400 NtSetValueKey (156, (156, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\03\0\0\0", 188, ... ) , 0, 1, (156, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\03\0\0\0", 188, ... ) , 188, ... ) == 0x0 01106 400 NtSetValueKey (160, (160, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\04\0\0\0", 188, ... ) , 0, 1, (160, "CachePath", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\\0C\0o\0n\0t\0e\0n\0t\0.\0I\0E\05\0\\0C\0a\0c\0h\0e\04\0\0\0", 188, ... ) , 188, ... ) == 0x0 01107 400 NtSetValueKey (148, (148, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (148, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 01108 400 NtSetValueKey (152, (152, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (152, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 01109 400 NtSetValueKey (156, (156, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (156, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 01110 400 NtSetValueKey (160, (160, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 0, 4, (160, "CacheLimit", 0, 4, "\252_\0\0", 4, ... ) , 4, ... ) == 0x0 01111 400 NtClose (160, ... ) == 0x0 01112 400 NtClose (156, ... ) == 0x0 01113 400 NtClose (152, ... ) == 0x0 01114 400 NtClose (148, ... ) == 0x0 01115 400 NtClose (144, ... ) == 0x0 01116 400 NtClose (164, ... ) == 0x0 01117 400 NtClose (140, ... ) == 0x0 01118 400 NtOpenKey (0xf, {24, 120, 0x40, 0, 0, (0xf, {24, 120, 0x40, 0, 0, "Cookies"}, ... 140, ) }, ... 140, ) == 0x0 01119 400 NtQueryValueKey (140, (140, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (140, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01120 400 NtClose (140, ... ) == 0x0 01121 400 NtClose (128, ... ) == 0x0 01122 400 NtOpenKey (0xf, {24, 120, 0x40, 0, 0, (0xf, {24, 120, 0x40, 0, 0, "Cookies"}, ... 128, ) }, ... 128, ) == 0x0 01123 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01124 400 NtReleaseSemaphore (132, 1, ... 0, ) == 0x0 01125 400 NtWaitForSingleObject (132, 0, {0, 0}, ... ) == 0x0 01126 400 NtCreateKey (0x2000000, {24, 32, 0x40, 0, 0, (0x2000000, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01127 400 NtQueryValueKey (140, (140, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (140, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 01128 400 NtClose (140, ... ) == 0x0 01129 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies"}, 1238492, ... ) }, 1238492, ... ) == 0x0 01130 400 NtCreateKey (0x2000000, {24, 32, 0x40, 0, 0, (0x2000000, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01131 400 NtSetValueKey (140, (140, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 86, ... ) , 0, 1, (140, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 86, ... ) , 86, ... ) == 0x0 01132 400 NtClose (140, ... ) == 0x0 01133 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies"}, 1239824, ... ) }, 1239824, ... ) == 0x0 01134 400 NtQueryValueKey (128, (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) }, 28, ) == 0x0 01135 400 NtQueryValueKey (128, (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="C\0o\0o\0k\0i\0e\0:\0\0\0"}, 28, ) }, 28, ) == 0x0 01136 400 NtQueryValueKey (128, (128, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (128, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 01137 400 NtOpenKey (0xf, {24, 120, 0x40, 0, 0, (0xf, {24, 120, 0x40, 0, 0, "History"}, ... 140, ) }, ... 140, ) == 0x0 01138 400 NtQueryValueKey (140, (140, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (140, "PerUserItem", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01139 400 NtClose (140, ... ) == 0x0 01140 400 NtClose (128, ... ) == 0x0 01141 400 NtOpenKey (0xf, {24, 120, 0x40, 0, 0, (0xf, {24, 120, 0x40, 0, 0, "History"}, ... 128, ) }, ... 128, ) == 0x0 01142 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 01143 400 NtReleaseSemaphore (132, 1, ... 0, ) == 0x0 01144 400 NtWaitForSingleObject (132, 0, {0, 0}, ... ) == 0x0 01145 400 NtCreateKey (0x2000000, {24, 32, 0x40, 0, 0, (0x2000000, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01146 400 NtQueryValueKey (140, (140, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (140, "History", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0"}, 86, ) }, 86, ) == 0x0 01147 400 NtClose (140, ... ) == 0x0 01148 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 1238492, ... ) }, 1238492, ... ) == 0x0 01149 400 NtCreateKey (0x2000000, {24, 32, 0x40, 0, 0, (0x2000000, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 140, 2, ) }, 0, 0x0, 0, ... 140, 2, ) == 0x0 01150 400 NtSetValueKey (140, (140, "History", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0", 116, ... ) , 0, 1, (140, "History", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\0\0", 116, ... ) , 116, ... ) == 0x0 01151 400 NtClose (140, ... ) == 0x0 01152 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 1239824, ... ) }, 1239824, ... ) == 0x0 01153 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 1239556, ... ) }, 1239556, ... ) == 0x0 01154 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History"}, 7, 2113568, ... 140, {status=0x0, info=1}, ) }, 7, 2113568, ... 140, {status=0x0, info=1}, ) == 0x0 01155 400 NtSetInformationFile (140, 1239532, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01156 400 NtClose (140, ... ) == 0x0 01157 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\desktop.ini"}, 1239556, ... ) }, 1239556, ... ) == 0x0 01158 400 NtQueryValueKey (128, (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) }, 30, ) == 0x0 01159 400 NtQueryValueKey (128, (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (128, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data="V\0i\0s\0i\0t\0e\0d\0:\0\0\0"}, 30, ) }, 30, ) == 0x0 01160 400 NtQueryValueKey (128, (128, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (128, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 01161 400 NtClose (128, ... ) == 0x0 01162 400 NtClose (124, ... ) == 0x0 01163 400 NtClose (116, ... ) == 0x0 01164 400 NtClose (120, ... ) == 0x0 01165 400 NtClose (112, ... ) == 0x0 01166 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "_!MSFTHISTORY!_"}, ... 112, ) }, ... 112, ) == 0x0 01167 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "c:!documents and settings!sri-user!local settings!temporary internet files!content.ie5!"}, ... 120, ) }, ... 120, ) == 0x0 01168 400 NtWaitForSingleObject (120, 0, 0x0, ... ) == 0x0 01169 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 3, 8388641, ... 116, {status=0x0, info=1}, ) }, 3, 8388641, ... 116, {status=0x0, info=1}, ) == 0x0 01170 400 NtQueryVolumeInformationFile (116, 1241076, 24, Size, ... {status=0x0, info=24}, ) == 0x0 01171 400 NtClose (116, ... ) == 0x0 01172 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 8388641, ... 116, {status=0x0, info=1}, ) }, 3, 8388641, ... 116, {status=0x0, info=1}, ) == 0x0 01173 400 NtQueryVolumeInformationFile (116, 1241100, 24, Size, ... {status=0x0, info=24}, ) == 0x0 01174 400 NtClose (116, ... ) == 0x0 01175 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 1241428, ... ) }, 1241428, ... ) == 0x0 01176 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 7, 2113568, ... 116, {status=0x0, info=1}, ) }, 7, 2113568, ... 116, {status=0x0, info=1}, ) == 0x0 01177 400 NtSetInformationFile (116, 1241404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01178 400 NtClose (116, ... ) == 0x0 01179 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 1367176, 1241420, (0xc0100080, {24, 0, 0x40, 1367176, 1241420, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 116, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 116, {status=0x0, info=1}, ) == 0x0 01180 400 NtSetInformationFile (116, 1241472, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01181 400 NtQueryInformationFile (116, 1241472, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01182 400 NtClose (116, ... ) == 0x0 01183 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 1367176, 1241404, (0xc0100080, {24, 0, 0x40, 1367176, 1241404, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 116, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 116, {status=0x0, info=1}, ) == 0x0 01184 400 NtOpenSection (0x2, {24, 76, 0x0, 0, 0, (0x2, {24, 76, 0x0, 0, 0, "C:_Documents and Settings_SRI-user_Local Settings_Temporary Internet Files_Content.IE5_index.dat_32768"}, ... 124, ) }, ... 124, ) == 0x0 01185 400 NtMapViewOfSection (124, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x1a80000), {0, 0}, 32768, ) == 0x0 01186 400 NtReleaseMutant (120, ... 0x0, ) == 0x0 01187 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "c:!documents and settings!sri-user!cookies!"}, ... 128, ) }, ... 128, ) == 0x0 01188 400 NtWaitForSingleObject (128, 0, 0x0, ... ) == 0x0 01189 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies\"}, 3, 8388641, ... 140, {status=0x0, info=1}, ) }, 3, 8388641, ... 140, {status=0x0, info=1}, ) == 0x0 01190 400 NtQueryVolumeInformationFile (140, 1241076, 24, Size, ... {status=0x0, info=24}, ) == 0x0 01191 400 NtClose (140, ... ) == 0x0 01192 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 8388641, ... 140, {status=0x0, info=1}, ) }, 3, 8388641, ... 140, {status=0x0, info=1}, ) == 0x0 01193 400 NtQueryVolumeInformationFile (140, 1241100, 24, Size, ... {status=0x0, info=24}, ) == 0x0 01194 400 NtClose (140, ... ) == 0x0 01195 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies\"}, 1241428, ... ) }, 1241428, ... ) == 0x0 01196 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Cookies\"}, 7, 2113568, ... 140, {status=0x0, info=1}, ) }, 7, 2113568, ... 140, {status=0x0, info=1}, ) == 0x0 01197 400 NtSetInformationFile (140, 1241404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01198 400 NtClose (140, ... ) == 0x0 01199 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 1367176, 1241420, (0xc0100080, {24, 0, 0x40, 1367176, 1241420, "\??\C:\Documents and Settings\SRI-user\Cookies\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 140, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 140, {status=0x0, info=1}, ) == 0x0 01200 400 NtSetInformationFile (140, 1241472, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01201 400 NtQueryInformationFile (140, 1241472, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01202 400 NtClose (140, ... ) == 0x0 01203 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 1367176, 1241404, (0xc0100080, {24, 0, 0x40, 1367176, 1241404, "\??\C:\Documents and Settings\SRI-user\Cookies\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 140, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 140, {status=0x0, info=1}, ) == 0x0 01204 400 NtOpenSection (0x2, {24, 76, 0x0, 0, 0, (0x2, {24, 76, 0x0, 0, 0, "C:_Documents and Settings_SRI-user_Cookies_index.dat_16384"}, ... 164, ) }, ... 164, ) == 0x0 01205 400 NtMapViewOfSection (164, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x1a90000), {0, 0}, 16384, ) == 0x0 01206 400 NtReleaseMutant (128, ... 0x0, ) == 0x0 01207 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "c:!documents and settings!sri-user!local settings!history!history.ie5!"}, ... 144, ) }, ... 144, ) == 0x0 01208 400 NtWaitForSingleObject (144, 0, 0x0, ... ) == 0x0 01209 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 3, 8388641, ... 148, {status=0x0, info=1}, ) }, 3, 8388641, ... 148, {status=0x0, info=1}, ) == 0x0 01210 400 NtQueryVolumeInformationFile (148, 1241076, 24, Size, ... {status=0x0, info=24}, ) == 0x0 01211 400 NtClose (148, ... ) == 0x0 01212 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 8388641, ... 148, {status=0x0, info=1}, ) }, 3, 8388641, ... 148, {status=0x0, info=1}, ) == 0x0 01213 400 NtQueryVolumeInformationFile (148, 1241100, 24, Size, ... {status=0x0, info=24}, ) == 0x0 01214 400 NtClose (148, ... ) == 0x0 01215 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 1241428, ... ) }, 1241428, ... ) == 0x0 01216 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 7, 2113568, ... 148, {status=0x0, info=1}, ) }, 7, 2113568, ... 148, {status=0x0, info=1}, ) == 0x0 01217 400 NtSetInformationFile (148, 1241404, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01218 400 NtClose (148, ... ) == 0x0 01219 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 1367176, 1241420, (0xc0100080, {24, 0, 0x40, 1367176, 1241420, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 148, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 148, {status=0x0, info=1}, ) == 0x0 01220 400 NtSetInformationFile (148, 1241472, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01221 400 NtQueryInformationFile (148, 1241472, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01222 400 NtClose (148, ... ) == 0x0 01223 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 1367176, 1241404, (0xc0100080, {24, 0, 0x40, 1367176, 1241404, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\index.dat"}, 0x0, 0, 3, 3, 2144, 0, 0, ... 148, {status=0x0, info=1}, ) }, 0x0, 0, 3, 3, 2144, 0, 0, ... 148, {status=0x0, info=1}, ) == 0x0 01224 400 NtOpenSection (0x2, {24, 76, 0x0, 0, 0, (0x2, {24, 76, 0x0, 0, 0, "C:_Documents and Settings_SRI-user_Local Settings_History_History.IE5_index.dat_32768"}, ... 152, ) }, ... 152, ) == 0x0 01225 400 NtMapViewOfSection (152, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x1aa0000), {0, 0}, 32768, ) == 0x0 01226 400 NtReleaseMutant (144, ... 0x0, ) == 0x0 01227 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 1241484, ... ) }, 1241484, ... ) == 0x0 01228 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\"}, 7, 2113568, ... 156, {status=0x0, info=1}, ) }, 7, 2113568, ... 156, {status=0x0, info=1}, ) == 0x0 01229 400 NtSetInformationFile (156, 1241460, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01230 400 NtClose (156, ... ) == 0x0 01231 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini"}, 1241484, ... ) }, 1241484, ... ) == 0x0 01232 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 1241484, ... ) }, 1241484, ... ) == 0x0 01233 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\"}, 7, 2113568, ... 156, {status=0x0, info=1}, ) }, 7, 2113568, ... 156, {status=0x0, info=1}, ) == 0x0 01234 400 NtSetInformationFile (156, 1241460, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 01235 400 NtClose (156, ... ) == 0x0 01236 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\SRI-user\Local Settings\History\History.IE5\desktop.ini"}, 1241484, ... ) }, 1241484, ... ) == 0x0 01237 400 NtWaitForSingleObject (120, 0, 0x0, ... ) == 0x0 01238 400 NtQueryInformationFile (116, 1239868, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01239 400 NtReleaseMutant (120, ... 0x0, ) == 0x0 01240 400 NtOpenKey (0xf, {24, 32, 0x40, 0, 0, (0xf, {24, 32, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 156, ) }, ... 156, ) == 0x0 01241 400 NtOpenKey (0xf, {24, 156, 0x40, 0, 0, (0xf, {24, 156, 0x40, 0, 0, "Extensible Cache"}, ... 160, ) }, ... 160, ) == 0x0 01242 400 NtClose (156, ... ) == 0x0 01243 400 NtWaitForSingleObject (112, 0, {-600000000, -1}, ... ) == 0x0 01244 400 NtEnumerateKey (160, 0, Basic, 288, ... {LastWrite={0x89210de2,0x1c79d95}, TitleIdx=0, Name= (160, 0, Basic, 288, ... {LastWrite={0x89210de2,0x1c79d95}, TitleIdx=0, Name="MSHist012007051420070521"}, 64, ) }, 64, ) == 0x0 01245 400 NtOpenKey (0xf, {24, 160, 0x40, 0, 0, (0xf, {24, 160, 0x40, 0, 0, "MSHist012007051420070521"}, ... 156, ) }, ... 156, ) == 0x0 01246 400 NtQueryValueKey (156, (156, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01247 400 NtQueryValueKey (156, (156, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01248 400 NtQueryValueKey (156, (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 01249 400 NtAllocateVirtualMemory (-1, 1368064, 0, 4096, 4096, 4, ... 1368064, 4096, ) == 0x0 01250 400 NtQueryValueKey (156, (156, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01251 400 NtQueryValueKey (156, (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 01252 400 NtQueryValueKey (156, (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 01253 400 NtQueryValueKey (156, (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\01\04\02\00\00\07\00\05\02\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 01254 400 NtQueryValueKey (156, (156, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 01255 400 NtQueryValueKey (156, (156, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 01256 400 NtClose (156, ... ) == 0x0 01257 400 NtEnumerateKey (160, 1, Basic, 288, ... {LastWrite={0xfe4bb184,0x1c7a3a9}, TitleIdx=0, Name= (160, 1, Basic, 288, ... {LastWrite={0xfe4bb184,0x1c7a3a9}, TitleIdx=0, Name="MSHist012007052120070528"}, 64, ) }, 64, ) == 0x0 01258 400 NtOpenKey (0xf, {24, 160, 0x40, 0, 0, (0xf, {24, 160, 0x40, 0, 0, "MSHist012007052120070528"}, ... 156, ) }, ... 156, ) == 0x0 01259 400 NtQueryValueKey (156, (156, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01260 400 NtQueryValueKey (156, (156, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01261 400 NtQueryValueKey (156, (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 01262 400 NtQueryValueKey (156, (156, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01263 400 NtQueryValueKey (156, (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 01264 400 NtQueryValueKey (156, (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 01265 400 NtQueryValueKey (156, (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\02\01\02\00\00\07\00\05\02\08\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 01266 400 NtQueryValueKey (156, (156, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 01267 400 NtQueryValueKey (156, (156, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 01268 400 NtClose (156, ... ) == 0x0 01269 400 NtEnumerateKey (160, 2, Basic, 288, ... {LastWrite={0xfe4e13de,0x1c7a3a9}, TitleIdx=0, Name= (160, 2, Basic, 288, ... {LastWrite={0xfe4e13de,0x1c7a3a9}, TitleIdx=0, Name="MSHist012007053120070601"}, 64, ) }, 64, ) == 0x0 01270 400 NtOpenKey (0xf, {24, 160, 0x40, 0, 0, (0xf, {24, 160, 0x40, 0, 0, "MSHist012007053120070601"}, ... 156, ) }, ... 156, ) == 0x0 01271 400 NtQueryValueKey (156, (156, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheRepair", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01272 400 NtQueryValueKey (156, (156, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01273 400 NtQueryValueKey (156, (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 01274 400 NtQueryValueKey (156, (156, "CachePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01275 400 NtQueryValueKey (156, (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=2, Data= (156, "CachePath", Partial, 162, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0H\0i\0s\0t\0o\0r\0y\0\\0H\0i\0s\0t\0o\0r\0y\0.\0I\0E\05\0\\0M\0S\0H\0i\0s\0t\00\01\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0\\0\0\0"}, 162, ) }, 162, ) == 0x0 01276 400 NtQueryValueKey (156, (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 01277 400 NtQueryValueKey (156, (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (156, "CachePrefix", Partial, 144, ... TitleIdx=0, Type=1, Data=":\02\00\00\07\00\05\03\01\02\00\00\07\00\06\00\01\0:\0 \0\0\0"}, 52, ) }, 52, ) == 0x0 01278 400 NtQueryValueKey (156, (156, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheLimit", Partial, 144, ... TitleIdx=0, Type=4, Data="\0 \0\0"}, 16, ) }, 16, ) == 0x0 01279 400 NtQueryValueKey (156, (156, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (156, "CacheOptions", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 01280 400 NtClose (156, ... ) == 0x0 01281 400 NtEnumerateKey (160, 3, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 01282 400 NtReleaseMutant (112, ... 0x0, ) == 0x0 01283 400 NtClose (160, ... ) == 0x0 01284 400 NtWaitForSingleObject (120, 0, 0x0, ... ) == 0x0 01285 400 NtQueryInformationFile (116, 1241796, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01286 400 NtReleaseMutant (120, ... 0x0, ) == 0x0 01287 400 NtWaitForSingleObject (120, 0, 0x0, ... ) == 0x0 01288 400 NtQueryInformationFile (116, 1241868, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01289 400 NtReleaseMutant (120, ... 0x0, ) == 0x0 01290 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01291 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01292 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01293 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01294 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01295 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 160, ) }, ... 160, ) == 0x0 01296 400 NtQueryValueKey (160, (160, "DisableWorkerThreadHibernation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01297 400 NtClose (160, ... ) == 0x0 01298 400 NtQueryValueKey (100, (100, "DisableWorkerThreadHibernation", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01299 400 NtQueryValueKey (100, (100, "DisableReadRange", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01300 400 NtQueryValueKey (100, (100, "SocketSendBufferLength", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01301 400 NtQueryValueKey (100, (100, "SocketReceiveBufferLength", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01302 400 NtQueryValueKey (100, (100, "KeepAliveTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01303 400 NtQueryValueKey (100, (100, "MaxHttpRedirects", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01304 400 NtQueryValueKey (100, (100, "MaxConnectionsPerServer", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01305 400 NtQueryValueKey (100, (100, "MaxConnectionsPer1_0Server", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01306 400 NtQueryValueKey (100, (100, "ServerInfoTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01307 400 NtQueryValueKey (100, (100, "ReceiveTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01308 400 NtQueryValueKey (100, (100, "DisableNTLMPreAuth", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01309 400 NtQueryValueKey (100, (100, "ScavengeCacheLowerBound", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01310 400 NtOpenKey (0x1, {24, 32, 0x40, 0, 0, (0x1, {24, 32, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache"}, ... 160, ) }, ... 160, ) == 0x0 01311 400 NtQueryValueKey (160, (160, "ScavengeCacheFileLifeTime", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01312 400 NtClose (160, ... ) == 0x0 01313 400 NtQueryValueKey (100, (100, "HttpDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01314 400 NtQueryValueKey (100, (100, "FtpDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01315 400 NtQueryValueKey (100, (100, "GopherDefaultExpiryTimeSecs", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01316 400 NtQueryValueKey (100, (100, "DisableCachingOfSSLPages", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01317 400 NtQueryValueKey (100, (100, "PerUserCookies", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01318 400 NtQueryValueKey (100, (100, "LeashLegacyCookies", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01319 400 NtQueryValueKey (100, (100, "DisableNT4RasCheck", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01320 400 NtQueryValueKey (100, (100, "DialupUseLanSettings", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01321 400 NtQueryValueKey (100, (100, "SendExtraCRLF", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01322 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 160, ) }, ... 160, ) == 0x0 01323 400 NtQueryValueKey (160, (160, "DontUseDNSLoadBalancing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01324 400 NtClose (160, ... ) == 0x0 01325 400 NtQueryValueKey (100, (100, "DontUseDNSLoadBalancing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01326 400 NtQueryValueKey (100, (100, "NonBlockingClient32", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01327 400 NtQueryValueKey (100, (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 01328 400 NtQueryValueKey (100, (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 01329 400 NtQueryValueKey (100, (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 01330 400 NtQueryValueKey (100, (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (100, "MimeExclusionListForCache", Partial, 144, ... TitleIdx=0, Type=1, Data="m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0m\0i\0x\0e\0d\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0m\0i\0x\0e\0d\0-\0r\0e\0p\0l\0a\0c\0e\0 \0m\0u\0l\0t\0i\0p\0a\0r\0t\0/\0x\0-\0b\0y\0t\0e\0r\0a\0n\0g\0e\0s\0 \0\0\0"}, 144, ) }, 144, ) == 0x0 01331 400 NtQueryValueKey (100, (100, "HeaderExclusionListForCache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01332 400 NtQueryValueKey (100, (100, "DnsCacheEnabled", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01333 400 NtQueryValueKey (100, (100, "DnsCacheEntries", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01334 400 NtQueryValueKey (100, (100, "DnsCacheTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01335 400 NtQueryValueKey (100, (100, "WarnOnPost", Partial, 144, ... TitleIdx=0, Type=3, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (100, "WarnOnPost", Partial, 144, ... TitleIdx=0, Type=3, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01336 400 NtQueryValueKey (100, (100, "WarnAlwaysOnPost", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01337 400 NtQueryValueKey (100, (100, "WarnOnZoneCrossing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01338 400 NtQueryValueKey (100, (100, "WarnOnBadCertSending", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01339 400 NtQueryValueKey (100, (100, "WarnOnBadCertRecving", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01340 400 NtQueryValueKey (100, (100, "WarnOnPostRedirect", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01341 400 NtQueryValueKey (100, (100, "AlwaysDrainOnRedirect", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01342 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "WininetStartupMutex"}, ... 160, ) }, ... 160, ) == 0x0 01343 400 NtCreateEvent (0x1f0003, 0x0, 1, 1, ... 156, ) == 0x0 01344 400 NtQueryValueKey (100, (100, "GlobalUserOffline", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01345 400 NtWaitForSingleObject (120, 0, 0x0, ... ) == 0x0 01346 400 NtQueryInformationFile (116, 1241844, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01347 400 NtReleaseMutant (120, ... 0x0, ) == 0x0 01348 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "WininetConnectionMutex"}, ... 168, ) }, ... 168, ) == 0x0 01349 400 NtCreateMutant (0x1f0001, 0x0, 0, ... 172, ) == 0x0 01350 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "WininetProxyRegistryMutex"}, ... 176, ) }, ... 176, ) == 0x0 01351 400 NtQueryValueKey (100, (100, "EnableAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (100, "EnableAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01352 400 NtQueryValueKey (100, (100, "NoNetAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (100, "NoNetAutodial", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01353 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 180, ) }, ... 180, ) == 0x0 01354 400 NtQueryValueKey (180, (180, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (180, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) }, 34, ) == 0x0 01355 400 NtQueryValueKey (180, (180, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (180, "UrlEncoding", Partial, 144, ... TitleIdx=0, Type=1, Data="0\0x\00\00\00\00\00\00\00\00\0\0\0"}, 34, ) }, 34, ) == 0x0 01356 400 NtClose (180, ... ) == 0x0 01357 400 NtCreateEvent (0x1f0003, 0x0, 1, 1, ... 180, ) == 0x0 01358 400 NtWaitForSingleObject (180, 0, 0x0, ... ) == 0x0 01359 400 NtClearEvent (180, ... ) == 0x0 01360 400 NtSetEvent (180, ... 0x0, ) == 0x0 01361 400 NtAllocateVirtualMemory (-1, 1372160, 0, 4096, 4096, 4, ... 1372160, 4096, ) == 0x0 01362 400 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\WinSock2\Parameters"}, ... 184, ) }, ... 184, ) == 0x0 01363 400 NtQueryValueKey (184, (184, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (184, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) }, 20, ) == 0x0 01364 400 NtQueryValueKey (184, (184, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (184, "WinSock_Registry_Version", Partial, 144, ... TitleIdx=0, Type=1, Data="2\0.\00\0\0\0"}, 20, ) }, 20, ) == 0x0 01365 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 188, ) == 0x0 01366 400 NtOpenKey (0x2000000, {24, 184, 0x40, 0, 0, (0x2000000, {24, 184, 0x40, 0, 0, "Protocol_Catalog9"}, ... 192, ) }, ... 192, ) == 0x0 01367 400 NtQueryValueKey (192, (192, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (192, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) }, 16, ) == 0x0 01368 400 NtNotifyChangeKey (192, 188, 0, 0, 2011390432, 1, 0, 0, 0, 1, ... ) == 0x103 01369 400 NtQueryValueKey (192, (192, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (192, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\31\0\0\0"}, 16, ) }, 16, ) == 0x0 01370 400 NtOpenKey (0x2000000, {24, 192, 0x40, 0, 0, (0x2000000, {24, 192, 0x40, 0, 0, "00000019"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01371 400 NtQueryValueKey (192, (192, "Next_Catalog_Entry_ID", Partial, 144, ... TitleIdx=0, Type=4, Data="\376\3\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (192, "Next_Catalog_Entry_ID", Partial, 144, ... TitleIdx=0, Type=4, Data="\376\3\0\0"}, 16, ) }, 16, ) == 0x0 01372 400 NtQueryValueKey (192, (192, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (192, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\13\0\0\0"}, 16, ) }, 16, ) == 0x0 01373 400 NtOpenKey (0x2000000, {24, 192, 0x40, 0, 0, (0x2000000, {24, 192, 0x40, 0, 0, "Catalog_Entries"}, ... 196, ) }, ... 196, ) == 0x0 01374 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000001"}, ... 200, ) }, ... 200, ) == 0x0 01375 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01376 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01377 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\351\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0T\0C\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0b\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0b\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0c\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\02\0c\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0e\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\351\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0T\0C\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0b\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0b\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0c\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\02\0c\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0e\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0e\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\351\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0T\0C\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0b\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0b\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0c\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\02\0c\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0d\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0e\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01378 400 NtClose (200, ... ) == 0x0 01379 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000002"}, ... 200, ) }, ... 200, ) == 0x0 01380 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01381 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01382 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\352\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0U\0D\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0g\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0g\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0h\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\03\0h\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0j\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\352\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0U\0D\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0g\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0g\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0h\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\03\0h\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0j\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0j\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\352\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0U\0D\0P\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0g\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0g\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0h\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\03\0h\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0i\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0j\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01383 400 NtClose (200, ... ) == 0x0 01384 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000003"}, ... 200, ) }, ... 200, ) == 0x0 01385 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01386 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01387 400 NtAllocateVirtualMemory (-1, 1376256, 0, 4096, 4096, 4, ... 1376256, 4096, ) == 0x0 01388 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\14\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\353\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\3\0\0\0\0\0\0\0\377\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0R\0A\0W\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0m\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0m\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0n\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\04\0n\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0p\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\14\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\353\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\3\0\0\0\0\0\0\0\377\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0R\0A\0W\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0m\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0m\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0n\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\04\0n\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0p\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0p\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\6\2\0\0\0\0\0\0\0\0\0\0\0\0\0\14\0\0\0\240\32\17\347\213\253\317\21\214\243\0\200_H\241\222\353\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\3\0\0\0\0\0\0\0\377\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0T\0c\0p\0i\0p\0 \0[\0R\0A\0W\0/\0I\0P\0]\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\3\0\0m\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0m\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0n\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\04\0n\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0o\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0p\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01389 400 NtClose (200, ... ) == 0x0 01390 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000004"}, ... 200, ) }, ... 200, ) == 0x0 01391 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01392 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01393 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11&\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\354\3\0\0\1\0\0\0\310\371\252\1\26\0\30\0\10<_u\0\0\0\0|\370\252\1\27\207`u\0\0\0\0\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0R\0S\0V\0P\0 \0U\0D\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\30\371\252\1\17.\365w\13\30\365w\1\0\0\0\0\374\252\1\4\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\17.\365w\0\0\0\0\250\371\252\1 \22\365wO\22\365wT\22\365w\0\0\0\0\204\3\0\0r\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0r\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0s\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\05\0s\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0u\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11&\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\354\3\0\0\1\0\0\0\310\371\252\1\26\0\30\0\10<_u\0\0\0\0|\370\252\1\27\207`u\0\0\0\0\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0R\0S\0V\0P\0 \0U\0D\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\30\371\252\1\17.\365w\13\30\365w\1\0\0\0\0\374\252\1\4\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\17.\365w\0\0\0\0\250\371\252\1 \22\365wO\22\365wT\22\365w\0\0\0\0\204\3\0\0r\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0r\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0s\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\05\0s\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0u\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0u\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11&\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\354\3\0\0\1\0\0\0\310\371\252\1\26\0\30\0\10<_u\0\0\0\0|\370\252\1\27\207`u\0\0\0\0\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\2\0\0\0\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\273\377\0\0\0\0\0\0R\0S\0V\0P\0 \0U\0D\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\30\371\252\1\17.\365w\13\30\365w\1\0\0\0\0\374\252\1\4\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\17.\365w\0\0\0\0\250\371\252\1 \22\365wO\22\365wT\22\365w\0\0\0\0\204\3\0\0r\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0r\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0s\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\05\0s\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0t\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0u\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01394 400 NtClose (200, ... ) == 0x0 01395 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000005"}, ... 200, ) }, ... 200, ) == 0x0 01396 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01397 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01398 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f \2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\355\3\0\0\1\0\0\0\17.\365w\13\30\365w\0\0\0\0\4+Y\1\2\0\0\0\1\0\0\0\17.\365w\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0R\0S\0V\0P\0 \0T\0C\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\0\0\0\0\362_du\3`du\240\1\10\0\250\5N\1 \0\0\0\0\0\0\0\240\1\10\0\310\5N\1H\344\301\0\0\0\0\0\0\0\0\0\0\0\245\0\0\0\10\0@\5N\1\0\0\0\0\204\3\0\0w\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0w\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0x\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\06\0x\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0z\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f \2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\355\3\0\0\1\0\0\0\17.\365w\13\30\365w\0\0\0\0\4+Y\1\2\0\0\0\1\0\0\0\17.\365w\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0R\0S\0V\0P\0 \0T\0C\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\0\0\0\0\362_du\3`du\240\1\10\0\250\5N\1 \0\0\0\0\0\0\0\240\1\10\0\310\5N\1H\344\301\0\0\0\0\0\0\0\0\0\0\0\245\0\0\0\10\0@\5N\1\0\0\0\0\204\3\0\0w\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0w\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0x\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\06\0x\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0z\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0z\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\rsvpsp.dll\0\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0f \2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\0\340\251`\235z3\320\21\275\210\0\0\300\202\346\232\355\3\0\0\1\0\0\0\17.\365w\13\30\365w\0\0\0\0\4+Y\1\2\0\0\0\1\0\0\0\17.\365w\6\0\0\0\2\0\0\0\20\0\0\0\20\0\0\0\1\0\0\0\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0R\0S\0V\0P\0 \0T\0C\0P\0 \0S\0e\0r\0v\0i\0c\0e\0 \0P\0r\0o\0v\0i\0d\0e\0r\0\0\0\0\0\0\0\362_du\3`du\240\1\10\0\250\5N\1 \0\0\0\0\0\0\0\240\1\10\0\310\5N\1H\344\301\0\0\0\0\0\0\0\0\0\0\0\245\0\0\0\10\0@\5N\1\0\0\0\0\204\3\0\0w\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0w\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0x\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\06\0x\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0y\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0z\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01399 400 NtClose (200, ... ) == 0x0 01400 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000006"}, ... 200, ) }, ... 200, ) == 0x0 01401 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01402 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01403 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\356\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0|\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0|\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0}\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\07\0}\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\177\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\356\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0|\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0|\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0}\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\07\0}\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\177\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\177\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\356\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0|\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0|\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0}\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\07\0}\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0~\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\177\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01404 400 NtClose (200, ... ) == 0x0 01405 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000007"}, ... 200, ) }, ... 200, ) == 0x0 01406 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01407 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01408 400 NtAllocateVirtualMemory (-1, 1380352, 0, 4096, 4096, 4, ... 1380352, 4096, ) == 0x0 01409 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\357\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\202\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\202\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\203\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\08\0\203\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\205\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\357\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\202\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\202\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\203\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\08\0\203\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\205\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\205\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\357\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\04\0F\0E\05\07\0D\07\0B\0-\00\03\0A\05\0-\04\08\0B\02\0-\08\0\0\0\0\0\204\3\0\0\202\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\202\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\203\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\08\0\203\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\204\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\205\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01410 400 NtClose (200, ... ) == 0x0 01411 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000008"}, ... 200, ) }, ... 200, ) == 0x0 01412 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01413 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01414 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\360\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\207\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\207\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\210\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\09\0\210\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\212\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\360\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\207\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\207\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\210\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\09\0\210\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\212\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\212\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\360\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\207\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\207\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\210\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\00\09\0\210\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\211\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\212\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01415 400 NtClose (200, ... ) == 0x0 01416 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000009"}, ... 200, ) }, ... 200, ) == 0x0 01417 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01418 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01419 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\361\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\214\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\214\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\215\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\00\0\215\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\217\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\361\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\214\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\214\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\215\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\00\0\215\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\217\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\217\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\361\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0A\0B\0E\07\0E\00\06\0F\0-\06\02\00\0F\0-\04\0E\0A\0A\0-\0A\0\0\0\0\0\204\3\0\0\214\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\214\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\215\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\00\0\215\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\216\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\217\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01420 400 NtClose (200, ... ) == 0x0 01421 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000010"}, ... 200, ) }, ... 200, ) == 0x0 01422 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01423 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01424 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\362\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\221\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\221\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\222\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\01\0\222\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\224\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\362\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\221\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\221\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\222\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\01\0\222\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\224\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) \0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\224\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0 (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\16\0\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\362\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\5\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\221\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\221\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\222\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0H\0\0\0\31\0\2\0\0\0\0\0\30\0\0\0\304\0\0\0\260\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\32\0\0\361\24\0\0\0\0\00\00\00\00\00\00\00\00\00\00\01\01\0\222\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\310\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0t\0e\0m\0\24\0\2\0\0\0\220\0\0\0\223\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\1\0\1\0\5\0\0\200\0\0\0\0\224\5\0\0\214\1\0\0\220\1\0\0\200\0\0\0\0\0\1\0\0\0\0\0@\0\0\0\310\0\0\0\0\0\0\0"\0\12\2\0\354\375\177\0\0\0\0P\0a\0c\0k\0e\0d\0C\0a\0t\0a\0l\0o\0g\0I\0"}, 900, ) }, 900, ) == 0x0 01425 400 NtClose (200, ... ) == 0x0 01426 400 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "000000000011"}, ... 200, ) }, ... 200, ) == 0x0 01427 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01428 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01429 400 NtQueryValueKey (200, (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\363\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\226\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\226\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\227\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\304\0\0\0\227\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\230\5\0\0\214\1\0\0\220\1\0\0\305\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\230\5\0\0\214\1\0\0\220\1\0\0\305\0\0\0\1\0\1\0\2\1\0\0\0\0\0\0\231\5\0\0\214\1\0\0\220\1\0\0\25\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0\3\0\37\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\231\5\0\0\214\1\0\0\220\1\0\0\25\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\304\0\0\0\232\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0T\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0\270\0\0\0\314\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0$\0&\0\320\360\24\0\0\0\0\0N\0a\0m\0e\0S\0p\0a\0c\0e\0_\0C\0a\0t\0a\0l\0o\0g\05\0"}, 900, ) , Partial, 900, ... TitleIdx=0, Type=3, Data= (200, "PackedCatalogItem", Partial, 900, ... TitleIdx=0, Type=3, Data="%SystemRoot%\system32\mswsock.dll\0gram\FSLSP.DLL\0\00\0\0\0\10\0\2\0\10\0\4\1\10\0h\220\354\28\220\354\2\2\0\12\0\4\1\12\00\00\0\0\0\10\0\2\0\14\0\4\1\10\0\210\220\354\2X\220\354\2\2\0\16\0\4\1\12\00\00\0\0\0\10\0\2\0\20\0\4\1\10\0\250\220\354\2x\220\354\2\2\0\22\0\4\1\12\00\00\0\0\0\10\0\2\0\24\0\4\1\10\0\310\220\354\2\230\220\354\2\2\0\26\0\4\1\12\00\00\0\0\0\10\0\2\0\30\0\4\1\10\0\0\0\0\0\270\220\354\2\2\0\32\0\4\1\10\0H\0K\0R\0\0\0\3\0\34\0\4\1\10\0\360\222\354\2\0\0\0\0\0\221\354\2\16\0\0\0<\0\37\0\4\0\10\0X\3\10\0X\3\10\0\4\0\2\0\11\2\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\30_\215s\302\317\21\225\310\0\200_H\241\222\363\3\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\21\0\0\0\24\0\0\0\24\0\0\0\2\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\372\0\0\0\0\0\0M\0S\0A\0F\0D\0 \0N\0e\0t\0B\0I\0O\0S\0 \0[\0\\0D\0e\0v\0i\0c\0e\0\\0N\0e\0t\0B\0T\0_\0T\0c\0p\0i\0p\0_\0{\0D\01\09\0D\0F\08\08\02\0-\0A\09\0C\0B\0-\04\01\04\04\0-\08\0\0\0\0\0\204\3\0\0\226\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\310\0\0\0\226\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\227\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\304\0\0\0\227\5\0\0\214\1\0\0\220\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\230\5\0\0\214\1\0\0\220\1\0\0\305\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\230\5\0\0\214\1\0\0\220\1\0\0\305\0\0\0\1\0\1\0\2\1\0\0\0\0\0\0\231\5\0\0\214\1\0\0\220\1\0\0\25\0\0\0\0\0\1\0\0\0\0\0\24\0\0\0\3\0\37\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\231\5\0\0\214\1\0\0\220\1\0\0\25\0\0\0\1\0\1\0\0\0\0\0\10\0\0\0\0\0\0\0\304\0\0\0\232\5\0\0\214\1\0\0\220\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0T\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0\270\0\0\0\314\361\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0$\0&\0\320\360\24\0\0\0\0\0N\0a\0m\0e\0S\0p\0a\0c\0e\0_\0C\0a\0t\0a\0l\0o\0g\05\0"}, 900, ) }, 900, ) == 0x0 01430 400 NtClose (200, ... ) == 0x0 01431 400 NtClose (196, ... ) == 0x0 01432 400 NtWaitForSingleObject (188, 0, {0, 0}, ... ) == 0x102 01433 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 196, ) == 0x0 01434 400 NtOpenKey (0x2000000, {24, 184, 0x40, 0, 0, (0x2000000, {24, 184, 0x40, 0, 0, "NameSpace_Catalog5"}, ... 200, ) }, ... 200, ) == 0x0 01435 400 NtQueryValueKey (200, (200, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (200, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) }, 16, ) == 0x0 01436 400 NtNotifyChangeKey (200, 196, 0, 0, 2011390432, 1, 0, 0, 0, 1, ... ) == 0x103 01437 400 NtQueryValueKey (200, (200, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (200, "Serial_Access_Num", Partial, 144, ... TitleIdx=0, Type=4, Data="\4\0\0\0"}, 16, ) }, 16, ) == 0x0 01438 400 NtOpenKey (0x2000000, {24, 200, 0x40, 0, 0, (0x2000000, {24, 200, 0x40, 0, 0, "00000004"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01439 400 NtQueryValueKey (200, (200, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (200, "Num_Catalog_Entries", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) }, 16, ) == 0x0 01440 400 NtOpenKey (0x2000000, {24, 200, 0x40, 0, 0, (0x2000000, {24, 200, 0x40, 0, 0, "Catalog_Entries"}, ... 204, ) }, ... 204, ) == 0x0 01441 400 NtAllocateVirtualMemory (-1, 1384448, 0, 4096, 4096, 4, ... 1384448, 4096, ) == 0x0 01442 400 NtOpenKey (0x20019, {24, 204, 0x40, 0, 0, (0x20019, {24, 204, 0x40, 0, 0, "000000000001"}, ... 208, ) }, ... 208, ) == 0x0 01443 400 NtQueryValueKey (208, (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01444 400 NtQueryValueKey (208, (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01445 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 01446 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 01447 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 01448 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="T\0c\0p\0i\0p\0\0\0"}, 24, ) }, 24, ) == 0x0 01449 400 NtQueryValueKey (208, (208, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="@\235\5"\236~\317\21\256Z\0\252\0\247\21+"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (208, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="@\235\5"\236~\317\21\256Z\0\252\0\247\21+"}, 28, ) \236~\317\21\256Z\0\252\0\247\21+"}, 28, ) == 0x0 01450 400 NtQueryValueKey (208, (208, "AddressFamily", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01451 400 NtQueryValueKey (208, (208, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\14\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\14\0\0\0"}, 16, ) }, 16, ) == 0x0 01452 400 NtQueryValueKey (208, (208, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01453 400 NtQueryValueKey (208, (208, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01454 400 NtQueryValueKey (208, (208, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01455 400 NtClose (208, ... ) == 0x0 01456 400 NtOpenKey (0x20019, {24, 204, 0x40, 0, 0, (0x20019, {24, 204, 0x40, 0, 0, "000000000002"}, ... 208, ) }, ... 208, ) == 0x0 01457 400 NtQueryValueKey (208, (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) }, 78, ) == 0x0 01458 400 NtQueryValueKey (208, (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0w\0i\0n\0r\0n\0r\0.\0d\0l\0l\0\0\0"}, 78, ) }, 78, ) == 0x0 01459 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 01460 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 01461 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 01462 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0T\0D\0S\0\0\0"}, 22, ) }, 22, ) == 0x0 01463 400 NtQueryValueKey (208, (208, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="\3567&;\200\345\317\21\245U\0\300O\330\324\254"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (208, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data="\3567&;\200\345\317\21\245U\0\300O\330\324\254"}, 28, ) }, 28, ) == 0x0 01464 400 NtQueryValueKey (208, (208, "AddressFamily", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01465 400 NtQueryValueKey (208, (208, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 01466 400 NtQueryValueKey (208, (208, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01467 400 NtQueryValueKey (208, (208, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01468 400 NtQueryValueKey (208, (208, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01469 400 NtClose (208, ... ) == 0x0 01470 400 NtOpenKey (0x20019, {24, 204, 0x40, 0, 0, (0x20019, {24, 204, 0x40, 0, 0, "000000000003"}, ... 208, ) }, ... 208, ) == 0x0 01471 400 NtQueryValueKey (208, (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01472 400 NtQueryValueKey (208, (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "LibraryPath", Partial, 144, ... TitleIdx=0, Type=1, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0m\0s\0w\0s\0o\0c\0k\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 01473 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 01474 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 01475 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 01476 400 NtQueryValueKey (208, (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (208, "DisplayString", Partial, 144, ... TitleIdx=0, Type=1, Data="N\0e\0t\0w\0o\0r\0k\0 \0L\0o\0c\0a\0t\0i\0o\0n\0 \0A\0w\0a\0r\0e\0n\0e\0s\0s\0 \0(\0N\0L\0A\0)\0 \0N\0a\0m\0e\0s\0p\0a\0c\0e\0\0\0"}, 98, ) }, 98, ) == 0x0 01477 400 NtQueryValueKey (208, (208, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data=":$Bf\250;\246J\272\245.\13\327\37\335\203"}, 28, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (208, "ProviderId", Partial, 144, ... TitleIdx=0, Type=3, Data=":$Bf\250;\246J\272\245.\13\327\37\335\203"}, 28, ) }, 28, ) == 0x0 01478 400 NtQueryValueKey (208, (208, "AddressFamily", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01479 400 NtQueryValueKey (208, (208, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\17\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "SupportedNameSpace", Partial, 144, ... TitleIdx=0, Type=4, Data="\17\0\0\0"}, 16, ) }, 16, ) == 0x0 01480 400 NtQueryValueKey (208, (208, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01481 400 NtQueryValueKey (208, (208, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "Version", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01482 400 NtQueryValueKey (208, (208, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (208, "StoresServiceClassInfo", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01483 400 NtClose (208, ... ) == 0x0 01484 400 NtClose (204, ... ) == 0x0 01485 400 NtWaitForSingleObject (196, 0, {0, 0}, ... ) == 0x102 01486 400 NtClose (184, ... ) == 0x0 01487 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01488 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01489 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Winsock2\Parameters"}, ... 184, ) }, ... 184, ) == 0x0 01490 400 NtQueryValueKey (184, (184, "Ws2_32NumHandleBuckets", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01491 400 NtClose (184, ... ) == 0x0 01492 400 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 184, ) == 0x0 01493 400 NtClearEvent (156, ... ) == 0x0 01494 400 NtSetEvent (156, ... 0x0, ) == 0x0 01495 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "icmp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01496 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\icmp.dll"}, 1240308, ... ) }, 1240308, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01497 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "icmp.dll"}, 1240308, ... ) }, 1240308, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01498 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\icmp.dll"}, 1240308, ... ) }, 1240308, ... ) == 0x0 01499 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\icmp.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01500 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01501 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01502 400 NtClose (204, ... ) == 0x0 01503 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x74290000), 0x0, 16384, ) == 0x0 01504 400 NtClose (208, ... ) == 0x0 01505 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "iphlpapi.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01506 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\iphlpapi.dll"}, 1240772, ... ) }, 1240772, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01507 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "iphlpapi.dll"}, 1240772, ... ) }, 1240772, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01508 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\iphlpapi.dll"}, 1240772, ... ) }, 1240772, ... ) == 0x0 01509 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\iphlpapi.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01510 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01511 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01512 400 NtClose (208, ... ) == 0x0 01513 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76d60000), 0x0, 86016, ) == 0x0 01514 400 NtClose (204, ... ) == 0x0 01515 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "netman.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01516 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\netman.dll"}, 1239968, ... ) }, 1239968, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01517 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "netman.dll"}, 1239968, ... ) }, 1239968, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01518 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\netman.dll"}, 1239968, ... ) }, 1239968, ... ) == 0x0 01519 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\netman.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01520 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01521 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01522 400 NtClose (204, ... ) == 0x0 01523 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76de0000), 0x0, 155648, ) == 0x0 01524 400 NtClose (208, ... ) == 0x0 01525 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MPRAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01526 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\MPRAPI.dll"}, 1239164, ... ) }, 1239164, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01527 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "MPRAPI.dll"}, 1239164, ... ) }, 1239164, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01528 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\MPRAPI.dll"}, 1239164, ... ) }, 1239164, ... ) == 0x0 01529 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\MPRAPI.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01530 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01531 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01532 400 NtClose (208, ... ) == 0x0 01533 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76d40000), 0x0, 90112, ) == 0x0 01534 400 NtClose (204, ... ) == 0x0 01535 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ACTIVEDS.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01536 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ACTIVEDS.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01537 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "ACTIVEDS.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01538 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ACTIVEDS.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01539 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ACTIVEDS.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01540 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01541 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01542 400 NtClose (204, ... ) == 0x0 01543 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76e40000), 0x0, 192512, ) == 0x0 01544 400 NtClose (208, ... ) == 0x0 01545 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "adsldpc.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01546 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\adsldpc.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01547 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "adsldpc.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01548 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\adsldpc.dll"}, 1237556, ... ) }, 1237556, ... ) == 0x0 01549 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\adsldpc.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01550 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01551 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01552 400 NtClose (208, ... ) == 0x0 01553 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76e10000), 0x0, 147456, ) == 0x0 01554 400 NtClose (204, ... ) == 0x0 01555 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "NETAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01556 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\NETAPI32.dll"}, 1236752, ... ) }, 1236752, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01557 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "NETAPI32.dll"}, 1236752, ... ) }, 1236752, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01558 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETAPI32.dll"}, 1236752, ... ) }, 1236752, ... ) == 0x0 01559 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\NETAPI32.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01560 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01561 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01562 400 NtClose (204, ... ) == 0x0 01563 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71c20000), 0x0, 323584, ) == 0x0 01564 400 NtClose (208, ... ) == 0x0 01565 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WLDAP32.dll"}, ... 208, ) }, ... 208, ) == 0x0 01566 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f60000), 0x0, 180224, ) == 0x0 01567 400 NtClose (208, ... ) == 0x0 01568 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ATL.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01569 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ATL.DLL"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01570 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "ATL.DLL"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01571 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ATL.DLL"}, 1237556, ... ) }, 1237556, ... ) == 0x0 01572 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ATL.DLL"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01573 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01574 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01575 400 NtClose (208, ... ) == 0x0 01576 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76b20000), 0x0, 86016, ) == 0x0 01577 400 NtClose (204, ... ) == 0x0 01578 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "rtutils.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01579 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\rtutils.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01580 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "rtutils.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01581 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rtutils.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01582 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rtutils.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01583 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01584 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01585 400 NtClose (204, ... ) == 0x0 01586 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76e80000), 0x0, 53248, ) == 0x0 01587 400 NtClose (208, ... ) == 0x0 01588 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SAMLIB.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01589 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\SAMLIB.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01590 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "SAMLIB.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01591 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SAMLIB.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01592 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SAMLIB.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01593 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01594 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01595 400 NtClose (208, ... ) == 0x0 01596 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71bf0000), 0x0, 69632, ) == 0x0 01597 400 NtClose (204, ... ) == 0x0 01598 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01599 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\SETUPAPI.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01600 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "SETUPAPI.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01601 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SETUPAPI.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01602 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\SETUPAPI.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01603 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01604 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01605 400 NtClose (204, ... ) == 0x0 01606 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76670000), 0x0, 933888, ) == 0x0 01607 400 NtClose (208, ... ) == 0x0 01608 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RASAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01609 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\RASAPI32.dll"}, 1239164, ... ) }, 1239164, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01610 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "RASAPI32.dll"}, 1239164, ... ) }, 1239164, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01611 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\RASAPI32.dll"}, 1239164, ... ) }, 1239164, ... ) == 0x0 01612 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\RASAPI32.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01613 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01614 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01615 400 NtClose (208, ... ) == 0x0 01616 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76ee0000), 0x0, 225280, ) == 0x0 01617 400 NtClose (204, ... ) == 0x0 01618 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "rasman.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01619 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\rasman.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01620 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "rasman.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01621 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rasman.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01622 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\rasman.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01623 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01624 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01625 400 NtClose (204, ... ) == 0x0 01626 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76e90000), 0x0, 69632, ) == 0x0 01627 400 NtClose (208, ... ) == 0x0 01628 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "TAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01629 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\TAPI32.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01630 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "TAPI32.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01631 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01632 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01633 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01634 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01635 400 NtClose (208, ... ) == 0x0 01636 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76eb0000), 0x0, 172032, ) == 0x0 01637 400 NtClose (204, ... ) == 0x0 01638 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WINMM.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01639 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WINMM.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01640 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WINMM.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01641 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINMM.dll"}, 1237556, ... ) }, 1237556, ... ) == 0x0 01642 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINMM.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01643 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01644 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01645 400 NtClose (204, ... ) == 0x0 01646 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76b40000), 0x0, 180224, ) == 0x0 01647 400 NtClose (208, ... ) == 0x0 01648 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WZCSvc.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01649 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WZCSvc.DLL"}, 1239164, ... ) }, 1239164, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01650 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WZCSvc.DLL"}, 1239164, ... ) }, 1239164, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01651 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WZCSvc.DLL"}, 1239164, ... ) }, 1239164, ... ) == 0x0 01652 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WZCSvc.DLL"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01653 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01654 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01655 400 NtClose (208, ... ) == 0x0 01656 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76da0000), 0x0, 196608, ) == 0x0 01657 400 NtClose (204, ... ) == 0x0 01658 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WMI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01659 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WMI.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01660 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WMI.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01661 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WMI.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01662 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WMI.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01663 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01664 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01665 400 NtClose (204, ... ) == 0x0 01666 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76d30000), 0x0, 16384, ) == 0x0 01667 400 NtClose (208, ... ) == 0x0 01668 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "DHCPCSVC.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01669 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\DHCPCSVC.DLL"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01670 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "DHCPCSVC.DLL"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01671 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\DHCPCSVC.DLL"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01672 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\DHCPCSVC.DLL"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01673 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01674 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01675 400 NtClose (208, ... ) == 0x0 01676 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76d80000), 0x0, 106496, ) == 0x0 01677 400 NtClose (204, ... ) == 0x0 01678 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "DNSAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01679 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\DNSAPI.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01680 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "DNSAPI.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01681 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\DNSAPI.dll"}, 1237556, ... ) }, 1237556, ... ) == 0x0 01682 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\DNSAPI.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01683 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01684 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01685 400 NtClose (204, ... ) == 0x0 01686 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f20000), 0x0, 151552, ) == 0x0 01687 400 NtClose (208, ... ) == 0x0 01688 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WTSAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01689 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WTSAPI32.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01690 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WTSAPI32.dll"}, 1238360, ... ) }, 1238360, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01691 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WTSAPI32.dll"}, 1238360, ... ) }, 1238360, ... ) == 0x0 01692 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WTSAPI32.dll"}, 5, 96, ... 208, {status=0x0, info=1}, ) }, 5, 96, ... 208, {status=0x0, info=1}, ) == 0x0 01693 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 208, ... 204, ) == 0x0 01694 400 NtQuerySection (204, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01695 400 NtClose (208, ... ) == 0x0 01696 400 NtMapViewOfSection (204, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76f50000), 0x0, 32768, ) == 0x0 01697 400 NtClose (204, ... ) == 0x0 01698 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WINSTA.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01699 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WINSTA.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01700 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WINSTA.dll"}, 1237556, ... ) }, 1237556, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01701 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINSTA.dll"}, 1237556, ... ) }, 1237556, ... ) == 0x0 01702 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WINSTA.dll"}, 5, 96, ... 204, {status=0x0, info=1}, ) }, 5, 96, ... 204, {status=0x0, info=1}, ) == 0x0 01703 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 204, ... 208, ) == 0x0 01704 400 NtQuerySection (208, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01705 400 NtClose (204, ... ) == 0x0 01706 400 NtMapViewOfSection (208, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76360000), 0x0, 61440, ) == 0x0 01707 400 NtClose (208, ... ) == 0x0 01708 400 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 208, ) == 0x0 01709 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\LDAP"}, ... 204, ) }, ... 204, ) == 0x0 01710 400 NtQueryValueKey (204, (204, "LdapClientIntegrity", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (204, "LdapClientIntegrity", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01711 400 NtClose (204, ... ) == 0x0 01712 400 NtAllocateVirtualMemory (-1, 1388544, 0, 4096, 4096, 4, ... 1388544, 4096, ) == 0x0 01713 400 NtQueryDefaultLocale (1, 1241416, ... ) == 0x0 01714 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01715 400 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 27983872, 262144, ) == 0x0 01716 400 NtAllocateVirtualMemory (-1, 27983872, 0, 4096, 4096, 4, ... 27983872, 4096, ) == 0x0 01717 400 NtAllocateVirtualMemory (-1, 27987968, 0, 8192, 4096, 4, ... 27987968, 8192, ) == 0x0 01718 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01719 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01720 400 NtQueryDefaultLocale (1, 1241376, ... ) == 0x0 01721 400 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 01722 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\Setup"}, ... 204, ) }, ... 204, ) == 0x0 01723 400 NtQueryValueKey (204, (204, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (204, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01724 400 NtClose (204, ... ) == 0x0 01725 400 NtUserGetProcessWindowStation (... ) == 0x2c 01726 400 NtUserGetObjectInformation (44, 1, 1241048, 12, 1241060, ... ) == 0x1 01727 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Control\Session Manager\WPA\PnP"}, ... 204, ) }, ... 204, ) == 0x0 01728 400 NtQueryValueKey (204, (204, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\345\252r\363"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (204, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\345\252r\363"}, 16, ) }, 16, ) == 0x0 01729 400 NtClose (204, ... ) == 0x0 01730 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 204, ) }, ... 204, ) == 0x0 01731 400 NtQueryValueKey (204, (204, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 01732 400 NtQueryValueKey (204, (204, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 01733 400 NtClose (204, ... ) == 0x0 01734 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 204, ) }, ... 204, ) == 0x0 01735 400 NtQueryValueKey (204, (204, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 01736 400 NtQueryValueKey (204, (204, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 01737 400 NtClose (204, ... ) == 0x0 01738 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 204, ) }, ... 204, ) == 0x0 01739 400 NtQueryValueKey (204, (204, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01740 400 NtQueryValueKey (204, (204, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01741 400 NtClose (204, ... ) == 0x0 01742 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 204, ) }, ... 204, ) == 0x0 01743 400 NtQueryValueKey (204, (204, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01744 400 NtQueryValueKey (204, (204, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (204, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 01745 400 NtClose (204, ... ) == 0x0 01746 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 204, ) }, ... 204, ) == 0x0 01747 400 NtQueryValueKey (204, (204, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (204, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 01748 400 NtQueryValueKey (204, (204, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (204, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 01749 400 NtClose (204, ... ) == 0x0 01750 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 204, ) }, ... 204, ) == 0x0 01751 400 NtQueryValueKey (204, (204, "DevicePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0\0\0"}, 46, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (204, "DevicePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0\0\0"}, 46, ) }, 46, ) == 0x0 01752 400 NtClose (204, ... ) == 0x0 01753 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 204, ) == 0x0 01754 400 NtCreateMutant (0x1f0001, 0x0, 0, ... 212, ) == 0x0 01755 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 216, ) == 0x0 01756 400 NtCreateMutant (0x1f0001, 0x0, 0, ... 220, ) == 0x0 01757 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 224, ) == 0x0 01758 400 NtCreateMutant (0x1f0001, 0x0, 0, ... 228, ) == 0x0 01759 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 232, ) }, ... 232, ) == 0x0 01760 400 NtQueryValueKey (232, (232, "LogLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01761 400 NtQueryValueKey (232, (232, "LogPath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01762 400 NtOpenKey (0x1, {24, 232, 0x40, 0, 0, (0x1, {24, 232, 0x40, 0, 0, "AppLogLevels"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01763 400 NtClose (232, ... ) == 0x0 01764 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 1240968, ... ) }, 1240968, ... ) == 0x0 01765 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName"}, ... 232, ) }, ... 232, ) == 0x0 01766 400 NtQueryValueKey (232, (232, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (232, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (232, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 01767 400 NtClose (232, ... ) == 0x0 01768 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 232, ) }, ... 232, ) == 0x0 01769 400 NtQueryValueKey (232, (232, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 52, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (232, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 52, ) , Data= (232, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 52, ) }, 52, ) == 0x0 01770 400 NtClose (232, ... ) == 0x0 01771 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\System\DNSclient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01772 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 232, ) }, ... 232, ) == 0x0 01773 400 NtQueryValueKey (232, (232, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (232, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Data= (232, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) }, 34, ) == 0x0 01774 400 NtClose (232, ... ) == 0x0 01775 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 232, ) == 0x0 01776 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 236, ) == 0x0 01777 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 240, ) == 0x0 01778 400 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\DRIVERS32"}, ... 244, ) }, ... 244, ) == 0x0 01779 400 NtQueryValueKey (244, (244, "wave", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01780 400 NtQueryValueKey (244, (244, "wave1", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01781 400 NtQueryValueKey (244, (244, "wave2", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01782 400 NtQueryValueKey (244, (244, "wave3", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01783 400 NtQueryValueKey (244, (244, "wave4", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01784 400 NtQueryValueKey (244, (244, "wave5", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01785 400 NtQueryValueKey (244, (244, "wave6", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01786 400 NtQueryValueKey (244, (244, "wave7", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01787 400 NtQueryValueKey (244, (244, "wave8", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01788 400 NtQueryValueKey (244, (244, "wave9", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01789 400 NtQueryValueKey (244, (244, "midi", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01790 400 NtQueryValueKey (244, (244, "midi1", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01791 400 NtQueryValueKey (244, (244, "midi2", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01792 400 NtQueryValueKey (244, (244, "midi3", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01793 400 NtQueryValueKey (244, (244, "midi4", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01794 400 NtQueryValueKey (244, (244, "midi5", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01795 400 NtQueryValueKey (244, (244, "midi6", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01796 400 NtQueryValueKey (244, (244, "midi7", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01797 400 NtQueryValueKey (244, (244, "midi8", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01798 400 NtQueryValueKey (244, (244, "midi9", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01799 400 NtQueryTimerResolution (... 156250, 10000, 156250, ) == 0x0 01800 400 NtQueryValueKey (244, (244, "aux", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01801 400 NtQueryValueKey (244, (244, "aux1", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01802 400 NtQueryValueKey (244, (244, "aux2", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01803 400 NtQueryValueKey (244, (244, "aux3", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01804 400 NtQueryValueKey (244, (244, "aux4", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01805 400 NtQueryValueKey (244, (244, "aux5", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01806 400 NtQueryValueKey (244, (244, "aux6", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01807 400 NtQueryValueKey (244, (244, "aux7", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01808 400 NtQueryValueKey (244, (244, "aux8", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01809 400 NtQueryValueKey (244, (244, "aux9", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01810 400 NtUserRegisterWindowMessage ( ("MSJSTICK_VJOYD_MSGSTR", ... ) , ... ) == 0xc07c 01811 400 NtOpenKey (0xf003f, {24, 28, 0x40, 0, 0, (0xf003f, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm"}, ... 248, ) }, ... 248, ) == 0x0 01812 400 NtQueryValueKey (248, (248, "wheel", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (248, "wheel", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01813 400 NtClose (248, ... ) == 0x0 01814 400 NtCreateEvent (0x1f0003, {24, 76, 0x80, 0, 0, (0x1f0003, {24, 76, 0x80, 0, 0, "DINPUTWINMM"}, 0, 0, ... ) }, 0, 0, ... ) == STATUS_ACCESS_DENIED 01815 400 NtQueryValueKey (244, (244, "mixer", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01816 400 NtQueryValueKey (244, (244, "mixer1", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01817 400 NtQueryValueKey (244, (244, "mixer2", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01818 400 NtQueryValueKey (244, (244, "mixer3", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01819 400 NtQueryValueKey (244, (244, "mixer4", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01820 400 NtQueryValueKey (244, (244, "mixer5", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01821 400 NtQueryValueKey (244, (244, "mixer6", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01822 400 NtQueryValueKey (244, (244, "mixer7", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01823 400 NtQueryValueKey (244, (244, "mixer8", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01824 400 NtQueryValueKey (244, (244, "mixer9", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01825 400 NtQueryDefaultUILanguage (1239936, ... 01826 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01827 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482032, ) == 0x0 01828 400 NtQueryInformationToken (-2147482032, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01829 400 NtClose (-2147482032, ... ) == 0x0 01830 400 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 01831 400 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01832 400 NtOpenKey (0x80000000, {24, -2147482032, 0x640, 0, 0, (0x80000000, {24, -2147482032, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482044, ) }, ... -2147482044, ) == 0x0 01833 400 NtQueryValueKey (-2147482044, (-2147482044, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01834 400 NtClose (-2147482044, ... ) == 0x0 01835 400 NtClose (-2147482032, ... ) == 0x0 01825 400 NtQueryDefaultUILanguage ... ) == 0x0 01836 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01837 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll"}, 1, 96, ... 248, {status=0x0, info=1}, ) }, 1, 96, ... 248, {status=0x0, info=1}, ) == 0x0 01838 400 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 248, ... 252, ) == 0x0 01839 400 NtMapViewOfSection (252, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x1b10000), 0x0, 163840, ) == 0x0 01840 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01841 400 NtQueryDefaultLocale (1, 1237972, ... ) == 0x0 01842 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\TAPI32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01843 400 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 1238828, 1, 96, 0} (24, {128, 156, new_msg, 0, 1238828, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\370\0\0\0\377\377\377\377\0\0\0\0\360Z\263\1\0\0\0\0\251\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\356\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1512, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\370\0\0\0\377\377\377\377\0\0\0\0\360Z\263\1\0\0\0\0\251\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\356\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 396, 400, 1512, 0} (24, {128, 156, new_msg, 0, 1238828, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\370\0\0\0\377\377\377\377\0\0\0\0\360Z\263\1\0\0\0\0\251\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\356\22\0\0\0\0\0" ... {128, 156, reply, 0, 396, 400, 1512, 0} "\210\347\26\0\33\0\1\0\0\0\0\0\1\352\22\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\370\0\0\0\377\377\377\377\0\0\0\0\360Z\263\1\0\0\0\0\251\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\356\22\0\0\0\0\0" ) ) == 0x0 01844 400 NtClose (248, ... ) == 0x0 01845 400 NtClose (252, ... ) == 0x0 01846 400 NtUnmapViewOfSection (-1, 0x1b10000, ... ) == 0x0 01847 400 NtUnmapViewOfSection (-1, 0x12ee2c, ... ) == STATUS_NOT_MAPPED_VIEW 01848 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01849 400 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01850 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01851 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01852 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1237056, ... ) }, 1237056, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01853 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01854 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01855 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01856 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 1237648, ... ) }, 1237648, ... ) == 0x0 01857 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 252, {status=0x0, info=1}, ) }, 3, 33, ... 252, {status=0x0, info=1}, ) == 0x0 01858 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01859 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Telephony"}, ... 248, ) }, ... 248, ) == 0x0 01860 400 NtQueryValueKey (248, (248, "Tapi32MaxNumRequestRetries", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01861 400 NtQueryValueKey (248, (248, "Tapi32RequestRetryTimeout", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01862 400 NtClose (248, ... ) == 0x0 01863 400 NtCreateMutant (0x1f0001, 0x0, 0, ... 248, ) == 0x0 01864 400 NtCreateMutant (0x1f0001, {24, 76, 0x80, 1391616, 0, (0x1f0001, {24, 76, 0x80, 1391616, 0, "RasPbFile"}, 0, ... ) }, 0, ... ) == STATUS_ACCESS_DENIED 01865 400 NtOpenMutant (0x100000, {24, 76, 0x0, 0, 0, (0x100000, {24, 76, 0x0, 0, 0, "RasPbFile"}, ... 256, ) }, ... 256, ) == 0x0 01866 400 NtCreateEvent (0x1f0003, 0x0, 0, 1, ... 260, ) == 0x0 01867 400 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 264, ) == 0x0 01868 400 NtCreateEvent (0x1f0003, 0x0, 0, 1, ... 268, ) == 0x0 01869 400 NtCreateKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 272, 2, ) }, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, 0, "Class", 0, ... 272, 2, ) , 0, ... 272, 2, ) == 0x0 01870 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\DnsCache\Parameters"}, ... 276, ) }, ... 276, ) == 0x0 01871 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\DnsClient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01872 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\DNS"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01873 400 NtQueryValueKey (276, (276, "QueryAdapterName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01874 400 NtQueryValueKey (272, (272, "DisableAdapterDomainName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01875 400 NtQueryValueKey (276, (276, "UseDomainNameDevolution", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01876 400 NtQueryValueKey (272, (272, "UseDomainNameDevolution", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (272, "UseDomainNameDevolution", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01877 400 NtQueryValueKey (276, (276, "PrioritizeRecordData", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01878 400 NtQueryValueKey (272, (272, "PrioritizeRecordData", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01879 400 NtQueryValueKey (276, (276, "AllowUnqualifiedQuery", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01880 400 NtQueryValueKey (272, (272, "AllowUnqualifiedQuery", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01881 400 NtQueryValueKey (276, (276, "AppendToMultiLabelName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01882 400 NtQueryValueKey (276, (276, "ScreenBadTlds", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01883 400 NtQueryValueKey (276, (276, "ScreenUnreachableServers", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01884 400 NtQueryValueKey (276, (276, "FilterClusterIp", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01885 400 NtQueryValueKey (276, (276, "WaitForNameErrorOnAll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01886 400 NtQueryValueKey (276, (276, "UseEdns", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01887 400 NtQueryValueKey (276, (276, "RegistrationEnabled", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01888 400 NtQueryValueKey (272, (272, "DisableDynamicUpdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01889 400 NtQueryValueKey (276, (276, "RegisterPrimaryName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01890 400 NtQueryValueKey (276, (276, "RegisterAdapterName", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01891 400 NtQueryValueKey (272, (272, "EnableAdapterDomainNameRegistration", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01892 400 NtQueryValueKey (276, (276, "RegisterReverseLookup", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01893 400 NtQueryValueKey (272, (272, "DisableReverseAddressRegistrations", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01894 400 NtQueryValueKey (276, (276, "RegisterWanAdapters", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01895 400 NtQueryValueKey (272, (272, "DisableWanDynamicUpdate", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01896 400 NtQueryValueKey (276, (276, "RegistrationOverwritesInConflict", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01897 400 NtQueryValueKey (272, (272, "DisableReplaceAddressesInConflicts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01898 400 NtQueryValueKey (276, (276, "RegistrationTtl", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01899 400 NtQueryValueKey (272, (272, "DefaultRegistrationTTL", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01900 400 NtQueryValueKey (276, (276, "RegistrationRefreshInterval", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01901 400 NtQueryValueKey (272, (272, "DefaultRegistrationRefreshInterval", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01902 400 NtQueryValueKey (276, (276, "RegistrationMaxAddressCount", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01903 400 NtQueryValueKey (272, (272, "MaxNumberOfAddressesToRegister", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01904 400 NtQueryValueKey (276, (276, "UpdateSecurityLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01905 400 NtQueryValueKey (272, (272, "UpdateSecurityLevel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01906 400 NtQueryValueKey (276, (276, "UpdateZoneExcludeFile", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01907 400 NtQueryValueKey (276, (276, "UpdateTopLevelDomainZones", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01908 400 NtQueryValueKey (276, (276, "DnsTest", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01909 400 NtQueryValueKey (276, (276, "MaxCacheSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01910 400 NtQueryValueKey (276, (276, "MaxCacheTtl", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01911 400 NtQueryValueKey (276, (276, "MaxNegativeCacheTtl", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01912 400 NtQueryValueKey (276, (276, "AdapterTimeoutLimit", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01913 400 NtQueryValueKey (276, (276, "ServerPriorityTimeLimit", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01914 400 NtQueryValueKey (276, (276, "MaxCachedSockets", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01915 400 NtQueryValueKey (276, (276, "UseMulticast", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01916 400 NtQueryValueKey (276, (276, "MulticastOnNameError", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01917 400 NtQueryValueKey (276, (276, "UseDotLocalDomain", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01918 400 NtQueryValueKey (276, (276, "ListenOnMulticast", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01919 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "System\Setup"}, ... 280, ) }, ... 280, ) == 0x0 01920 400 NtQueryValueKey (280, (280, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (280, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01921 400 NtClose (280, ... ) == 0x0 01922 400 NtClose (272, ... ) == 0x0 01923 400 NtClose (276, ... ) == 0x0 01924 400 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 276, ) }, ... 276, ) == 0x0 01925 400 NtQueryValueKey (276, (276, "DnsQueryTimeouts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01926 400 NtQueryValueKey (276, (276, "DnsQuickQueryTimeouts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01927 400 NtQueryValueKey (276, (276, "DnsMulticastQueryTimeouts", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01928 400 NtClose (276, ... ) == 0x0 01929 400 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 1392640, 4096, ) == 0x0 01930 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 276, ) == 0x0 01931 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 272, ) == 0x0 01932 400 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 280, ) == 0x0 01933 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01934 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28377088, 65536, ) == 0x0 01935 400 NtAllocateVirtualMemory (-1, 28377088, 0, 4096, 4096, 4, ... 28377088, 4096, ) == 0x0 01936 400 NtAllocateVirtualMemory (-1, 28381184, 0, 8192, 4096, 4, ... 28381184, 8192, ) == 0x0 01937 400 NtCreateFile (0x20000000, {24, 0, 0x40, 0, 0, (0x20000000, {24, 0, 0x40, 0, 0, "\Device\Tcp"}, 0x0, 128, 3, 3, 0, 0, 0, ... 284, {status=0x0, info=0}, ) }, 0x0, 128, 3, 3, 0, 0, 0, ... 284, {status=0x0, info=0}, ) == 0x0 01938 400 NtCreateFile (0x40000000, {24, 0, 0x40, 0, 0, (0x40000000, {24, 0, 0x40, 0, 0, "\Device\Tcp"}, 0x0, 128, 3, 3, 0, 0, 0, ... 288, {status=0x0, info=0}, ) }, 0x0, 128, 3, 3, 0, 0, 0, ... 288, {status=0x0, info=0}, ) == 0x0 01939 400 NtCreateFile (0x20000000, {24, 0, 0x40, 0, 0, (0x20000000, {24, 0, 0x40, 0, 0, "\Device\Ip"}, 0x0, 128, 3, 3, 0, 0, 0, ... 292, {status=0x0, info=0}, ) }, 0x0, 128, 3, 3, 0, 0, 0, ... 292, {status=0x0, info=0}, ) == 0x0 01940 400 NtCreateFile (0x100003, {24, 0, 0x40, 0, 0, (0x100003, {24, 0, 0x40, 0, 0, "\Device\Ip"}, 0x0, 128, 3, 3, 0, 0, 0, ... 296, {status=0x0, info=0}, ) }, 0x0, 128, 3, 3, 0, 0, 0, ... 296, {status=0x0, info=0}, ) == 0x0 01941 400 NtCreateFile (0x20100080, {24, 0, 0x40, 0, 1241500, (0x20100080, {24, 0, 0x40, 0, 1241500, "\??\Ip"}, 0x0, 128, 3, 1, 64, 0, 0, ... 300, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 64, 0, 0, ... 300, {status=0x0, info=0}, ) == 0x0 01942 400 NtAllocateVirtualMemory (-1, 28389376, 0, 36864, 4096, 4, ... 28389376, 36864, ) == 0x0 01943 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 01944 400 NtDeviceIoControlFile (284, 304, 0x0, 0x0, 0x120003, (284, 304, 0x0, 0x0, 0x120003, "\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 32768, ... {status=0x0, info=56}, "\0\4\0\0\0\0\0\0\1\4\0\0\0\0\0\0\1\3\0\0\0\0\0\0\200\3\0\0\0\0\0\0\0\2\0\0\0\0\0\0\200\2\0\0\0\0\0\0\0\2\0\0\1\0\0\0", ) , 36, 32768, ... {status=0x0, info=56}, (284, 304, 0x0, 0x0, 0x120003, "\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 32768, ... {status=0x0, info=56}, "\0\4\0\0\0\0\0\0\1\4\0\0\0\0\0\0\1\3\0\0\0\0\0\0\200\3\0\0\0\0\0\0\0\2\0\0\0\0\0\0\200\2\0\0\0\0\0\0\0\2\0\0\1\0\0\0", ) , ) == 0x0 01945 400 NtClose (304, ... ) == 0x0 01946 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 01947 400 NtDeviceIoControlFile (284, 304, 0x0, 0x0, 0x120003, (284, 304, 0x0, 0x0, 0x120003, "\0\2\0\0\0\0\0\0\0\2\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 348, ... {status=0x0, info=118}, "\1\0\0\0\30\0\0\0\360\5\0\0\200\226\230\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0a\177\257\327\241\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\241\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\32\0\0\0MS TCP Loopback interface\0", ) , 36, 348, ... {status=0x0, info=118}, (284, 304, 0x0, 0x0, 0x120003, "\0\2\0\0\0\0\0\0\0\2\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 348, ... {status=0x0, info=118}, "\1\0\0\0\30\0\0\0\360\5\0\0\200\226\230\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0a\177\257\327\241\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\241\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\32\0\0\0MS TCP Loopback interface\0", ) , ) == 0x0 01948 400 NtClose (304, ... ) == 0x0 01949 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 01950 400 NtDeviceIoControlFile (284, 304, 0x0, 0x0, 0x120003, (284, 304, 0x0, 0x0, 0x120003, "\0\2\0\0\1\0\0\0\0\2\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 348, ... {status=0x0, info=158}, "\3\0\1\0\6\0\0\0\334\5\0\0\0\312\232;\6\0\0\0\0\14)\371\246\305\0\0\1\0\0\0\5\0\0\0\201\177\257\327\16\277\4\0N\1\0\00\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0?\216\0\0\371\0\0\0.\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0B\0\0\0AMD PCNET Family PCI Ethernet Adapter - Packet Scheduler Miniport\0", ) , 36, 348, ... {status=0x0, info=158}, (284, 304, 0x0, 0x0, 0x120003, "\0\2\0\0\1\0\0\0\0\2\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 348, ... {status=0x0, info=158}, "\3\0\1\0\6\0\0\0\334\5\0\0\0\312\232;\6\0\0\0\0\14)\371\246\305\0\0\1\0\0\0\5\0\0\0\201\177\257\327\16\277\4\0N\1\0\00\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0?\216\0\0\371\0\0\0.\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0B\0\0\0AMD PCNET Family PCI Ethernet Adapter - Packet Scheduler Miniport\0", ) , ) == 0x0 01951 400 NtClose (304, ... ) == 0x0 01952 400 NtCreateFile (0x20000000, {24, 0, 0x40, 0, 0, (0x20000000, {24, 0, 0x40, 0, 0, "\Device\Tcp6"}, 0x0, 128, 3, 3, 0, 0, 0, ... ) }, 0x0, 128, 3, 3, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01953 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 01954 400 NtDeviceIoControlFile (284, 304, 0x0, 0x0, 0x120003, (284, 304, 0x0, 0x0, 0x120003, "\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 32768, ... {status=0x0, info=56}, "\0\4\0\0\0\0\0\0\1\4\0\0\0\0\0\0\1\3\0\0\0\0\0\0\200\3\0\0\0\0\0\0\0\2\0\0\0\0\0\0\200\2\0\0\0\0\0\0\0\2\0\0\1\0\0\0", ) , 36, 32768, ... {status=0x0, info=56}, (284, 304, 0x0, 0x0, 0x120003, "\0\0\0\0\0\0\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 32768, ... {status=0x0, info=56}, "\0\4\0\0\0\0\0\0\1\4\0\0\0\0\0\0\1\3\0\0\0\0\0\0\200\3\0\0\0\0\0\0\0\2\0\0\0\0\0\0\200\2\0\0\0\0\0\0\0\2\0\0\1\0\0\0", ) , ) == 0x0 01955 400 NtClose (304, ... ) == 0x0 01956 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 01957 400 NtDeviceIoControlFile (284, 304, 0x0, 0x0, 0x120003, (284, 304, 0x0, 0x0, 0x120003, "\200\2\0\0\0\0\0\0\0\1\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 4, ... {status=0x0, info=4}, "\200\2\0\0", ) , 36, 4, ... {status=0x0, info=4}, (284, 304, 0x0, 0x0, 0x120003, "\200\2\0\0\0\0\0\0\0\1\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 4, ... {status=0x0, info=4}, "\200\2\0\0", ) , ) == 0x0 01958 400 NtClose (304, ... ) == 0x0 01959 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 01960 400 NtDeviceIoControlFile (284, 304, 0x0, 0x0, 0x120003, (284, 304, 0x0, 0x0, 0x120003, "\200\2\0\0\0\0\0\0\0\2\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 8, ... {status=0x0, info=8}, "\1\0\0\0\3\0\1\0", ) , 36, 8, ... {status=0x0, info=8}, (284, 304, 0x0, 0x0, 0x120003, "\200\2\0\0\0\0\0\0\0\2\0\0\0\1\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 36, 8, ... {status=0x0, info=8}, "\1\0\0\0\3\0\1\0", ) , ) == 0x0 01961 400 NtClose (304, ... ) == 0x0 01962 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01963 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01964 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01965 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01966 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01967 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01968 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01969 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01970 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01971 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01972 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01973 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01974 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01975 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01976 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01977 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01978 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01979 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01980 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01981 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01982 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01983 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01984 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01985 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01986 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01987 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01988 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01989 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01990 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01991 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01992 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01993 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01994 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 01995 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 01996 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 01997 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 01998 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 01999 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02000 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02001 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02002 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02003 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02004 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02005 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02006 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02007 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02008 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02009 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02010 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02011 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02012 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02013 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02014 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02015 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02016 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02017 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02018 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02019 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02020 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02021 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02022 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02023 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02024 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02025 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02026 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02027 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02028 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02029 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02030 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02031 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02032 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02033 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02034 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02035 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02036 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02037 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02038 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02039 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02040 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02041 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02042 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02043 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02044 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02045 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02046 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02047 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02048 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02049 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02050 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02051 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02052 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02053 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02054 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02055 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02056 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02057 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02058 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02059 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02060 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02061 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02062 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02063 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02064 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02065 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02066 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02067 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02068 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02069 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02070 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02071 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02072 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02073 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02074 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02075 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02076 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02077 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02078 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02079 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02080 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02081 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02082 400 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 28442624, 65536, ) == 0x0 02083 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x20000,}, 28, ) == 0x0 02084 400 NtAllocateVirtualMemory (-1, 28442624, 0, 1, 4096, 4, ... 28442624, 4096, ) == 0x0 02085 400 NtQueryVirtualMemory (-1, 0x1b20000, Basic, 28, ... {BaseAddress=0x1b20000,AllocationBase=0x1b20000,AllocationProtect=0x4,RegionSize=0x1000,State=0x1000,Protect=0x4,Type=0x20000,}, 28, ) == 0x0 02086 400 NtFreeVirtualMemory (-1, (0x1b20000), 0, 32768, ... (0x1b20000), 65536, ) == 0x0 02087 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\Tcpip\Linkage"}, ... 304, ) }, ... 304, ) == 0x0 02088 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\"}, ... 308, ) }, ... 308, ) == 0x0 02089 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces"}, ... 312, ) }, ... 312, ) == 0x0 02090 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\NetBT\Parameters"}, ... 316, ) }, ... 316, ) == 0x0 02091 400 NtQueryDefaultLocale (1, 1241436, ... ) == 0x0 02092 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "odbc32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02093 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\odbc32.dll"}, 1240308, ... ) }, 1240308, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02094 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "odbc32.dll"}, 1240308, ... ) }, 1240308, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02095 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbc32.dll"}, 1240308, ... ) }, 1240308, ... ) == 0x0 02096 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbc32.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02097 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 324, ) == 0x0 02098 400 NtQuerySection (324, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02099 400 NtClose (320, ... ) == 0x0 02100 400 NtMapViewOfSection (324, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x1f7b0000), 0x0, 200704, ) == 0x0 02101 400 NtClose (324, ... ) == 0x0 02102 400 NtProtectVirtualMemory (-1, (0x1f7b1000), 724, 4, ... (0x1f7b1000), 4096, 32, ) == 0x0 02103 400 NtProtectVirtualMemory (-1, (0x1f7b1000), 4096, 32, ... (0x1f7b1000), 4096, 4, ) == 0x0 02104 400 NtFlushInstructionCache (-1, 528158720, 724, ... ) == 0x0 02105 400 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "comdlg32.dll"}, ... 324, ) }, ... 324, ) == 0x0 02106 400 NtMapViewOfSection (324, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x763b0000), 0x0, 282624, ) == 0x0 02107 400 NtClose (324, ... ) == 0x0 02108 400 NtProtectVirtualMemory (-1, (0x763b1000), 1536, 4, ... (0x763b1000), 4096, 32, ) == 0x0 02109 400 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 02110 400 NtFlushInstructionCache (-1, 1983582208, 1536, ... ) == 0x0 02111 400 NtUserRegisterWindowMessage ( ("WOWLFChange", ... ) , ... ) == 0xc06b 02112 400 NtUserRegisterWindowMessage ( ("WOWDirChange", ... ) , ... ) == 0xc06c 02113 400 NtUserRegisterWindowMessage ( ("WOWCHOOSEFONT_GETLOGFONT", ... ) , ... ) == 0xc06d 02114 400 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 02115 400 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 02116 400 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 02117 400 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 02118 400 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 02119 400 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 02120 400 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 02121 400 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 02122 400 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 02123 400 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 02124 400 NtUserRegisterWindowMessage ( ("Shell IDList Array", ... ) , ... ) == 0xc073 02125 400 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 02126 400 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 02127 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\MDAC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02128 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02129 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02130 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02131 400 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 28442624, 262144, ) == 0x0 02132 400 NtAllocateVirtualMemory (-1, 28442624, 0, 4096, 4096, 4, ... 28442624, 4096, ) == 0x0 02133 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02134 400 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 28704768, 262144, ) == 0x0 02135 400 NtAllocateVirtualMemory (-1, 28704768, 0, 4096, 4096, 4, ... 28704768, 4096, ) == 0x0 02136 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02137 400 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 28966912, 262144, ) == 0x0 02138 400 NtAllocateVirtualMemory (-1, 28966912, 0, 4096, 4096, 4, ... 28966912, 4096, ) == 0x0 02139 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02140 400 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 29229056, 262144, ) == 0x0 02141 400 NtAllocateVirtualMemory (-1, 29229056, 0, 4096, 4096, 4, ... 29229056, 4096, ) == 0x0 02142 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02143 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02144 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02145 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02146 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 1236280, ... ) }, 1236280, ... ) == 0x0 02147 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 5, 96, ... 324, {status=0x0, info=1}, ) }, 5, 96, ... 324, {status=0x0, info=1}, ) == 0x0 02148 400 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 324, ... 320, ) == 0x0 02149 400 NtClose (324, ... ) == 0x0 02150 400 NtMapViewOfSection (320, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x1c20000), 0x0, 90112, ) == 0x0 02151 400 NtClose (320, ... ) == 0x0 02152 400 NtUnmapViewOfSection (-1, 0x1c20000, ... ) == 0x0 02153 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 1236596, ... ) }, 1236596, ... ) == 0x0 02154 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02155 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 320, ... 324, ) == 0x0 02156 400 NtQuerySection (324, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02157 400 NtClose (320, ... ) == 0x0 02158 400 NtMapViewOfSection (324, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x1f850000), 0x0, 90112, ) == 0x0 02159 400 NtClose (324, ... ) == 0x0 02160 400 NtQueryDefaultLocale (1, 1238284, ... ) == 0x0 02161 400 NtAllocateVirtualMemory (-1, 28446720, 0, 4096, 4096, 4, ... 28446720, 4096, ) == 0x0 02162 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE"}, ... 324, ) }, ... 324, ) == 0x0 02163 400 NtClose (324, ... ) == 0x0 02164 400 NtOpenKey (0x20019, {24, 32, 0x40, 0, 0, (0x20019, {24, 32, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02165 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02166 400 NtOpenKey (0x20019, {24, 32, 0x40, 0, 0, (0x20019, {24, 32, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02167 400 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02168 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02169 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02170 400 NtCreateMutant (0x1f0001, {24, 76, 0x80, 0, 0, (0x1f0001, {24, 76, 0x80, 0, 0, "Bot018"}, 0, ... 324, ) }, 0, ... 324, ) == 0x0 02171 400 NtWaitForSingleObject (324, 0, {-300000000, -1}, ... ) == 0x0 02172 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 1242252, ... ) }, 1242252, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02173 400 NtDelayExecution (0, {-20000000, -1}, ... ) == 0x0 02174 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1241168, (0x80100080, {24, 0, 0x40, 0, 1241168, "\??\u:\work\packed.exe"}, 0x0, 0, 1, 1, 2097252, 0, 0, ... 320, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 2097252, 0, 0, ... 320, {status=0x0, info=1}, ) == 0x0 02175 400 NtQueryInformationFile (320, 1242104, 8, AttributeFlag, ... {status=0x0, info=8}, ) == 0x0 02176 400 NtQueryInformationFile (320, 1242076, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02177 400 NtQueryInformationFile (320, 1242028, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02178 400 NtAllocateVirtualMemory (-1, 1396736, 0, 8192, 4096, 4, ... 1396736, 8192, ) == 0x0 02179 400 NtQueryInformationFile (320, 1395680, 4094, Stream, ... {status=0x0, info=38}, ) == 0x0 02180 400 NtQueryInformationFile (320, 1240572, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02181 400 NtQueryInformationFile (320, 1240416, 4, Ea, ... {status=0x0, info=4}, ) == 0x0 02182 400 NtCreateFile (0x40110080, {24, 0, 0x40, 0, 1240424, (0x40110080, {24, 0, 0x40, 0, 1240424, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 0x0, 32, 0, 5, 100, 0, 0, ... }, 0x0, 32, 0, 5, 100, 0, 0, ... 02183 400 NtClose (-2147482044, ... ) == 0x0 02182 400 NtCreateFile ... 328, {status=0x0, info=2}, ) == 0x0 02184 400 NtQueryVolumeInformationFile (328, 1239796, 536, Attribute, ... {status=0x0, info=22}, ) == 0x0 02185 400 NtQueryInformationFile (328, 1239756, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02186 400 NtQueryVolumeInformationFile (320, 1239796, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 02187 400 NtQueryVolumeInformationFile (320, 1239480, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02188 400 NtSetInformationFile (328, 1239584, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 02189 400 NtAllocateVirtualMemory (-1, 1404928, 0, 65536, 4096, 4, ... 1404928, 65536, ) == 0x0 02190 400 NtReadFile (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0,\354.\261h\215@\342h\215@\342h\215@\342\242\256g\342i\215@\342\222\251\0\342v\215@\342\222\251\\342\344\215@\342\222\256Y\342m\215@\342h\215A\342\344\215@\342\222\251]\342-\215@\342\222\251}\342i\215@\342Richh\215@\342\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\5\0\247\25{C\0\0\0\0\0\0\0\0\340\0\17\1\13\1\7\0\0\332\1\0\0\274\5\0\0\0\0\0\0\340\7\0\0\20\0\0\0\360\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\360\7\0\0\4\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\334\3\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\300\7\0\36\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\304\330\1\0\0\20\0\0\0\16\1\0\0\4\0\0\0\0\0\0", ) , ) == 0x0 02191 400 NtWriteFile (328, 0, 0, 0, (328, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0,\354.\261h\215@\342h\215@\342h\215@\342\242\256g\342i\215@\342\222\251\0\342v\215@\342\222\251\\342\344\215@\342\222\256Y\342m\215@\342h\215A\342\344\215@\342\222\251]\342-\215@\342\222\251}\342i\215@\342Richh\215@\342\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\5\0\247\25{C\0\0\0\0\0\0\0\0\340\0\17\1\13\1\7\0\0\332\1\0\0\274\5\0\0\0\0\0\0\340\7\0\0\20\0\0\0\360\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\360\7\0\0\4\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\334\3\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\300\7\0\36\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\304\330\1\0\0\20\0\0\0\16\1\0\0\4\0\0\0\0\0\0", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 02192 400 NtReadFile (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, "J$\230\340\235\362\222\357\23\20\13\327\200yt8\251\250^\21\212\5\16:\17uXR\323\324~\305\301N\222\16@\278\321uE\360N\241\357W\3176\25;4\322e\306\6\350\2\265\343_^\361d%\220\270+\363H\247\201~HN\3179W\347M\20G\365F\14.\357\315\352\353 \35\2\267.b\24\314\13_\203\330\330\16\210\204\304\213r\26\24\178\312\307@f\34\362\356\362\336\240\11\23\201H\341\302\235\224\342\63;r\311j+\312\240\177\2508\246\231B\14\201\361\215F\377&\232H\320\205;\15\365 \3\376s%\232\301G\6>FJ\274+\236\326<\350\227-6l\316\2645\237\24\237\36\222\351\7\36\20I7\10?a\23Sj\3641\276\223\12\365\30\276\12\366\377%\250\245&\7\372\20\4\232'[\360\237/\230\305\224\343{\226\205 \304\215|\21X\255*%\371\2\117\2038a\3002nsQ\37\25\266+\310\177\210PN\260\236\241\302\203\14\215\263J\220\377\31\342\276\276\33Ps\36\225\25\30\262\6\201\242w\3\213\360`+\326\304C\236\324\341HA\215SVv\260q}W\215\34\250<\2133\240\305\300\301P\347\267\367\274?D9\352\302\340(\177\10\332\15\37Y\222#\362g\304\352\3d\206\25E-r\260\367\221J\33/\31s\37c\10\213\270\13\27D8\14\355?\222\3524\307Ps\254\274D|\201\235\323*\234QAUj\13\203\315\370\3504\332\211\301Uy\217-!!\13\350\240\211'3\333\361\201\11\24\277L\2577'\205\366Q.\211\215\206\331\12\37^\324F\367\24uN\275\310-\210k\260Q\27\16#-\212tm\261\302\262\257 \215^\14S\254\256\200Ct\33\373X\223\213\325\337\217;\306(\5`\3;\360r\236\353\34\362\16_\300{+\7-", ) , ) == 0x0 02193 400 NtWriteFile (328, 0, 0, 0, (328, 0, 0, 0, "J$\230\340\235\362\222\357\23\20\13\327\200yt8\251\250^\21\212\5\16:\17uXR\323\324~\305\301N\222\16@\278\321uE\360N\241\357W\3176\25;4\322e\306\6\350\2\265\343_^\361d%\220\270+\363H\247\201~HN\3179W\347M\20G\365F\14.\357\315\352\353 \35\2\267.b\24\314\13_\203\330\330\16\210\204\304\213r\26\24\178\312\307@f\34\362\356\362\336\240\11\23\201H\341\302\235\224\342\63;r\311j+\312\240\177\2508\246\231B\14\201\361\215F\377&\232H\320\205;\15\365 \3\376s%\232\301G\6>FJ\274+\236\326<\350\227-6l\316\2645\237\24\237\36\222\351\7\36\20I7\10?a\23Sj\3641\276\223\12\365\30\276\12\366\377%\250\245&\7\372\20\4\232'[\360\237/\230\305\224\343{\226\205 \304\215|\21X\255*%\371\2\117\2038a\3002nsQ\37\25\266+\310\177\210PN\260\236\241\302\203\14\215\263J\220\377\31\342\276\276\33Ps\36\225\25\30\262\6\201\242w\3\213\360`+\326\304C\236\324\341HA\215SVv\260q}W\215\34\250<\2133\240\305\300\301P\347\267\367\274?D9\352\302\340(\177\10\332\15\37Y\222#\362g\304\352\3d\206\25E-r\260\367\221J\33/\31s\37c\10\213\270\13\27D8\14\355?\222\3524\307Ps\254\274D|\201\235\323*\234QAUj\13\203\315\370\3504\332\211\301Uy\217-!!\13\350\240\211'3\333\361\201\11\24\277L\2577'\205\366Q.\211\215\206\331\12\37^\324F\367\24uN\275\310-\210k\260Q\27\16#-\212tm\261\302\262\257 \215^\14S\254\256\200Ct\33\373X\223\213\325\337\217;\306(\5`\3;\360r\236\353\34\362\16_\300{+\7-", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 02194 400 NtReadFile (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, "\267Z+\207\212YA\200H\0\35\220\261T\37\277\353dT\271\3066+\273C\345\337\276\270!#\263\203\226\14M\240\14;\253\376\35\206\273\31z3\356\252@eZJC_\247\310\3010^F\235\324\273\265\20\341\253i\363vp\204%]S\3369d_\302\274HPT9\325\232^\14\307\264\222\323\260,\370\276gQ\225\10u\13\2469\271\235i3\345\222\7\256\327\7\205\4\266\267\227]\370\337\2244\274\235\315\306\371\231\306\270\3417\306\5C\225\327>KL\230V\177\255p\310\245]\357\366J\320RK\17\203\21\13\335\\207?D\253\21k\340\3669\221\363?\32\257{\23\323\367N\365*\27\253\235\263l<\\274\31\253X\201T=\256\267\1a\330Z\4 .\343\322\305\213\304D_\331\345\304\312\245Ywt\352\33\212\7\230\226\10\263$\220\267\20\333\332\215:\324Y|G\334\343\300\305\325\351J\263\256e~\356\200\\E)\316\16\271\30\15\237\6\2560o\24p#\371X\233\366\16N\342*~\222~\265\5b\37\351\200w\374\335MK\200)\302=?W\257 lm\202;t[\321F\272\331\212\10Q\370\201\277\211<\356\256$\15\177\224Q\212c\333Q\214\12\312\200\201o#\247\314\13Y\303]\36B\342&\355B%\212\32\317<\159\204'e\0\0\312\312\33:7?\355y\331c \3300\32?\317>\15:\371\33?\355U00\35\305\267\310\221#\303\220\305\335$\20\11\267<\231u\277Tq:\304\344a\4\317\344\327\266\22x\325\203\236\224\323\267@)-\255\345l\230\205\334,\261=\320\245\15@d\33\3\5\7x\5s\34-\321\301\1-B\252U\353\1\216Q\323\200\264\331\240\121\16\244\307\241\334\326rM\335\241\37\\250\302\4\305\326p\0u^\367\226\342n\334O\20\270", ) , ) == 0x0 02195 400 NtWriteFile (328, 0, 0, 0, (328, 0, 0, 0, "\267Z+\207\212YA\200H\0\35\220\261T\37\277\353dT\271\3066+\273C\345\337\276\270!#\263\203\226\14M\240\14;\253\376\35\206\273\31z3\356\252@eZJC_\247\310\3010^F\235\324\273\265\20\341\253i\363vp\204%]S\3369d_\302\274HPT9\325\232^\14\307\264\222\323\260,\370\276gQ\225\10u\13\2469\271\235i3\345\222\7\256\327\7\205\4\266\267\227]\370\337\2244\274\235\315\306\371\231\306\270\3417\306\5C\225\327>KL\230V\177\255p\310\245]\357\366J\320RK\17\203\21\13\335\\207?D\253\21k\340\3669\221\363?\32\257{\23\323\367N\365*\27\253\235\263l<\\274\31\253X\201T=\256\267\1a\330Z\4 .\343\322\305\213\304D_\331\345\304\312\245Ywt\352\33\212\7\230\226\10\263$\220\267\20\333\332\215:\324Y|G\334\343\300\305\325\351J\263\256e~\356\200\\E)\316\16\271\30\15\237\6\2560o\24p#\371X\233\366\16N\342*~\222~\265\5b\37\351\200w\374\335MK\200)\302=?W\257 lm\202;t[\321F\272\331\212\10Q\370\201\277\211<\356\256$\15\177\224Q\212c\333Q\214\12\312\200\201o#\247\314\13Y\303]\36B\342&\355B%\212\32\317<\159\204'e\0\0\312\312\33:7?\355y\331c \3300\32?\317>\15:\371\33?\355U00\35\305\267\310\221#\303\220\305\335$\20\11\267<\231u\277Tq:\304\344a\4\317\344\327\266\22x\325\203\236\224\323\267@)-\255\345l\230\205\334,\261=\320\245\15@d\33\3\5\7x\5s\34-\321\301\1-B\252U\353\1\216Q\323\200\264\331\240\121\16\244\307\241\334\326rM\335\241\37\\250\302\4\305\326p\0u^\367\226\342n\334O\20\270", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) , 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 02196 400 NtReadFile (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, "\300\234\255\322\276\1Kd\236 \371\217\336\360~\334(\17\5\227x~o\300Il\26\243;P\4\307\334\212\220\21\233\25\263G\350P\36\250\5\16^\332\320\216\300\222\307\4\354\370\252\203Z\333u\322\323\363\3210l\270\331|S]\3358\201\334\302\213\12+R\0cE\2716_\246\6H1\36\317 \32+\10\25\336\351hd4\233\314\325)\11&YG\331BCA\342\321\4J\220x`=\350\22\303)7\311\311\232\266bh\353\327\307<\335\216\14\222\255\313\312I\224\25\244\11\317\32\370\336"yw_\377\303\362\206C\223\226\3\307\22\331\211\31\342\4\23\14\241\2001\337R\237\354\204\243>\205\237HZ\\231\301\225`\134\3231TI\200\350\333\353>E!\0\362\1H\245\251\321\3\332\274z\367\3526\27>\271\226K8\16ZLV\337\342\37\273\373\362\200\263\331\5\25\7\320\262\235\231\206\27A\313\306h\32\362\222\0\204\355'$YuY\1\235+&z\216\300\331\200\10\337w9]\3232%b+6\200;\312v\344\230\307\3661.V\371\364\210\251s\322\377u\370{V\332\203E]\211_H\36\367+\332\227\320\351\203\32\330\251.\108\245\24\331\323\312`\220\274\7#F\243X\206\210\4\34#\14\12\22\260\10\230\333\27\330\331\372g\236(\232\356\304}\300n\255`\3G\320\332$a\227\252\248\301\313\177\211\203\336\11\2146%\336\351sV\\227\237}5\36\367I\220\275\316\3125\313\365\0\251\365m\34?\313\360\316E2\312\220P\242\235\245u\272\334\351\271\361\331\220\242FqR\200\363\217=\2N\263\305\13f\201#=\267\6`\375\305\212T\246\310NJ\14#\212\376\331\210\337\16{\315b\252]\311\255Gtk\31Vu\33\206\300\10\232R\200D\33?\214JW\302f\267u", ) yw_\377\303\362\206C\223\226\3\307\22\331\211\31\342\4\23\14\241\2001\337R\237\354\204\243>\205\237HZ\\231\301\225`\134\3231TI\200\350\333\353>E!\0\362\1H\245\251\321\3\332\274z\367\3526\27>\271\226K8\16ZLV\337\342\37\273\373\362\200\263\331\5\25\7\320\262\235\231\206\27A\313\306h\32\362\222\0\204\355'$YuY\1\235+&z\216\300\331\200\10\337w9]\3232%b+6\200;\312v\344\230\307\3661.V\371\364\210\251s\322\377u\370{V\332\203E]\211_H\36\367+\332\227\320\351\203\32\330\251.\108\245\24\331\323\312`\220\274\7#F\243X\206\210\4\34#\14\12\22\260\10\230\333\27\330\331\372g\236(\232\356\304}\300n\255`\3G\320\332$a\227\252\248\301\313\177\211\203\336\11\2146%\336\351sV\\227\237}5\36\367I\220\275\316\3125\313\365\0\251\365m\34?\313\360\316E2\312\220P\242\235\245u\272\334\351\271\361\331\220\242FqR\200\363\217=\2N\263\305\13f\201#=\267\6`\375\305\212T\246\310NJ\14#\212\376\331\210\337\16{\315b\252]\311\255Gtk\31Vu\33\206\300\10\232R\200D\33?\214JW\302f\267u", ) == 0x0 02197 400 NtWriteFile (328, 0, 0, 0, (328, 0, 0, 0, "\300\234\255\322\276\1Kd\236 \371\217\336\360~\334(\17\5\227x~o\300Il\26\243;P\4\307\334\212\220\21\233\25\263G\350P\36\250\5\16^\332\320\216\300\222\307\4\354\370\252\203Z\333u\322\323\363\3210l\270\331|S]\3358\201\334\302\213\12+R\0cE\2716_\246\6H1\36\317 \32+\10\25\336\351hd4\233\314\325)\11&YG\331BCA\342\321\4J\220x`=\350\22\303)7\311\311\232\266bh\353\327\307<\335\216\14\222\255\313\312I\224\25\244\11\317\32\370\336"yw_\377\303\362\206C\223\226\3\307\22\331\211\31\342\4\23\14\241\2001\337R\237\354\204\243>\205\237HZ\\231\301\225`\134\3231TI\200\350\333\353>E!\0\362\1H\245\251\321\3\332\274z\367\3526\27>\271\226K8\16ZLV\337\342\37\273\373\362\200\263\331\5\25\7\320\262\235\231\206\27A\313\306h\32\362\222\0\204\355'$YuY\1\235+&z\216\300\331\200\10\337w9]\3232%b+6\200;\312v\344\230\307\3661.V\371\364\210\251s\322\377u\370{V\332\203E]\211_H\36\367+\332\227\320\351\203\32\330\251.\108\245\24\331\323\312`\220\274\7#F\243X\206\210\4\34#\14\12\22\260\10\230\333\27\330\331\372g\236(\232\356\304}\300n\255`\3G\320\332$a\227\252\248\301\313\177\211\203\336\11\2146%\336\351sV\\227\237}5\36\367I\220\275\316\3125\313\365\0\251\365m\34?\313\360\316E2\312\220P\242\235\245u\272\334\351\271\361\331\220\242FqR\200\363\217=\2N\263\305\13f\201#=\267\6`\375\305\212T\246\310NJ\14#\212\376\331\210\337\16{\315b\252]\311\255Gtk\31Vu\33\206\300\10\232R\200D\33?\214JW\302f\267u", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) yw_\377\303\362\206C\223\226\3\307\22\331\211\31\342\4\23\14\241\2001\337R\237\354\204\243>\205\237HZ\\231\301\225`\134\3231TI\200\350\333\353>E!\0\362\1H\245\251\321\3\332\274z\367\3526\27>\271\226K8\16ZLV\337\342\37\273\373\362\200\263\331\5\25\7\320\262\235\231\206\27A\313\306h\32\362\222\0\204\355'$YuY\1\235+&z\216\300\331\200\10\337w9]\3232%b+6\200;\312v\344\230\307\3661.V\371\364\210\251s\322\377u\370{V\332\203E]\211_H\36\367+\332\227\320\351\203\32\330\251.\108\245\24\331\323\312`\220\274\7#F\243X\206\210\4\34#\14\12\22\260\10\230\333\27\330\331\372g\236(\232\356\304}\300n\255`\3G\320\332$a\227\252\248\301\313\177\211\203\336\11\2146%\336\351sV\\227\237}5\36\367I\220\275\316\3125\313\365\0\251\365m\34?\313\360\316E2\312\220P\242\235\245u\272\334\351\271\361\331\220\242FqR\200\363\217=\2N\263\305\13f\201#=\267\6`\375\305\212T\246\310NJ\14#\212\376\331\210\337\16{\315b\252]\311\255Gtk\31Vu\33\206\300\10\232R\200D\33?\214JW\302f\267u", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 02198 400 NtReadFile (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=32730}, (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=32730}, "\351\3738y\257\31\377\312\317\353\264\255=\377#$\325\16oyG\12t\226*\177\337\330\352\0Oj\247\213\373\211)x\206\203\370\223\274\223`\244*\14\5Gl\377\227\253]N\231\3523\2\16\213\303d\375\267\334:\13;\363\313WZ\206y\200X\237__K\225h\24\257\355\370\32\205\216\312\24\206\302j?}\340\345|\245\264}\330\250ZR\14\227\3132\202/\12@\330\264\261\324\304Co4o\256\266E\267\314$?h\16\246\327\5\367\201\324\15\265\202w\32\2672\300\17\304\350\214N\13YK\350\26**\226\336[f\36\377?b\17e[\245\30\X\256\223\200\215\261\201\15\244;t\11\333\317\247g[S\21\354\16\331\144\366\11\213W\212\205\341q\236\315\237\31\34\1\364p\352yw\370J\205\3k$\337~\232\36\312_|\360\206\224\363\346\354\301\331\324Q%\363\271L\360i_\223\13N\221K\3]\333\336[#\203n\350sC\12\5\264/\336\10h\320\316\f\337\22_\303\350\237\361\366\361\367:\20=\363\352\221\275\370\7aG\34\354\324#kRy\303m\323/\203\303 \331\327\346S\213\201a\0+Rn?&\373\376\355"\302\1\205\211\223\301\261\27{"/\312*\273\313\272\322,\307H\321\370:\352 \243\22\213\203\351\344\273\21\202\\277\352\213\205a\312OG\303\323\346\26\203\2062\317r\34\370\33i\2\262]c\0\22X\357\305(X\360"\323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\\RJG\12\336I\360j\330\354\34k\344\334*\12I\323;\31\324\342\14\307a\213%\\355\351}BP\22\201H\360", ) \302\1\205\211\223\301\261\27{ (320, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=32730}, "\351\3738y\257\31\377\312\317\353\264\255=\377#$\325\16oyG\12t\226*\177\337\330\352\0Oj\247\213\373\211)x\206\203\370\223\274\223`\244*\14\5Gl\377\227\253]N\231\3523\2\16\213\303d\375\267\334:\13;\363\313WZ\206y\200X\237__K\225h\24\257\355\370\32\205\216\312\24\206\302j?}\340\345|\245\264}\330\250ZR\14\227\3132\202/\12@\330\264\261\324\304Co4o\256\266E\267\314$?h\16\246\327\5\367\201\324\15\265\202w\32\2672\300\17\304\350\214N\13YK\350\26**\226\336[f\36\377?b\17e[\245\30\X\256\223\200\215\261\201\15\244;t\11\333\317\247g[S\21\354\16\331\144\366\11\213W\212\205\341q\236\315\237\31\34\1\364p\352yw\370J\205\3k$\337~\232\36\312_|\360\206\224\363\346\354\301\331\324Q%\363\271L\360i_\223\13N\221K\3]\333\336[#\203n\350sC\12\5\264/\336\10h\320\316\f\337\22_\303\350\237\361\366\361\367:\20=\363\352\221\275\370\7aG\34\354\324#kRy\303m\323/\203\303 \331\327\346S\213\201a\0+Rn?&\373\376\355"\302\1\205\211\223\301\261\27{"/\312*\273\313\272\322,\307H\321\370:\352 \243\22\213\203\351\344\273\21\202\\277\352\213\205a\312OG\303\323\346\26\203\2062\317r\34\370\33i\2\262]c\0\22X\357\305(X\360"\323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\\RJG\12\336I\360j\330\354\34k\344\334*\12I\323;\31\324\342\14\307a\213%\\355\351}BP\22\201H\360", ) \323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\\RJG\12\336I\360j\330\354\34k\344\334*\12I\323;\31\324\342\14\307a\213%\\355\351}BP\22\201H\360", ) == 0x0 02199 400 NtWriteFile (328, 0, 0, 0, (328, 0, 0, 0, "\351\3738y\257\31\377\312\317\353\264\255=\377#$\325\16oyG\12t\226*\177\337\330\352\0Oj\247\213\373\211)x\206\203\370\223\274\223`\244*\14\5Gl\377\227\253]N\231\3523\2\16\213\303d\375\267\334:\13;\363\313WZ\206y\200X\237__K\225h\24\257\355\370\32\205\216\312\24\206\302j?}\340\345|\245\264}\330\250ZR\14\227\3132\202/\12@\330\264\261\324\304Co4o\256\266E\267\314$?h\16\246\327\5\367\201\324\15\265\202w\32\2672\300\17\304\350\214N\13YK\350\26**\226\336[f\36\377?b\17e[\245\30\X\256\223\200\215\261\201\15\244;t\11\333\317\247g[S\21\354\16\331\144\366\11\213W\212\205\341q\236\315\237\31\34\1\364p\352yw\370J\205\3k$\337~\232\36\312_|\360\206\224\363\346\354\301\331\324Q%\363\271L\360i_\223\13N\221K\3]\333\336[#\203n\350sC\12\5\264/\336\10h\320\316\f\337\22_\303\350\237\361\366\361\367:\20=\363\352\221\275\370\7aG\34\354\324#kRy\303m\323/\203\303 \331\327\346S\213\201a\0+Rn?&\373\376\355"\302\1\205\211\223\301\261\27{"/\312*\273\313\272\322,\307H\321\370:\352 \243\22\213\203\351\344\273\21\202\\277\352\213\205a\312OG\303\323\346\26\203\2062\317r\34\370\33i\2\262]c\0\22X\357\305(X\360"\323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\\RJG\12\336I\360j\330\354\34k\344\334*\12I\323;\31\324\342\14\307a\213%\\355\351}BP\22\201H\360", 32730, 0x0, 0, ... {status=0x0, info=32730}, ) \302\1\205\211\223\301\261\27{ (328, 0, 0, 0, "\351\3738y\257\31\377\312\317\353\264\255=\377#$\325\16oyG\12t\226*\177\337\330\352\0Oj\247\213\373\211)x\206\203\370\223\274\223`\244*\14\5Gl\377\227\253]N\231\3523\2\16\213\303d\375\267\334:\13;\363\313WZ\206y\200X\237__K\225h\24\257\355\370\32\205\216\312\24\206\302j?}\340\345|\245\264}\330\250ZR\14\227\3132\202/\12@\330\264\261\324\304Co4o\256\266E\267\314$?h\16\246\327\5\367\201\324\15\265\202w\32\2672\300\17\304\350\214N\13YK\350\26**\226\336[f\36\377?b\17e[\245\30\X\256\223\200\215\261\201\15\244;t\11\333\317\247g[S\21\354\16\331\144\366\11\213W\212\205\341q\236\315\237\31\34\1\364p\352yw\370J\205\3k$\337~\232\36\312_|\360\206\224\363\346\354\301\331\324Q%\363\271L\360i_\223\13N\221K\3]\333\336[#\203n\350sC\12\5\264/\336\10h\320\316\f\337\22_\303\350\237\361\366\361\367:\20=\363\352\221\275\370\7aG\34\354\324#kRy\303m\323/\203\303 \331\327\346S\213\201a\0+Rn?&\373\376\355"\302\1\205\211\223\301\261\27{"/\312*\273\313\272\322,\307H\321\370:\352 \243\22\213\203\351\344\273\21\202\\277\352\213\205a\312OG\303\323\346\26\203\2062\317r\34\370\33i\2\262]c\0\22X\357\305(X\360"\323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\\RJG\12\336I\360j\330\354\34k\344\334*\12I\323;\31\324\342\14\307a\213%\\355\351}BP\22\201H\360", 32730, 0x0, 0, ... {status=0x0, info=32730}, ) \323\253\202\22c\31\337\261\17I\350ED\214o\331\260\347]\212x\34\316\202\376\224\332S{\330V\316\224\12\334\323\12\315O|k\367:\0;P\340]%\307\224\354^/\370\361\224\230\25k\240\255\321\\RJG\12\336I\360j\330\354\34k\344\334*\12I\323;\31\324\342\14\307a\213%\\355\351}BP\22\201H\360", 32730, 0x0, 0, ... {status=0x0, info=32730}, ) == 0x0 02200 400 NtReadFile (320, 0, 0, 0, 61440, 0x0, 0, ... ) == STATUS_END_OF_FILE 02201 400 NtFreeVirtualMemory (-1, (0x156000), 69632, 16384, ... (0x156000), 69632, ) == 0x0 02202 400 NtSetInformationFile (328, 1242028, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02203 400 NtClose (320, ... ) == 0x0 02204 400 NtClose (328, ... ) == 0x0 02205 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\explorer.exe"}, 1241176, ... ) }, 1241176, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02206 400 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "explorer.exe"}, 1241176, ... ) }, 1241176, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02207 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\explorer.exe"}, 1241176, ... ) }, 1241176, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02208 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system\explorer.exe"}, 1241176, ... ) }, 1241176, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02209 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\explorer.exe"}, 1241176, ... ) }, 1241176, ... ) == 0x0 02210 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1241924, (0x80100080, {24, 0, 0x40, 0, 1241924, "\??\C:\WINDOWS\explorer.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... 328, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 328, {status=0x0, info=1}, ) == 0x0 02211 400 NtQueryInformationFile (328, 1241976, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02212 400 NtClose (328, ... ) == 0x0 02213 400 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1241924, (0x40100080, {24, 0, 0x40, 0, 1241924, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 0x0, 128, 2, 1, 96, 0, 0, ... 328, {status=0x0, info=1}, ) }, 0x0, 128, 2, 1, 96, 0, 0, ... 328, {status=0x0, info=1}, ) == 0x0 02214 400 NtSetInformationFile (328, 1241976, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02215 400 NtClose (328, ... ) == 0x0 02216 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 7, 2113568, ... 328, {status=0x0, info=1}, ) }, 7, 2113568, ... 328, {status=0x0, info=1}, ) == 0x0 02217 400 NtSetInformationFile (328, 1242228, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02218 400 NtClose (328, ... ) == 0x0 02219 400 NtOpenProcess (0x100000, {24, 0, 0x2, 0, 0, 0x0}, {396, 0}, ... 328, ) == 0x0 02220 400 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 02221 400 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 5, 96, ... 320, {status=0x0, info=1}, ) }, 5, 96, ... 320, {status=0x0, info=1}, ) == 0x0 02222 400 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 320, ... 332, ) == 0x0 02223 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02224 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 336, ) }, ... 336, ) == 0x0 02225 400 NtQueryValueKey (336, (336, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02226 400 NtClose (336, ... ) == 0x0 02227 400 NtQueryVolumeInformationFile (320, 1238724, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02228 400 NtOpenMutant (0x120001, {24, 76, 0x0, 0, 0, (0x120001, {24, 76, 0x0, 0, 0, "ShimCacheMutex"}, ... 336, ) }, ... 336, ) == 0x0 02229 400 NtWaitForSingleObject (336, 0, {-1000000, -1}, ... ) == 0x0 02230 400 NtOpenSection (0x2, {24, 76, 0x0, 0, 0, (0x2, {24, 76, 0x0, 0, 0, "ShimSharedMemory"}, ... 340, ) }, ... 340, ) == 0x0 02231 400 NtMapViewOfSection (340, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x1c20000), {0, 0}, 57344, ) == 0x0 02232 400 NtReleaseMutant (336, ... 0x0, ) == 0x0 02233 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1236708, ... ) }, 1236708, ... ) == 0x0 02234 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 344, {status=0x0, info=1}, ) }, 5, 96, ... 344, {status=0x0, info=1}, ) == 0x0 02235 400 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 344, ... 348, ) == 0x0 02236 400 NtClose (344, ... ) == 0x0 02237 400 NtMapViewOfSection (348, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x1c30000), 0x0, 106496, ) == 0x0 02238 400 NtClose (348, ... ) == 0x0 02239 400 NtUnmapViewOfSection (-1, 0x1c30000, ... ) == 0x0 02240 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1237024, ... ) }, 1237024, ... ) == 0x0 02241 400 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 348, {status=0x0, info=1}, ) }, 5, 96, ... 348, {status=0x0, info=1}, ) == 0x0 02242 400 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 348, ... 344, ) == 0x0 02243 400 NtQuerySection (344, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02244 400 NtClose (348, ... ) == 0x0 02245 400 NtMapViewOfSection (344, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75f40000), 0x0, 118784, ) == 0x0 02246 400 NtClose (344, ... ) == 0x0 02247 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 344, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 344, {status=0x0, info=1}, ) == 0x0 02248 400 NtQueryInformationFile (344, 1237312, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02249 400 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 344, ... 348, ) == 0x0 02250 400 NtMapViewOfSection (348, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x1c30000), 0x0, 1028096, ) == 0x0 02251 400 NtQueryInformationFile (344, 1237408, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02252 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02253 400 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02254 400 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 02255 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02256 400 NtQueryDirectoryFile (352, 0, 0, 0, 1234972, 616, BothDirectory, 1, (352, 0, 0, 0, 1234972, 616, BothDirectory, 1, "tlefnpe32.exe", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 02257 400 NtClose (352, ... ) == 0x0 02258 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02259 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02260 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 1234360, ... ) }, 1234360, ... ) == 0x0 02261 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02262 400 NtQueryDirectoryFile (352, 0, 0, 0, 1233720, 616, BothDirectory, 1, (352, 0, 0, 0, 1233720, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02263 400 NtClose (352, ... ) == 0x0 02264 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02265 400 NtQueryDirectoryFile (352, 0, 0, 0, 1233720, 616, BothDirectory, 1, (352, 0, 0, 0, 1233720, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02266 400 NtClose (352, ... ) == 0x0 02267 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02268 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02269 400 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02270 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02271 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02272 400 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02273 400 NtClose (352, ... ) == 0x0 02274 400 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02275 400 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\tlefnpe32.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02276 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02277 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02278 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 1236640, ... ) }, 1236640, ... ) == 0x0 02279 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02280 400 NtQueryDirectoryFile (352, 0, 0, 0, 1236000, 616, BothDirectory, 1, (352, 0, 0, 0, 1236000, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02281 400 NtClose (352, ... ) == 0x0 02282 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02283 400 NtQueryDirectoryFile (352, 0, 0, 0, 1236000, 616, BothDirectory, 1, (352, 0, 0, 0, 1236000, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02284 400 NtClose (352, ... ) == 0x0 02285 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02286 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02287 400 NtWaitForSingleObject (336, 0, {-1000000, -1}, ... ) == 0x0 02288 400 NtQueryVolumeInformationFile (320, 1237284, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02289 400 NtQueryInformationFile (320, 1237264, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 02290 400 NtQueryInformationFile (320, 1237304, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02291 400 NtReleaseMutant (336, ... 0x0, ) == 0x0 02292 400 NtUnmapViewOfSection (-1, 0x1c30000, ... ) == 0x0 02293 400 NtClose (348, ... ) == 0x0 02294 400 NtClose (344, ... ) == 0x0 02295 400 NtQuerySection (332, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02296 400 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tlefnpe32.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02297 400 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 02298 400 NtOpenProcessToken (-1, 0xa, ... 344, ) == 0x0 02299 400 NtQueryInformationToken (344, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 02300 400 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02301 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 348, ) }, ... 348, ) == 0x0 02302 400 NtQueryValueKey (348, (348, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (348, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02303 400 NtQueryValueKey (348, (348, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (348, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02304 400 NtClose (348, ... ) == 0x0 02305 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 348, ) }, ... 348, ) == 0x0 02306 400 NtQueryValueKey (348, (348, "ExecutableTypes", Partial, 0, ... ) , Partial, 0, ... ) == STATUS_BUFFER_TOO_SMALL 02307 400 NtQueryValueKey (348, (348, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) , Partial, 260, ... TitleIdx=0, Type=7, Data= (348, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) }, 260, ) == 0x0 02308 400 NtClose (348, ... ) == 0x0 02309 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02310 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 348, ) }, ... 348, ) == 0x0 02311 400 NtQueryValueKey (348, (348, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02312 400 NtClose (348, ... ) == 0x0 02313 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02314 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02315 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02316 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02317 400 NtAllocateVirtualMemory (-1, 1400832, 0, 4096, 4096, 4, ... 1400832, 4096, ) == 0x0 02318 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02319 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02320 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02321 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02322 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02323 400 NtQueryDefaultLocale (1, 1238096, ... ) == 0x0 02324 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 348, ) }, ... 348, ) == 0x0 02325 400 NtEnumerateKey (348, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name= (348, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 02326 400 NtOpenKey (0x20019, {24, 348, 0x40, 0, 0, (0x20019, {24, 348, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 352, ) }, ... 352, ) == 0x0 02327 400 NtQueryValueKey (352, (352, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (352, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 02328 400 NtQueryValueKey (352, (352, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (352, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02329 400 NtClose (352, ... ) == 0x0 02330 400 NtEnumerateKey (348, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02331 400 NtClose (348, ... ) == 0x0 02332 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02333 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02334 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02335 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02336 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02337 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02338 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02339 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02340 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02341 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02342 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02343 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02344 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02345 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02346 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02347 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02348 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02349 400 NtClose (348, ... ) == 0x0 02350 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02351 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02352 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02353 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02354 400 NtClose (348, ... ) == 0x0 02355 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02356 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02357 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02358 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02359 400 NtClose (348, ... ) == 0x0 02360 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02361 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02362 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02363 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02364 400 NtClose (348, ... ) == 0x0 02365 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02366 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02367 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02368 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02369 400 NtClose (348, ... ) == 0x0 02370 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02371 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02372 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02373 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02374 400 NtClose (348, ... ) == 0x0 02375 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02376 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02377 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02378 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02379 400 NtClose (348, ... ) == 0x0 02380 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02381 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02382 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02383 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02384 400 NtClose (348, ... ) == 0x0 02385 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02386 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02387 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02388 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02389 400 NtClose (348, ... ) == 0x0 02390 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02391 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02392 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02393 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02394 400 NtClose (348, ... ) == 0x0 02395 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02396 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02397 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02398 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02399 400 NtClose (348, ... ) == 0x0 02400 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02401 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02402 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02403 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02404 400 NtClose (348, ... ) == 0x0 02405 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02406 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02407 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02408 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02409 400 NtClose (348, ... ) == 0x0 02410 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02411 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02412 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02413 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02414 400 NtClose (348, ... ) == 0x0 02415 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02416 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02417 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02418 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02419 400 NtClose (348, ... ) == 0x0 02420 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02421 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 348, ) }, ... 348, ) == 0x0 02422 400 NtQueryValueKey (348, (348, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (348, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (348, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 02423 400 NtClose (348, ... ) == 0x0 02424 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02425 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 348, ) == 0x0 02426 400 NtQueryInformationToken (348, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02427 400 NtClose (348, ... ) == 0x0 02428 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02429 400 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 02430 400 NtOpenProcessToken (-1, 0xa, ... 348, ) == 0x0 02431 400 NtDuplicateToken (348, 0xc, {24, 0, 0x0, 0, 1238616, 0x0}, 0, 2, ... 352, ) == 0x0 02432 400 NtClose (348, ... ) == 0x0 02433 400 NtAccessCheck (1402384, 352, 0x1, 1238744, 1238688, 56, 1238772, ... (0x1), ) == 0x0 02434 400 NtClose (352, ... ) == 0x0 02435 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 352, ) }, ... 352, ) == 0x0 02436 400 NtQueryValueKey (352, (352, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (352, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02437 400 NtClose (352, ... ) == 0x0 02438 400 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 352, ) }, ... 352, ) == 0x0 02439 400 NtQuerySymbolicLinkObject (352, ... (352, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 02440 400 NtClose (352, ... ) == 0x0 02441 400 NtQueryInformationFile (320, 1237076, 528, Name, ... {status=0x0, info=66}, ) == 0x0 02442 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02443 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02444 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe"}, 1235756, ... ) }, 1235756, ... ) == 0x0 02445 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02446 400 NtQueryDirectoryFile (352, 0, 0, 0, 1235116, 616, BothDirectory, 1, (352, 0, 0, 0, 1235116, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02447 400 NtClose (352, ... ) == 0x0 02448 400 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 352, {status=0x0, info=1}, ) }, 3, 16417, ... 352, {status=0x0, info=1}, ) == 0x0 02449 400 NtQueryDirectoryFile (352, 0, 0, 0, 1235116, 616, BothDirectory, 1, (352, 0, 0, 0, 1235116, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02450 400 NtClose (352, ... ) == 0x0 02451 400 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02452 400 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02453 400 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02454 400 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 352, ) == 0x0 02455 400 NtQueryInformationToken (352, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02456 400 NtClose (352, ... ) == 0x0 02457 400 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 352, ) }, ... 352, ) == 0x0 02458 400 NtOpenKey (0x20019, {24, 352, 0x40, 0, 0, (0x20019, {24, 352, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 348, ) }, ... 348, ) == 0x0 02459 400 NtClose (352, ... ) == 0x0 02460 400 NtQueryValueKey (348, (348, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02461 400 NtQueryValueKey (348, (348, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=1, Data= (348, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) }, 162, ) == 0x0 02462 400 NtClose (348, ... ) == 0x0 02463 400 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 29556736, 4096, ) == 0x0 02464 400 NtAllocateVirtualMemory (-1, 29556736, 0, 4096, 4096, 4, ... 29556736, 4096, ) == 0x0 02465 400 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 348, ) }, ... 348, ) == 0x0 02466 400 NtQueryValueKey (348, (348, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02467 400 NtClose (348, ... ) == 0x0 02468 400 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02469 400 NtQueryInformationToken (344, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 02470 400 NtQueryInformationToken (344, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 02471 400 NtClose (344, ... ) == 0x0 02472 400 NtCreateProcessEx (1241352, 2035711, 0, -1, 4, 332, 0, 0, 0, ... ) == 0x0 02473 400 NtSetInformationProcess (344, PriorityClass, {process info, class 18, size 2}, 83886592, ... ) == 0x0 02474 400 NtQueryInformationProcess (344, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=1824,ParentPid=396,}, 0x0, ) == 0x0 02475 400 NtReadVirtualMemory (344, 0x7ffdf008, 4, ... (344, 0x7ffdf008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 02476 400 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\tlefnpe32.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02477 400 NtAllocateVirtualMemory (-1, 1404928, 0, 8192, 4096, 4, ... 1404928, 8192, ) == 0x0 02478 400 NtReadVirtualMemory (344, 0x400000, 4096, ... (344, 0x400000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0,\354.\261h\215@\342h\215@\342h\215@\342\242\256g\342i\215@\342\222\251\0\342v\215@\342\222\251\\342\344\215@\342\222\256Y\342m\215@\342h\215A\342\344\215@\342\222\251]\342-\215@\342\222\251}\342i\215@\342Richh\215@\342\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\5\0\247\25{C\0\0\0\0\0\0\0\0\340\0\17\1\13\1\7\0\0\332\1\0\0\274\5\0\0\0\0\0\0\340\7\0\0\20\0\0\0\360\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\360\7\0\0\4\0\0\0\0\0\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\334\3\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\300\7\0\36\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\304\330\1\0\0\20\0\0\0\16\1\0\0\4\0\0\0\0\0\0", 4096, ) , 4096, ) == 0x0 02479 400 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02480 400 NtQueryInformationProcess (344, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=1824,ParentPid=396,}, 0x0, ) == 0x0 02481 400 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32"}, 1239416, ... ) }, 1239416, ... ) == 0x0 02482 400 NtAllocateVirtualMemory (-1, 0, 0, 1660, 4096, 4, ... 29622272, 4096, ) == 0x0 02483 400 NtAllocateVirtualMemory (344, 0, 0, 1910, 4096, 4, ... 65536, 4096, ) == 0x0 02484 400 NtWriteVirtualMemory (344, 0x10000, (344, 0x10000, "=\0:\0:\0=\0:\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0p\0o\0l\0y\0u\0n\0p\0a\0c\0k\0\0\0=\0E\0x\0i\0t\0C\0o\0d\0e\0=\00\00\00\00\00\00\00\02\0\0\0=\0U\0:\0=\0U\0:\0\\0s\0t\0a\0r\0t\0u\0p\0s\0c\0r\0i\0p\0t\0s\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0C\0L\0I\0E\0N\0T\0N\0A\0M\0E\0=\0C\0o\0n\0s\0o\0l\0e\0\0\0C\0o\0m\0m\0o\0n\0P\0r\0o\0g\0r\0a\0m\0F\0i\0l\0e\0s\0=\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0C\0O\0M\0", 1910, ... 0x0, ) , 1910, ... 0x0, ) == 0x0 02485 400 NtAllocateVirtualMemory (344, 0, 0, 1660, 4096, 4, ... 131072, 4096, ) == 0x0 02486 400 NtWriteVirtualMemory (344, 0x20000, (344, 0x20000, "\0\20\0\0|\6\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0&\0\10\2\220\2\0\0\16\0\0\0\374\0\376\0\230\4\0\0B\0D\0\230\5\0\0t\0v\0\334\5\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\2\0T\6\0\0\36\0 \0X\6\0\0\0\0\2\0x\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1660, ... 0x0, ) , 1660, ... 0x0, ) == 0x0 02487 400 NtWriteVirtualMemory (344, 0x7ffdf010, (344, 0x7ffdf010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02488 400 NtWriteVirtualMemory (344, 0x7ffdf1e8, (344, 0x7ffdf1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02489 400 NtFreeVirtualMemory (-1, (0x1c40000), 0, 32768, ... (0x1c40000), 4096, ) == 0x0 02490 400 NtAllocateVirtualMemory (344, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 02491 400 NtAllocateVirtualMemory (344, 1236992, 0, 8192, 4096, 4, ... 1236992, 8192, ) == 0x0 02492 400 NtProtectVirtualMemory (344, (0x12e000), 4096, 260, ... (0x12e000), 4096, 4, ) == 0x0 02493 400 NtCreateThread (0x1f03ff, 0x0, 344, 1239616, 1240336, 1, ... 348, {1824, 1820}, ) == 0x0 02494 400 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 1312680, 1310720, 1394184, 1241436} (24, {168, 196, new_msg, 0, 1312680, 1310720, 1394184, 1241436} "\0\0\0\0\0\0\1\0\2$\370w U\367w[\1\0\0\\1\0\0 \7\0\0\34\7\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\350\6\24\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0s\0t\0e\0" ... {168, 196, reply, 0, 396, 400, 1584, 0} "\0\0\0\0\0\0\1\0\0\0\0\0 U\367wX\1\0\0\\1\0\0 \7\0\0\34\7\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\350\6\24\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0s\0t\0e\0" ) ... {168, 196, reply, 0, 396, 400, 1584, 0} (24, {168, 196, new_msg, 0, 1312680, 1310720, 1394184, 1241436} "\0\0\0\0\0\0\1\0\2$\370w U\367w[\1\0\0\\1\0\0 \7\0\0\34\7\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\350\6\24\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0s\0t\0e\0" ... {168, 196, reply, 0, 396, 400, 1584, 0} "\0\0\0\0\0\0\1\0\0\0\0\0 U\367wX\1\0\0\\1\0\0 \7\0\0\34\7\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\350\6\24\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\375\177\0\0\0\0\0\0s\0t\0e\0" ) ) == 0x0 02495 400 NtResumeThread (348, ... 1, ) == 0x0 02496 400 NtClose (320, ... ) == 0x0 02497 400 NtClose (332, ... ) == 0x0 02498 400 NtDelayExecution (0, {-2000000, -1}, ... ) == 0x0 02499 400 NtClose (344, ... ) == 0x0 02500 400 NtClose (348, ... ) == 0x0 02501 400 NtTerminateProcess (0, 0, ... ) == 0x0 02502 400 NtFreeVirtualMemory (-1, (0x1b10000), 0, 32768, ... (0x1b10000), 65536, ) == 0x0 02503 400 NtClose (284, ... ) == 0x0 02504 400 NtClose (288, ... ) == 0x0 02505 400 NtClose (296, ... ) == 0x0 02506 400 NtClose (292, ... ) == 0x0 02507 400 NtClose (300, ... ) == 0x0 02508 400 NtClose (272, ... ) == 0x0 02509 400 NtClose (280, ... ) == 0x0 02510 400 NtClose (316, ... ) == 0x0 02511 400 NtClose (312, ... ) == 0x0 02512 400 NtClose (308, ... ) == 0x0 02513 400 NtClose (304, ... ) == 0x0 02514 400 NtClose (276, ... ) == 0x0 02515 400 NtClose (260, ... ) == 0x0 02516 400 NtClose (256, ... ) == 0x0 02517 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x11,}, 4, ... ) == 0x0 02518 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x12,}, 4, ... ) == 0x0 02519 400 NtClose (248, ... ) == 0x0 02520 400 NtUnmapViewOfSection (-1, 0x1af0000, ... ) == 0x0 02521 400 NtClose (252, ... ) == 0x0 02522 400 NtClose (244, ... ) == 0x0 02523 400 NtClose (232, ... ) == 0x0 02524 400 NtClose (236, ... ) == 0x0 02525 400 NtClose (240, ... ) == 0x0 02526 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x10,}, 4, ... ) == 0x0 02527 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xf,}, 4, ... ) == 0x0 02528 400 NtWaitForMultipleObjects (2, (204, 212, ), 1, 0, 0x0, ... ) == 0x1 02529 400 NtClose (212, ... ) == 0x0 02530 400 NtSetEvent (204, ... 0x0, ) == 0x0 02531 400 NtClose (204, ... ) == 0x0 02532 400 NtWaitForMultipleObjects (2, (216, 220, ), 1, 0, 0x0, ... ) == 0x1 02533 400 NtClose (220, ... ) == 0x0 02534 400 NtSetEvent (216, ... 0x0, ) == 0x0 02535 400 NtClose (216, ... ) == 0x0 02536 400 NtWaitForMultipleObjects (2, (224, 228, ), 1, 0, 0x0, ... ) == 0x1 02537 400 NtClose (228, ... ) == 0x0 02538 400 NtSetEvent (224, ... 0x0, ) == 0x0 02539 400 NtClose (224, ... ) == 0x0 02540 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xe,}, 4, ... ) == 0x0 02541 400 NtFreeVirtualMemory (-1, (0x1ab0000), 0, 32768, ... (0x1ab0000), 262144, ) == 0x0 02542 400 NtUserUnregisterClass (1241736, 1991376896, 1241724, ... ) == 0x0 02543 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xc,}, 4, ... ) == 0x0 02544 400 NtClose (132, ... ) == 0x0 02545 400 NtUnmapViewOfSection (-1, 0x1a60000, ... ) == 0x0 02546 400 NtClose (136, ... ) == 0x0 02547 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 02548 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xb,}, 4, ... ) == 0x0 02549 400 NtClose (104, ... ) == 0x0 02550 400 NtClose (92, ... ) == 0x0 02551 400 NtClose (108, ... ) == 0x0 02552 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc03b 02553 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02554 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc03d 02555 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02556 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc03f 02557 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02558 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc041 02559 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02560 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc043 02561 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02562 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc045 02563 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02564 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc047 02565 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02566 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc049 02567 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02568 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc04b 02569 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02570 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc04d 02571 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02572 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc04f 02573 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02574 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc051 02575 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02576 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc053 02577 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02578 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc057 02579 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02580 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc059 02581 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02582 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc05b 02583 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02584 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc05d 02585 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02586 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc05f 02587 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02588 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc017 02589 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02590 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc019 02591 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02592 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc018 02593 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02594 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc01a 02595 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02596 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc01c 02597 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02598 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc01e 02599 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02600 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc01b 02601 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02602 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc068 02603 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02604 400 NtUserGetClassInfo (1905590272, 1241824, 1241776, 1241852, 0, ... ) == 0xc06a 02605 400 NtUserUnregisterClass (1241828, 1905590272, 1241816, ... ) == 0x1 02606 400 NtUnmapViewOfSection (-1, 0x1a70000, ... ) == 0x0 02607 400 NtClose (100, ... ) == 0x0 02608 400 NtClose (88, ... ) == 0x0 02609 400 NtWaitForSingleObject (156, 0, 0x0, ... ) == 0x0 02610 400 NtClearEvent (156, ... ) == 0x0 02611 400 NtSetEvent (156, ... 0x0, ) == 0x0 02612 400 NtClose (156, ... ) == 0x0 02613 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 02614 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 02615 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x7,}, 4, ... ) == 0x0 02616 400 NtQueryVirtualMemory (-1, 0x356d20, Basic, 28, ... {BaseAddress=0x356000,AllocationBase=0x320000,AllocationProtect=0x80,RegionSize=0x12000,State=0x1000,Protect=0x4,Type=0x1000000,}, 28, ) == 0x0 02617 400 NtQueryVirtualMemory (-1, 0x35762c, Basic, 28, ... {BaseAddress=0x357000,AllocationBase=0x320000,AllocationProtect=0x80,RegionSize=0x11000,State=0x1000,Protect=0x4,Type=0x1000000,}, 28, ) == 0x0 02618 400 NtQueryVirtualMemory (-1, 0x32cef4, Basic, 28, ... {BaseAddress=0x32c000,AllocationBase=0x320000,AllocationProtect=0x80,RegionSize=0x3c000,State=0x1000,Protect=0x4,Type=0x1000000,}, 28, ) == 0x0 02619 400 NtGdiDeleteObjectApp (973734880, ... ) == 0x1 02620 400 NtGdiDeleteObjectApp (487195621, ... ) == 0x1 02621 400 NtGdiDeleteObjectApp (1040843748, ... ) == 0x1 02622 400 NtUserDestroyCursor (65687, 1, ... ) == 0x1 02623 400 NtUserDestroyCursor (65685, 1, ... ) == 0x1 02624 400 NtUserDestroyCursor (327773, 1, ... ) == 0x1 02625 400 NtUserDestroyCursor (196741, 1, ... ) == 0x1 02626 400 NtUserDestroyCursor (196715, 1, ... ) == 0x1 02627 400 NtUserDestroyCursor (196717, 1, ... ) == 0x1 02628 400 NtUserDestroyCursor (131219, 1, ... ) == 0x1 02629 400 NtUserFindExistingCursorIcon (1241124, 1241140, 1241708, ... ) == 0x10011 02630 400 NtDeleteAtom (49180, ... ) == 0x0 02631 400 NtDeleteAtom (49181, ... ) == 0x0 02632 400 NtGdiDeleteObjectApp (117965790, ... ) == 0x1 02633 400 NtClose (80, ... ) == 0x0 02634 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 02635 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x1,}, 4, ... ) == 0x0 02636 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc03b 02637 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02638 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc03d 02639 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02640 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc03f 02641 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02642 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc041 02643 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02644 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc043 02645 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02646 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc045 02647 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02648 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc047 02649 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02650 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc049 02651 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02652 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc04b 02653 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02654 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc04d 02655 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02656 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc04f 02657 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02658 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc051 02659 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02660 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc053 02661 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02662 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc057 02663 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02664 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc059 02665 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02666 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc05b 02667 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02668 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc05d 02669 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02670 400 NtUserGetClassInfo (1999896576, 1241824, 1241776, 1241852, 0, ... ) == 0xc05f 02671 400 NtUserUnregisterClass (1241828, 1999896576, 1241816, ... ) == 0x1 02672 400 NtFreeVirtualMemory (-1, (0x1c30000), 4096, 32768, ... (0x1c30000), 4096, ) == 0x0 02673 400 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 65536, 4323958, 1, 68} (24, {20, 48, new_msg, 0, 65536, 4323958, 1, 68} "\0\0\0\0\3\0\1\0\250=\25\0\0\0\0\0\0\0\0\0" ... {20, 48, reply, 0, 396, 400, 1599, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {20, 48, reply, 0, 396, 400, 1599, 0} (24, {20, 48, new_msg, 0, 65536, 4323958, 1, 68} "\0\0\0\0\3\0\1\0\250=\25\0\0\0\0\0\0\0\0\0" ... {20, 48, reply, 0, 396, 400, 1599, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 02674 400 NtTerminateProcess (-1, 0, ... 02675 400 NtClose (48, ... ) == 0x0