Summary:
NtAddAtom(>) | 1 | NtAccessCheck(>) | 2 | NtFsControlFile(>) | 7 | NtUserRegisterClassExWOW(>) | 33 |
NtConnectPort(>) | 1 | NtCallbackReturn(>) | 2 | NtOpenThreadToken(>) | 7 | NtQuerySystemInformation(>) | 34 |
NtCreateProcessEx(>) | 1 | NtCreateIoCompletion(>) | 2 | NtCreateSemaphore(>) | 8 | NtQueryInformationToken(>) | 38 |
NtDuplicateToken(>) | 1 | NtGdiCreateSolidBrush(>) | 2 | NtDeviceIoControlFile(>) | 8 | NtCreateEvent(>) | 40 |
NtGdiCreateBitmap(>) | 1 | NtOpenMutant(>) | 2 | NtEnumerateKey(>) | 8 | NtRequestWaitReplyPort(>) | 41 |
NtGdiInit(>) | 1 | NtQueryInformationJobObject(>) | 2 | NtWaitForMultipleObjects(>) | 8 | NtCreateSection(>) | 42 |
NtGdiQueryFontAssocInfo(>) | 1 | NtUserCloseWindowStation(>) | 2 | NtQueryInformationFile(>) | 11 | NtQueryInformationProcess(>) | 43 |
NtGdiSelectBitmap(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtWriteFile(>) | 11 | NtSetInformationThread(>) | 44 |
NtNotifyChangeKey(>) | 1 | NtOpenDirectoryObject(>) | 3 | NtQueryDefaultUILanguage(>) | 12 | NtQueryDefaultLocale(>) | 51 |
NtOpenKeyedEvent(>) | 1 | NtOpenSymbolicLinkObject(>) | 3 | NtQueryDebugFilterState(>) | 14 | NtFreeVirtualMemory(>) | 57 |
NtOpenProcess(>) | 1 | NtQuerySymbolicLinkObject(>) | 3 | NtQuerySection(>) | 17 | NtOpenFile(>) | 57 |
NtQueryInstallUILanguage(>) | 1 | NtReadVirtualMemory(>) | 3 | NtUserFindWindowEx(>) | 17 | NtQueryAttributesFile(>) | 63 |
NtQueryObject(>) | 1 | NtReleaseMutant(>) | 3 | NtUserGetAtomName(>) | 19 | NtQueryVirtualMemory(>) | 67 |
NtQueryPerformanceCounter(>) | 1 | NtSetInformationObject(>) | 3 | NtUserUnregisterClass(>) | 19 | NtUnmapViewOfSection(>) | 67 |
NtQuerySystemTime(>) | 1 | NtTerminateProcess(>) | 3 | NtQueryDirectoryFile(>) | 24 | NtSetEvent(>) | 89 |
NtQueryTimerResolution(>) | 1 | NtUserQueryWindow(>) | 3 | NtQueryInformationThread(>) | 25 | NtMapViewOfSection(>) | 92 |
NtRaiseException(>) | 1 | NtUserRegisterWindowMessage(>) | 3 | NtSetInformationProcess(>) | 25 | NtFlushInstructionCache(>) | 95 |
NtSecureConnectPort(>) | 1 | NtDuplicateObject(>) | 4 | NtUserFindExistingCursorIcon(>) | 25 | NtWaitForSingleObject(>) | 125 |
NtSetValueKey(>) | 1 | NtCreateKey(>) | 5 | NtCreateFile(>) | 26 | NtDelayExecution(>) | 134 |
NtUserCallNoParam(>) | 1 | NtCreateMutant(>) | 5 | NtCreateThread(>) | 26 | NtOpenKey(>) | 176 |
NtUserGetDC(>) | 1 | NtGdiGetStockObject(>) | 5 | NtRegisterThreadTerminatePort(>) | 26 | NtQueryValueKey(>) | 198 |
NtUserGetForegroundWindow(>) | 1 | NtReadFile(>) | 5 | NtResumeThread(>) | 26 | NtProtectVirtualMemory(>) | 223 |
NtUserGetObjectInformation(>) | 1 | NtSetInformationFile(>) | 5 | NtTestAlert(>) | 26 | NtAllocateVirtualMemory(>) | 224 |
NtUserGetProcessWindowStation(>) | 1 | NtUserSystemParametersInfo(>) | 5 | NtOpenProcessTokenEx(>) | 30 | NtClose(>) | 290 |
NtUserGetThreadDesktop(>) | 1 | NtWriteVirtualMemory(>) | 5 | NtOpenThreadTokenEx(>) | 30 | ||
NtUserOpenWindowStation(>) | 1 | NtOpenProcessToken(>) | 6 | NtContinue(>) | 32 | ||
NtUserValidateHandleSecure(>) | 1 |
p\1\350\236\212\7Lw\365\2\352jn^Qy\273\\304\227v\323\223\247\213x\205\263\4M\226\16\212\373z/\355\5\24\32\257\24\13\234\262P\277P\253(\6)\274"
, ) , ) == 0x0 02019 860 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 368, ) == 0x0 02020 860 NtConnectPort ( ("\RPC Control\IcaApi", {12, 2, 1, 0}, 0x0, 0x0, 1234784, 188, ... 372, 0x0, 0x0, 0x0, 188, ) , {12, 2, 1, 0}, 0x0, 0x0, 1234784, 188, ... 372, 0x0, 0x0, 0x0, 188, ) == 0x0 02021 860 NtRequestWaitReplyPort (372, {200, 224, new_msg, 0, 2621478, 1346952, 12, 2} (372, {200, 224, new_msg, 0, 2621478, 1346952, 12, 2} "\0\0\24\0 \4\24\0\274\0\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\2\0\4\0\0\0\260/\24\0\1\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\1\0\0\08:\221/\205q\365\235X\215\24\0d\1\24\0\12\0\0\0\0\0\0\0X\215\24\0(\0\0\0`\215\24\0\270\261\36\234 \4\24\0(\0\0\0\272\30\0\0\0\0\24\0\274\325\22\0U\0\0\0\0\0\0\0\300H\24\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\340\325\22\0\372\31\221|t\335\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ... {200, 224, reply, 0, 464, 860, 58000, 0} "\7\0\24\0 \4\24\0\274\0\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\260/\24\0\377\377\377\377\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\1\0\0\08:\221/\205q\365\235X\215\24\0d\1\24\0\12\0\0\0\0\0\0\0X\215\24\0(\0\0\0`\215\24\0\270\261\36\234 \4\24\0(\0\0\0\272\30\0\0\0\0\24\0\274\325\22\0U\0\0\0\0\0\0\0\300H\24\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\340\325\22\0\372\31\221|t\335\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ) ... {200, 224, reply, 0, 464, 860, 58000, 0} (372, {200, 224, new_msg, 0, 2621478, 1346952, 12, 2} "\0\0\24\0 \4\24\0\274\0\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\2\0\4\0\0\0\260/\24\0\1\0\0\0\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\1\0\0\08:\221/\205q\365\235X\215\24\0d\1\24\0\12\0\0\0\0\0\0\0X\215\24\0(\0\0\0`\215\24\0\270\261\36\234 \4\24\0(\0\0\0\272\30\0\0\0\0\24\0\274\325\22\0U\0\0\0\0\0\0\0\300H\24\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\340\325\22\0\372\31\221|t\335\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ... {200, 224, reply, 0, 464, 860, 58000, 0} "\7\0\24\0 \4\24\0\274\0\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\260/\24\0\377\377\377\377\10\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\1\0\0\08:\221/\205q\365\235X\215\24\0d\1\24\0\12\0\0\0\0\0\0\0X\215\24\0(\0\0\0`\215\24\0\270\261\36\234 \4\24\0(\0\0\0\272\30\0\0\0\0\24\0\274\325\22\0U\0\0\0\0\0\0\0\300H\24\0\360\6\221|\377\377\377\377P\0\0\0\346\31\0|\0\0\24\0\340\325\22\0\372\31\221|t\335\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ) ) == 0x0 02022 860 NtRequestWaitReplyPort (372, {32, 56, new_msg, 0, 0, 0, 0, 0} (372, {32, 56, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\3\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\377\377\377\377\0\0\0\0" ... {124, 148, reply, 0, 464, 860, 58001, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\0\0\0\0\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201\0;\251\201\1`\202\201\0\0\0\0\0\376?\300\344\243n\371\20W\271\201\2\0\0\0\240V\271\201\240V\271\201" ) ... {124, 148, reply, 0, 464, 860, 58001, 0} (372, {32, 56, new_msg, 0, 0, 0, 0, 0} "\1\0\0\0A\3\0\0`\247\244\\261\353\317\21\206\21\0\240$T \355\377\377\377\377\0\0\0\0" ... {124, 148, reply, 0, 464, 860, 58001, 0} "\2\356Q\200\1\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\0\0\0\0\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201\0;\251\201\1`\202\201\0\0\0\0\0\376?\300\344\243n\371\20W\271\201\2\0\0\0\240V\271\201\240V\271\201" ) ) == 0x0 02023 860 NtAllocateVirtualMemory (-1, 1347584, 0, 4096, 4096, 4, ... 1347584, 4096, ) == 0x0 02024 860 NtRequestWaitReplyPort (372, {44, 68, new_msg, 56, 464, 860, 58001, 0} (372, {44, 68, new_msg, 56, 464, 860, 58001, 0} "\1\356\0\0B\2\5\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\10\220\24\0\10\5\0\0" ... {40, 64, reply, 0, 464, 860, 58002, 0} "\2\376\255\201\4\0\0\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200X;\350\371\324\376\255\201\14\5\0\0\320\371\15\0" ) ... {40, 64, reply, 0, 464, 860, 58002, 0} (372, {44, 68, new_msg, 56, 464, 860, 58001, 0} "\1\356\0\0B\2\5\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\1\0\0\0\10\220\24\0\10\5\0\0" ... {40, 64, reply, 0, 464, 860, 58002, 0} "\2\376\255\201\4\0\0\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200X;\350\371\324\376\255\201\14\5\0\0\320\371\15\0" ) ) == 0x0 02025 860 NtRequestWaitReplyPort (372, {64, 88, new_msg, 56, 1347312, 1235360, 1347584, 0} (372, {64, 88, new_msg, 56, 1347312, 1235360, 1347584, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 464, 860, 58003, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ... {64, 88, reply, 56, 464, 860, 58003, 0} (372, {64, 88, new_msg, 56, 1347312, 1235360, 1347584, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 464, 860, 58003, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02026 860 NtRequestWaitReplyPort (372, {44, 68, new_msg, 56, 464, 860, 58002, 0} (372, {44, 68, new_msg, 56, 464, 860, 58002, 0} "\1\376\0\0B\2\5\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200\377\377\377\377\324\376\255\201\1\0\0\0\10\220\24\0\10\5\0\0" ... {40, 64, reply, 0, 464, 860, 58004, 0} "\2\356Q\200\4\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\14\5\0\0\320\371\15\0" ) ... {40, 64, reply, 0, 464, 860, 58004, 0} (372, {44, 68, new_msg, 56, 464, 860, 58002, 0} "\1\376\0\0B\2\5\0\200Y\274\201V\347\340\341\264\311\275\201:\332R\200\377\377\377\377\324\376\255\201\1\0\0\0\10\220\24\0\10\5\0\0" ... {40, 64, reply, 0, 464, 860, 58004, 0} "\2\356Q\200\4\0\0\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300lk\364\367X\353Q\200\14\5\0\0\320\371\15\0" ) ) == 0x0 02027 860 NtRequestWaitReplyPort (372, {64, 88, new_msg, 56, 1347312, 1235360, 1347584, 0} (372, {64, 88, new_msg, 56, 1347312, 1235360, 1347584, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 464, 860, 58005, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ... {64, 88, reply, 56, 464, 860, 58005, 0} (372, {64, 88, new_msg, 56, 1347312, 1235360, 1347584, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ... {64, 88, reply, 56, 464, 860, 58005, 0} "\10\0\0\0@\0\1\1\0\2\0\0\230\330\22\0\10\220\24\0\264\335\22\0\30\356\220|p\5\221|\1\0\0\0\10\220\24\0\14\5\0\0\14\5\0\0\320\371\15\0\0\0\0\0\0\0\0\0\273f\347w" ) ) == 0x0 02028 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 376, ) }, ... 376, ) == 0x0 02029 860 NtOpenKey (0x20019, {24, 376, 0x40, 0, 0, (0x20019, {24, 376, 0x40, 0, 0, "ActiveComputerName"}, ... 380, ) }, ... 380, ) == 0x0 02030 860 NtQueryValueKey (380, (380, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (380, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (380, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 02031 860 NtClose (380, ... ) == 0x0 02032 860 NtClose (376, ... ) == 0x0 02033 860 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 376, ) == 0x0 02034 860 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 380, ) == 0x0 02035 860 NtDuplicateObject (-1, 376, -1, 0x0, 0, 2, ... 384, ) == 0x0 02036 860 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02037 860 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 388, ) == 0x0 02038 860 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02039 860 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02040 860 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234820, (0xc0100080, {24, 0, 0x40, 0, 1234820, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 392, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 392, {status=0x0, info=1}, ) == 0x0 02041 860 NtSetInformationFile (392, 1234876, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02042 860 NtSetInformationFile (392, 1234864, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02043 860 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02044 860 NtWriteFile (392, 357, 0, 0, (392, 357, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02045 860 NtReadFile (392, 357, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (392, 357, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02046 860 NtFsControlFile (392, 357, 0x0, 0x0, 0x11c017, (392, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0L\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (392, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0L\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02047 860 NtFsControlFile (392, 357, 0x0, 0x0, 0x11c017, (392, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\1\0\0\0\1\0\0\0,\0.\0\0\341\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) , 140, 1024, ... {status=0x103, info=48}, (392, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\1\0\0\0\1\0\0\0,\0.\0\0\341\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) , ) == 0x103 02048 860 NtFsControlFile (392, 357, 0x0, 0x0, 0x11c017, (392, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\200\233\24\0\1\0\0\0\214\233\24\0 \0\0\0\1\0\0\0\16\0\20\0\230\233\24\0\250\233\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\350\233\24\0\1\0\0\0\1\0\0\0\370\233\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=180}, (392, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\200\233\24\0\1\0\0\0\214\233\24\0 \0\0\0\1\0\0\0\16\0\20\0\230\233\24\0\250\233\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\350\233\24\0\1\0\0\0\1\0\0\0\370\233\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 02049 860 NtClose (388, ... ) == 0x0 02050 860 NtClose (392, ... ) == 0x0 02051 860 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02052 860 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 392, ) == 0x0 02053 860 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02054 860 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02055 860 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234792, (0xc0100080, {24, 0, 0x40, 0, 1234792, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 388, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 388, {status=0x0, info=1}, ) == 0x0 02056 860 NtSetInformationFile (388, 1234848, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02057 860 NtSetInformationFile (388, 1234836, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02058 860 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02059 860 NtWriteFile (388, 357, 0, 0, (388, 357, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02060 860 NtReadFile (388, 357, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (388, 357, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02061 860 NtFsControlFile (388, 357, 0x0, 0x0, 0x11c017, (388, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (388, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\00\336\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02062 860 NtFsControlFile (388, 357, 0x0, 0x0, 0x11c017, (388, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\1\0\0\0\1\0\0\0,\0.\0\0\341\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , 140, 1024, ... {status=0x103, info=48}, (388, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\214\0\0\0\2\0\0\0t\0\0\0\0\0D\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\1\0\0\0\1\0\0\0,\0.\0\0\341\22\0\27\0\0\0\0\0\0\0\26\0\0\0V\0I\0R\0T\0U\0A\0L\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0", 140, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , ) == 0x103 02063 860 NtFsControlFile (388, 357, 0x0, 0x0, 0x11c017, (388, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\200\233\24\0\1\0\0\0\214\233\24\0 \0\0\0\1\0\0\0\16\0\20\0\230\233\24\0\250\233\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\350\233\24\0\1\0\0\0\1\0\0\0\370\233\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=180}, (388, 357, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=180}, "\5\0\2\3\20\0\0\0\264\0\0\0\2\0\0\0\234\0\0\0\0\0\0\0\200\233\24\0\1\0\0\0\214\233\24\0 \0\0\0\1\0\0\0\16\0\20\0\230\233\24\0\250\233\24\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\5\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\1\0\0\0\350\233\24\0\1\0\0\0\1\0\0\0\370\233\24\0\0\0\0\0\0\0\0\0\5\0\0\0\1\5\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\353\3\0\0\1\0\0\0\0\0\0\0", ) , ) == 0x103 02064 860 NtClose (392, ... ) == 0x0 02065 860 NtClose (388, ... ) == 0x0 02066 860 NtOpenProcessToken (-1, 0x20008, ... 388, ) == 0x0 02067 860 NtQueryInformationToken (388, User, 0, ... ) == STATUS_BUFFER_TOO_SMALL 02068 860 NtQueryInformationToken (388, User, 36, ... {token info, class 1, size 36}, 36, ) == 0x0 02069 860 NtOpenDirectoryObject (0x2, {24, 0, 0x40, 0, 0, (0x2, {24, 0, 0x40, 0, 0, "\Windows\WindowStations"}, ... 392, ) }, ... 392, ) == 0x0 02070 860 NtUserOpenWindowStation ({24, 392, 0x40, 0, 0, ({24, 392, 0x40, 0, 0, "winsta0"}, 0x37f, ... ) }, 0x37f, ... ) == 0x18c 02071 860 NtClose (392, ... ) == 0x0 02072 860 NtUserCloseWindowStation (396, ... 02073 860 NtClose (396, ... ) == 0x0 02072 860 NtUserCloseWindowStation ... ) == 0x1 02074 860 NtClose (388, ... ) == 0x0 02075 860 NtCreateEvent (0x1f0003, {24, 0, 0x2, 0, 0, 0x0}, 1, 0, ... 388, ) == 0x0 02076 860 NtCreateEvent (0x1f0003, {24, 0, 0x2, 0, 0, 0x0}, 1, 0, ... 396, ) == 0x0 02077 860 NtCreateMutant (0x1f0001, {24, 0, 0x2, 0, 0, 0x0}, 0, ... 392, ) == 0x0 02078 860 NtDuplicateObject (-1, -1, -1, 0x1f0fff, 2, 0, ... 400, ) == 0x0 02079 860 NtCreateSection (0xf0007, {24, 0, 0x2, 0, 0, 0x0}, {7248, 0}, 4, 134217728, 0, ... 404, ) == 0x0 02080 860 NtMapViewOfSection (404, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2560000), {0, 0}, 8192, ) == 0x0 02081 860 NtQueryDefaultUILanguage (1235484, ... 02082 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02083 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0 02084 860 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02085 860 NtClose (-2147482740, ... ) == 0x0 02086 860 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 02087 860 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02088 860 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0 02089 860 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02090 860 NtClose (-2147481328, ... ) == 0x0 02091 860 NtClose (-2147482740, ... ) == 0x0 02081 860 NtQueryDefaultUILanguage ... ) == 0x0 02092 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02093 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02094 860 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0 02095 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1233728, ... ) }, 1233728, ... ) == 0x0 02096 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1232500, ... ) }, 1232500, ... ) == 0x0 02097 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02098 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02099 860 NtCreateFile (0x10100080, {24, 0, 0x40, 0, 1234836, (0x10100080, {24, 0, 0x40, 0, 1234836, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\a28_appcompat.txt"}, 0x0, 128, 0, 2, 96, 0, 0, ... }, 0x0, 128, 0, 2, 96, 0, 0, ... 02100 860 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, "DOCUME~1", 1, ... {status=0x0, info=56}, ) , 1, ... {status=0x0, info=56}, ) == 0x0 02101 860 NtClose (-2147482740, ... ) == 0x0 02102 860 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, "MARTIM~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 02103 860 NtClose (-2147482740, ... ) == 0x0 02104 860 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, "LOCALS~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 02105 860 NtClose (-2147482740, ... ) == 0x0 02099 860 NtCreateFile ... 408, {status=0x0, info=2}, ) == 0x0 02106 860 NtClose (408, ... ) == 0x0 02107 860 NtCreateSection (0xf001f, 0x0, {4194304, 0}, 4, 67108864, 0, ... 408, ) == 0x0 02108 860 NtMapViewOfSection (408, -1, (0x0), 0, 0, 0x0, 4194304, 2, 0, 4, ... (0x2960000), 0x0, 4194304, ) == 0x0 02109 860 NtAllocateVirtualMemory (-1, 43384832, 0, 1, 4096, 4, ... 43384832, 4096, ) == 0x0 02110 860 NtAllocateVirtualMemory (-1, 43388928, 0, 3672, 4096, 4, ... 43388928, 4096, ) == 0x0 02111 860 NtCreateSection (0xf0007, 0x0, {28780, 0}, 4, 134217728, 0, ... 412, ) == 0x0 02112 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02113 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02114 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02115 860 NtClose (408, ... ) == 0x0 02116 860 NtUnmapViewOfSection (-1, 0x2960000, ... ) == 0x0 02117 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02118 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02119 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02120 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02121 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02122 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02123 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02124 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02125 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02126 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02127 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02128 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02129 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02130 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02131 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02132 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02133 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02134 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02135 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02136 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02137 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02138 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02139 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02140 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02141 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02142 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02143 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02144 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02145 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02146 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02147 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02148 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02149 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02150 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02151 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02152 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02153 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02154 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02155 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02156 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02157 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02158 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02159 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02160 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02161 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02162 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02163 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02164 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02165 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02166 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02167 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02168 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02169 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02170 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02171 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02172 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 32768, ) == 0x0 02173 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02174 860 NtClose (412, ... ) == 0x0 02175 860 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02176 860 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\u:"}, 3, 96, ... 412, {status=0x0, info=1}, ) }, 3, 96, ... 412, {status=0x0, info=1}, ) == 0x0 02177 860 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\u:"}, ... 408, ) }, ... 408, ) == 0x0 02178 860 NtQuerySymbolicLinkObject (408, ... (408, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 02179 860 NtClose (408, ... ) == 0x0 02180 860 NtQueryVolumeInformationFile (412, 1234052, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02181 860 NtClose (412, ... ) == 0x0 02182 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 1232848, ... ) }, 1232848, ... ) == 0x0 02183 860 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 5, 96, ... 412, {status=0x0, info=1}, ) }, 5, 96, ... 412, {status=0x0, info=1}, ) == 0x0 02184 860 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 412, ... 408, ) == 0x0 02185 860 NtClose (412, ... ) == 0x0 02186 860 NtMapViewOfSection (408, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x2580000), 0x0, 126976, ) == 0x0 02187 860 NtClose (408, ... ) == 0x0 02188 860 NtUnmapViewOfSection (-1, 0x2580000, ... ) == 0x0 02189 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 1233156, ... ) }, 1233156, ... ) == 0x0 02190 860 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\apphelp.dll"}, 5, 96, ... 408, {status=0x0, info=1}, ) }, 5, 96, ... 408, {status=0x0, info=1}, ) == 0x0 02191 860 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 408, ... 412, ) == 0x0 02192 860 NtQuerySection (412, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02193 860 NtClose (408, ... ) == 0x0 02194 860 NtMapViewOfSection (412, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 02195 860 NtClose (412, ... ) == 0x0 02196 860 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 02197 860 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 02198 860 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 02199 860 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02200 860 NtAllocateVirtualMemory (-1, 1351680, 0, 12288, 4096, 4, ... 1351680, 12288, ) == 0x0 02201 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1234544, ... ) }, 1234544, ... ) == 0x0 02202 860 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1234552, (0x40100080, {24, 0, 0x40, 0, 1234552, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\a28_appcompat.txt"}, 0x0, 128, 0, 5, 96, 0, 0, ... }, 0x0, 128, 0, 5, 96, 0, 0, ... 02203 860 NtClose (-2147482740, ... ) == 0x0 02204 860 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, "DOCUME~1", 1, ... {status=0x0, info=56}, ) , 1, ... {status=0x0, info=56}, ) == 0x0 02205 860 NtClose (-2147482740, ... ) == 0x0 02206 860 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, "MARTIM~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 02207 860 NtClose (-2147482740, ... ) == 0x0 02208 860 NtQueryDirectoryFile (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, (-2147482740, 0, 0, 0, -518905856, 4096, Names, 1, "LOCALS~1", 1, ... {status=0x0, info=40}, ) , 1, ... {status=0x0, info=40}, ) == 0x0 02209 860 NtClose (-2147482740, ... ) == 0x0 02202 860 NtCreateFile ... 412, {status=0x0, info=3}, ) == 0x0 02210 860 NtAllocateVirtualMemory (-1, 1363968, 0, 12288, 4096, 4, ... 1363968, 12288, ) == 0x0 02211 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work\"}, 3, 16417, ... 408, {status=0x0, info=1}, ) }, 3, 16417, ... 408, {status=0x0, info=1}, ) == 0x0 02212 860 NtQueryDirectoryFile (408, 0, 0, 0, 1233256, 616, BothDirectory, 1, (408, 0, 0, 0, 1233256, 616, BothDirectory, 1, "packed.exe", 0, ... {status=0x0, info=120}, ) , 0, ... {status=0x0, info=120}, ) == 0x0 02213 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, "\377\376", 2, 0x0, 0, ... {status=0x0, info=2}, ) , 2, 0x0, 0, ... {status=0x0, info=2}, ) == 0x0 02214 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) \01\0.\00\0 (412, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) \0U\0T\0F\0-\01\06\0 (412, 0, 0, 0, "<\0?\0x\0m\0l\0 \0v\0e\0r\0s\0i\0o\0n\0=\0"\01\0.\00\0"\0 \0e\0n\0c\0o\0d\0i\0n\0g\0=\0"\0U\0T\0F\0-\01\06\0"\0?\0>\0\15\0\12\0<\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 106, 0x0, 0, ... {status=0x0, info=106}, ) , 106, 0x0, 0, ... {status=0x0, info=106}, ) == 0x0 02215 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) \0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0 (412, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) \0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0 (412, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 122, 0x0, 0, ... {status=0x0, info=122}, ) , 122, 0x0, 0, ... {status=0x0, info=122}, ) == 0x0 02216 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1233636, ... ) }, 1233636, ... ) == 0x0 02217 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\u:\work"}, 3, 16417, ... 416, {status=0x0, info=1}, ) }, 3, 16417, ... 416, {status=0x0, info=1}, ) == 0x0 02218 860 NtQueryDirectoryFile (416, 0, 0, 0, 1233248, 592, Directory, 1, (416, 0, 0, 0, 1233248, 592, Directory, 1, "packed.exe", 0, ... {status=0x0, info=84}, ) , 0, ... {status=0x0, info=84}, ) == 0x0 02219 860 NtClose (416, ... ) == 0x0 02220 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02221 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02222 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1232168, ... ) }, 1232168, ... ) == 0x0 02223 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 1230940, ... ) }, 1230940, ... ) == 0x0 02224 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02225 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02226 860 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... 416, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 416, {status=0x0, info=1}, ) == 0x0 02227 860 NtQueryInformationFile (416, 1233724, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02228 860 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 416, ... 420, ) == 0x0 02229 860 NtMapViewOfSection (420, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2960000), 0x0, 1179648, ) == 0x0 02230 860 NtUnmapViewOfSection (-1, 0x2960000, ... ) == 0x0 02231 860 NtClose (420, ... ) == 0x0 02232 860 NtClose (416, ... ) == 0x0 02233 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \01\01\07\09\06\04\08\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \00\0x\06\0E\04\08\05\0C\03\08\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \0W\0I\0N\03\02\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \00\0x\00\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \00\0x\00\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... \00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0"\0 \0S\0I\0Z\0E\0=\0"\01\01\07\09\06\04\08\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\06\0E\04\08\05\0C\03\08\0"\0 \0M\0O\0D\0U\0L\0E\0_\0T\0Y\0P\0E\0=\0"\0W\0I\0N\03\02\0"\0 \0P\0E\0_\0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0E\0R\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\00\0x\00\0"\0 \0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0U\0P\0T\0O\0_\0L\0I\0N\0K\0_\0D\0A\0T\0E\0=\0"\00\02\0/\01\07\0/\02\00\00\08\0 \01\03\0:\00\02\0:\05\06\0"\0 \0/\0>\0\15\0\12\0", 412, 0x0, 0, ... , 412, 0x0, 0, ... 02234 860 NtContinue (-139612716, 0, ... 02233 860 NtWriteFile ... {status=0x0, info=412}, ) == 0x0 02235 860 NtQueryDirectoryFile (408, 0, 0, 0, 1367624, 4096, BothDirectory, 0, 0x0, 0, ... ) == STATUS_NO_MORE_FILES 02236 860 NtClose (408, ... ) == 0x0 02237 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, "<\0/\0E\0X\0E\0>\0\15\0\12\0", 16, 0x0, 0, ... {status=0x0, info=16}, ) , 16, 0x0, 0, ... {status=0x0, info=16}, ) == 0x0 02238 860 NtClose (412, ... ) == 0x0 02239 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1234544, ... ) }, 1234544, ... ) == 0x0 02240 860 NtCreateFile (0x40100080, {24, 0, 0x40, 0, 1234552, (0x40100080, {24, 0, 0x40, 0, 1234552, "\??\C:\DOCUME~1\MARTIM~1\LOCALS~1\Temp\a28_appcompat.txt"}, 0x0, 128, 0, 3, 96, 0, 0, ... 412, {status=0x0, info=1}, ) }, 0x0, 128, 0, 3, 96, 0, 0, ... 412, {status=0x0, info=1}, ) == 0x0 02241 860 NtQueryInformationFile (412, 1234576, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02242 860 NtSetInformationFile (412, 1234608, 8, Position, ... {status=0x0, info=0}, ) == 0x0 02243 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 408, {status=0x0, info=1}, ) }, 3, 16417, ... 408, {status=0x0, info=1}, ) == 0x0 02244 860 NtQueryDirectoryFile (408, 0, 0, 0, 1233256, 616, BothDirectory, 1, (408, 0, 0, 0, 1233256, 616, BothDirectory, 1, "kernel32.dll", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 02245 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) \0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0 (412, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) \0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0 (412, 0, 0, 0, "<\0E\0X\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0F\0I\0L\0T\0E\0R\0=\0"\0G\0R\0A\0B\0M\0I\0_\0F\0I\0L\0T\0E\0R\0_\0T\0H\0I\0S\0F\0I\0L\0E\0O\0N\0L\0Y\0"\0>\0\15\0\12\0", 126, 0x0, 0, ... {status=0x0, info=126}, ) , 126, 0x0, 0, ... {status=0x0, info=126}, ) == 0x0 02246 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1233608, ... ) }, 1233608, ... ) == 0x0 02247 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 3, 16417, ... 416, {status=0x0, info=1}, ) }, 3, 16417, ... 416, {status=0x0, info=1}, ) == 0x0 02248 860 NtQueryDirectoryFile (416, 0, 0, 0, 1233248, 592, Directory, 1, (416, 0, 0, 0, 1233248, 592, Directory, 1, "kernel32.dll", 0, ... {status=0x0, info=88}, ) , 0, ... {status=0x0, info=88}, ) == 0x0 02249 860 NtClose (416, ... ) == 0x0 02250 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02251 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02252 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1232168, ... ) }, 1232168, ... ) == 0x0 02253 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1230940, ... ) }, 1230940, ... ) == 0x0 02254 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02255 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02256 860 NtQueryDefaultLocale (1, 1233128, ... ) == 0x0 02257 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02258 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02259 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1232160, ... ) }, 1232160, ... ) == 0x0 02260 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 1230932, ... ) }, 1230932, ... ) == 0x0 02261 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02262 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02263 860 NtQueryDefaultLocale (1, 1233120, ... ) == 0x0 02264 860 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\kernel32.dll"}, 0x0, 128, 1, 1, 96, 0, 0, ... 416, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 416, {status=0x0, info=1}, ) == 0x0 02265 860 NtQueryInformationFile (416, 1233724, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02266 860 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 416, ... 420, ) == 0x0 02267 860 NtMapViewOfSection (420, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2960000), 0x0, 987136, ) == 0x0 02268 860 NtUnmapViewOfSection (-1, 0x2960000, ... ) == 0x0 02269 860 NtClose (420, ... ) == 0x0 02270 860 NtClose (416, ... ) == 0x0 02271 860 NtQueryDefaultUILanguage (1233080, ... 02272 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02273 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482740, ) == 0x0 02274 860 NtQueryInformationToken (-2147482740, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02275 860 NtClose (-2147482740, ... ) == 0x0 02276 860 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482740, ) }, ... -2147482740, ) == 0x0 02277 860 NtOpenKey (0x80000000, {24, -2147482740, 0x240, 0, 0, (0x80000000, {24, -2147482740, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02278 860 NtOpenKey (0x80000000, {24, -2147482740, 0x640, 0, 0, (0x80000000, {24, -2147482740, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481328, ) }, ... -2147481328, ) == 0x0 02279 860 NtQueryValueKey (-2147481328, (-2147481328, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02280 860 NtClose (-2147481328, ... ) == 0x0 02281 860 NtClose (-2147482740, ... ) == 0x0 02271 860 NtQueryDefaultUILanguage ... ) == 0x0 02282 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \09\08\04\05\07\06\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \00\0x\0F\00\0B\03\03\01\0F\06\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0 (412, 0, 0, 0, " \0 \0 \0 \0<\0M\0A\0T\0C\0H\0I\0N\0G\0_\0F\0I\0L\0E\0 \0N\0A\0M\0E\0=\0"\0k\0e\0r\0n\0e\0l\03\02\0.\0d\0l\0l\0"\0 \0S\0I\0Z\0E\0=\0"\09\08\04\05\07\06\0"\0 \0C\0H\0E\0C\0K\0S\0U\0M\0=\0"\00\0x\0F\00\0B\03\03\01\0F\06\0"\0 \0B\0I\0N\0_\0F\0I\0L\0E\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0B\0I\0N\0_\0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0P\0R\0O\0D\0U\0C\0T\0_\0V\0E\0R\0S\0I\0O\0N\0=\0"\05\0.\01\0.\02\06\00\00\0.\03\01\01\09\0"\0 \0F\0I\0L\0E\0_\0D\0E\0S\0C\0R\0I\0P\0T\0I\0O\0N\0=\0"\0W\0i\0n\0d\0o\0w\0s\0 \0N\0T\0 \0B\0A\0S\0E\0 \0A\0P\0I\0 \0C\0l\0i\0e\0n\0t\0 \0D\0L\0L\0"\0 \0C\0O\0M\0P\0A\0N\0Y\0_\0N\0A\0M\0E\0=\0"\0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) \0M\0i\0c\0r\0o\0s\0o\0f\0t\0 \0", 1666, 0x0, 0, ... {status=0x0, info=1666}, ) == 0x0 02283 860 NtQueryDirectoryFile (408, 0, 0, 0, 1359456, 4096, BothDirectory, 0, 0x0, 0, ... ) == STATUS_NO_MORE_FILES 02284 860 NtClose (408, ... ) == 0x0 02285 860 NtWriteFile (412, 0, 0, 0, (412, 0, 0, 0, "<\0/\0E\0X\0E\0>\0\15\0\12\0<\0/\0D\0A\0T\0A\0B\0A\0S\0E\0>\0\15\0\12\0", 42, 0x0, 0, ... {status=0x0, info=42}, ) , 42, 0x0, 0, ... {status=0x0, info=42}, ) == 0x0 02286 860 NtClose (412, ... ) == 0x0 02287 860 NtUnmapViewOfSection (-1, 0x77b40000, ... ) == 0x0 02288 860 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 02289 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1231816, ... ) }, 1231816, ... ) == 0x0 02290 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1232552, ... ) }, 1232552, ... ) == 0x0 02291 860 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 412, {status=0x0, info=1}, ) }, 5, 96, ... 412, {status=0x0, info=1}, ) == 0x0 02292 860 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 412, ... 408, ) == 0x0 02293 860 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02294 860 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 416, ) }, ... 416, ) == 0x0 02295 860 NtQueryValueKey (416, (416, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02296 860 NtClose (416, ... ) == 0x0 02297 860 NtQueryVolumeInformationFile (412, 1231828, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02298 860 NtOpenMutant (0x120001, {24, 44, 0x0, 0, 0, (0x120001, {24, 44, 0x0, 0, 0, "ShimCacheMutex"}, ... 416, ) }, ... 416, ) == 0x0 02299 860 NtWaitForSingleObject (416, 0, {-1000000, -1}, ... ) == 0x0 02300 860 NtOpenSection (0x2, {24, 44, 0x0, 0, 0, (0x2, {24, 44, 0x0, 0, 0, "ShimSharedMemory"}, ... 420, ) }, ... 420, ) == 0x0 02301 860 NtMapViewOfSection (420, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x2580000), {0, 0}, 57344, ) == 0x0 02302 860 NtReleaseMutant (416, ... 0x0, ) == 0x0 02303 860 NtAllocateVirtualMemory (-1, 1220608, 0, 4096, 4096, 260, ... 1220608, 4096, ) == 0x0 02304 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1229760, ... ) }, 1229760, ... ) == 0x0 02305 860 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 424, {status=0x0, info=1}, ) }, 5, 96, ... 424, {status=0x0, info=1}, ) == 0x0 02306 860 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 424, ... 428, ) == 0x0 02307 860 NtClose (424, ... ) == 0x0 02308 860 NtMapViewOfSection (428, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x2590000), 0x0, 126976, ) == 0x0 02309 860 NtClose (428, ... ) == 0x0 02310 860 NtUnmapViewOfSection (-1, 0x2590000, ... ) == 0x0 02311 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1230068, ... ) }, 1230068, ... ) == 0x0 02312 860 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 428, {status=0x0, info=1}, ) }, 5, 96, ... 428, {status=0x0, info=1}, ) == 0x0 02313 860 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 428, ... 424, ) == 0x0 02314 860 NtQuerySection (424, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02315 860 NtClose (428, ... ) == 0x0 02316 860 NtMapViewOfSection (424, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 02317 860 NtClose (424, ... ) == 0x0 02318 860 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 02319 860 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 02320 860 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 02321 860 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02322 860 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 424, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 424, {status=0x0, info=1}, ) == 0x0 02323 860 NtQueryInformationFile (424, 1230084, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02324 860 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 424, ... 428, ) == 0x0 02325 860 NtMapViewOfSection (428, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2960000), 0x0, 1191936, ) == 0x0 02326 860 NtQueryInformationFile (424, 1230184, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02327 860 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02328 860 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 02329 860 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 02330 860 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02331 860 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 432, ) }, ... 432, ) == 0x0 02332 860 NtQueryValueKey (432, (432, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (432, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02333 860 NtClose (432, ... ) == 0x0 02334 860 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02335 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02336 860 NtQueryDirectoryFile (432, 0, 0, 0, 1227780, 616, BothDirectory, 1, (432, 0, 0, 0, 1227780, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02337 860 NtClose (432, ... ) == 0x0 02338 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02339 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02340 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228156, ... ) }, 1228156, ... ) == 0x0 02341 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02342 860 NtQueryDirectoryFile (432, 0, 0, 0, 1227584, 616, BothDirectory, 1, (432, 0, 0, 0, 1227584, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02343 860 NtClose (432, ... ) == 0x0 02344 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02345 860 NtQueryDirectoryFile (432, 0, 0, 0, 1227584, 616, BothDirectory, 1, (432, 0, 0, 0, 1227584, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02346 860 NtClose (432, ... ) == 0x0 02347 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02348 860 NtQueryDirectoryFile (432, 0, 0, 0, 1227584, 616, BothDirectory, 1, (432, 0, 0, 0, 1227584, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02349 860 NtClose (432, ... ) == 0x0 02350 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02351 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02352 860 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02353 860 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02354 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02355 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 432, ) == 0x0 02356 860 NtQueryInformationToken (432, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02357 860 NtClose (432, ... ) == 0x0 02358 860 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02359 860 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\dwwin.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02360 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228988, ... ) }, 1228988, ... ) == 0x0 02361 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02362 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02363 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227856, ... ) }, 1227856, ... ) == 0x0 02364 860 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 432, {status=0x0, info=1}, ) }, 5, 96, ... 432, {status=0x0, info=1}, ) == 0x0 02365 860 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 432, ... 436, ) == 0x0 02366 860 NtClose (432, ... ) == 0x0 02367 860 NtMapViewOfSection (436, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x2590000), 0x0, 180224, ) == 0x0 02368 860 NtClose (436, ... ) == 0x0 02369 860 NtUnmapViewOfSection (-1, 0x2590000, ... ) == 0x0 02370 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227452, ... ) }, 1227452, ... ) == 0x0 02371 860 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1228196, (0x80100080, {24, 0, 0x40, 0, 1228196, "\??\C:\WINDOWS\system32\dwwin.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 436, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 436, {status=0x0, info=1}, ) == 0x0 02372 860 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 436, ... 432, ) == 0x0 02373 860 NtClose (436, ... ) == 0x0 02374 860 NtMapViewOfSection (432, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x2590000), {0, 0}, 180224, ) == 0x0 02375 860 NtClose (432, ... ) == 0x0 02376 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02377 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02378 860 NtQueryDefaultLocale (1, 1228816, ... ) == 0x0 02379 860 NtQueryVirtualMemory (-1, 0x2590000, Basic, 28, ... {BaseAddress=0x2590000,AllocationBase=0x2590000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 02380 860 NtQueryVirtualMemory (-1, 0x2590000, Basic, 28, ... {BaseAddress=0x2590000,AllocationBase=0x2590000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 02381 860 NtUnmapViewOfSection (-1, 0x2590000, ... ) == 0x0 02382 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02383 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02384 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227848, ... ) }, 1227848, ... ) == 0x0 02385 860 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 5, 96, ... 432, {status=0x0, info=1}, ) }, 5, 96, ... 432, {status=0x0, info=1}, ) == 0x0 02386 860 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 432, ... 436, ) == 0x0 02387 860 NtClose (432, ... ) == 0x0 02388 860 NtMapViewOfSection (436, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x2590000), 0x0, 180224, ) == 0x0 02389 860 NtClose (436, ... ) == 0x0 02390 860 NtUnmapViewOfSection (-1, 0x2590000, ... ) == 0x0 02391 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1227444, ... ) }, 1227444, ... ) == 0x0 02392 860 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1228188, (0x80100080, {24, 0, 0x40, 0, 1228188, "\??\C:\WINDOWS\system32\dwwin.exe"}, 0x0, 0, 5, 1, 96, 0, 0, ... 436, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 436, {status=0x0, info=1}, ) == 0x0 02393 860 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 436, ... 432, ) == 0x0 02394 860 NtClose (436, ... ) == 0x0 02395 860 NtMapViewOfSection (432, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x2590000), {0, 0}, 180224, ) == 0x0 02396 860 NtClose (432, ... ) == 0x0 02397 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02398 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02399 860 NtQueryDefaultLocale (1, 1228808, ... ) == 0x0 02400 860 NtQueryVirtualMemory (-1, 0x2590000, Basic, 28, ... {BaseAddress=0x2590000,AllocationBase=0x2590000,AllocationProtect=0x2,RegionSize=0x2c000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 02401 860 NtUnmapViewOfSection (-1, 0x2590000, ... ) == 0x0 02402 860 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02403 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02404 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 432, ) == 0x0 02405 860 NtQueryInformationToken (432, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02406 860 NtClose (432, ... ) == 0x0 02407 860 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02408 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02409 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02410 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1229408, ... ) }, 1229408, ... ) == 0x0 02411 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02412 860 NtQueryDirectoryFile (432, 0, 0, 0, 1228836, 616, BothDirectory, 1, (432, 0, 0, 0, 1228836, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02413 860 NtClose (432, ... ) == 0x0 02414 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02415 860 NtQueryDirectoryFile (432, 0, 0, 0, 1228836, 616, BothDirectory, 1, (432, 0, 0, 0, 1228836, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02416 860 NtClose (432, ... ) == 0x0 02417 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02418 860 NtQueryDirectoryFile (432, 0, 0, 0, 1228836, 616, BothDirectory, 1, (432, 0, 0, 0, 1228836, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02419 860 NtClose (432, ... ) == 0x0 02420 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02421 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02422 860 NtWaitForSingleObject (416, 0, {-1000000, -1}, ... ) == 0x0 02423 860 NtReleaseMutant (416, ... 0x0, ) == 0x0 02424 860 NtUnmapViewOfSection (-1, 0x2960000, ... ) == 0x0 02425 860 NtClose (428, ... ) == 0x0 02426 860 NtClose (424, ... ) == 0x0 02427 860 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 02428 860 NtOpenProcessToken (-1, 0xa, ... 424, ) == 0x0 02429 860 NtQueryInformationToken (424, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 02430 860 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02431 860 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 428, ) }, ... 428, ) == 0x0 02432 860 NtQueryValueKey (428, (428, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (428, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02433 860 NtQueryValueKey (428, (428, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (428, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02434 860 NtClose (428, ... ) == 0x0 02435 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02436 860 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 428, ) }, ... 428, ) == 0x0 02437 860 NtQueryValueKey (428, (428, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02438 860 NtClose (428, ... ) == 0x0 02439 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02440 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02441 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02442 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02443 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02444 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02445 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02446 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02447 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02448 860 NtQueryDefaultLocale (1, 1231256, ... ) == 0x0 02449 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 428, ) }, ... 428, ) == 0x0 02450 860 NtEnumerateKey (428, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (428, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 02451 860 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 432, ) }, ... 432, ) == 0x0 02452 860 NtQueryValueKey (432, (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 02453 860 NtQueryValueKey (432, (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02454 860 NtClose (432, ... ) == 0x0 02455 860 NtEnumerateKey (428, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02456 860 NtClose (428, ... ) == 0x0 02457 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... 428, ) }, ... 428, ) == 0x0 02458 860 NtEnumerateKey (428, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (428, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, 92, ) }, 92, ) == 0x0 02459 860 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, ... 432, ) }, ... 432, ) == 0x0 02460 860 NtQueryValueKey (432, (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) }, 28, ) == 0x0 02461 860 NtQueryValueKey (432, (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02462 860 NtQueryValueKey (432, (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02463 860 NtQueryValueKey (432, (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02464 860 NtClose (432, ... ) == 0x0 02465 860 NtEnumerateKey (428, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (428, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, 92, ) }, 92, ) == 0x0 02466 860 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, ... 432, ) }, ... 432, ) == 0x0 02467 860 NtQueryValueKey (432, (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) }, 28, ) == 0x0 02468 860 NtQueryValueKey (432, (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02469 860 NtQueryValueKey (432, (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02470 860 NtQueryValueKey (432, (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02471 860 NtClose (432, ... ) == 0x0 02472 860 NtEnumerateKey (428, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (428, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, 92, ) }, 92, ) == 0x0 02473 860 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, ... 432, ) }, ... 432, ) == 0x0 02474 860 NtQueryValueKey (432, (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) }, 28, ) == 0x0 02475 860 NtQueryValueKey (432, (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02476 860 NtQueryValueKey (432, (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02477 860 NtQueryValueKey (432, (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02478 860 NtClose (432, ... ) == 0x0 02479 860 NtEnumerateKey (428, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (428, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, 92, ) }, 92, ) == 0x0 02480 860 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, ... 432, ) }, ... 432, ) == 0x0 02481 860 NtQueryValueKey (432, (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) }, 28, ) == 0x0 02482 860 NtQueryValueKey (432, (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02483 860 NtQueryValueKey (432, (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02484 860 NtQueryValueKey (432, (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02485 860 NtClose (432, ... ) == 0x0 02486 860 NtEnumerateKey (428, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (428, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, 92, ) }, 92, ) == 0x0 02487 860 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, ... 432, ) }, ... 432, ) == 0x0 02488 860 NtQueryValueKey (432, (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (432, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) \300\36\200"}, 28, ) == 0x0 02489 860 NtQueryValueKey (432, (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 02490 860 NtQueryValueKey (432, (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (432, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 02491 860 NtQueryValueKey (432, (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (432, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02492 860 NtClose (432, ... ) == 0x0 02493 860 NtEnumerateKey (428, 5, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 02494 860 NtClose (428, ... ) == 0x0 02495 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02496 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02497 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02498 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02499 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02500 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02501 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02502 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02503 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02504 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02505 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02506 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02507 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02508 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02509 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02510 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02511 860 NtClose (428, ... ) == 0x0 02512 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02513 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02514 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02515 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02516 860 NtClose (428, ... ) == 0x0 02517 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02518 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02519 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02520 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02521 860 NtClose (428, ... ) == 0x0 02522 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02523 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02524 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02525 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02526 860 NtClose (428, ... ) == 0x0 02527 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02528 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02529 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02530 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02531 860 NtClose (428, ... ) == 0x0 02532 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02533 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02534 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02535 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02536 860 NtClose (428, ... ) == 0x0 02537 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02538 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02539 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02540 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02541 860 NtClose (428, ... ) == 0x0 02542 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02543 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02544 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02545 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02546 860 NtClose (428, ... ) == 0x0 02547 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02548 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02549 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02550 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02551 860 NtClose (428, ... ) == 0x0 02552 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02553 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02554 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02555 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02556 860 NtClose (428, ... ) == 0x0 02557 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02558 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02559 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02560 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02561 860 NtClose (428, ... ) == 0x0 02562 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02563 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02564 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02565 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02566 860 NtClose (428, ... ) == 0x0 02567 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02568 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02569 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02570 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02571 860 NtClose (428, ... ) == 0x0 02572 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02573 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02574 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02575 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02576 860 NtClose (428, ... ) == 0x0 02577 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02578 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02579 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02580 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02581 860 NtClose (428, ... ) == 0x0 02582 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02583 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 428, ) }, ... 428, ) == 0x0 02584 860 NtQueryValueKey (428, (428, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (428, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (428, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 02585 860 NtClose (428, ... ) == 0x0 02586 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02587 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 428, ) == 0x0 02588 860 NtQueryInformationToken (428, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02589 860 NtClose (428, ... ) == 0x0 02590 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02591 860 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 02592 860 NtOpenProcessToken (-1, 0xa, ... 428, ) == 0x0 02593 860 NtDuplicateToken (428, 0xc, {24, 0, 0x0, 0, 1231688, 0x0}, 0, 2, ... 432, ) == 0x0 02594 860 NtClose (428, ... ) == 0x0 02595 860 NtAccessCheck (1339064, 432, 0x1, 1231764, 1231816, 56, 1231796, ... (0x1), ) == 0x0 02596 860 NtClose (432, ... ) == 0x0 02597 860 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 432, ) }, ... 432, ) == 0x0 02598 860 NtQueryValueKey (432, (432, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (432, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02599 860 NtClose (432, ... ) == 0x0 02600 860 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 432, ) }, ... 432, ) == 0x0 02601 860 NtQuerySymbolicLinkObject (432, ... (432, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 02602 860 NtClose (432, ... ) == 0x0 02603 860 NtQueryVolumeInformationFile (412, 1229520, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02604 860 NtQueryInformationFile (412, 1229636, 528, Name, ... {status=0x0, info=58}, ) == 0x0 02605 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02606 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02607 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe"}, 1228808, ... ) }, 1228808, ... ) == 0x0 02608 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02609 860 NtQueryDirectoryFile (432, 0, 0, 0, 1228236, 616, BothDirectory, 1, (432, 0, 0, 0, 1228236, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02610 860 NtClose (432, ... ) == 0x0 02611 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02612 860 NtQueryDirectoryFile (432, 0, 0, 0, 1228236, 616, BothDirectory, 1, (432, 0, 0, 0, 1228236, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 02613 860 NtClose (432, ... ) == 0x0 02614 860 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 432, {status=0x0, info=1}, ) }, 3, 16417, ... 432, {status=0x0, info=1}, ) == 0x0 02615 860 NtQueryDirectoryFile (432, 0, 0, 0, 1228236, 616, BothDirectory, 1, (432, 0, 0, 0, 1228236, 616, BothDirectory, 1, "dwwin.exe", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02616 860 NtClose (432, ... ) == 0x0 02617 860 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02618 860 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02619 860 NtQueryInformationFile (412, 1231676, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02620 860 NtCreateSection (0xf0005, 0x0, {180224, 0}, 2, 134217728, 412, ... 432, ) == 0x0 02621 860 NtMapViewOfSection (432, -1, (0x0), 0, 0, {0, 0}, 180224, 1, 0, 2, ... (0x2590000), {0, 0}, 180224, ) == 0x0 02622 860 NtClose (432, ... ) == 0x0 02623 860 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02624 860 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 432, ) == 0x0 02625 860 NtQueryInformationToken (432, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02626 860 NtClose (432, ... ) == 0x0 02627 860 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 432, ) }, ... 432, ) == 0x0 02628 860 NtOpenKey (0x20019, {24, 432, 0x40, 0, 0, (0x20019, {24, 432, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 428, ) }, ... 428, ) == 0x0 02629 860 NtClose (432, ... ) == 0x0 02630 860 NtQueryValueKey (428, (428, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02631 860 NtQueryValueKey (428, (428, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) , Partial, 174, ... TitleIdx=0, Type=1, Data= (428, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) }, 174, ) == 0x0 02632 860 NtClose (428, ... ) == 0x0 02633 860 NtUnmapViewOfSection (-1, 0x2590000, ... ) == 0x0 02634 860 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 39387136, 4096, ) == 0x0 02635 860 NtAllocateVirtualMemory (-1, 39387136, 0, 4096, 4096, 4, ... 39387136, 4096, ) == 0x0 02636 860 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 428, ) }, ... 428, ) == 0x0 02637 860 NtQueryValueKey (428, (428, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02638 860 NtClose (428, ... ) == 0x0 02639 860 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02640 860 NtQueryInformationToken (424, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 02641 860 NtQueryInformationToken (424, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 02642 860 NtClose (424, ... ) == 0x0 02643 860 NtQuerySection (408, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02644 860 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwin.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02645 860 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0 02646 860 NtCreateProcessEx (1233600, 2035711, 0, -1, 4, 408, 0, 0, 0, ... ) == 0x0 02647 860 NtSetInformationProcess (424, PriorityClass, {process info, class 18, size 2}, 512, ... ) == 0x0 02648 860 NtSetInformationProcess (424, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02649 860 NtQueryInformationProcess (424, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffd9000,AffinityMask=0x1,BasePriority=8,Pid=380,ParentPid=464,}, 0x0, ) == 0x0 02650 860 NtReadVirtualMemory (424, 0x7ffd9008, 4, ... (424, 0x7ffd9008, 4, ... "\0\0\00", 0x0, ) , 0x0, ) == 0x0 02651 860 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\dwwin.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02652 860 NtReadVirtualMemory (424, 0x30000000, 4096, ... (424, 0x30000000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\360\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0$\206\244\23`\347\312@`\347\312@`\347\312@9\304\331@b\347\312@`\347\313@d\347\312@\210\370\301@a\347\312@\343\373\304@j\347\312@\210\370\300@I\347\312@6\370\331@h\347\312@\272\304\326@i\347\312@\220\370\301@p\347\312@`\347\312@H\346\312@Rich`\347\312@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0PE\0\0L\1\3\0N\23\216?\0\0\0\0\0\0\0\0\340\0\17\1\13\1\6\24\0\220\2\0\0\240\0\0\0\0\0\0\232t\0\0\0\20\0\0\0\320\3\0\0\0\00\0\20\0\0\0\20\0\0\4\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0@\3\0\0\20\0\0\237*\3\0\2\0\0\0\0\0\20\0\0\20\0\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\327\211\2\0z\1\0\0\00\3\0\244\12\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0Z\236\2\08\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0`\2\0\0\370\0\0\0\0\20\0\0\270\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\222\216\2\0", 4096, ) , 4096, ) == 0x0 02653 860 NtReadVirtualMemory (424, 0x30033000, 256, ... (424, 0x30033000, 256, ... "\0\0\0\0J\23\216?\0\0\0\0\0\0\3\0\5\0\0\0(\0\0\200\13\0\0\0@\0\0\200\20\0\0\0X\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0e\0\0\0p\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\1\0\0\0\210\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\1\0\0\0\240\0\0\200\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\270\0\0\0\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\310\0\0\0\0\0\0\0J\23\216?\0\0\0\0\0\0\1\0\11\4\0\0\330\0\0\0\3600\3\0\26\3\0\0\0\0\0\0\0\0\0\0\104\3\0\254\1\0\0\0\0\0\0\0\0\0\0\2645\3\0\360\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\300\0\310\200\0\0\0\0\14\0\0\0\0\0f\1", 256, ) , 256, ) == 0x0 02654 860 NtQueryDebugFilterState (53, 2, ... ) == 0x0 02655 860 NtQueryInformationProcess (424, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffd9000,AffinityMask=0x1,BasePriority=8,Pid=380,ParentPid=464,}, 0x0, ) == 0x0 02656 860 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32"}, 1232552, ... ) }, 1232552, ... ) == 0x0 02657 860 NtAllocateVirtualMemory (-1, 0, 0, 2428, 4096, 4, ... 39452672, 4096, ) == 0x0 02658 860 NtAllocateVirtualMemory (424, 0, 0, 6464, 4096, 4, ... 65536, 8192, ) == 0x0 02659 860 NtWriteVirtualMemory (424, 0x10000, (424, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6464, ... 0x0, ) , 6464, ... 0x0, ) == 0x0 02660 860 NtAllocateVirtualMemory (424, 0, 0, 2428, 4096, 4, ... 131072, 4096, ) == 0x0 02661 860 NtWriteVirtualMemory (424, 0x20000, (424, 0x20000, "\0\20\0\0|\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\3\0\0\0\0\0\0\0\13\0\0\0&\0\10\2\220\2\0\06\1\0\0\364\3\366\3\230\4\0\0:\0<\0\220\10\0\0N\0P\0\314\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0:\0<\0\34\11\0\0\36\0 \0X\11\0\0\0\0\2\0x\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2428, ... 0x0, ) , 2428, ... 0x0, ) == 0x0 02662 860 NtWriteVirtualMemory (424, 0x7ffd9010, (424, 0x7ffd9010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02663 860 NtAllocateVirtualMemory (424, 0, 0, 388, 4096, 4, ... 196608, 4096, ) == 0x0 02664 860 NtWriteVirtualMemory (424, 0x30000, (424, 0x30000, "S\0h\0i\0m\0E\0n\0g\0.\0d\0l\0l\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\1\0\0\253\355\15\254\210\255\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\21\21\21\21\21\21\21\21\21\21\21\21\21\21\21\21\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 388, ... 0x0, ) , 388, ... 0x0, ) == 0x0 02665 860 NtWriteVirtualMemory (424, 0x7ffd91e8, (424, 0x7ffd91e8, "\0\0\3\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 02666 860 NtFreeVirtualMemory (-1, (0x25a0000), 0, 32768, ... (0x25a0000), 4096, ) == 0x0 02667 860 NtAllocateVirtualMemory (424, 0, 0, 1048576, 8192, 4, ... 262144, 1048576, ) == 0x0 02668 860 NtAllocateVirtualMemory (424, 1302528, 0, 8192, 4096, 4, ... 1302528, 8192, ) == 0x0 02669 860 NtProtectVirtualMemory (424, (0x13e000), 4096, 260, ... (0x13e000), 4096, 4, ) == 0x0 02670 860 NtCreateThread (0x1f03ff, 0x0, 424, 1233608, 1233272, 1, ... 428, {380, 1692}, ) == 0x0 02671 860 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 0, 2147348480, 2008285840, 0} (24, {168, 196, new_msg, 0, 0, 2147348480, 2008285840, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\253\1\0\0\254\1\0\0|\1\0\0\234\6\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\260\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\220\375\177\0\0\0\0\0\0\24\0\10 \0\0" ... {168, 196, reply, 0, 464, 860, 58008, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\250\1\0\0\254\1\0\0|\1\0\0\234\6\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\260\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\220\375\177\0\0\0\0\0\0\24\0\10 \0\0" ) ... {168, 196, reply, 0, 464, 860, 58008, 0} (24, {168, 196, new_msg, 0, 0, 2147348480, 2008285840, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\253\1\0\0\254\1\0\0|\1\0\0\234\6\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\260\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\220\375\177\0\0\0\0\0\0\24\0\10 \0\0" ... {168, 196, reply, 0, 464, 860, 58008, 0} "\0\0\0\0\0\0\1\0\0\0\0\0x\2\264w\250\1\0\0\254\1\0\0|\1\0\0\234\6\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\260\326\22\0x\1\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\220\375\177\0\0\0\0\0\0\24\0\10 \0\0" ) ) == 0x0 02672 860 NtResumeThread (428, ... 1, ) == 0x0 02673 860 NtClose (412, ... ) == 0x0 02674 860 NtClose (408, ... ) == 0x0 02675 860 NtClose (428, ... ) == 0x0 02676 860 NtWaitForMultipleObjects (2, (396, 424, ), 1, 0, {1294967296, -1}, ... ) == 0x0 02677 860 NtWaitForSingleObject (388, 0, {0, 0}, ... ) == 0x102 02678 860 NtWaitForMultipleObjects (2, (396, 424, ), 1, 0, {1294967296, -1}, ... ) == 0x0 02679 860 NtWaitForSingleObject (388, 0, {0, 0}, ... ) == 0x102 02680 860 NtWaitForMultipleObjects (2, (396, 424, ), 1, 0, {1294967296, -1}, ... 00582 1292 NtDelayExecution ... ) == 0x0 02681 1292 NtDelayExecution (0, {-20010000, -1}, ... 00583 1956 NtDelayExecution ... ) == 0x0 02682 1956 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 428, ) == 0x0 02683 1956 NtCallbackReturn (0, 0, 0, ... 02684 1956 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00584 1980 NtDelayExecution ... ) == 0x0 00585 1784 NtDelayExecution ... ) == 0x0 00586 1480 NtDelayExecution ... ) == 0x0 00587 1556 NtDelayExecution ... ) == 0x0 00588 460 NtDelayExecution ... ) == 0x0 00592 1068 NtDelayExecution ... ) == 0x0 02685 1980 NtDelayExecution (0, {-20010000, -1}, ... 02686 1784 NtDelayExecution (0, {-20010000, -1}, ... 02687 1480 NtDelayExecution (0, {-20010000, -1}, ... 02688 1556 NtDelayExecution (0, {-20010000, -1}, ... 02689 460 NtDelayExecution (0, {-20010000, -1}, ... 02690 1068 NtDelayExecution (0, {-20010000, -1}, ... 02691 1956 NtUserFindWindowEx (0, 0, (0, 0, "GBDYLLO", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 02692 1956 NtUserFindWindowEx (0, 0, (0, 0, "pediy06", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 02693 1956 NtDelayExecution (0, {-20010000, -1}, ... 02680 860 NtWaitForMultipleObjects ... ) == 0x0 02694 860 NtWaitForSingleObject (388, 0, {0, 0}, ... ) == 0x102 02695 860 NtWaitForMultipleObjects (2, (396, 424, ), 1, 0, {1294967296, -1}, ... ) == 0x0 02696 860 NtWaitForSingleObject (388, 0, {0, 0}, ... ) == 0x0 02697 860 NtClose (424, ... ) == 0x0 02698 860 NtUnmapViewOfSection (-1, 0x2560000, ... ) == 0x0 02699 860 NtClose (404, ... ) == 0x0 02700 860 NtClose (388, ... ) == 0x0 02701 860 NtClose (396, ... ) == 0x0 02702 860 NtClose (392, ... ) == 0x0 02703 860 NtClose (400, ... ) == 0x0 02704 860 NtClose (340, ... ) == 0x0 02705 860 NtClose (344, ... ) == 0x0 02706 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 02707 860 NtWaitForMultipleObjects (2, (304, 316, ), 1, 0, 0x0, ... ) == 0x1 02708 860 NtClose (316, ... ) == 0x0 02709 860 NtSetEvent (304, ... 0x0, ) == 0x0 02710 860 NtClose (304, ... ) == 0x0 02711 860 NtWaitForMultipleObjects (2, (320, 324, ), 1, 0, 0x0, ... ) == 0x1 02712 860 NtClose (324, ... ) == 0x0 02713 860 NtSetEvent (320, ... 0x0, ) == 0x0 02714 860 NtClose (320, ... ) == 0x0 02715 860 NtWaitForMultipleObjects (2, (328, 332, ), 1, 0, 0x0, ... ) == 0x1 02716 860 NtClose (332, ... ) == 0x0 02717 860 NtSetEvent (328, ... 0x0, ) == 0x0 02718 860 NtClose (328, ... ) == 0x0 02719 860 NtRequestWaitReplyPort (372, {88, 112, new_msg, 0, 464, 860, 58004, 0} (372, {88, 112, new_msg, 0, 464, 860, 58004, 0} "\1\356\0\0A\2<\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201" ... {124, 148, reply, 0, 464, 860, 58148, 0} "\2\31\221|\1\0\221|\200\300\227|p\31\221|\250$\12\0\330\0\0\0d\365\11\0\0\300\372\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\1\365\11\0\1\0\0\0d\365\11\0\0\0\0\0\0\0\0\0\1\0\0\0\10\376\257\0\0\0\0\0\334\377\257\0\30\356\220|p\5\221|\377\377\377\377m\5\221|\344f\347w" ) ... {124, 148, reply, 0, 464, 860, 58148, 0} (372, {88, 112, new_msg, 0, 464, 860, 58004, 0} "\1\356\0\0A\2<\0\30b\202\201\0\260\375\177\220k\364\367\370\37`\300\377\377\377\377X\353Q\200\0\0\0\0)%\25E?>\A\250\245\22\360\331E\16S\331E\16S\1\300\375\177(l\364\367\253\362Q\200\324k\364\367\300\250U\200aFT\200\0\0\0\0h\242\250\201" ... {124, 148, reply, 0, 464, 860, 58148, 0} "\2\31\221|\1\0\221|\200\300\227|p\31\221|\250$\12\0\330\0\0\0d\365\11\0\0\300\372\177\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\1\365\11\0\1\0\0\0d\365\11\0\0\0\0\0\0\0\0\0\1\0\0\0\10\376\257\0\0\0\0\0\334\377\257\0\30\356\220|p\5\221|\377\377\377\377m\5\221|\344f\347w" ) ) == 0x0 02720 860 NtClose (368, ... ) == 0x0 02721 860 NtClose (372, ... ) == 0x0 02722 860 NtClose (312, ... ) == 0x0 02723 860 NtUnmapViewOfSection (-1, 0x69450000, ... ) == 0x0 02724 860 NtUnmapViewOfSection (-1, 0x77920000, ... ) == 0x0 02725 860 NtUnmapViewOfSection (-1, 0x76f50000, ... ) == 0x0 02726 860 NtUnmapViewOfSection (-1, 0x76360000, ... ) == 0x0 02727 860 NtUnmapViewOfSection (-1, 0x5b860000, ... ) == 0x0 02728 860 NtUnmapViewOfSection (-1, 0x769c0000, ... ) == 0x0 02729 860 NtContinue (1242968, 0, ... 02730 860 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 02731 860 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 02732 860 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 02733 860 NtTerminateProcess (0, -1073741681, ... 02681 1292 NtDelayExecution ... ) == 0xc0 02693 1956 NtDelayExecution ... ) == 0xc0 02685 1980 NtDelayExecution ... ) == 0xc0 02686 1784 NtDelayExecution ... ) == 0xc0 02687 1480 NtDelayExecution ... ) == 0xc0 02688 1556 NtDelayExecution ... ) == 0xc0 02689 460 NtDelayExecution ... ) == 0xc0 02690 1068 NtDelayExecution ... ) == 0xc0 01557 1856 NtWaitForSingleObject ... ) == 0xc0 01515 1596 NtWaitForSingleObject ... ) == 0xc0 01490 1128 NtWaitForSingleObject ... ) == 0xc0 01664 1256 NtWaitForSingleObject ... ) == 0xc0 01551 220 NtWaitForSingleObject ... ) == 0xc0 00679 1800 NtWaitForSingleObject ... ) == 0xc0 00876 1796 NtWaitForSingleObject ... ) == 0xc0 01674 1808 NtWaitForSingleObject ... ) == 0xc0 01495 1700 NtWaitForSingleObject ... ) == 0xc0 00803 1156 NtWaitForSingleObject ... ) == 0xc0 01499 712 NtWaitForSingleObject ... ) == 0xc0 00895 1728 NtWaitForSingleObject ... ) == 0xc0 01535 1356 NtWaitForSingleObject ... ) == 0xc0 01519 1536 NtWaitForSingleObject ... ) == 0xc0 01660 444 NtWaitForSingleObject ... ) == 0xc0 01507 1904 NtWaitForSingleObject ... ) == 0xc0 01569 148 NtDelayExecution ... ) == 0xc0 02733 860 NtTerminateProcess ... ) == 0x0 02734 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x9,}, 4, ... ) == 0x0 02735 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x8,}, 4, ... ) == 0x0 02736 860 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 02737 860 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 02738 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 02739 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 02740 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x7,}, 4, ... ) == 0x0 02741 860 NtClose (280, ... ) == 0x0 02742 860 NtFreeVirtualMemory (-1, (0x2550000), 0, 32768, ... (0x2550000), 65536, ) == 0x0 02743 860 NtClose (12, ... ) == 0x0 02744 860 NtClose (236, ... ) == 0x0 02745 860 NtClose (248, ... ) == 0x0 02746 860 NtClose (244, ... ) == 0x0 02747 860 NtClose (252, ... ) == 0x0 02748 860 NtClose (256, ... ) == 0x0 02749 860 NtClose (260, ... ) == 0x0 02750 860 NtClose (276, ... ) == 0x0 02751 860 NtClose (272, ... ) == 0x0 02752 860 NtClose (268, ... ) == 0x0 02753 860 NtClose (264, ... ) == 0x0 02754 860 NtClose (68, ... ) == 0x0 02755 860 NtClose (60, ... ) == 0x0 02756 860 NtClose (56, ... ) == 0x0 02757 860 NtClose (64, ... ) == 0x0 02758 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 02759 860 NtUserGetAtomName (49211, 1243560, ... ) == 0xf 02760 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02761 860 NtUserGetAtomName (49213, 1243560, ... ) == 0xd 02762 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02763 860 NtUserGetAtomName (49215, 1243560, ... ) == 0x10 02764 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02765 860 NtUserGetAtomName (49217, 1243560, ... ) == 0x12 02766 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02767 860 NtUserGetAtomName (49219, 1243560, ... ) == 0xd 02768 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02769 860 NtUserGetAtomName (49221, 1243560, ... ) == 0xb 02770 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02771 860 NtUserGetAtomName (49223, 1243560, ... ) == 0xf 02772 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02773 860 NtUserGetAtomName (49225, 1243560, ... ) == 0xd 02774 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02775 860 NtUserGetAtomName (49227, 1243560, ... ) == 0x11 02776 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02777 860 NtUserGetAtomName (49229, 1243560, ... ) == 0xf 02778 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02779 860 NtUserGetAtomName (49231, 1243560, ... ) == 0x11 02780 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02781 860 NtUserGetAtomName (49233, 1243560, ... ) == 0xf 02782 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02783 860 NtUserGetAtomName (49235, 1243560, ... ) == 0xc 02784 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02785 860 NtUserGetAtomName (49237, 1243552, ... ) == 0xd 02786 860 NtUserUnregisterClass (1243612, 1560870912, 1243600, ... ) == 0x1 02787 860 NtUserGetAtomName (49239, 1243552, ... ) == 0x11 02788 860 NtUserUnregisterClass (1243612, 1560870912, 1243600, ... ) == 0x1 02789 860 NtUserGetAtomName (49241, 1243560, ... ) == 0xc 02790 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02791 860 NtUserGetAtomName (49243, 1243560, ... ) == 0xe 02792 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02793 860 NtUserGetAtomName (49245, 1243560, ... ) == 0x8 02794 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02795 860 NtUserGetAtomName (49247, 1243560, ... ) == 0xd 02796 860 NtUserUnregisterClass (1243620, 1560870912, 1243608, ... ) == 0x1 02797 860 NtUnmapViewOfSection (-1, 0xb00000, ... ) == 0x0 02798 860 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x1,}, 4, ... ) == 0x0 02799 860 NtFreeVirtualMemory (-1, (0xa40000), 0, 32768, ... (0xa40000), 65536, ) == 0x0 02800 860 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 64, ) }, ... 64, ) == 0x0 02801 860 NtQueryValueKey (64, (64, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02802 860 NtClose (64, ... ) == 0x0 02803 860 NtClose (364, ... ) == 0x0 02804 860 NtFreeVirtualMemory (-1, (0x2590000), 4096, 32768, ... (0x2590000), 4096, ) == 0x0 02805 860 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 1177928, 2011674340, 1, 1337824} (24, {20, 48, new_msg, 0, 1177928, 2011674340, 1, 1337824} "\0\0\0\0\3\0\1\0\340i\24\0\354\371\21\0\217\0\0\300" ... {20, 48, reply, 0, 464, 860, 58175, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\354\371\21\0\217\0\0\300" ) ... {20, 48, reply, 0, 464, 860, 58175, 0} (24, {20, 48, new_msg, 0, 1177928, 2011674340, 1, 1337824} "\0\0\0\0\3\0\1\0\340i\24\0\354\371\21\0\217\0\0\300" ... {20, 48, reply, 0, 464, 860, 58175, 0} "\0\0\0\0\3\0\1\0\0\0\0\0\354\371\21\0\217\0\0\300" ) ) == 0x0 02806 860 NtTerminateProcess (-1, -1073741681, ...