Summary:

NtAddAtom(>) 1 NtUserGetDC(>) 1 NtUserBuildHwndList(>) 4 NtQueryDefaultLocale(>) 15
NtCallbackReturn(>) 1 NtUserGetThreadDesktop(>) 1 NtUserFindWindowEx(>) 4 NtUnmapViewOfSection(>) 15
NtCreateProcessEx(>) 1 NtAccessCheck(>) 2 NtWaitForSingleObject(>) 4 NtCreateSection(>) 18
NtCreateThread(>) 1 NtCreateKey(>) 2 NtWriteFile(>) 4 NtUserRegisterWindowMessage(>) 19
NtDuplicateToken(>) 1 NtEnumerateKey(>) 2 NtWriteVirtualMemory(>) 4 NtOpenProcessTokenEx(>) 25
NtEnumerateValueKey(>) 1 NtGdiCreateSolidBrush(>) 2 NtFreeVirtualMemory(>) 5 NtOpenThreadTokenEx(>) 25
NtFsControlFile(>) 1 NtOpenDirectoryObject(>) 2 NtGdiGetStockObject(>) 5 NtQueryAttributesFile(>) 25
NtGdiCreateBitmap(>) 1 NtOpenEvent(>) 2 NtOpenProcessToken(>) 5 NtQuerySystemInformation(>) 27
NtGdiInit(>) 1 NtOpenSymbolicLinkObject(>) 2 NtCreateFile(>) 6 NtReadVirtualMemory(>) 28
NtGdiQueryFontAssocInfo(>) 1 NtOpenThreadToken(>) 2 NtQueryVolumeInformationFile(>) 6 NtOpenSection(>) 29
NtGdiSelectBitmap(>) 1 NtQueryInstallUILanguage(>) 2 NtSetInformationThread(>) 6 NtQueryInformationToken(>) 31
NtNotifyChangeKey(>) 1 NtQuerySymbolicLinkObject(>) 2 NtOpenProcess(>) 7 NtOpenFile(>) 34
NtOpenKeyedEvent(>) 1 NtRaiseException(>) 2 NtSetInformationProcess(>) 7 NtQueryValueKey(>) 38
NtQueryInformationJobObject(>) 1 NtSetInformationFile(>) 2 NtContinue(>) 8 NtMapViewOfSection(>) 39
NtQueryObject(>) 1 NtTerminateProcess(>) 2 NtQueryDefaultUILanguage(>) 8 NtProtectVirtualMemory(>) 41
NtQueryPerformanceCounter(>) 1 NtCreateEvent(>) 3 NtQuerySection(>) 8 NtUserUnregisterClass(>) 45
NtRegisterThreadTerminatePort(>) 1 NtCreateSemaphore(>) 3 NtRequestWaitReplyPort(>) 8 NtUserFindExistingCursorIcon(>) 48
NtResumeThread(>) 1 NtDuplicateObject(>) 3 NtQueryDirectoryFile(>) 10 NtAllocateVirtualMemory(>) 51
NtSecureConnectPort(>) 1 NtGdiCreateCompatibleDC(>) 3 NtUserSystemParametersInfo(>) 10 NtUserRegisterClassExWOW(>) 63
NtSetSecurityObject(>) 1 NtOpenMutant(>) 3 NtFlushInstructionCache(>) 11 NtUserGetClassInfo(>) 82
NtTestAlert(>) 1 NtSetInformationObject(>) 3 NtQueryInformationProcess(>) 12 NtOpenKey(>) 102
NtUserCallNoParam(>) 1 NtQueryVirtualMemory(>) 4 NtQueryInformationFile(>) 13 NtUserQueryWindow(>) 132
NtUserCallOneParam(>) 1 NtReleaseMutant(>) 4 NtQueryDebugFilterState(>) 15 NtClose(>) 154

Trace:

00001 432 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 432 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00003 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00004 432 NtAllocateVirtualMemory (-1, 0, 0, 2097152, 8192, 4, ... 4784128, 2097152, ) == 0x0 00005 432 NtAllocateVirtualMemory (-1, 4784128, 0, 4096, 4096, 4, ... 4784128, 4096, ) == 0x0 00006 432 NtAllocateVirtualMemory (-1, 4788224, 0, 8192, 4096, 4, ... 4788224, 8192, ) == 0x0 00007 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00008 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2424832, 65536, ) == 0x0 00009 432 NtAllocateVirtualMemory (-1, 2424832, 0, 24576, 4096, 4, ... 2424832, 24576, ) == 0x0 00010 432 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00011 432 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00012 432 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00013 432 NtClose (12, ... ) == 0x0 00014 432 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\U:\startupscripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00015 432 NtQueryVolumeInformationFile (12, 2292424, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00016 432 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... ) == STATUS_INVALID_PARAMETER 00017 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local"}, 2292408, ... ) }, 2292408, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00018 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00019 432 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e60000), 0x0, 937984, ) == 0x0 00020 432 NtClose (16, ... ) == 0x0 00021 432 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00022 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00023 432 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00024 432 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 4793144, {12, 0, 0}, 2290592, 44, ... 24, {24, 16, 0, 65536, 2490368, 18415616}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 4793144, {12, 0, 0}, 2290592, 44, ... 24, {24, 16, 0, 65536, 2490368, 18415616}, {0, 0, 0}, 200, 44, ) == 0x0 00025 432 NtClose (16, ... ) == 0x0 00026 432 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00027 432 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00028 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00029 432 NtQueryVirtualMemory (-1, 0x260000, Basic, 28, ... {BaseAddress=0x260000,AllocationBase=0x260000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00030 432 NtAllocateVirtualMemory (-1, 2490368, 0, 4096, 4096, 4, ... 2490368, 4096, ) == 0x0 00031 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 0, 0, 0, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 412, 432, 1488, 0} "\220;\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ... {28, 56, reply, 0, 412, 432, 1488, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 412, 432, 1488, 0} "\220;\27\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ) == 0x0 00032 432 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00033 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00034 432 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00035 432 NtClose (16, ... ) == 0x0 00036 432 NtAllocateVirtualMemory (-1, 2281472, 0, 4096, 4096, 260, ... 2281472, 4096, ) == 0x0 00037 432 NtOpenMutant (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\NlsCacheMutant"}, ... 16, ) }, ... 16, ) == 0x0 00038 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 28, ) }, ... 28, ) == 0x0 00039 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x270000), 0x0, 90112, ) == 0x0 00040 432 NtClose (28, ... ) == 0x0 00041 432 NtQueryDefaultLocale (0, 2012046252, ... ) == 0x0 00042 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 28, ) }, ... 28, ) == 0x0 00043 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x290000), 0x0, 212992, ) == 0x0 00044 432 NtClose (28, ... ) == 0x0 00045 432 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 28, ) }, ... 28, ) == 0x0 00046 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2d0000), 0x0, 266240, ) == 0x0 00047 432 NtQuerySection (28, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00048 432 NtClose (28, ... ) == 0x0 00049 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 28, ) }, ... 28, ) == 0x0 00050 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x320000), 0x0, 24576, ) == 0x0 00051 432 NtClose (28, ... ) == 0x0 00052 432 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00053 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00054 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00055 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 412, 432, 1490, 0} "8\244\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ... {28, 56, reply, 0, 412, 432, 1490, 0} (24, {28, 56, new_msg, 0, 2012558373, 2012047104, 2013025280, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 412, 432, 1490, 0} "8\244\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ) == 0x0 00056 432 NtProtectVirtualMemory (-1, (0x45d000), 204800, 4, ... (0x45d000), 204800, 128, ) == 0x0 00057 432 NtProtectVirtualMemory (-1, (0x45d000), 204800, 128, ... (0x45d000), 204800, 4, ) == 0x0 00058 432 NtFlushInstructionCache (-1, 4575232, 204800, ... ) == 0x0 00059 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "user32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00060 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77d40000), 0x0, 577536, ) == 0x0 00061 432 NtClose (28, ... ) == 0x0 00062 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00063 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c70000), 0x0, 262144, ) == 0x0 00064 432 NtClose (28, ... ) == 0x0 00065 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00066 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 569344, ) == 0x0 00067 432 NtClose (28, ... ) == 0x0 00068 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 28, ) }, ... 28, ) == 0x0 00069 432 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77cc0000), 0x0, 479232, ) == 0x0 00070 432 NtClose (28, ... ) == 0x0 00071 432 NtProtectVirtualMemory (-1, (0x45d000), 204800, 4, ... (0x45d000), 204800, 64, ) == 0x0 00072 432 NtProtectVirtualMemory (-1, (0x45d000), 204800, 64, ... (0x45d000), 204800, 4, ) == 0x0 00073 432 NtFlushInstructionCache (-1, 4575232, 204800, ... ) == 0x0 00074 432 NtOpenProcessToken (-1, 0x8, ... 28, ) == 0x0 00075 432 NtQueryInformationToken (28, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00076 432 NtClose (28, ... ) == 0x0 00077 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00078 432 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00079 432 NtClose (28, ... ) == 0x0 00080 432 NtAllocateVirtualMemory (-1, 4796416, 0, 4096, 4096, 4, ... 4796416, 4096, ) == 0x0 00081 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00082 432 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00083 432 NtQueryValueKey (28, (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00084 432 NtClose (28, ... ) == 0x0 00085 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 28, ) }, ... 28, ) == 0x0 00086 432 NtQueryValueKey (28, (28, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00087 432 NtClose (28, ... ) == 0x0 00088 432 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 28, ) }, ... 28, ) == 0x0 00089 432 NtSetInformationObject (28, Handle, {Inherit=0,ProtectFromClose=1,}, 2011365632, ... ) == 0x0 00090 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00091 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00092 432 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2, 2147347448, 2294988, 0} (24, {28, 56, new_msg, 0, 2, 2147347448, 2294988, 0} "\210\6\31\1\0\0\0\0\314\4#\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 412, 432, 1492, 0} "XQ\26\0\0\0\0\0\0\0\0\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ) ... {28, 56, reply, 0, 412, 432, 1492, 0} (24, {28, 56, new_msg, 0, 2, 2147347448, 2294988, 0} "\210\6\31\1\0\0\0\0\314\4#\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 412, 432, 1492, 0} "XQ\26\0\0\0\0\0\0\0\0\0!\215\30\34\3\0\0\0\234\6\31\1$\1\0\0" ) ) == 0x0 00093 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00094 432 NtMapViewOfSection (32, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x690000), 0x0, 1060864, ) == 0x0 00095 432 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 36, ) == 0x0 00096 432 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00097 432 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482020, ) == 0x0 00098 432 NtQueryInformationToken (-2147482020, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00099 432 NtQueryInformationToken (-2147482020, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00100 432 NtClose (-2147482020, ... ) == 0x0 00101 432 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 7995392, 4096, ) == 0x0 00102 432 NtFreeVirtualMemory (-1, (0x7a0000), 4096, 32768, ... (0x7a0000), 4096, ) == 0x0 00103 432 NtDuplicateObject (-1, 40, -1, 0x0, 0, 2, ... 48, ) == 0x0 00104 432 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00105 432 NtQueryValueKey (-2147482020, (-2147482020, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00106 432 NtClose (-2147482020, ... ) == 0x0 00107 432 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00108 432 NtQueryValueKey (-2147482020, (-2147482020, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00109 432 NtClose (-2147482020, ... ) == 0x0 00110 432 NtQueryDefaultLocale (0, -104224244, ... ) == 0x0 00111 432 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00112 432 NtUserCallNoParam (24, ... ) == 0x0 00113 432 NtGdiCreateCompatibleDC (0, ... 00114 432 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 7995392, 4096, ) == 0x0 00113 432 NtGdiCreateCompatibleDC ... ) == 0x100103ce 00115 432 NtGdiGetStockObject (0, ... ) == 0x1900010 00116 432 NtGdiGetStockObject (4, ... ) == 0x1900011 00117 432 NtGdiCreateBitmap (8, 8, 1, 1, 2010393708, ... ) == 0x13050402 00118 432 NtGdiCreateSolidBrush (0, 0, ... 00119 432 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 11206656, 4096, ) == 0x0 00118 432 NtGdiCreateSolidBrush ... ) == 0xe100408 00120 432 NtGdiGetStockObject (13, ... ) == 0x18a0021 00121 432 NtGdiCreateCompatibleDC (0, ... ) == 0x39010416 00122 432 NtGdiSelectBitmap (956367894, 319095810, ... ) == 0x185000f 00123 432 NtUserGetThreadDesktop (432, 0, ... ) == 0x2c 00124 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 52, ) }, ... 52, ) == 0x0 00125 432 NtQueryValueKey (52, (52, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (52, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00126 432 NtClose (52, ... ) == 0x0 00127 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00128 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 673, 128, 0, ... ) == 0x810dc017 00129 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00130 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 674, 128, 0, ... ) == 0x810dc01c 00131 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00132 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 675, 128, 0, ... ) == 0x810dc01e 00133 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00134 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 676, 128, 0, ... ) == 0x810d8002 00135 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10013 00136 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 677, 128, 0, ... ) == 0x810dc018 00137 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00138 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 678, 128, 0, ... ) == 0x810dc01a 00139 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00140 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 679, 128, 0, ... ) == 0x810dc01d 00141 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00142 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 681, 128, 0, ... 00143 432 NtAllocateVirtualMemory (-1, 8155136, 0, 4096, 4096, 32, ... 8155136, 4096, ) == 0x0 00142 432 NtUserRegisterClassExWOW ... ) == 0x810dc026 00144 432 NtUserFindExistingCursorIcon (2289780, 2289796, 2290364, ... ) == 0x10011 00145 432 NtUserRegisterClassExWOW (2290300, 2290380, 2290364, 2290396, 680, 128, 0, ... ) == 0x810dc019 00146 432 NtUserRegisterClassExWOW (2290252, 2290332, 2290316, 2290348, 0, 128, 0, ... ) == 0x810dc020 00147 432 NtUserRegisterClassExWOW (2290252, 2290328, 2290344, 2290316, 0, 130, 0, ... ) == 0x810dc022 00148 432 NtUserRegisterClassExWOW (2290252, 2290332, 2290316, 2290348, 0, 128, 0, ... ) == 0x810dc023 00149 432 NtUserRegisterClassExWOW (2290252, 2290328, 2290344, 2290316, 0, 130, 0, ... ) == 0x810dc024 00150 432 NtUserRegisterClassExWOW (2290252, 2290332, 2290316, 2290348, 0, 128, 0, ... ) == 0x810dc025 00151 432 NtCallbackReturn (0, 0, 0, ... 00152 432 NtGdiInit (... ) == 0x1 00153 432 NtGdiGetStockObject (18, ... ) == 0x290001c 00154 432 NtGdiGetStockObject (19, ... ) == 0x1b00019 00155 432 NtAllocateVirtualMemory (-1, 0, 0, 17506, 4096, 4, ... 11272192, 20480, ) == 0x0 00156 432 NtFreeVirtualMemory (-1, (0xac0000), 0, 32768, ... (0xac0000), 20480, ) == 0x0 00157 432 NtQueryVirtualMemory (-1, 0x401000, Basic, 52, ... {BaseAddress=0x401000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x23000,State=0x1000,Protect=0x80,Type=0x1000000,}, 28, ) == 0x0 00158 432 NtQueryVirtualMemory (-1, 0x45754c, Basic, 28, ... {BaseAddress=0x457000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x6000,State=0x1000,Protect=0x4,Type=0x1000000,}, 28, ) == 0x0 00159 432 NtAllocateVirtualMemory (-1, 4800512, 0, 4096, 4096, 4, ... 4800512, 4096, ) == 0x0 00160 432 NtProtectVirtualMemory (-1, (0x4001f0), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00161 432 NtProtectVirtualMemory (-1, (0x4001f0), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00162 432 NtProtectVirtualMemory (-1, (0x400218), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00163 432 NtProtectVirtualMemory (-1, (0x400218), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00164 432 NtProtectVirtualMemory (-1, (0x400240), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00165 432 NtProtectVirtualMemory (-1, (0x400240), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00166 432 NtProtectVirtualMemory (-1, (0x400268), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00167 432 NtProtectVirtualMemory (-1, (0x400268), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00168 432 NtProtectVirtualMemory (-1, (0x400290), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00169 432 NtProtectVirtualMemory (-1, (0x400290), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00170 432 NtProtectVirtualMemory (-1, (0x4002b8), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00171 432 NtProtectVirtualMemory (-1, (0x4002b8), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00172 432 NtProtectVirtualMemory (-1, (0x4002e0), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00173 432 NtProtectVirtualMemory (-1, (0x4002e0), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00174 432 NtProtectVirtualMemory (-1, (0x400308), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00175 432 NtProtectVirtualMemory (-1, (0x400308), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00176 432 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00177 432 NtUserFindWindowEx (0, 0, (0, 0, "WispWindowClass", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00178 432 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x100aa, 0x100a8, 0x100a6, 0x20060, 0x100a4, 0x1007e, 0x10074, 0x10068, 0x3004a, 0x10066, 0x3004c, 0x3003c, 0x1009c, 0x10090, 0x1007c, 0x10026, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b6, 0x100b4, 0x100b2, 0x100ae, 0x20064, 0x100ac, 0x20062, 0x1006c, 0x50050, 0x40054, 0x5004e, 0x10082, 0x10076, 0x1, ), 34, ) == 0x0 00179 432 NtUserQueryWindow (65706, 0, ... ) == 0x7e8 00180 432 NtUserQueryWindow (65706, 1, ... ) == 0x7ec 00181 432 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {2024, 0}, ... 52, ) == 0x0 00182 432 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 \1\0\0", 64, ) , 64, ) == 0x0 00183 432 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00184 432 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00185 432 NtClose (52, ... ) == 0x0 00186 432 NtUserQueryWindow (65704, 0, ... ) == 0x7e8 00187 432 NtUserQueryWindow (65704, 1, ... ) == 0x7ec 00188 432 NtUserQueryWindow (65702, 0, ... ) == 0x7e8 00189 432 NtUserQueryWindow (65702, 1, ... ) == 0x7ec 00190 432 NtUserQueryWindow (131168, 0, ... ) == 0x7e8 00191 432 NtUserQueryWindow (131168, 1, ... ) == 0x7ec 00192 432 NtUserQueryWindow (65700, 0, ... ) == 0x77c 00193 432 NtUserQueryWindow (65700, 1, ... ) == 0x78c 00194 432 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {1916, 0}, ... 52, ) == 0x0 00195 432 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00196 432 NtReadVirtualMemory (52, 0x4b1c86, 4, ... 00197 432 NtContinue (-104227684, 0, ... 00196 432 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00198 432 NtReadVirtualMemory (52, 0x4c91a0, 256, ... 00199 432 NtContinue (-104227684, 0, ... 00198 432 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00200 432 NtClose (52, ... ) == 0x0 00201 432 NtUserQueryWindow (65662, 0, ... ) == 0x77c 00202 432 NtUserQueryWindow (65662, 1, ... ) == 0x78c 00203 432 NtUserQueryWindow (65652, 0, ... ) == 0x77c 00204 432 NtUserQueryWindow (65652, 1, ... ) == 0x78c 00205 432 NtUserQueryWindow (65640, 0, ... ) == 0x77c 00206 432 NtUserQueryWindow (65640, 1, ... ) == 0x78c 00207 432 NtUserQueryWindow (196682, 0, ... ) == 0x77c 00208 432 NtUserQueryWindow (196682, 1, ... ) == 0x78c 00209 432 NtUserQueryWindow (65638, 0, ... ) == 0x77c 00210 432 NtUserQueryWindow (65638, 1, ... ) == 0x78c 00211 432 NtUserQueryWindow (196684, 0, ... ) == 0x77c 00212 432 NtUserQueryWindow (196684, 1, ... ) == 0x78c 00213 432 NtUserQueryWindow (196668, 0, ... ) == 0x77c 00214 432 NtUserQueryWindow (196668, 1, ... ) == 0x78c 00215 432 NtUserQueryWindow (65692, 0, ... ) == 0x77c 00216 432 NtUserQueryWindow (65692, 1, ... ) == 0x78c 00217 432 NtUserQueryWindow (65680, 0, ... ) == 0x77c 00218 432 NtUserQueryWindow (65680, 1, ... ) == 0x78c 00219 432 NtUserQueryWindow (65660, 0, ... ) == 0x77c 00220 432 NtUserQueryWindow (65660, 1, ... ) == 0x780 00221 432 NtUserQueryWindow (65574, 0, ... ) == 0x268 00222 432 NtUserQueryWindow (65574, 1, ... ) == 0x2c4 00223 432 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {616, 0}, ... 52, ) == 0x0 00224 432 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00225 432 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00226 432 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00227 432 NtClose (52, ... ) == 0x0 00228 432 NtUserQueryWindow (65726, 0, ... ) == 0x7f0 00229 432 NtUserQueryWindow (65726, 1, ... ) == 0x7f4 00230 432 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {2032, 0}, ... 52, ) == 0x0 00231 432 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0", 64, ) , 64, ) == 0x0 00232 432 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\377\0\377\377", 4, ) , 4, ) == 0x0 00233 432 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\210fvx\210x\206wfvGe$\306d\21\26\210ls\210\210\250g\207\210hhx\207xhvwdfF|d\21\27\210\206hx\250\252\206\210\207v\207\210x\207\207gfv4F\306G\21\21\210\206\207\210\212\250\250h\210\207x\210\210wvwgFD$d!\21\21x\250g\210\212\252\250\206\210\207w\210\207\207wvvgBGd\21\21\21\210\212\203\210\250\252\212\210x\210w\210\210xwgcd%F\1\21\21\21\27\212\250\210\212\252\252\210f\210\207x\210\207w7fR@`\21\21\21\21\21\210\2508\212\252\250\250\210gw\21088vvu$$!\21\21\21\21\21\30\210\210\210\212\252\210\206vgw\210\203wsb`\7\21\21\21\21\21\21\21\210\203\210\210\210\210\207vvwwwsf4\7\21\21\21\21\21\21\21\21\30\210\210\210\210\210wGwvwww5\2\21\21\21\21\21\21", 256, ) , 256, ) == 0x0 00234 432 NtClose (52, ... ) == 0x0 00235 432 NtUserQueryWindow (65724, 0, ... ) == 0x7f0 00236 432 NtUserQueryWindow (65724, 1, ... ) == 0x7f4 00237 432 NtUserQueryWindow (65722, 0, ... ) == 0x7f0 00238 432 NtUserQueryWindow (65722, 1, ... ) == 0x7f4 00239 432 NtUserQueryWindow (65720, 0, ... ) == 0x7f0 00240 432 NtUserQueryWindow (65720, 1, ... ) == 0x7f4 00241 432 NtUserQueryWindow (65718, 0, ... ) == 0x7f0 00242 432 NtUserQueryWindow (65718, 1, ... ) == 0x7f4 00243 432 NtUserQueryWindow (65716, 0, ... ) == 0x7f0 00244 432 NtUserQueryWindow (65716, 1, ... ) == 0x7f4 00245 432 NtUserQueryWindow (65714, 0, ... ) == 0x7f0 00246 432 NtUserQueryWindow (65714, 1, ... ) == 0x7f4 00247 432 NtUserQueryWindow (65710, 0, ... ) == 0x7f0 00248 432 NtUserQueryWindow (65710, 1, ... ) == 0x7f4 00249 432 NtUserQueryWindow (131172, 0, ... ) == 0x7fc 00250 432 NtUserQueryWindow (131172, 1, ... ) == 0x70 00251 432 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {2044, 0}, ... 52, ) == 0x0 00252 432 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "\301\0\0\0\0\1\0\0\377\356\377\356\11\0\0\0\11\0\0\0\0\376\0\0\0\0\20\0\0 \0\0\0\2\0\0\0 \0\0q\0\0\0\377\357\375\177\0\0\10\6\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00253 432 NtReadVirtualMemory (52, 0x4b1c86, 4, ... (52, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00254 432 NtReadVirtualMemory (52, 0x4c91a0, 256, ... (52, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00255 432 NtClose (52, ... ) == 0x0 00256 432 NtUserQueryWindow (65708, 0, ... ) == 0x7e8 00257 432 NtUserQueryWindow (65708, 1, ... ) == 0x7ec 00258 432 NtUserQueryWindow (131170, 0, ... ) == 0x7e0 00259 432 NtUserQueryWindow (131170, 1, ... ) == 0x7e4 00260 432 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {2016, 0}, ... 52, ) == 0x0 00261 432 NtReadVirtualMemory (52, 0x400000, 64, ... (52, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0", 64, ) , 64, ) == 0x0 00262 432 NtReadVirtualMemory (52, 0x4b1c86, 4, ... 00263 432 NtContinue (-104227684, 0, ... 00262 432 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00264 432 NtReadVirtualMemory (52, 0x4c91a0, 256, ... 00265 432 NtContinue (-104227684, 0, ... 00264 432 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00266 432 NtClose (52, ... ) == 0x0 00267 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 00268 432 NtUserQueryWindow (65644, 1, ... ) == 0x7bc 00269 432 NtUserQueryWindow (327760, 0, ... ) == 0x77c 00270 432 NtUserQueryWindow (327760, 1, ... ) == 0x780 00271 432 NtUserQueryWindow (262228, 0, ... ) == 0x77c 00272 432 NtUserQueryWindow (262228, 1, ... ) == 0x780 00273 432 NtUserQueryWindow (327758, 0, ... ) == 0x77c 00274 432 NtUserQueryWindow (327758, 1, ... ) == 0x780 00275 432 NtUserQueryWindow (65666, 0, ... ) == 0x77c 00276 432 NtUserQueryWindow (65666, 1, ... ) == 0x780 00277 432 NtUserQueryWindow (65654, 0, ... ) == 0x77c 00278 432 NtUserQueryWindow (65654, 1, ... ) == 0x780 00279 432 NtRaiseException (2291272, 2290532, 1, ... 00280 432 NtContinue (2289328, 0, ... 00281 432 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 52, ) }, ... 52, ) == 0x0 00282 432 NtOpenMutant (0x120001, {24, 52, 0x2, 0, 0, (0x120001, {24, 52, 0x2, 0, 0, "DBWinMutex"}, ... 56, ) }, ... 56, ) == 0x0 00283 432 NtWaitForSingleObject (56, 0, 0x0, ... ) == 0x0 00284 432 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00285 432 NtReleaseMutant (56, ... 0x0, ) == 0x0 00286 432 NtDuplicateObject (-1, 2877, -1, 0x0, 0, 2, ... ) == STATUS_INVALID_HANDLE 00287 432 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00288 432 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00289 432 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x100aa, 0x100a8, 0x100a6, 0x20060, 0x100a4, 0x1007e, 0x10074, 0x10068, 0x3004a, 0x10066, 0x3004c, 0x3003c, 0x1009c, 0x10090, 0x1007c, 0x10026, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b6, 0x100b4, 0x100b2, 0x100ae, 0x20064, 0x100ac, 0x20062, 0x1006c, 0x50050, 0x40054, 0x5004e, 0x10082, 0x10076, 0x1, ), 34, ) == 0x0 00290 432 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00291 432 NtUserFindWindowEx (0, 0, (0, 0, "WispWindowClass", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00292 432 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x100aa, 0x100a8, 0x100a6, 0x20060, 0x100a4, 0x1007e, 0x10074, 0x10068, 0x3004a, 0x10066, 0x3004c, 0x3003c, 0x1009c, 0x10090, 0x1007c, 0x10026, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b6, 0x100b4, 0x100b2, 0x100ae, 0x20064, 0x100ac, 0x20062, 0x1006c, 0x50050, 0x40054, 0x5004e, 0x10082, 0x10076, 0x1, ), 34, ) == 0x0 00293 432 NtUserQueryWindow (65706, 0, ... ) == 0x7e8 00294 432 NtUserQueryWindow (65706, 1, ... ) == 0x7ec 00295 432 NtUserQueryWindow (65704, 0, ... ) == 0x7e8 00296 432 NtUserQueryWindow (65704, 1, ... ) == 0x7ec 00297 432 NtUserQueryWindow (65702, 0, ... ) == 0x7e8 00298 432 NtUserQueryWindow (65702, 1, ... ) == 0x7ec 00299 432 NtUserQueryWindow (131168, 0, ... ) == 0x7e8 00300 432 NtUserQueryWindow (131168, 1, ... ) == 0x7ec 00301 432 NtUserQueryWindow (65700, 0, ... ) == 0x77c 00302 432 NtUserQueryWindow (65700, 1, ... ) == 0x78c 00303 432 NtUserQueryWindow (65662, 0, ... ) == 0x77c 00304 432 NtUserQueryWindow (65662, 1, ... ) == 0x78c 00305 432 NtUserQueryWindow (65652, 0, ... ) == 0x77c 00306 432 NtUserQueryWindow (65652, 1, ... ) == 0x78c 00307 432 NtUserQueryWindow (65640, 0, ... ) == 0x77c 00308 432 NtUserQueryWindow (65640, 1, ... ) == 0x78c 00309 432 NtUserQueryWindow (196682, 0, ... ) == 0x77c 00310 432 NtUserQueryWindow (196682, 1, ... ) == 0x78c 00311 432 NtUserQueryWindow (65638, 0, ... ) == 0x77c 00312 432 NtUserQueryWindow (65638, 1, ... ) == 0x78c 00313 432 NtUserQueryWindow (196684, 0, ... ) == 0x77c 00314 432 NtUserQueryWindow (196684, 1, ... ) == 0x78c 00315 432 NtUserQueryWindow (196668, 0, ... ) == 0x77c 00316 432 NtUserQueryWindow (196668, 1, ... ) == 0x78c 00317 432 NtUserQueryWindow (65692, 0, ... ) == 0x77c 00318 432 NtUserQueryWindow (65692, 1, ... ) == 0x78c 00319 432 NtUserQueryWindow (65680, 0, ... ) == 0x77c 00320 432 NtUserQueryWindow (65680, 1, ... ) == 0x78c 00321 432 NtUserQueryWindow (65660, 0, ... ) == 0x77c 00322 432 NtUserQueryWindow (65660, 1, ... ) == 0x780 00323 432 NtUserQueryWindow (65574, 0, ... ) == 0x268 00324 432 NtUserQueryWindow (65574, 1, ... ) == 0x2c4 00325 432 NtUserQueryWindow (65726, 0, ... ) == 0x7f0 00326 432 NtUserQueryWindow (65726, 1, ... ) == 0x7f4 00327 432 NtUserQueryWindow (65724, 0, ... ) == 0x7f0 00328 432 NtUserQueryWindow (65724, 1, ... ) == 0x7f4 00329 432 NtUserQueryWindow (65722, 0, ... ) == 0x7f0 00330 432 NtUserQueryWindow (65722, 1, ... ) == 0x7f4 00331 432 NtUserQueryWindow (65720, 0, ... ) == 0x7f0 00332 432 NtUserQueryWindow (65720, 1, ... ) == 0x7f4 00333 432 NtUserQueryWindow (65718, 0, ... ) == 0x7f0 00334 432 NtUserQueryWindow (65718, 1, ... ) == 0x7f4 00335 432 NtUserQueryWindow (65716, 0, ... ) == 0x7f0 00336 432 NtUserQueryWindow (65716, 1, ... ) == 0x7f4 00337 432 NtUserQueryWindow (65714, 0, ... ) == 0x7f0 00338 432 NtUserQueryWindow (65714, 1, ... ) == 0x7f4 00339 432 NtUserQueryWindow (65710, 0, ... ) == 0x7f0 00340 432 NtUserQueryWindow (65710, 1, ... ) == 0x7f4 00341 432 NtUserQueryWindow (131172, 0, ... ) == 0x7fc 00342 432 NtUserQueryWindow (131172, 1, ... ) == 0x70 00343 432 NtUserQueryWindow (65708, 0, ... ) == 0x7e8 00344 432 NtUserQueryWindow (65708, 1, ... ) == 0x7ec 00345 432 NtUserQueryWindow (131170, 0, ... ) == 0x7e0 00346 432 NtUserQueryWindow (131170, 1, ... ) == 0x7e4 00347 432 NtUserQueryWindow (65644, 0, ... ) == 0x77c 00348 432 NtUserQueryWindow (65644, 1, ... ) == 0x7bc 00349 432 NtUserQueryWindow (327760, 0, ... ) == 0x77c 00350 432 NtUserQueryWindow (327760, 1, ... ) == 0x780 00351 432 NtUserQueryWindow (262228, 0, ... ) == 0x77c 00352 432 NtUserQueryWindow (262228, 1, ... ) == 0x780 00353 432 NtUserQueryWindow (327758, 0, ... ) == 0x77c 00354 432 NtUserQueryWindow (327758, 1, ... ) == 0x780 00355 432 NtUserQueryWindow (65666, 0, ... ) == 0x77c 00356 432 NtUserQueryWindow (65666, 1, ... ) == 0x780 00357 432 NtUserQueryWindow (65654, 0, ... ) == 0x77c 00358 432 NtUserQueryWindow (65654, 1, ... ) == 0x780 00359 432 NtRaiseException (2291216, 2290476, 1, ... 00360 432 NtContinue (2289272, 0, ... 00361 432 NtWaitForSingleObject (56, 0, 0x0, ... ) == 0x0 00362 432 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00363 432 NtReleaseMutant (56, ... 0x0, ) == 0x0 00364 432 NtDuplicateObject (-1, 3156, -1, 0x0, 0, 2, ... ) == STATUS_INVALID_HANDLE 00365 432 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00366 432 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00367 432 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x100aa, 0x100a8, 0x100a6, 0x20060, 0x100a4, 0x1007e, 0x10074, 0x10068, 0x3004a, 0x10066, 0x3004c, 0x3003c, 0x1009c, 0x10090, 0x1007c, 0x10026, 0x100be, 0x100bc, 0x100ba, 0x100b8, 0x100b6, 0x100b4, 0x100b2, 0x100ae, 0x20064, 0x100ac, 0x20062, 0x1006c, 0x50050, 0x40054, 0x5004e, 0x10082, 0x10076, 0x1, ), 34, ) == 0x0 00368 432 NtSetSecurityObject (-1, 4, {1, 0, 0x4, 0, 0, 0, 2291052}, ... ) == 0x0 00369 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 60, ) }, ... 60, ) == 0x0 00370 432 NtQueryValueKey (60, (60, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00371 432 NtClose (60, ... ) == 0x0 00372 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MPR.dll"}, ... 60, ) }, ... 60, ) == 0x0 00373 432 NtMapViewOfSection (60, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71b20000), 0x0, 69632, ) == 0x0 00374 432 NtClose (60, ... ) == 0x0 00375 432 NtCreateSemaphore (0x1f0003, 0x0, 1, 1, ... 60, ) == 0x0 00376 432 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 64, ) == 0x0 00377 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "system\CurrentControlSet\control\NetworkProvider\HwOrder"}, ... 68, ) }, ... 68, ) == 0x0 00378 432 NtNotifyChangeKey (68, 64, 0, 0, 2011390432, 4, 0, 0, 0, 1, ... ) == 0x103 00379 432 NtQueryInformationProcess (-1, 28, 4, ... {process info, class 28, size 4}, 0x0, ) == 0x0 00380 432 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 72, ) == 0x0 00381 432 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 76, ) == 0x0 00382 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ODBC32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00383 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ODBC32.dll"}, 2290060, ... ) }, 2290060, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00384 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "ODBC32.dll"}, 2290060, ... ) }, 2290060, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00385 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ODBC32.dll"}, 2290060, ... ) }, 2290060, ... ) == 0x0 00386 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\ODBC32.dll"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00387 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 80, ... 84, ) == 0x0 00388 432 NtQuerySection (84, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00389 432 NtOpenProcessToken (-1, 0x8, ... 88, ) == 0x0 00390 432 NtQueryInformationToken (88, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00391 432 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00392 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 92, ) }, ... 92, ) == 0x0 00393 432 NtQueryValueKey (92, (92, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (92, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00394 432 NtClose (92, ... ) == 0x0 00395 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00396 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 92, ) == 0x0 00397 432 NtQueryInformationToken (92, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00398 432 NtClose (92, ... ) == 0x0 00399 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00400 432 NtClose (88, ... ) == 0x0 00401 432 NtClose (80, ... ) == 0x0 00402 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x1f7b0000), 0x0, 200704, ) == 0x0 00403 432 NtClose (84, ... ) == 0x0 00404 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMCTL32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00405 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77340000), 0x0, 569344, ) == 0x0 00406 432 NtClose (84, ... ) == 0x0 00407 432 NtProtectVirtualMemory (-1, (0x1f7b1000), 724, 4, ... (0x1f7b1000), 4096, 32, ) == 0x0 00408 432 NtProtectVirtualMemory (-1, (0x1f7b1000), 4096, 32, ... (0x1f7b1000), 4096, 4, ) == 0x0 00409 432 NtFlushInstructionCache (-1, 528158720, 724, ... ) == 0x0 00410 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "comdlg32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00411 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x763b0000), 0x0, 282624, ) == 0x0 00412 432 NtClose (84, ... ) == 0x0 00413 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHLWAPI.dll"}, ... 84, ) }, ... 84, ) == 0x0 00414 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x772d0000), 0x0, 405504, ) == 0x0 00415 432 NtClose (84, ... ) == 0x0 00416 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "msvcrt.dll"}, ... 84, ) }, ... 84, ) == 0x0 00417 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 339968, ) == 0x0 00418 432 NtClose (84, ... ) == 0x0 00419 432 NtProtectVirtualMemory (-1, (0x763b1000), 1536, 4, ... (0x763b1000), 4096, 32, ) == 0x0 00420 432 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 00421 432 NtFlushInstructionCache (-1, 1983582208, 1536, ... ) == 0x0 00422 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHELL32.dll"}, ... 84, ) }, ... 84, ) == 0x0 00423 432 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x773d0000), 0x0, 8339456, ) == 0x0 00424 432 NtClose (84, ... ) == 0x0 00425 432 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {412, 0}, ... 84, ) == 0x0 00426 432 NtQueryInformationProcess (84, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 00427 432 NtClose (84, ... ) == 0x0 00428 432 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00429 432 NtUserSystemParametersInfo (104, 0, 2000318720, 0, ... ) == 0x1 00430 432 NtUserSystemParametersInfo (38, 4, 2000318708, 0, ... ) == 0x1 00431 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00432 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 84, ) == 0x0 00433 432 NtQueryInformationToken (84, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00434 432 NtClose (84, ... ) == 0x0 00435 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 84, ) }, ... 84, ) == 0x0 00436 432 NtSetInformationObject (84, Handle, {Inherit=0,ProtectFromClose=1,}, 2228480, ... ) == 0x0 00437 432 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Control Panel\Desktop"}, ... 80, ) }, ... 80, ) == 0x0 00438 432 NtQueryValueKey (80, (80, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00439 432 NtClose (80, ... ) == 0x0 00440 432 NtUserSystemParametersInfo (41, 500, 2289792, 0, ... ) == 0x1 00441 432 NtUserSystemParametersInfo (102, 0, 2000318732, 0, ... ) == 0x1 00442 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00443 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00444 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc03b 00445 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00446 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc03d 00447 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00448 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00449 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc03f 00450 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00451 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00452 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc041 00453 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00454 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00455 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc043 00456 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00457 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc045 00458 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00459 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00460 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc047 00461 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00462 432 NtUserFindExistingCursorIcon (2289580, 2289596, 2290164, ... ) == 0x10011 00463 432 NtUserRegisterClassExWOW (2290032, 2290112, 2290096, 2290128, 0, 384, 0, ... ) == 0x810dc049 00464 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00465 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00466 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc04b 00467 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00468 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00469 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc04d 00470 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00471 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00472 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc04f 00473 432 NtUserGetClassInfo (1999896576, 2290204, 2290156, 2290232, 0, ... ) == 0x0 00474 432 NtUserRegisterClassExWOW (2290040, 2290120, 2290104, 2290136, 0, 384, 0, ... ) == 0x810dc051 00475 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00476 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00477 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc053 00478 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00479 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00480 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc055 00481 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc057 00482 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00483 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00484 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc059 00485 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00486 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10013 00487 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc05b 00488 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00489 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00490 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc05d 00491 432 NtUserGetClassInfo (1999896576, 2290200, 2290152, 2290228, 0, ... ) == 0x0 00492 432 NtUserFindExistingCursorIcon (2289584, 2289600, 2290168, ... ) == 0x10011 00493 432 NtUserRegisterClassExWOW (2290036, 2290116, 2290100, 2290132, 0, 384, 0, ... ) == 0x810dc05f 00494 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00495 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 11272192, 65536, ) == 0x0 00496 432 NtAllocateVirtualMemory (-1, 11272192, 0, 4096, 4096, 4, ... 11272192, 4096, ) == 0x0 00497 432 NtAllocateVirtualMemory (-1, 11276288, 0, 8192, 4096, 4, ... 11276288, 8192, ) == 0x0 00498 432 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 80, ) }, ... 80, ) == 0x0 00499 432 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xad0000), 0x0, 12288, ) == 0x0 00500 432 NtClose (80, ... ) == 0x0 00501 432 NtAllocateVirtualMemory (-1, 11284480, 0, 4096, 4096, 4, ... 11284480, 4096, ) == 0x0 00502 432 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00503 432 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 80, ) }, ... 80, ) == 0x0 00504 432 NtQueryValueKey (80, (80, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (80, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00505 432 NtClose (80, ... ) == 0x0 00506 432 NtQueryDefaultUILanguage (2288416, ... 00507 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00508 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00509 432 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00510 432 NtClose (-2147482020, ... ) == 0x0 00511 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00512 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00513 432 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00514 432 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00515 432 NtClose (-2147482032, ... ) == 0x0 00516 432 NtClose (-2147482020, ... ) == 0x0 00506 432 NtQueryDefaultUILanguage ... ) == 0x0 00517 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00518 432 NtQueryInstallUILanguage (2012047340, ... ) == 0x0 00519 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1, 96, ... 80, {status=0x0, info=1}, ) }, 1, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00520 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 80, ... 88, ) == 0x0 00521 432 NtMapViewOfSection (88, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0xae0000), 0x0, 8323072, ) == 0x0 00522 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00523 432 NtQueryDefaultUILanguage (2013024600, ... 00524 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00525 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00526 432 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00527 432 NtClose (-2147482020, ... ) == 0x0 00528 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00529 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00530 432 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00531 432 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00532 432 NtClose (-2147482032, ... ) == 0x0 00533 432 NtClose (-2147482020, ... ) == 0x0 00523 432 NtQueryDefaultUILanguage ... ) == 0x0 00534 432 NtAllocateVirtualMemory (-1, 2277376, 0, 4096, 4096, 260, ... 2277376, 4096, ) == 0x0 00535 432 NtQueryInstallUILanguage (2013024602, ... ) == 0x0 00536 432 NtQueryDefaultLocale (1, 2286452, ... ) == 0x0 00537 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00538 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2287308, 1, 96, 0} (24, {128, 156, new_msg, 0, 2287308, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1503, 0} " S\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ) \0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355 (24, {128, 156, new_msg, 0, 2287308, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1503, 0} " S\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ) ... {128, 156, reply, 0, 412, 432, 1503, 0} (24, {128, 156, new_msg, 0, 2287308, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1503, 0} " S\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ) \0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355 (24, {128, 156, new_msg, 0, 2287308, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1503, 0} " S\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1P\0\0\0\377\377\377\377\0\0\0\0\20\311\345\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\314\355"\0\0\0\0\0" ) ) == 0x0 00539 432 NtClose (80, ... ) == 0x0 00540 432 NtClose (88, ... ) == 0x0 00541 432 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 00542 432 NtUnmapViewOfSection (-1, 0x22edcc, ... ) == STATUS_NOT_MAPPED_VIEW 00543 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00544 432 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00545 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00546 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00547 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 2285536, ... ) }, 2285536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00548 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00549 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00550 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00551 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 2286128, ... ) }, 2286128, ... ) == 0x0 00552 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 88, {status=0x0, info=1}, ) }, 3, 33, ... 88, {status=0x0, info=1}, ) == 0x0 00553 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00554 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00555 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 80, ... 92, ) == 0x0 00556 432 NtClose (80, ... ) == 0x0 00557 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xae0000), 0x0, 921600, ) == 0x0 00558 432 NtClose (92, ... ) == 0x0 00559 432 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 00560 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00561 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 92, ... 80, ) == 0x0 00562 432 NtQuerySection (80, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00563 432 NtClose (92, ... ) == 0x0 00564 432 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71950000), 0x0, 933888, ) == 0x0 00565 432 NtClose (80, ... ) == 0x0 00566 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00567 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00568 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00569 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00570 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00571 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00572 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00573 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00574 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00575 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00576 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00577 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00578 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00579 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00580 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00581 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00582 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00583 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00584 432 NtProtectVirtualMemory (-1, (0x71951000), 1952, 4, ... (0x71951000), 4096, 32, ) == 0x0 00585 432 NtProtectVirtualMemory (-1, (0x71951000), 4096, 32, ... (0x71951000), 4096, 4, ) == 0x0 00586 432 NtFlushInstructionCache (-1, 1905594368, 1952, ... ) == 0x0 00587 432 NtAddAtom ( ("T\0h\0e\0m\0e\0P\0r\0o\0p\0S\0c\0r\0o\0l\0l\0B\0a\0r\0C\0t\0l\0", 42, 2287312, ... ) , 42, 2287312, ... ) == 0x0 00588 432 NtQueryDefaultUILanguage (2286028, ... 00589 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00590 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00591 432 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00592 432 NtClose (-2147482020, ... ) == 0x0 00593 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00594 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00595 432 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00596 432 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00597 432 NtClose (-2147482032, ... ) == 0x0 00598 432 NtClose (-2147482020, ... ) == 0x0 00588 432 NtQueryDefaultUILanguage ... ) == 0x0 00599 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00600 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 2284880, ... ) }, 2284880, ... ) == 0x0 00601 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00602 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 80, ... 92, ) == 0x0 00603 432 NtClose (80, ... ) == 0x0 00604 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xae0000), 0x0, 4096, ) == 0x0 00605 432 NtClose (92, ... ) == 0x0 00606 432 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 00607 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 2284520, ... ) }, 2284520, ... ) == 0x0 00608 432 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 2285220, (0x80100080, {24, 0, 0x40, 0, 2285220, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 0x0, 0, 5, 1, 96, 0, 0, ... 92, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 92, {status=0x0, info=1}, ) == 0x0 00609 432 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 92, ... 80, ) == 0x0 00610 432 NtClose (92, ... ) == 0x0 00611 432 NtMapViewOfSection (80, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xae0000), {0, 0}, 4096, ) == 0x0 00612 432 NtClose (80, ... ) == 0x0 00613 432 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 00614 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1, 96, ... 80, {status=0x0, info=1}, ) }, 1, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00615 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 80, ... 92, ) == 0x0 00616 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0xae0000), 0x0, 4096, ) == 0x0 00617 432 NtQueryInformationFile (80, 2284840, 56, NetworkOpen, ... {status=0x0, info=56}, ) == 0x0 00618 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00619 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2284920, 1, 96, 0} (24, {128, 156, new_msg, 0, 2284920, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1504, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344"\0\0\0\0\0" ) \0\0\0\0\0 (24, {128, 156, new_msg, 0, 2284920, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1504, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344"\0\0\0\0\0" ) h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344 (24, {128, 156, new_msg, 0, 2284920, 1, 96, 0} "\210\6\31\1\33\0\1\0\240\315Z\371\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1504, 0} "h\334\26\0\33\0\1\0\0\0\0\0\2209\307\1\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1P\0\0\0\\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\344"\0\0\0\0\0" ) ) == 0x0 00620 432 NtClose (80, ... ) == 0x0 00621 432 NtClose (92, ... ) == 0x0 00622 432 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 00623 432 NtUnmapViewOfSection (-1, 0x22e478, ... ) == STATUS_NOT_MAPPED_VIEW 00624 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00625 432 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 00626 432 NtUserSystemParametersInfo (104, 0, 1906151468, 0, ... ) == 0x1 00627 432 NtUserGetDC (0, ... ) == 0x1010050 00628 432 NtUserCallOneParam (16842832, 56, ... ) == 0x1 00629 432 NtUserSystemParametersInfo (38, 4, 1906153440, 0, ... ) == 0x1 00630 432 NtUserSystemParametersInfo (66, 12, 2287332, 0, ... ) == 0x1 00631 432 NtOpenProcessToken (-1, 0x8, ... 92, ) == 0x0 00632 432 NtAccessCheck (4801512, 92, 0x1, 2286736, 2286680, 56, 2286764, ... ) == STATUS_NO_IMPERSONATION_TOKEN 00633 432 NtClose (92, ... ) == 0x0 00634 432 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Control Panel\Desktop"}, ... 92, ) }, ... 92, ) == 0x0 00635 432 NtQueryValueKey (92, (92, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00636 432 NtClose (92, ... ) == 0x0 00637 432 NtUserSystemParametersInfo (41, 500, 2286832, 0, ... ) == 0x1 00638 432 NtAllocateVirtualMemory (-1, 4804608, 0, 4096, 4096, 4, ... 4804608, 4096, ) == 0x0 00639 432 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 92, ) }, ... 92, ) == 0x0 00640 432 NtQueryValueKey (92, (92, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00641 432 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 80, ) }, ... 80, ) == 0x0 00642 432 NtQueryValueKey (80, (80, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00643 432 NtClose (80, ... ) == 0x0 00644 432 NtClose (92, ... ) == 0x0 00645 432 NtUserSystemParametersInfo (102, 0, 1906153328, 0, ... ) == 0x1 00646 432 NtUserSystemParametersInfo (4130, 0, 2287356, 0, ... ) == 0x1 00647 432 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\LanguagePack"}, ... 92, ) }, ... 92, ) == 0x0 00648 432 NtEnumerateValueKey (92, 0, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 00649 432 NtClose (92, ... ) == 0x0 00650 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00651 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc03b 00652 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc03d 00653 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00654 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc03f 00655 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00656 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc041 00657 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00658 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... 00659 432 NtAllocateVirtualMemory (-1, 8159232, 0, 4096, 4096, 32, ... 8159232, 4096, ) == 0x0 00658 432 NtUserRegisterClassExWOW ... ) == 0x810dc043 00660 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc045 00661 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00662 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc047 00663 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00664 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc049 00665 432 NtUserGetClassInfo (1905590272, 2287252, 2287204, 2287280, 0, ... ) == 0xc049 00666 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00667 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc04b 00668 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00669 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc04d 00670 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00671 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc04f 00672 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc051 00673 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00674 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc053 00675 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00676 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc055 00677 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc057 00678 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00679 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc059 00680 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10013 00681 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc05b 00682 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00683 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc05d 00684 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00685 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc05f 00686 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00687 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc017 00688 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00689 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc019 00690 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10013 00691 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc018 00692 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00693 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc01a 00694 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00695 432 NtUserRegisterClassExWOW (2287088, 2287168, 2287152, 2287184, 0, 384, 0, ... ) == 0x810dc01c 00696 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00697 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc01e 00698 432 NtUserFindExistingCursorIcon (2286636, 2286652, 2287220, ... ) == 0x10011 00699 432 NtUserRegisterClassExWOW (2287148, 2287228, 2287212, 2287244, 0, 384, 0, ... ) == 0x810dc01b 00700 432 NtUserFindExistingCursorIcon (2286632, 2286648, 2287216, ... ) == 0x10011 00701 432 NtUserRegisterClassExWOW (2287144, 2287224, 2287208, 2287240, 0, 384, 0, ... ) == 0x810dc068 00702 432 NtUserFindExistingCursorIcon (2286640, 2286656, 2287224, ... ) == 0x10011 00703 432 NtUserRegisterClassExWOW (2287092, 2287172, 2287156, 2287188, 0, 384, 0, ... ) == 0x810dc06a 00704 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc03b 00705 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc03d 00706 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc03f 00707 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc041 00708 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc043 00709 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc045 00710 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc047 00711 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc049 00712 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc04b 00713 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc04d 00714 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc04f 00715 432 NtUserGetClassInfo (1999896576, 2290156, 2290108, 2290184, 0, ... ) == 0xc051 00716 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc053 00717 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc055 00718 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc059 00719 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc05b 00720 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc05d 00721 432 NtUserGetClassInfo (1999896576, 2290152, 2290104, 2290180, 0, ... ) == 0xc05f 00722 432 NtUserRegisterWindowMessage ( ("WOWLFChange", ... ) , ... ) == 0xc06b 00723 432 NtUserRegisterWindowMessage ( ("WOWDirChange", ... ) , ... ) == 0xc06c 00724 432 NtUserRegisterWindowMessage ( ("WOWCHOOSEFONT_GETLOGFONT", ... ) , ... ) == 0xc06d 00725 432 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 00726 432 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 00727 432 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 00728 432 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 00729 432 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 00730 432 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06e 00731 432 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc06f 00732 432 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc070 00733 432 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc071 00734 432 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc072 00735 432 NtUserRegisterWindowMessage ( ("Shell IDList Array", ... ) , ... ) == 0xc073 00736 432 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 00737 432 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc074 00738 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\MDAC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00739 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00740 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00741 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00742 432 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 11534336, 262144, ) == 0x0 00743 432 NtAllocateVirtualMemory (-1, 11534336, 0, 4096, 4096, 4, ... 11534336, 4096, ) == 0x0 00744 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00745 432 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 11796480, 262144, ) == 0x0 00746 432 NtAllocateVirtualMemory (-1, 11796480, 0, 4096, 4096, 4, ... 11796480, 4096, ) == 0x0 00747 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00748 432 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 12058624, 262144, ) == 0x0 00749 432 NtAllocateVirtualMemory (-1, 12058624, 0, 4096, 4096, 4, ... 12058624, 4096, ) == 0x0 00750 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00751 432 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 12320768, 262144, ) == 0x0 00752 432 NtAllocateVirtualMemory (-1, 12320768, 0, 4096, 4096, 4, ... 12320768, 4096, ) == 0x0 00753 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00754 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00755 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00756 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00757 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 2286032, ... ) }, 2286032, ... ) == 0x0 00758 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 5, 96, ... 92, {status=0x0, info=1}, ) }, 5, 96, ... 92, {status=0x0, info=1}, ) == 0x0 00759 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 92, ... 80, ) == 0x0 00760 432 NtClose (92, ... ) == 0x0 00761 432 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xc00000), 0x0, 90112, ) == 0x0 00762 432 NtClose (80, ... ) == 0x0 00763 432 NtUnmapViewOfSection (-1, 0xc00000, ... ) == 0x0 00764 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 2286348, ... ) }, 2286348, ... ) == 0x0 00765 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\odbcint.dll"}, 5, 96, ... 80, {status=0x0, info=1}, ) }, 5, 96, ... 80, {status=0x0, info=1}, ) == 0x0 00766 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 80, ... 92, ) == 0x0 00767 432 NtQuerySection (92, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00768 432 NtClose (80, ... ) == 0x0 00769 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x1f850000), 0x0, 90112, ) == 0x0 00770 432 NtClose (92, ... ) == 0x0 00771 432 NtQueryDefaultLocale (1, 2288036, ... ) == 0x0 00772 432 NtAllocateVirtualMemory (-1, 11538432, 0, 4096, 4096, 4, ... 11538432, 4096, ) == 0x0 00773 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE"}, ... 92, ) }, ... 92, ) == 0x0 00774 432 NtClose (92, ... ) == 0x0 00775 432 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00776 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00777 432 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00778 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00779 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WININET.dll"}, ... 92, ) }, ... 92, ) == 0x0 00780 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76200000), 0x0, 618496, ) == 0x0 00781 432 NtClose (92, ... ) == 0x0 00782 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CRYPT32.dll"}, ... 92, ) }, ... 92, ) == 0x0 00783 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762c0000), 0x0, 565248, ) == 0x0 00784 432 NtClose (92, ... ) == 0x0 00785 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MSASN1.dll"}, ... 92, ) }, ... 92, ) == 0x0 00786 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x762a0000), 0x0, 61440, ) == 0x0 00787 432 NtClose (92, ... ) == 0x0 00788 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLEAUT32.dll"}, ... 92, ) }, ... 92, ) == 0x0 00789 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77120000), 0x0, 569344, ) == 0x0 00790 432 NtClose (92, ... ) == 0x0 00791 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLE32.DLL"}, ... 92, ) }, ... 92, ) == 0x0 00792 432 NtMapViewOfSection (92, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x771b0000), 0x0, 1155072, ) == 0x0 00793 432 NtClose (92, ... ) == 0x0 00794 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Services\crypt32\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00795 432 NtAllocateVirtualMemory (-1, 4808704, 0, 4096, 4096, 4, ... 4808704, 4096, ) == 0x0 00796 432 NtAllocateVirtualMemory (-1, 4812800, 0, 4096, 4096, 4, ... 4812800, 4096, ) == 0x0 00797 432 NtAllocateVirtualMemory (-1, 4816896, 0, 4096, 4096, 4, ... 4816896, 4096, ) == 0x0 00798 432 NtCreateEvent (0x1f0003, {24, 52, 0x80, 2290192, 0, (0x1f0003, {24, 52, 0x80, 2290192, 0, "Global\crypt32LogoffEvent"}, 0, 0, ... ) }, 0, 0, ... ) == STATUS_ACCESS_DENIED 00799 432 NtOpenEvent (0x100000, {24, 52, 0x0, 0, 0, (0x100000, {24, 52, 0x0, 0, 0, "Global\crypt32LogoffEvent"}, ... 92, ) }, ... 92, ) == 0x0 00800 432 NtAllocateVirtualMemory (-1, 4820992, 0, 4096, 4096, 4, ... 4820992, 4096, ) == 0x0 00801 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00802 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00803 432 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 80, ) }, ... 80, ) == 0x0 00804 432 NtQueryValueKey (80, (80, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (80, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 00805 432 NtClose (80, ... ) == 0x0 00806 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00807 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00808 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00809 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00810 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 80, ) }, ... 80, ) == 0x0 00811 432 NtQueryValueKey (80, (80, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00812 432 NtQueryValueKey (80, (80, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00813 432 NtQueryValueKey (80, (80, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00814 432 NtClose (80, ... ) == 0x0 00815 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 80, ) }, ... 80, ) == 0x0 00816 432 NtQueryValueKey (80, (80, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00817 432 NtQueryValueKey (80, (80, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00818 432 NtClose (80, ... ) == 0x0 00819 432 NtOpenEvent (0x1f0003, {24, 52, 0x0, 0, 0, (0x1f0003, {24, 52, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00820 432 NtUserRegisterWindowMessage ( ("{FB8F0821-0164-101B-84ED-08002B2EC713}", ... ) , ... ) == 0xc07b 00821 432 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00822 432 NtOpenKey (0x9, {24, 28, 0x40, 0, 0, (0x9, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT\UserEra"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00823 432 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00824 432 NtAllocateVirtualMemory (-1, 4825088, 0, 8192, 4096, 4, ... 4825088, 8192, ) == 0x0 00825 432 NtCreateKey (0xf003f, {24, 84, 0x40, 0, 0, (0xf003f, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History"}, 0, 0x0, 0, ... 80, 2, ) }, 0, 0x0, 0, ... 80, 2, ) == 0x0 00826 432 NtQueryDefaultUILanguage (2288428, ... 00827 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00828 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482020, ) == 0x0 00829 432 NtQueryInformationToken (-2147482020, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00830 432 NtClose (-2147482020, ... ) == 0x0 00831 432 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... -2147482020, ) }, ... -2147482020, ) == 0x0 00832 432 NtOpenKey (0x80000000, {24, 0, 0x240, 0, 0, (0x80000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00833 432 NtOpenKey (0x80000000, {24, -2147482020, 0x640, 0, 0, (0x80000000, {24, -2147482020, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147482032, ) }, ... -2147482032, ) == 0x0 00834 432 NtQueryValueKey (-2147482032, (-2147482032, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00835 432 NtClose (-2147482032, ... ) == 0x0 00836 432 NtClose (-2147482020, ... ) == 0x0 00826 432 NtQueryDefaultUILanguage ... ) == 0x0 00837 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Nls\MUILanguages"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00838 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll"}, 1, 96, ... 96, {status=0x0, info=1}, ) }, 1, 96, ... 96, {status=0x0, info=1}, ) == 0x0 00839 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 96, ... 100, ) == 0x0 00840 432 NtMapViewOfSection (100, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0xc00000), 0x0, 593920, ) == 0x0 00841 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00842 432 NtQueryDefaultLocale (1, 2286464, ... ) == 0x0 00843 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00844 432 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2287320, 1, 96, 0} (24, {128, 156, new_msg, 0, 2287320, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1505, 0} "(\350\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ) \0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355 (24, {128, 156, new_msg, 0, 2287320, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1505, 0} "(\350\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ) ... {128, 156, reply, 0, 412, 432, 1505, 0} (24, {128, 156, new_msg, 0, 2287320, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1505, 0} "(\350\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ) \0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355 (24, {128, 156, new_msg, 0, 2287320, 1, 96, 0} "\210\6\31\1\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ... {128, 156, reply, 0, 412, 432, 1505, 0} "(\350\26\0\33\0\1\0\0\0\0\0\1\352"\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1`\0\0\0\377\377\377\377\0\0\0\0P\275\307\0\0\0\0\0\312\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\330\355"\0\0\0\0\0" ) ) == 0x0 00845 432 NtClose (96, ... ) == 0x0 00846 432 NtClose (100, ... ) == 0x0 00847 432 NtUnmapViewOfSection (-1, 0xc00000, ... ) == 0x0 00848 432 NtUnmapViewOfSection (-1, 0x22edd8, ... ) == STATUS_NOT_MAPPED_VIEW 00849 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00850 432 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00851 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00852 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00853 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 2285004, ... ) }, 2285004, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00854 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00855 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00856 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00857 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 2285596, ... ) }, 2285596, ... ) == 0x0 00858 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a"}, 3, 33, ... 100, {status=0x0, info=1}, ) }, 3, 33, ... 100, {status=0x0, info=1}, ) == 0x0 00859 432 NtQueryDebugFilterState (53, 2, ... ) == 0x0 00860 432 NtCreateKey (0x2001f, {24, 84, 0x40, 0, 0, (0x2001f, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, 0, 0x0, 0, ... 96, 2, ) }, 0, 0x0, 0, ... 96, 2, ) == 0x0 00861 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2_32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00862 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2_32.dll"}, 2290060, ... ) }, 2290060, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00863 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2_32.dll"}, 2290060, ... ) }, 2290060, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00864 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 2290060, ... ) }, 2290060, ... ) == 0x0 00865 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2_32.dll"}, 5, 96, ... 104, {status=0x0, info=1}, ) }, 5, 96, ... 104, {status=0x0, info=1}, ) == 0x0 00866 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 104, ... 108, ) == 0x0 00867 432 NtQuerySection (108, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00868 432 NtClose (104, ... ) == 0x0 00869 432 NtMapViewOfSection (108, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ab0000), 0x0, 86016, ) == 0x0 00870 432 NtClose (108, ... ) == 0x0 00871 432 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00872 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2HELP.dll"}, 2289256, ... ) }, 2289256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00873 432 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "WS2HELP.dll"}, 2289256, ... ) }, 2289256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00874 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 2289256, ... ) }, 2289256, ... ) == 0x0 00875 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\WS2HELP.dll"}, 5, 96, ... 108, {status=0x0, info=1}, ) }, 5, 96, ... 108, {status=0x0, info=1}, ) == 0x0 00876 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 108, ... 104, ) == 0x0 00877 432 NtQuerySection (104, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00878 432 NtClose (108, ... ) == 0x0 00879 432 NtMapViewOfSection (104, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71aa0000), 0x0, 32768, ) == 0x0 00880 432 NtClose (104, ... ) == 0x0 00881 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00882 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00883 432 NtTestAlert (... ) == 0x0 00884 432 NtContinue (2293040, 1, ... 00885 432 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x48efae,}, 4, ... ) == 0x0 00886 432 NtQueryPerformanceCounter (... {105616408, 0}, {3579545, 0}, ) == 0x0 00887 432 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00888 432 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 12582912, 65536, ) == 0x0 00889 432 NtAllocateVirtualMemory (-1, 12582912, 0, 4096, 4096, 4, ... 12582912, 4096, ) == 0x0 00890 432 NtAllocateVirtualMemory (-1, 12587008, 0, 8192, 4096, 4, ... 12587008, 8192, ) == 0x0 00891 432 NtAllocateVirtualMemory (-1, 12595200, 0, 4096, 4096, 4, ... 12595200, 4096, ) == 0x0 00892 432 NtAllocateVirtualMemory (-1, 12599296, 0, 4096, 4096, 4, ... 12599296, 4096, ) == 0x0 00893 432 NtAllocateVirtualMemory (-1, 0, 0, 6, 12288, 64, ... 12648448, 4096, ) == 0x0 00894 432 NtProtectVirtualMemory (-1, (0xc10000), 6, 64, ... 00895 432 NtContinue (-104227028, 0, ... 00894 432 NtProtectVirtualMemory ... ) == STATUS_ACCESS_VIOLATION 00896 432 NtFreeVirtualMemory (-1, (0xc10000), 0, 32768, ... (0xc10000), 4096, ) == 0x0 00897 432 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 2290508, (0x80100080, {24, 0, 0x40, 0, 2290508, "\??\u:\work\packed.exe"}, 0x0, 0, 1, 1, 2097252, 0, 0, ... 104, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 2097252, 0, 0, ... 104, {status=0x0, info=1}, ) == 0x0 00898 432 NtQueryInformationFile (104, 2291444, 8, AttributeFlag, ... {status=0x0, info=8}, ) == 0x0 00899 432 NtQueryInformationFile (104, 2291416, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 00900 432 NtQueryInformationFile (104, 2291368, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00901 432 NtAllocateVirtualMemory (-1, 4833280, 0, 8192, 4096, 4, ... 4833280, 8192, ) == 0x0 00902 432 NtQueryInformationFile (104, 4830824, 4094, Stream, ... {status=0x0, info=38}, ) == 0x0 00903 432 NtQueryInformationFile (104, 2289912, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00904 432 NtQueryInformationFile (104, 2289756, 4, Ea, ... {status=0x0, info=4}, ) == 0x0 00905 432 NtCreateFile (0x40110080, {24, 0, 0x40, 0, 2289764, (0x40110080, {24, 0, 0x40, 0, 2289764, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 0x0, 32, 0, 5, 100, 0, 0, ... }, 0x0, 32, 0, 5, 100, 0, 0, ... 00906 432 NtClose (-2147482020, ... ) == 0x0 00905 432 NtCreateFile ... 108, {status=0x0, info=2}, ) == 0x0 00907 432 NtQueryVolumeInformationFile (108, 2289136, 536, Attribute, ... {status=0x0, info=22}, ) == 0x0 00908 432 NtQueryInformationFile (108, 2289096, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 00909 432 NtQueryVolumeInformationFile (104, 2289136, 536, Attribute, ... {status=0x0, info=20}, ) == 0x0 00910 432 NtQueryVolumeInformationFile (104, 2288820, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00911 432 NtSetInformationFile (108, 2288924, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 00912 432 NtCreateSection (0xf001f, 0x0, 0x0, 2, 134217728, 104, ... 112, ) == 0x0 00913 432 NtMapViewOfSection (112, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xc10000), {0, 0}, 217088, ) == 0x0 00914 432 NtClose (112, ... ) == 0x0 00915 432 NtWriteFile (108, 0, 0, 0, (108, 0, 0, 0, "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\370\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0V^\2517\22?\307d\22?\307d\22?\307d5\371\272d\11?\307d5\371\252d\234?\307d5\371\251d ?\307d\2217\232d\20?\307d\3210\232d\35?\307d\22?\306d\277?\307d5\371\265d\16?\307d5\371\277d\23?\307dRich\22?\307d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0o\241\3\243"\202\300O\253\236\215\371S\364\26\360PE\0\0L\1\10\0!u\342E\0\0\0\0\0\0\0\0\340\0\3\1\13\1\10\0\0\320\1\0\0\260\0\0\0\0\0\0\256\357\10\0\0\320\5\0\0\340\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\15\0\1\0\4\0\0\0\0\0\0\0\0\0\11\0\0\20\0\0\322B\4\0\2\0\0\0\0\0 \0\0\20\0\0\0\0 \0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\320\5\0\20\1\0\0\0\220\3\0\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\321\5\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.tex", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) \202\300O\253\236\215\371S\364\26\360PE\0\0L\1\10\0!u\342E\0\0\0\0\0\0\0\0\340\0\3\1\13\1\10\0\0\320\1\0\0\260\0\0\0\0\0\0\256\357\10\0\0\320\5\0\0\340\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\15\0\1\0\4\0\0\0\0\0\0\0\0\0\11\0\0\20\0\0\322B\4\0\2\0\0\0\0\0 \0\0\20\0\0\0\0 \0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\320\5\0\20\1\0\0\0\220\3\0\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\321\5\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.tex", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 00916 432 NtWriteFile (108, 0, 0, 0, (108, 0, 0, 0, "\240\326\243_\3413\226\361\305d\223d\313?f\366\201\319\22\271\10\230\316Up}1T\356e\148\236@k\316\31f\346\324Z1-\354j\15\202\357K\321\352.uj\264r!\27I\355"\236\202I\0\4B\27\223\2005c\X\3]\235J\4[\12\216QY\200\211(\21\355RN\17AD\270%\255\21o\247\230\240\221\210$w\11\366H\6$\22\1=\31\371\240\230\202D\3046\356\0\344ru\377\207Kb\310\324)N\256\42D\314\267\265\276\251`\277AEM\16\270u\25\314U\3474\360Q\200\277\324\227\327\200\264(\1\7K\352"s\323\331\212\356jl5\225\223"b\253\301T\13\201\324\245\311\0\243%2\327\352\241\250\210\301m\272\330\325\270MY\26\37l\264\221\267\273\350\243\256\342\347\264\20z\273{\355\227BO\352Z\37\273\353"D\261\300q\341\11\247}G\353\26\365\236\324\336\2\334\316\344BE\216Z\231\20\312\363#\12\304\\304V\5\336W\374\212\325\250*\226\361U\210\331J\367*\365\3\266t\235\211\222@\301JF\21\316~=\275\306W.\252\30\5.\356I\367{\10\374\373^\214J\254'\351F|*\376\232\304.\256\7fCKB\267h\221\326\31\25,F.\355(+\343\334\35\14\204#\257k\223E24\210\223\5\364Y(?4i\3665]\227@\236\250v\214M::vS\355\367c\253\2031s\31\21\361\245*\356\311\316E\234\5\206)\316i)\316%a\203\326#\311x9A\247\374\12\274hs\201\245\4$W@\312h#"Xe\28R3\373\303;\212N\233\232\324!%i\271U\7\13\243][\370``\365\1\223\32V\21)\244\352\207C\305\200\342xc\220:`\232T\2302?\14\243\315\2kW\245\300\330\314\367\273\3001\225", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) \236\202I\0\4B\27\223\2005c\X\3]\235J\4[\12\216QY\200\211(\21\355RN\17AD\270%\255\21o\247\230\240\221\210$w\11\366H\6$\22\1=\31\371\240\230\202D\3046\356\0\344ru\377\207Kb\310\324)N\256\42D\314\267\265\276\251`\277AEM\16\270u\25\314U\3474\360Q\200\277\324\227\327\200\264(\1\7K\352 (108, 0, 0, 0, "\240\326\243_\3413\226\361\305d\223d\313?f\366\201\319\22\271\10\230\316Up}1T\356e\148\236@k\316\31f\346\324Z1-\354j\15\202\357K\321\352.uj\264r!\27I\355"\236\202I\0\4B\27\223\2005c\X\3]\235J\4[\12\216QY\200\211(\21\355RN\17AD\270%\255\21o\247\230\240\221\210$w\11\366H\6$\22\1=\31\371\240\230\202D\3046\356\0\344ru\377\207Kb\310\324)N\256\42D\314\267\265\276\251`\277AEM\16\270u\25\314U\3474\360Q\200\277\324\227\327\200\264(\1\7K\352"s\323\331\212\356jl5\225\223"b\253\301T\13\201\324\245\311\0\243%2\327\352\241\250\210\301m\272\330\325\270MY\26\37l\264\221\267\273\350\243\256\342\347\264\20z\273{\355\227BO\352Z\37\273\353"D\261\300q\341\11\247}G\353\26\365\236\324\336\2\334\316\344BE\216Z\231\20\312\363#\12\304\\304V\5\336W\374\212\325\250*\226\361U\210\331J\367*\365\3\266t\235\211\222@\301JF\21\316~=\275\306W.\252\30\5.\356I\367{\10\374\373^\214J\254'\351F|*\376\232\304.\256\7fCKB\267h\221\326\31\25,F.\355(+\343\334\35\14\204#\257k\223E24\210\223\5\364Y(?4i\3665]\227@\236\250v\214M::vS\355\367c\253\2031s\31\21\361\245*\356\311\316E\234\5\206)\316i)\316%a\203\326#\311x9A\247\374\12\274hs\201\245\4$W@\312h#"Xe\28R3\373\303;\212N\233\232\324!%i\271U\7\13\243][\370``\365\1\223\32V\21)\244\352\207C\305\200\342xc\220:`\232T\2302?\14\243\315\2kW\245\300\330\314\367\273\3001\225", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) b\253\301T\13\201\324\245\311\0\243%2\327\352\241\250\210\301m\272\330\325\270MY\26\37l\264\221\267\273\350\243\256\342\347\264\20z\273{\355\227BO\352Z\37\273\353 (108, 0, 0, 0, "\240\326\243_\3413\226\361\305d\223d\313?f\366\201\319\22\271\10\230\316Up}1T\356e\148\236@k\316\31f\346\324Z1-\354j\15\202\357K\321\352.uj\264r!\27I\355"\236\202I\0\4B\27\223\2005c\X\3]\235J\4[\12\216QY\200\211(\21\355RN\17AD\270%\255\21o\247\230\240\221\210$w\11\366H\6$\22\1=\31\371\240\230\202D\3046\356\0\344ru\377\207Kb\310\324)N\256\42D\314\267\265\276\251`\277AEM\16\270u\25\314U\3474\360Q\200\277\324\227\327\200\264(\1\7K\352"s\323\331\212\356jl5\225\223"b\253\301T\13\201\324\245\311\0\243%2\327\352\241\250\210\301m\272\330\325\270MY\26\37l\264\221\267\273\350\243\256\342\347\264\20z\273{\355\227BO\352Z\37\273\353"D\261\300q\341\11\247}G\353\26\365\236\324\336\2\334\316\344BE\216Z\231\20\312\363#\12\304\\304V\5\336W\374\212\325\250*\226\361U\210\331J\367*\365\3\266t\235\211\222@\301JF\21\316~=\275\306W.\252\30\5.\356I\367{\10\374\373^\214J\254'\351F|*\376\232\304.\256\7fCKB\267h\221\326\31\25,F.\355(+\343\334\35\14\204#\257k\223E24\210\223\5\364Y(?4i\3665]\227@\236\250v\214M::vS\355\367c\253\2031s\31\21\361\245*\356\311\316E\234\5\206)\316i)\316%a\203\326#\311x9A\247\374\12\274hs\201\245\4$W@\312h#"Xe\28R3\373\303;\212N\233\232\324!%i\271U\7\13\243][\370``\365\1\223\32V\21)\244\352\207C\305\200\342xc\220:`\232T\2302?\14\243\315\2kW\245\300\330\314\367\273\3001\225", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) Xe\28R3\373\303;\212N\233\232\324!%i\271U\7\13\243][\370``\365\1\223\32V\21)\244\352\207C\305\200\342xc\220:`\232T\2302?\14\243\315\2kW\245\300\330\314\367\273\3001\225", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 00917 432 NtWriteFile (108, 0, 0, 0, (108, 0, 0, 0, "\353`m\263\222\16Zi\373\3759\377Al:\306\233\30\21!g\226\254j\14Q\312\366P)6\252\361\374wR\276\216\30\3\6\310\255\6\303'tiZ\357L\17{\272\303\341\201\245\20\361\323yf&\17\6\11\261\207\300\303\321\17\30\367u@\301\324\371\356-\253.S\255\244"O2\34\22\255\274;T\237\363\354\11g\5\17\260Q\25e\345\233k\272O\313\202dw\355\277N\371:\373\346N\324R\352\11\21\36\225H\31\253\326g_\31-w\264'\304\336\245r\330\\277\3C&\3\341(\372\275\244\2113&y\366\12\331\11H\22E\331P\320\324\374\304\375b\232b\354\253nU\230\266\32U\372\330\266FP\207^b,\256\27G\325Hz|\264\315\216S\247\2c\263\34\267\10\320G\205\237\323\37\36\367\235\253\322\211\226\263\325#%\272\325\252V\357T\336Hw[9x\37\374\26G\207\35\253\7\225[<~\257\20221a\375\233\300<\374^\337\352\231D\225m\25\21s\225\244\340\3\206\15\302\331\13\257`\221\352\355=;\377}\104\363L\224\1181\243\346u\317\346\204\350\33=\276,z\263\203\227\353\342\361\340G\263\345\274\6\253c\230\262n\2260V-?\370\242\371\376=\235\355+\232\306\315\353\27\235[^\17\245\322\4K\271B\252\314\343E{0q\206\325\212\352\314\16\342\244\27\241\324U_[oL\327\332\320h\264\22\311\206\255\312\301\2774\364\300\242\310\34J\277.\261k\13g\353\251\32\307\234\7XX\301e7\227\26\322\360\226R\200\242\12m\363\331r\336+\202\30\341]\263\254\273l\21\27\343\210\24\255\245EV\4\305\310_\247\322\237|\326fT\213\251\255\267\2\255\13Uev(\374\375\37\226\275M\300]\310\215\316\303\7\202H\343p3\45\367\247}\377\26Fb\255", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) O2\34\22\255\274;T\237\363\354\11g\5\17\260Q\25e\345\233k\272O\313\202dw\355\277N\371:\373\346N\324R\352\11\21\36\225H\31\253\326g_\31-w\264'\304\336\245r\330\\277\3C&\3\341(\372\275\244\2113&y\366\12\331\11H\22E\331P\320\324\374\304\375b\232b\354\253nU\230\266\32U\372\330\266FP\207^b,\256\27G\325Hz|\264\315\216S\247\2c\263\34\267\10\320G\205\237\323\37\36\367\235\253\322\211\226\263\325#%\272\325\252V\357T\336Hw[9x\37\374\26G\207\35\253\7\225[<~\257\20221a\375\233\300<\374^\337\352\231D\225m\25\21s\225\244\340\3\206\15\302\331\13\257`\221\352\355=;\377}\104\363L\224\1181\243\346u\317\346\204\350\33=\276,z\263\203\227\353\342\361\340G\263\345\274\6\253c\230\262n\2260V-?\370\242\371\376=\235\355+\232\306\315\353\27\235[^\17\245\322\4K\271B\252\314\343E{0q\206\325\212\352\314\16\342\244\27\241\324U_[oL\327\332\320h\264\22\311\206\255\312\301\2774\364\300\242\310\34J\277.\261k\13g\353\251\32\307\234\7XX\301e7\227\26\322\360\226R\200\242\12m\363\331r\336+\202\30\341]\263\254\273l\21\27\343\210\24\255\245EV\4\305\310_\247\322\237|\326fT\213\251\255\267\2\255\13Uev(\374\375\37\226\275M\300]\310\215\316\303\7\202H\343p3\45\367\247}\377\26Fb\255", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 00918 432 NtWriteFile (108, 0, 0, 0, (108, 0, 0, 0, "\25\313\36\270\214\226\21B\304\243`\371\275\66-:\177\243\35\264OQ\207\273\321\2559\243/O\202\300\216\234\3505\315D*\27+\220\360\354\201\205G\337\266\240\331\221\303\273\333\242\5w\247\254\25_\376\332\12\240\26\4!\212e\22e\344\276/Y\341\235] \362\240!YK\343F\36\370\36\13\255\270\361\316\245\210#\16\3\332\215\371fC\263\243\253\262\220\323]\21\37\12\277o\222\252\231\316T\354\207U\205\334\25-r\251\274\373%\22\251\66\313\2534g}S\177\17\271\232\360~\313E\234U\305\2515z\252\226\376g\211\15\203\364\316\275\314\310\237Iz\227+\233\317\270f\21\310?\266\367\213\251\24\34\365\321\307\370;\31?\334+\232\231~\30\0i\231c\303\36\325\253\361[\276\205lp\264O\224<\365\353\200B@\247\4\360\225\366B\212H9\336\252\242Ui\265\330\331\364\371\305a\3663\347\213[\315\250\343m\321\273$\203\210\350\27\234\271"\16\3774\312\215^\26\275{Yv}\366\322Tc\321'\221&2\275\244\352\343\12%\245\323\274\231\320\237,\270{\333a2m\331G\352\243\261\320\262~_\376A~wS-\366X*\275d?_\241S\37J\321\311fITQF\341Zm\320\320\312\23\30QfoQ%\236\24\241\202T\334t\264\211\376\320\300\25jt\331\365\2\245\15\276s\26\307\\331\267m`n5\272J\312\360\201\317\324(\375f]\355\33\256\13#\6\320\5D\6\247%\200\376\210oe\30+\368\243\2454\2137\327e\371\27\336\201\314\331$\3N]\177\341\227\3270\5\236\355\352\344\306\366\303t0\370\230i->LX\4\263\345 \364/\10\342\325\363X\33\277\357\260\357>G\344\344\244D)\373\23\23?\321^\205\16\337\372\240C\342\276", 29696, 0x0, 0, ... {status=0x0, info=29696}, ) \16\3774\312\215^\26\275{Yv}\366\322Tc\321'\221&2\275\244\352\343\12%\245\323\274\231\320\237,\270{\333a2m\331G\352\243\261\320\262~_\376A~wS-\366X*\275d?_\241S\37J\321\311fITQF\341Zm\320\320\312\23\30QfoQ%\236\24\241\202T\334t\264\211\376\320\300\25jt\331\365\2\245\15\276s\26\307\\331\267m`n5\272J\312\360\201\317\324(\375f]\355\33\256\13#\6\320\5D\6\247%\200\376\210oe\30+\368\243\2454\2137\327e\371\27\336\201\314\331$\3N]\177\341\227\3270\5\236\355\352\344\306\366\303t0\370\230i->LX\4\263\345 \364/\10\342\325\363X\33\277\357\260\357>G\344\344\244D)\373\23\23?\321^\205\16\337\372\240C\342\276", 29696, 0x0, 0, ... {status=0x0, info=29696}, ) == 0x0 00919 432 NtUnmapViewOfSection (-1, 0xc10000, ... ) == 0x0 00920 432 NtSetInformationFile (108, 2291368, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 00921 432 NtClose (104, ... ) == 0x0 00922 432 NtClose (108, ... ) == 0x0 00923 432 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 00924 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 2287660, ... ) }, 2287660, ... ) == 0x0 00925 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 2288352, ... ) }, 2288352, ... ) == 0x0 00926 432 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 5, 96, ... 108, {status=0x0, info=1}, ) }, 5, 96, ... 108, {status=0x0, info=1}, ) == 0x0 00927 432 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 108, ... 104, ) == 0x0 00928 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00929 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 112, ) }, ... 112, ) == 0x0 00930 432 NtQueryValueKey (112, (112, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00931 432 NtClose (112, ... ) == 0x0 00932 432 NtQueryVolumeInformationFile (108, 2287660, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00933 432 NtOpenMutant (0x120001, {24, 52, 0x0, 0, 0, (0x120001, {24, 52, 0x0, 0, 0, "ShimCacheMutex"}, ... 112, ) }, ... 112, ) == 0x0 00934 432 NtWaitForSingleObject (112, 0, {-1000000, -1}, ... ) == 0x0 00935 432 NtOpenSection (0x2, {24, 52, 0x0, 0, 0, (0x2, {24, 52, 0x0, 0, 0, "ShimSharedMemory"}, ... 116, ) }, ... 116, ) == 0x0 00936 432 NtMapViewOfSection (116, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xc10000), {0, 0}, 57344, ) == 0x0 00937 432 NtReleaseMutant (112, ... 0x0, ) == 0x0 00938 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 2285644, ... ) }, 2285644, ... ) == 0x0 00939 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 120, {status=0x0, info=1}, ) }, 5, 96, ... 120, {status=0x0, info=1}, ) == 0x0 00940 432 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 120, ... 124, ) == 0x0 00941 432 NtClose (120, ... ) == 0x0 00942 432 NtMapViewOfSection (124, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xc20000), 0x0, 106496, ) == 0x0 00943 432 NtClose (124, ... ) == 0x0 00944 432 NtUnmapViewOfSection (-1, 0xc20000, ... ) == 0x0 00945 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 2285960, ... ) }, 2285960, ... ) == 0x0 00946 432 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 124, {status=0x0, info=1}, ) }, 5, 96, ... 124, {status=0x0, info=1}, ) == 0x0 00947 432 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 124, ... 120, ) == 0x0 00948 432 NtQuerySection (120, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00949 432 NtClose (124, ... ) == 0x0 00950 432 NtMapViewOfSection (120, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x75f40000), 0x0, 118784, ) == 0x0 00951 432 NtClose (120, ... ) == 0x0 00952 432 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 120, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 120, {status=0x0, info=1}, ) == 0x0 00953 432 NtQueryInformationFile (120, 2286248, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 00954 432 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 120, ... 124, ) == 0x0 00955 432 NtMapViewOfSection (124, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xc20000), 0x0, 1028096, ) == 0x0 00956 432 NtQueryInformationFile (120, 2286344, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 00957 432 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00958 432 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 00959 432 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 00960 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00961 432 NtQueryDirectoryFile (128, 0, 0, 0, 2283908, 616, BothDirectory, 1, (128, 0, 0, 0, 2283908, 616, BothDirectory, 1, "eupsvc.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 00962 432 NtClose (128, ... ) == 0x0 00963 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00964 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00965 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 2283296, ... ) }, 2283296, ... ) == 0x0 00966 432 NtAllocateVirtualMemory (-1, 2273280, 0, 4096, 4096, 260, ... 2273280, 4096, ) == 0x0 00967 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00968 432 NtQueryDirectoryFile (128, 0, 0, 0, 2282656, 616, BothDirectory, 1, (128, 0, 0, 0, 2282656, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 00969 432 NtClose (128, ... ) == 0x0 00970 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00971 432 NtQueryDirectoryFile (128, 0, 0, 0, 2282656, 616, BothDirectory, 1, (128, 0, 0, 0, 2282656, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 00972 432 NtClose (128, ... ) == 0x0 00973 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00974 432 NtQueryDirectoryFile (128, 0, 0, 0, 2282656, 616, BothDirectory, 1, (128, 0, 0, 0, 2282656, 616, BothDirectory, 1, "eupsvc.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 00975 432 NtClose (128, ... ) == 0x0 00976 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00977 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00978 432 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 00979 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00980 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 00981 432 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00982 432 NtClose (128, ... ) == 0x0 00983 432 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00984 432 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\eupsvc.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00985 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00986 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00987 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 2285576, ... ) }, 2285576, ... ) == 0x0 00988 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00989 432 NtQueryDirectoryFile (128, 0, 0, 0, 2284936, 616, BothDirectory, 1, (128, 0, 0, 0, 2284936, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 00990 432 NtClose (128, ... ) == 0x0 00991 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00992 432 NtQueryDirectoryFile (128, 0, 0, 0, 2284936, 616, BothDirectory, 1, (128, 0, 0, 0, 2284936, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 00993 432 NtClose (128, ... ) == 0x0 00994 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 00995 432 NtQueryDirectoryFile (128, 0, 0, 0, 2284936, 616, BothDirectory, 1, (128, 0, 0, 0, 2284936, 616, BothDirectory, 1, "eupsvc.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 00996 432 NtClose (128, ... ) == 0x0 00997 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 00998 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 00999 432 NtWaitForSingleObject (112, 0, {-1000000, -1}, ... ) == 0x0 01000 432 NtQueryVolumeInformationFile (108, 2286220, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01001 432 NtQueryInformationFile (108, 2286200, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 01002 432 NtQueryInformationFile (108, 2286240, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01003 432 NtReleaseMutant (112, ... 0x0, ) == 0x0 01004 432 NtUnmapViewOfSection (-1, 0xc20000, ... ) == 0x0 01005 432 NtClose (124, ... ) == 0x0 01006 432 NtClose (120, ... ) == 0x0 01007 432 NtQuerySection (104, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01008 432 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eupsvc.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01009 432 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 01010 432 NtOpenProcessToken (-1, 0xa, ... 120, ) == 0x0 01011 432 NtQueryInformationToken (120, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 01012 432 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01013 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 01014 432 NtQueryValueKey (124, (124, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (124, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 01015 432 NtQueryValueKey (124, (124, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (124, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01016 432 NtClose (124, ... ) == 0x0 01017 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 01018 432 NtQueryValueKey (124, (124, "ExecutableTypes", Partial, 0, ... ) , Partial, 0, ... ) == STATUS_BUFFER_TOO_SMALL 01019 432 NtQueryValueKey (124, (124, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) , Partial, 260, ... TitleIdx=0, Type=7, Data= (124, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) }, 260, ) == 0x0 01020 432 NtClose (124, ... ) == 0x0 01021 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01022 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 01023 432 NtQueryValueKey (124, (124, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01024 432 NtClose (124, ... ) == 0x0 01025 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01026 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01027 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01028 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01029 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01030 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01031 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01032 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01033 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01034 432 NtQueryDefaultLocale (1, 2287032, ... ) == 0x0 01035 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 124, ) }, ... 124, ) == 0x0 01036 432 NtEnumerateKey (124, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name= (124, 0, Basic, 280, ... {LastWrite={0x6f7a111e,0x1c73999}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 01037 432 NtOpenKey (0x20019, {24, 124, 0x40, 0, 0, (0x20019, {24, 124, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 128, ) }, ... 128, ) == 0x0 01038 432 NtQueryValueKey (128, (128, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (128, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 01039 432 NtQueryValueKey (128, (128, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (128, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01040 432 NtClose (128, ... ) == 0x0 01041 432 NtEnumerateKey (124, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 01042 432 NtClose (124, ... ) == 0x0 01043 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01044 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01045 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01046 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01047 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01048 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01049 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01050 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01051 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01052 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01053 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01054 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01055 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01056 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01057 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01058 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01059 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01060 432 NtClose (124, ... ) == 0x0 01061 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01062 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01063 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01064 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01065 432 NtClose (124, ... ) == 0x0 01066 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01067 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01068 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01069 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01070 432 NtClose (124, ... ) == 0x0 01071 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01072 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01073 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01074 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01075 432 NtClose (124, ... ) == 0x0 01076 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01077 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01078 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01079 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01080 432 NtClose (124, ... ) == 0x0 01081 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01082 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01083 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01084 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01085 432 NtClose (124, ... ) == 0x0 01086 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01087 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01088 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01089 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01090 432 NtClose (124, ... ) == 0x0 01091 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01092 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01093 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01094 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01095 432 NtClose (124, ... ) == 0x0 01096 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01097 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01098 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01099 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01100 432 NtClose (124, ... ) == 0x0 01101 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01102 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01103 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01104 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01105 432 NtClose (124, ... ) == 0x0 01106 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01107 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01108 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01109 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01110 432 NtClose (124, ... ) == 0x0 01111 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01112 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01113 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01114 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01115 432 NtClose (124, ... ) == 0x0 01116 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01117 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01118 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01119 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01120 432 NtClose (124, ... ) == 0x0 01121 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01122 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01123 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01124 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01125 432 NtClose (124, ... ) == 0x0 01126 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01127 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01128 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01129 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01130 432 NtClose (124, ... ) == 0x0 01131 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01132 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 01133 432 NtQueryValueKey (124, (124, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (124, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (124, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 01134 432 NtClose (124, ... ) == 0x0 01135 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01136 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 124, ) == 0x0 01137 432 NtQueryInformationToken (124, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01138 432 NtClose (124, ... ) == 0x0 01139 432 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01140 432 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 01141 432 NtOpenProcessToken (-1, 0xa, ... 124, ) == 0x0 01142 432 NtDuplicateToken (124, 0xc, {24, 0, 0x0, 0, 2287552, 0x0}, 0, 2, ... 128, ) == 0x0 01143 432 NtClose (124, ... ) == 0x0 01144 432 NtAccessCheck (4838656, 128, 0x1, 2287680, 2287624, 56, 2287708, ... (0x1), ) == 0x0 01145 432 NtClose (128, ... ) == 0x0 01146 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 128, ) }, ... 128, ) == 0x0 01147 432 NtQueryValueKey (128, (128, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (128, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01148 432 NtClose (128, ... ) == 0x0 01149 432 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 128, ) }, ... 128, ) == 0x0 01150 432 NtQuerySymbolicLinkObject (128, ... (128, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 01151 432 NtClose (128, ... ) == 0x0 01152 432 NtQueryInformationFile (108, 2286012, 528, Name, ... {status=0x0, info=60}, ) == 0x0 01153 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01154 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01155 432 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe"}, 2284692, ... ) }, 2284692, ... ) == 0x0 01156 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 01157 432 NtQueryDirectoryFile (128, 0, 0, 0, 2284052, 616, BothDirectory, 1, (128, 0, 0, 0, 2284052, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 01158 432 NtClose (128, ... ) == 0x0 01159 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 01160 432 NtQueryDirectoryFile (128, 0, 0, 0, 2284052, 616, BothDirectory, 1, (128, 0, 0, 0, 2284052, 616, BothDirectory, 1, "System32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 01161 432 NtClose (128, ... ) == 0x0 01162 432 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\"}, 3, 16417, ... 128, {status=0x0, info=1}, ) }, 3, 16417, ... 128, {status=0x0, info=1}, ) == 0x0 01163 432 NtQueryDirectoryFile (128, 0, 0, 0, 2284052, 616, BothDirectory, 1, (128, 0, 0, 0, 2284052, 616, BothDirectory, 1, "eupsvc.exe", 0, ... {status=0x0, info=114}, ) , 0, ... {status=0x0, info=114}, ) == 0x0 01164 432 NtClose (128, ... ) == 0x0 01165 432 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 01166 432 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 01167 432 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01168 432 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 128, ) == 0x0 01169 432 NtQueryInformationToken (128, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01170 432 NtClose (128, ... ) == 0x0 01171 432 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1078081533-484763869-839522115-1003"}, ... 128, ) }, ... 128, ) == 0x0 01172 432 NtOpenKey (0x20019, {24, 128, 0x40, 0, 0, (0x20019, {24, 128, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 124, ) }, ... 124, ) == 0x0 01173 432 NtClose (128, ... ) == 0x0 01174 432 NtQueryValueKey (124, (124, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 01175 432 NtQueryValueKey (124, (124, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) , Partial, 162, ... TitleIdx=0, Type=1, Data= (124, "Cache", Partial, 162, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 162, ) }, 162, ) == 0x0 01176 432 NtClose (124, ... ) == 0x0 01177 432 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 12713984, 4096, ) == 0x0 01178 432 NtAllocateVirtualMemory (-1, 12713984, 0, 4096, 4096, 4, ... 12713984, 4096, ) == 0x0 01179 432 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 124, ) }, ... 124, ) == 0x0 01180 432 NtQueryValueKey (124, (124, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01181 432 NtClose (124, ... ) == 0x0 01182 432 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01183 432 NtQueryInformationToken (120, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 01184 432 NtQueryInformationToken (120, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 01185 432 NtClose (120, ... ) == 0x0 01186 432 NtCreateProcessEx (2290288, 2035711, 0, -1, 0, 104, 0, 0, 0, ... ) == 0x0 01187 432 NtSetInformationProcess (120, PriorityClass, {process info, class 18, size 2}, 83886592, ... ) == 0x0 01188 432 NtQueryInformationProcess (120, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=568,ParentPid=412,}, 0x0, ) == 0x0 01189 432 NtReadVirtualMemory (120, 0x7ffdf008, 4, ... (120, 0x7ffdf008, 4, ... "\0\0@\0", 0x0, ) , 0x0, ) == 0x0 01190 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01191 432 NtAllocateVirtualMemory (-1, 4841472, 0, 8192, 4096, 4, ... 4841472, 8192, ) == 0x0 01192 432 NtReadVirtualMemory (120, 0x400000, 4096, ... (120, 0x400000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\370\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0V^\2517\22?\307d\22?\307d\22?\307d5\371\272d\11?\307d5\371\252d\234?\307d5\371\251d ?\307d\2217\232d\20?\307d\3210\232d\35?\307d\22?\306d\277?\307d5\371\265d\16?\307d5\371\277d\23?\307dRich\22?\307d\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0o\241\3\243"\202\300O\253\236\215\371S\364\26\360PE\0\0L\1\10\0!u\342E\0\0\0\0\0\0\0\0\340\0\3\1\13\1\10\0\0\320\1\0\0\260\0\0\0\0\0\0\256\357\10\0\0\320\5\0\0\340\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\15\0\1\0\4\0\0\0\0\0\0\0\0\0\11\0\0\20\0\0\322B\4\0\2\0\0\0\0\0 \0\0\20\0\0\0\0 \0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\320\5\0\20\1\0\0\0\220\3\0\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\321\5\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.tex", 4096, ) \202\300O\253\236\215\371S\364\26\360PE\0\0L\1\10\0!u\342E\0\0\0\0\0\0\0\0\340\0\3\1\13\1\10\0\0\320\1\0\0\260\0\0\0\0\0\0\256\357\10\0\0\320\5\0\0\340\1\0\0\0@\0\0\20\0\0\0\2\0\0\4\0\0\0\15\0\1\0\4\0\0\0\0\0\0\0\0\0\11\0\0\20\0\0\322B\4\0\2\0\0\0\0\0 \0\0\20\0\0\0\0 \0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\320\5\0\20\1\0\0\0\220\3\0\260\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\321\5\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.tex", 4096, ) == 0x0 01193 432 NtReadVirtualMemory (120, 0x439000, 256, ... (120, 0x439000, 256, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\30\0\0\0\30\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0X\220\3\0V\0\0\0\344\4\0\0\0\0\0\0\15\12PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING", 256, ) urn:schemas-microsoft-com:asm.v1 (120, 0x439000, 256, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\30\0\0\0\30\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0X\220\3\0V\0\0\0\344\4\0\0\0\0\0\0\15\12PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING", 256, ) 1.0 (120, 0x439000, 256, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\30\0\0\0\30\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0X\220\3\0V\0\0\0\344\4\0\0\0\0\0\0\15\12PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING", 256, ) , 256, ) == 0x0 01194 432 NtReadVirtualMemory (120, 0x439018, 24, ... (120, 0x439018, 24, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\1\0\0\00\0\0\200", 24, ) , 24, ) == 0x0 01195 432 NtReadVirtualMemory (120, 0x439030, 24, ... (120, 0x439030, 24, ... "\0\0\0\0\0\0\0\0\4\0\0\0\0\0\1\0\11\4\0\0H\0\0\0", 24, ) , 24, ) == 0x0 01196 432 NtReadVirtualMemory (120, 0x439048, 16, ... (120, 0x439048, 16, ... "X\220\3\0V\0\0\0\344\4\0\0\0\0\0\0", 16, ) , 16, ) == 0x0 01197 432 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\System32\eupsvc.exe.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01198 432 NtQueryInformationProcess (120, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffdf000,AffinityMask=0x1,BasePriority=8,Pid=568,ParentPid=412,}, 0x0, ) == 0x0 01199 432 NtAllocateVirtualMemory (-1, 0, 0, 1716, 4096, 4, ... 12779520, 4096, ) == 0x0 01200 432 NtAllocateVirtualMemory (120, 0, 0, 1910, 4096, 4, ... 65536, 4096, ) == 0x0 01201 432 NtWriteVirtualMemory (120, 0x10000, (120, 0x10000, "=\0:\0:\0=\0:\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0p\0o\0l\0y\0u\0n\0p\0a\0c\0k\0\0\0=\0E\0x\0i\0t\0C\0o\0d\0e\0=\00\00\00\00\00\00\00\02\0\0\0=\0U\0:\0=\0U\0:\0\\0s\0t\0a\0r\0t\0u\0p\0s\0c\0r\0i\0p\0t\0s\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0S\0R\0I\0-\0u\0s\0e\0r\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0C\0L\0I\0E\0N\0T\0N\0A\0M\0E\0=\0C\0o\0n\0s\0o\0l\0e\0\0\0C\0o\0m\0m\0o\0n\0P\0r\0o\0g\0r\0a\0m\0F\0i\0l\0e\0s\0=\0C\0:\0\\0P\0r\0o\0g\0r\0a\0m\0 \0F\0i\0l\0e\0s\0\\0C\0o\0m\0m\0o\0n\0 \0F\0i\0l\0e\0s\0\0\0C\0O\0M\0", 1910, ... 0x0, ) , 1910, ... 0x0, ) == 0x0 01202 432 NtAllocateVirtualMemory (120, 0, 0, 1716, 4096, 4, ... 131072, 4096, ) == 0x0 01203 432 NtWriteVirtualMemory (120, 0x20000, (120, 0x20000, "\0\20\0\0\264\6\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0$\0\10\2\220\2\0\0\0\0\0\0\374\0\376\0\230\4\0\0<\0>\0\230\5\0\0v\0x\0\330\5\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0<\0>\0P\6\0\0\36\0 \0\220\6\0\0\0\0\2\0\260\6\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1716, ... 0x0, ) , 1716, ... 0x0, ) == 0x0 01204 432 NtWriteVirtualMemory (120, 0x7ffdf010, (120, 0x7ffdf010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 01205 432 NtWriteVirtualMemory (120, 0x7ffdf1e8, (120, 0x7ffdf1e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 01206 432 NtFreeVirtualMemory (-1, (0xc30000), 0, 32768, ... (0xc30000), 4096, ) == 0x0 01207 432 NtAllocateVirtualMemory (120, 0, 0, 2097152, 8192, 4, ... 196608, 2097152, ) == 0x0 01208 432 NtAllocateVirtualMemory (120, 2285568, 0, 8192, 4096, 4, ... 2285568, 8192, ) == 0x0 01209 432 NtProtectVirtualMemory (120, (0x22e000), 4096, 260, ... (0x22e000), 4096, 4, ) == 0x0 01210 432 NtCreateThread (0x1f03ff, 0x0, 120, 2288552, 2289272, 1, ... 124, {568, 572}, ) == 0x0 01211 432 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 4786568, 4784128, 4804616, 2290372} (24, {168, 196, new_msg, 0, 4786568, 4784128, 4804616, 2290372} "\210\6\31\1\0\0\1\0\2$\370w U\367w{\0\0\0|\0\0\08\2\0\0<\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0<\0@\0\244\6\31\1l\0\0\0x\0\0\0\0\0\0\0X\220C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0@\0\344\6\31\1\0\360\375\177\0\0\0\0\0\0\300\0\220\36\300\0" ... {168, 196, reply, 0, 412, 432, 1506, 0} "\320\231\26\0\0\0\1\0\0\0\0\0 U\367wx\0\0\0|\0\0\08\2\0\0<\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0<\0@\0\244\6\31\1l\0\0\0x\0\0\0\0\0\0\0X\220C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0@\0\344\6\31\1\0\360\375\177\0\0\0\0\0\0\300\0\220\36\300\0" ) ... {168, 196, reply, 0, 412, 432, 1506, 0} (24, {168, 196, new_msg, 0, 4786568, 4784128, 4804616, 2290372} "\210\6\31\1\0\0\1\0\2$\370w U\367w{\0\0\0|\0\0\08\2\0\0<\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0<\0@\0\244\6\31\1l\0\0\0x\0\0\0\0\0\0\0X\220C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0@\0\344\6\31\1\0\360\375\177\0\0\0\0\0\0\300\0\220\36\300\0" ... {168, 196, reply, 0, 412, 432, 1506, 0} "\320\231\26\0\0\0\1\0\0\0\0\0 U\367wx\0\0\0|\0\0\08\2\0\0<\2\0\0\0\0\0\0\0\0\0\0\10\0\0\0\0\0\0\0\215\26\365w\0\0\0\0\1\0\0\0\0\0\0\0\1\1\1\0<\0@\0\244\6\31\1l\0\0\0x\0\0\0\0\0\0\0X\220C\0\0\0\0\0V\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0@\0\344\6\31\1\0\360\375\177\0\0\0\0\0\0\300\0\220\36\300\0" ) ) == 0x0 01212 432 NtResumeThread (124, ... 1, ) == 0x0 01213 432 NtClose (108, ... ) == 0x0 01214 432 NtClose (104, ... ) == 0x0 01215 432 NtTerminateProcess (0, 0, ... ) == 0x0 01216 432 NtClose (96, ... ) == 0x0 01217 432 NtUnmapViewOfSection (-1, 0xae0000, ... ) == 0x0 01218 432 NtClose (100, ... ) == 0x0 01219 432 NtClose (80, ... ) == 0x0 01220 432 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 01221 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc03b 01222 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01223 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc03d 01224 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01225 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc03f 01226 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01227 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc041 01228 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01229 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc043 01230 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01231 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc045 01232 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01233 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc047 01234 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01235 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc049 01236 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01237 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc04b 01238 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01239 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc04d 01240 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01241 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc04f 01242 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01243 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc051 01244 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01245 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc053 01246 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01247 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc057 01248 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01249 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc059 01250 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01251 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc05b 01252 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01253 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc05d 01254 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01255 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc05f 01256 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01257 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc017 01258 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01259 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc019 01260 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01261 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc018 01262 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01263 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc01a 01264 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01265 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc01c 01266 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01267 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc01e 01268 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01269 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc01b 01270 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01271 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc068 01272 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01273 432 NtUserGetClassInfo (1905590272, 2292956, 2292908, 2292984, 0, ... ) == 0xc06a 01274 432 NtUserUnregisterClass (2292960, 1905590272, 2292948, ... ) == 0x1 01275 432 NtUnmapViewOfSection (-1, 0xaf0000, ... ) == 0x0 01276 432 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 01277 432 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x1,}, 4, ... ) == 0x0 01278 432 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 01279 432 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 01280 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc03b 01281 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01282 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc03d 01283 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01284 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc03f 01285 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01286 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc041 01287 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01288 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc043 01289 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01290 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc045 01291 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01292 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc047 01293 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01294 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc049 01295 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01296 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc04b 01297 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01298 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc04d 01299 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01300 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc04f 01301 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01302 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc051 01303 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01304 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc053 01305 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01306 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc057 01307 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01308 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc059 01309 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01310 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc05b 01311 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01312 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc05d 01313 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01314 432 NtUserGetClassInfo (1999896576, 2292956, 2292908, 2292984, 0, ... ) == 0xc05f 01315 432 NtUserUnregisterClass (2292960, 1999896576, 2292948, ... ) == 0x1 01316 432 NtFreeVirtualMemory (-1, (0xc20000), 4096, 32768, ... (0xc20000), 4096, ) == 0x0 01317 432 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, -1, 4199054, 4310954, 4421244} (24, {20, 48, new_msg, 0, -1, 4199054, 4310954, 4421244} "\0\0\0\0\3\0\1\0\320vC\0C:\W\0\0\0\0" ... {20, 48, reply, 0, 412, 432, 1514, 0} "\0\0\0\0\3\0\1\0\0\0\0\0C:\W\0\0\0\0" ) ... {20, 48, reply, 0, 412, 432, 1514, 0} (24, {20, 48, new_msg, 0, -1, 4199054, 4310954, 4421244} "\0\0\0\0\3\0\1\0\320vC\0C:\W\0\0\0\0" ... {20, 48, reply, 0, 412, 432, 1514, 0} "\0\0\0\0\3\0\1\0\0\0\0\0C:\W\0\0\0\0" ) ) == 0x0 01318 432 NtTerminateProcess (-1, 0, ... 01319 432 NtClose (44, ... ) == 0x0