Summary:
NtAccessCheck(>) | 1 | NtQuerySymbolicLinkObject(>) | 1 | NtUserRegisterWindowMessage(>) | 3 | NtQueryDebugFilterState(>) | 15 |
NtAddAtom(>) | 1 | NtRegisterThreadTerminatePort(>) | 1 | NtCreateFile(>) | 4 | NtUnmapViewOfSection(>) | 15 |
NtCallbackReturn(>) | 1 | NtSecureConnectPort(>) | 1 | NtOpenProcessToken(>) | 4 | NtDeviceIoControlFile(>) | 16 |
NtCreateMutant(>) | 1 | NtSetInformationProcess(>) | 1 | NtQueryVolumeInformationFile(>) | 4 | NtCreateSection(>) | 19 |
NtDelayExecution(>) | 1 | NtTestAlert(>) | 1 | NtGdiGetStockObject(>) | 5 | NtOpenFile(>) | 25 |
NtDuplicateObject(>) | 1 | NtUserCallNoParam(>) | 1 | NtSetInformationFile(>) | 5 | NtProtectVirtualMemory(>) | 26 |
NtEnumerateValueKey(>) | 1 | NtUserCallOneParam(>) | 1 | NtFreeVirtualMemory(>) | 6 | NtOpenSection(>) | 28 |
NtFsControlFile(>) | 1 | NtUserGetDC(>) | 1 | NtSetInformationThread(>) | 6 | NtQueryDefaultLocale(>) | 29 |
NtGdiCreateBitmap(>) | 1 | NtUserGetThreadDesktop(>) | 1 | NtRequestWaitReplyPort(>) | 7 | NtQueryAttributesFile(>) | 31 |
NtGdiInit(>) | 1 | NtContinue(>) | 2 | NtOpenProcessTokenEx(>) | 8 | NtAllocateVirtualMemory(>) | 36 |
NtGdiQueryFontAssocInfo(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtOpenThreadTokenEx(>) | 8 | NtQueryValueKey(>) | 38 |
NtGdiSelectBitmap(>) | 1 | NtOpenDirectoryObject(>) | 2 | NtQueryDefaultUILanguage(>) | 8 | NtMapViewOfSection(>) | 39 |
NtNotifyChangeKey(>) | 1 | NtOpenEvent(>) | 2 | NtQueryVirtualMemory(>) | 8 | NtUserUnregisterClass(>) | 46 |
NtOpenKeyedEvent(>) | 1 | NtQueryInstallUILanguage(>) | 2 | NtSetValueKey(>) | 8 | NtUserFindExistingCursorIcon(>) | 48 |
NtOpenMutant(>) | 1 | NtTerminateProcess(>) | 2 | NtQueryInformationFile(>) | 9 | NtOpenKey(>) | 54 |
NtOpenProcess(>) | 1 | NtCreateEvent(>) | 3 | NtQuerySection(>) | 9 | NtUserRegisterClassExWOW(>) | 63 |
NtOpenSymbolicLinkObject(>) | 1 | NtCreateSemaphore(>) | 3 | NtCreateKey(>) | 10 | NtReadFile(>) | 68 |
NtOpenThreadToken(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtUserSystemParametersInfo(>) | 10 | NtQuerySystemInformation(>) | 75 |
NtQueryFullAttributesFile(>) | 1 | NtQueryInformationProcess(>) | 3 | NtQueryInformationToken(>) | 12 | NtUserGetClassInfo(>) | 82 |
NtQueryObject(>) | 1 | NtSetInformationObject(>) | 3 | NtFlushInstructionCache(>) | 13 | NtClose(>) | 116 |
, 80, ... ) , 0, 3, (-2147482052, "Seed", 0, 3, "\17\177\6\310\325\357\26 *, 80, ... ) , 80, ... ) == 0x0 00911 456 NtClose (-2147482052, ... ) == 0x0 00901 456 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\362\10o\226\307\371Y\221\177\334<^(\315\4\242\350\0\233\340\377\212V\2449\317\13c\301`\230\235\3270\370:\12\225\141\330\201\364_0\256\364\345\243?X\320\256\347R$XF\345\317P\244\365\361\3618\332\210\306K\366\352bT\324\7\210\240\204{@\24\246\206\201s\272[\310\30\33\273\16\316(B0\234\230\211\301\226}\13\325Y\271<\235\0\236\317\24w\253\246\230k\342\354Q\210\352n\320rv\256[ \331\15\21\16\337\201\235\376\312\27\334\302\304\32\26\25u\267\214\251y\2010\246U\310\300\362\302\343\274+_\33D)\222\360\325\275\232\177+Cetw\353\354\357\177w\261\313\313\200\214t\362\214\1\255\232&\376\221v\323\233\34\263zn\220\214\3047\371.\231$\16\350\22;,9\216\305{\355\26\377\21P\49\343\237[\24\22\316H\324>X\211\272\312='\307\245L\373EF\252\265\237\36q\256\247N", ) , ) == 0x0 00912 456 NtDeviceIoControlFile (112, 0, 0x0, 0x0, 0x390008, (112, 0, 0x0, 0x0, 0x390008, "lP!\304\34g\377\245\12\353'\262\300\21\17NH\374\237dz\322\212H\374\237dz\322\212H\374\237dz\322\212H\374\237dz\311#\31\345*\336\235Vd\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00913 456 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00914 456 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00915 456 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00916 456 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00917 456 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00918 456 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00919 456 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00920 456 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482052, 2, ) }, 0, 0x0, 0, ... -2147482052, 2, ) == 0x0 00921 456 NtSetValueKey (-2147482052, (-2147482052, "Seed", 0, 3, "&\37Z\323wh\31\16\217\202\223\333[T%\275W=\274\320]*Vs\207\10\317\266v\253\217\206\227\355\374\234\1\316\250\33`\301\0ojq\313\20\247\265\262\5\316\331u\32\332\351\307\220\241\22S\33306\230N\273\343\3~s\233:3\332\221\242\236", 80, ... ) , 0, 3, (-2147482052, "Seed", 0, 3, "&\37Z\323wh\31\16\217\202\223\333[T%\275W=\274\320]*Vs\207\10\317\266v\253\217\206\227\355\374\234\1\316\250\33`\301\0ojq\313\20\247\265\262\5\316\331u\32\332\351\307\220\241\22S\33306\230N\273\343\3~s\233:3\332\221\242\236", 80, ... ) , 80, ... ) == 0x0 00922 456 NtClose (-2147482052, ... ) == 0x0 00912 456 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\30~`\255,\207\313\16\35\223\34\17Q\234\6\347/_>0\245\350\336j\12~aV\312\341\344\245\323#7[\324\305\334\227tn{|\256\255\342\236P\371\17Lc>6\341D\363Jv\230\240\36\200\366\356\24\263yY\375\2626/m[\311,\247\34{;\222p\357\207\371\271q\345-\255\267\333D\274yT\37}\204r`\25\14\3143\331\16~\236\205\30\354t\312\367t\210\304\273\314j\260\11\257R\255\270;o$\264\312\362\213\375\24\213[\315:\6\3078ox\242U(%n\222\217\226\346\201\0\331\312\26c\206^\375\367\33\3047\353\6xe\35SAV4A\211\263\:\217\34awB\232\10\313\322b\277\230\11\371\0.\17>\14g\350M\342:F\207\204}\307\14>\224\363v\235\36\245\211\12\332\212k\27\261&\336\335\270\24i\312\331\255\257\303\300\246\32\352\256{I}\300\332xWO\245`\360\305", ) , ) == 0x0 00923 456 NtDeviceIoControlFile (112, 0, 0x0, 0x0, 0x390008, (112, 0, 0x0, 0x0, 0x390008, "lP!\304\34g\377\245\12\353'\262\300\21\17NH\374\237dz\322\212H\374\237dz\322\212H\374\237dz\322\212H\374\237dz\322\212H\374\237dz\311#\31\345*\336\235Vd\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00924 456 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00925 456 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00926 456 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00927 456 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00928 456 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00929 456 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00930 456 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00931 456 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482052, 2, ) }, 0, 0x0, 0, ... -2147482052, 2, ) == 0x0 00932 456 NtSetValueKey (-2147482052, (-2147482052, "Seed", 0, 3, "'+\22|\375\371P\347\346\230\305\11\216\215\211\307M\367\17\334\225\336\337\271|\304x\226?\342\212\31T\251\241p\232L8\205\3179\207\334]#\340:\253\221\300\277K\362\200\244\341\200\20\363YU\377\326\213l\217Dxq\247:2~C%9+\321\245", 80, ... ) , 0, 3, (-2147482052, "Seed", 0, 3, "'+\22|\375\371P\347\346\230\305\11\216\215\211\307M\367\17\334\225\336\337\271|\304x\226?\342\212\31T\251\241p\232L8\205\3179\207\334]#\340:\253\221\300\277K\362\200\244\341\200\20\363YU\377\326\213l\217Dxq\247:2~C%9+\321\245", 80, ... ) , 80, ... ) == 0x0 00933 456 NtClose (-2147482052, ... ) == 0x0 00923 456 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\362\7\370<\236\260\321\233\15q\10\221\217J\264\366\307O{\203Z4\301]X\246X=\317\256\222\231\301^y\213_\303.v^\242Q\335\360\253\361\226\236A\252\247\304\16;$s\3050C\345\216$\245\305\263Od\215\254^\201O8Ac\3725\344\245\337C0\33*u.\330\325\15\333X\207*\215t\221\15\335|$\375\361\220\310\225^)0e\235<\233\326\36d\272p\2]0\345\276\235CU\360Pt\265G\241\311\242\302\2R{\262P\7\30S;\226\34\224\234Z\346:\362H\246\240\365\362\4w\372(0\275x7rT%\0+\245\200\205V\324\367\221\346\27\255\33\200Y9\276\374YnA\225\3205\214\200\337\242\352w`\341]s\315\321\14m\354L\14k\242\320<\25:\235N\303\321.m\354\3022\246:\305\232\244\226|A\323\257\213\377\\370O\367\333\202\231\25\235\20\327,I\35\266\340j\237\34\263", ) , ) == 0x0 00934 456 NtDeviceIoControlFile (112, 0, 0x0, 0x0, 0x390008, (112, 0, 0x0, 0x0, 0x390008, "lP!\304\34g\377\245\12\353'\262\300\21\17NH\374\237dz\322\212H\374\237dz\322\212H\374\237dz\322\212H\374\237dz\322\212H\374\237dz\322\212H\374\237dz\311#\31\345*\336\235Vd\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 00935 456 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 00936 456 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 00937 456 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 00938 456 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 00939 456 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 00940 456 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 00941 456 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 00942 456 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482052, 2, ) }, 0, 0x0, 0, ... -2147482052, 2, ) == 0x0 00943 456 NtSetValueKey (-2147482052, (-2147482052, "Seed", 0, 3, "\7\304\344\306\277\3\37\370\202\2235!\211\303\0\235m 2\203\344Wu\26\355\325!\253\326m\23\312zsr\362N\2\327\355\5\357\361\325\202\327\266\306\213&\37K\341\341\223\31\22%\330\240R\30;0\25\236\204\367\4\322@\27\261\341\270Y\343\250.\27", 80, ... ) , 0, 3, (-2147482052, "Seed", 0, 3, "\7\304\344\306\277\3\37\370\202\2235!\211\303\0\235m 2\203\344Wu\26\355\325!\253\326m\23\312zsr\362N\2\327\355\5\357\361\325\202\327\266\306\213&\37K\341\341\223\31\22%\330\240R\30;0\25\236\204\367\4\322@\27\261\341\270Y\343\250.\27", 80, ... ) , 80, ... ) == 0x0 00944 456 NtClose (-2147482052, ... ) == 0x0 00934 456 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "n\350\235\2508O\261$\376\7\327W\252C\2014-$0K\36\2126Y\17Z\24\276#\262Q\13,\360\230\374w\220\371\5`\177\23\331: \234b\232\341\327Zmr\232\22\363\237\267\324{\353\230\223g\310T\3\305V\313K\333K\225\211e\177\317\330\337\31~\301O\264xu\241\237|\275\314\274\353u#%C\322B\34\27:<9\266e{(}\206D\22\5\303b\227Kb\244\267\276'\244J\10\244c6\211LF\214\352v\327\232\321\13vY:\271\277\372\334\261\314\266\366\25\200\21&\316\244\375\231|\240\32O\266=\346\374\5L5w"\355\203\352\3\342\335\305\25\243\340Qc\342\11O\304\256\245E\37\315\256\3\0JS\34\353\17u\326\233\27\371\275\34\276\360\317\352\262\307D\240\333\221z_\326_(+\22\10\244[j\252\237\266\343\311\25!\260\362\20\1\236\13\314\274\11\325\302#\32YR1\272\303;R", ) \355\203\352\3\342\335\305\25\243\340Qc\342\11O\304\256\245E\37\315\256\3\0JS\34\353\17u\326\233\27\371\275\34\276\360\317\352\262\307D\240\333\221z_\326_(+\22\10\244[j\252\237\266\343\311\25!\260\362\20\1\236\13\314\274\11\325\302#\32YR1\272\303;R", ) == 0x0 00945 456 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\u:\work\"}, 3, 33, ... 108, {status=0x0, info=1}, ) }, 3, 33, ... 108, {status=0x0, info=1}, ) == 0x0 00946 456 NtQueryVolumeInformationFile (108, 1238956, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00947 456 NtClose (12, ... ) == 0x0 00948 456 NtContinue (1237396, 0, ... 00949 456 NtTerminateProcess (0, 0, ... ) == 0x0 00950 456 NtClose (96, ... ) == 0x0 00951 456 NtUnmapViewOfSection (-1, 0x8a0000, ... ) == 0x0 00952 456 NtClose (100, ... ) == 0x0 00953 456 NtClose (92, ... ) == 0x0 00954 456 NtFreeVirtualMemory (-1, (0x8c0000), 0, 32768, ... (0x8c0000), 262144, ) == 0x0 00955 456 NtUserUnregisterClass (1239600, 1991376896, 1239588, ... ) == 0x0 00956 456 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 00957 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc03b 00958 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00959 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc03d 00960 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00961 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc03f 00962 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00963 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc041 00964 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00965 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc043 00966 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00967 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc045 00968 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00969 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc047 00970 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00971 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc049 00972 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00973 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc04b 00974 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00975 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc04d 00976 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00977 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc04f 00978 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00979 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc051 00980 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00981 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc053 00982 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00983 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc057 00984 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00985 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc059 00986 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00987 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc05b 00988 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00989 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc05d 00990 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00991 456 NtUserGetClassInfo (1999896576, 1239688, 1239640, 1239716, 0, ... ) == 0xc05f 00992 456 NtUserUnregisterClass (1239692, 1999896576, 1239680, ... ) == 0x1 00993 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc03b 00994 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 00995 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc03d 00996 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 00997 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc03f 00998 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 00999 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc041 01000 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01001 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc043 01002 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01003 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc045 01004 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01005 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc047 01006 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01007 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc049 01008 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01009 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc04b 01010 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01011 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc04d 01012 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01013 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc04f 01014 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01015 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc051 01016 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01017 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc053 01018 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01019 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc057 01020 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01021 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc059 01022 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01023 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc05b 01024 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01025 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc05d 01026 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01027 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc05f 01028 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01029 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc017 01030 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01031 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc019 01032 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01033 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc018 01034 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01035 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc01a 01036 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01037 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc01c 01038 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01039 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc01e 01040 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01041 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc01b 01042 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01043 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc068 01044 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01045 456 NtUserGetClassInfo (1905590272, 1239688, 1239640, 1239716, 0, ... ) == 0xc06a 01046 456 NtUserUnregisterClass (1239692, 1905590272, 1239680, ... ) == 0x1 01047 456 NtUnmapViewOfSection (-1, 0x8b0000, ... ) == 0x0 01048 456 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 01049 456 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 01050 456 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x3,}, 4, ... ) == 0x0 01051 456 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 01052 456 NtClose (112, ... ) == 0x0 01053 456 NtFreeVirtualMemory (-1, (0x0), 0, 32768, ... ) == STATUS_MEMORY_NOT_ALLOCATED 01054 456 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 1315560, 2012550797, 1240228, 18} (24, {20, 48, new_msg, 0, 1315560, 2012550797, 1240228, 18} "\0\0\0\0\3\0\1\0j\324f\376\350k\1$\0\0\0\0" ... {20, 48, reply, 0, 444, 456, 1500, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\350k\1$\0\0\0\0" ) ... {20, 48, reply, 0, 444, 456, 1500, 0} (24, {20, 48, new_msg, 0, 1315560, 2012550797, 1240228, 18} "\0\0\0\0\3\0\1\0j\324f\376\350k\1$\0\0\0\0" ... {20, 48, reply, 0, 444, 456, 1500, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\350k\1$\0\0\0\0" ) ) == 0x0 01055 456 NtTerminateProcess (-1, 0, ... 01056 456 NtClose (44, ... ) == 0x0