Summary:
NtCallbackReturn(>) | 1 | NtOpenProcessToken(>) | 2 | NtOpenProcessTokenEx(>) | 10 | NtUserRegisterClassExWOW(>) | 34 |
NtConnectPort(>) | 1 | NtQueryInstallUILanguage(>) | 2 | NtOpenThreadTokenEx(>) | 10 | NtContinue(>) | 35 |
NtGdiCreateBitmap(>) | 1 | NtRaiseException(>) | 2 | NtWriteFile(>) | 10 | NtQueryDebugFilterState(>) | 36 |
NtGdiInit(>) | 1 | NtAddAtom(>) | 3 | NtQueryVolumeInformationFile(>) | 12 | NtRequestWaitReplyPort(>) | 36 |
NtGdiQueryFontAssocInfo(>) | 1 | NtClearEvent(>) | 3 | NtQueryInformationToken(>) | 13 | NtQuerySystemInformation(>) | 44 |
NtGdiSelectBitmap(>) | 1 | NtGdiCreateCompatibleDC(>) | 3 | NtQueryDefaultUILanguage(>) | 14 | NtCreateEvent(>) | 45 |
NtOpenKeyedEvent(>) | 1 | NtNotifyChangeKey(>) | 3 | NtReadFile(>) | 14 | NtSetInformationThread(>) | 45 |
NtOpenProcess(>) | 1 | NtReleaseSemaphore(>) | 3 | NtUserFindWindowEx(>) | 14 | NtFreeVirtualMemory(>) | 49 |
NtOpenSymbolicLinkObject(>) | 1 | NtSetInformationObject(>) | 3 | NtCreateKey(>) | 15 | NtCreateSection(>) | 52 |
NtQueryEvent(>) | 1 | NtTerminateProcess(>) | 3 | NtSetValueKey(>) | 15 | NtQueryVirtualMemory(>) | 53 |
NtQueryObject(>) | 1 | NtUserGetDC(>) | 3 | NtSetInformationFile(>) | 17 | NtUserGetClassInfo(>) | 54 |
NtQuerySymbolicLinkObject(>) | 1 | NtWaitForMultipleObjects(>) | 3 | NtFsControlFile(>) | 18 | NtOpenSection(>) | 56 |
NtQuerySystemTime(>) | 1 | NtDuplicateObject(>) | 4 | NtUserUnregisterClass(>) | 19 | NtOpenFile(>) | 74 |
NtQueryTimerResolution(>) | 1 | NtEnumerateKey(>) | 4 | NtQueryInformationFile(>) | 20 | NtMapViewOfSection(>) | 80 |
NtSecureConnectPort(>) | 1 | NtGdiGetStockObject(>) | 5 | NtUserRegisterWindowMessage(>) | 22 | NtProtectVirtualMemory(>) | 82 |
NtSetInformationProcess(>) | 1 | NtCreateMutant(>) | 6 | NtUserFindExistingCursorIcon(>) | 24 | NtSetEvent(>) | 92 |
NtUserCallNoParam(>) | 1 | NtDeviceIoControlFile(>) | 6 | NtCreateThread(>) | 25 | NtDelayExecution(>) | 118 |
NtUserGetForegroundWindow(>) | 1 | NtOpenEvent(>) | 6 | NtFlushInstructionCache(>) | 25 | NtQueryAttributesFile(>) | 118 |
NtUserGetObjectInformation(>) | 1 | NtOpenThreadToken(>) | 7 | NtQueryInformationThread(>) | 25 | NtWaitForSingleObject(>) | 141 |
NtUserGetProcessWindowStation(>) | 1 | NtQueryInformationProcess(>) | 7 | NtResumeThread(>) | 25 | NtOpenKey(>) | 157 |
NtUserGetThreadDesktop(>) | 1 | NtUserSystemParametersInfo(>) | 7 | NtCreateFile(>) | 26 | NtAllocateVirtualMemory(>) | 224 |
NtUserQueryWindow(>) | 1 | NtQueryDefaultLocale(>) | 9 | NtRegisterThreadTerminatePort(>) | 26 | NtClose(>) | 318 |
NtCreateIoCompletion(>) | 2 | NtReleaseMutant(>) | 9 | NtTestAlert(>) | 26 | NtQueryValueKey(>) | 329 |
NtGdiCreateSolidBrush(>) | 2 | NtCreateSemaphore(>) | 10 | NtQuerySection(>) | 33 | ||
NtOpenDirectoryObject(>) | 2 | NtOpenMutant(>) | 10 |
\361\@\1\347\326\235\252l?5(\13HU8\315H'\34\205\262\300\322\204\306nV\212q\375\350\251\0\2421\310\376\273\37\200v\0<\322\364\260\341AD\25.sB\244\1\206\240\212n\337\364z\355\16r9+\316\212W\304\200\25\310\305$\14\250\350\223\0\15\33%\20\204\247"
\232\354\12\4c\344CK,\2008\217\16\375z\377\354\342\35p\177b\214\207.P\362)D\313@\0T\215=\342J\320\206DV\33\0\35o\225\215\255,\321\272\1\277\352\13\226\204j\212\345\365Bl", ) \303_\212\354\267X\5M|SY\336\300 \200\301\237\7\25\263y5\271\177\217k\263\0s,o\17d\16;\255\376\234\354c\200\201N>\271\236\32\1\375'\276\233<\342\365\354\323\320\0D\177x\221\37\240U\34%s\14\200\233go\360 y\1\254\26<\362$\253\340\200\211\11t\27\10{\316\0\272\341\332H\335\3318\24x\206\37\122u\1\333^e\177/\20489\Y\303\30.\310\274\234R\3[j\363\237\372S\0\30iE\235\16\260\253\331\50wZ\270\334\200U\271Di\3\345\237\3037\242\4Y\2429mq\220L[\220A\0\327\1\374\300MD}\2;\352\22\200\367\31\206\3\232\261\362\13\30\237!}I\333b\0'd\233E\243\27L\345\2\234\204{\245s\300\200\271\363\320B&\260\323\0 VT\17\205\211\344l\0\347\271R\264\20\365K (480, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=61440}, "b\346\10\274\207\273\0\202"\303_\212\354\267X\5M|SY\336\300 \200\301\237\7\25\263y5\271\177\217k\263\0s,o\17d\16;\255\376\234\354c\200\201N>\271\236\32\1\375'\276\233<\342\365\354\323\320\0D\177x\221\37\240U\34%s\14\200\233go\360 y\1\254\26<\362$\253\340\200\211\11t\27\10{\316\0\272\341\332H\335\3318\24x\206\37\122u\1\333^e\177/\20489\Y\303\30.\310\274\234R\3[j\363\237\372S\0\30iE\235\16\260\253\331\50wZ\270\334\200U\271Di\3\345\237\3037\242\4Y\2429mq\220L[\220A\0\327\1\374\300MD}\2;\352\22\200\367\31\206\3\232\261\362\13\30\237!}I\333b\0'd\233E\243\27L\345\2\234\204{\245s\300\200\271\363\320B&\260\323\0 VT\17\205\211\344l\0\347\271R\264\20\365K"\1\370\30\277o\16\26k\344L=\0\257\352N*\203\6U\265\0\264\337\377\313'\322fT\2\200Ip\311{H\340y\223\14\37\2418\307g\355\342P\213*\259\0P\365\23\220\177V\244\231\0H\204\266\24\236\302C!\354\361\@\1\347\326\235\252l?5(\13HU8\315H'\34\205\262\300\322\204\306nV\212q\375\350\251\0\2421\310\376\273\37\200v\0<\322\364\260\341AD\25.sB\244\1\206\240\212n\337\364z\355\16r9+\316\212W\304\200\25\310\305$\14\250\350\223\0\15\33%\20\204\247"
\232\354\12\4c\344CK,\2008\217\16\375z\377\354\342\35p\177b\214\207.P\362)D\313@\0T\215=\342J\320\206DV\33\0\35o\225\215\255,\321\272\1\277\352\13\226\204j\212\345\365Bl", ) \232\354\12\4c\344CK,\2008\217\16\375z\377\354\342\35p\177b\214\207.P\362)D\313@\0T\215=\342J\320\206DV\33\0\35o\225\215\255,\321\272\1\277\352\13\226\204j\212\345\365Bl", ) == 0x0 02556 400 NtWriteFile (476, 0, 0, 0, (476, 0, 0, 0, "b\346\10\274\207\273\0\202"\303_\212\354\267X\5M|SY\336\300 \200\301\237\7\25\263y5\271\177\217k\263\0s,o\17d\16;\255\376\234\354c\200\201N>\271\236\32\1\375'\276\233<\342\365\354\323\320\0D\177x\221\37\240U\34%s\14\200\233go\360 y\1\254\26<\362$\253\340\200\211\11t\27\10{\316\0\272\341\332H\335\3318\24x\206\37\122u\1\333^e\177/\20489\Y\303\30.\310\274\234R\3[j\363\237\372S\0\30iE\235\16\260\253\331\50wZ\270\334\200U\271Di\3\345\237\3037\242\4Y\2429mq\220L[\220A\0\327\1\374\300MD}\2;\352\22\200\367\31\206\3\232\261\362\13\30\237!}I\333b\0'd\233E\243\27L\345\2\234\204{\245s\300\200\271\363\320B&\260\323\0 VT\17\205\211\344l\0\347\271R\264\20\365K"\1\370\30\277o\16\26k\344L=\0\257\352N*\203\6U\265\0\264\337\377\313'\322fT\2\200Ip\311{H\340y\223\14\37\2418\307g\355\342P\213*\259\0P\365\23\220\177V\244\231\0H\204\266\24\236\302C!\354\361\@\1\347\326\235\252l?5(\13HU8\315H'\34\205\262\300\322\204\306nV\212q\375\350\251\0\2421\310\376\273\37\200v\0<\322\364\260\341AD\25.sB\244\1\206\240\212n\337\364z\355\16r9+\316\212W\304\200\25\310\305$\14\250\350\223\0\15\33%\20\204\247"
\232\354\12\4c\344CK,\2008\217\16\375z\377\354\342\35p\177b\214\207.P\362)D\313@\0T\215=\342J\320\206DV\33\0\35o\225\215\255,\321\272\1\277\352\13\226\204j\212\345\365Bl", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) \303_\212\354\267X\5M|SY\336\300 \200\301\237\7\25\263y5\271\177\217k\263\0s,o\17d\16;\255\376\234\354c\200\201N>\271\236\32\1\375'\276\233<\342\365\354\323\320\0D\177x\221\37\240U\34%s\14\200\233go\360 y\1\254\26<\362$\253\340\200\211\11t\27\10{\316\0\272\341\332H\335\3318\24x\206\37\122u\1\333^e\177/\20489\Y\303\30.\310\274\234R\3[j\363\237\372S\0\30iE\235\16\260\253\331\50wZ\270\334\200U\271Di\3\345\237\3037\242\4Y\2429mq\220L[\220A\0\327\1\374\300MD}\2;\352\22\200\367\31\206\3\232\261\362\13\30\237!}I\333b\0'd\233E\243\27L\345\2\234\204{\245s\300\200\271\363\320B&\260\323\0 VT\17\205\211\344l\0\347\271R\264\20\365K (476, 0, 0, 0, "b\346\10\274\207\273\0\202"\303_\212\354\267X\5M|SY\336\300 \200\301\237\7\25\263y5\271\177\217k\263\0s,o\17d\16;\255\376\234\354c\200\201N>\271\236\32\1\375'\276\233<\342\365\354\323\320\0D\177x\221\37\240U\34%s\14\200\233go\360 y\1\254\26<\362$\253\340\200\211\11t\27\10{\316\0\272\341\332H\335\3318\24x\206\37\122u\1\333^e\177/\20489\Y\303\30.\310\274\234R\3[j\363\237\372S\0\30iE\235\16\260\253\331\50wZ\270\334\200U\271Di\3\345\237\3037\242\4Y\2429mq\220L[\220A\0\327\1\374\300MD}\2;\352\22\200\367\31\206\3\232\261\362\13\30\237!}I\333b\0'd\233E\243\27L\345\2\234\204{\245s\300\200\271\363\320B&\260\323\0 VT\17\205\211\344l\0\347\271R\264\20\365K"\1\370\30\277o\16\26k\344L=\0\257\352N*\203\6U\265\0\264\337\377\313'\322fT\2\200Ip\311{H\340y\223\14\37\2418\307g\355\342P\213*\259\0P\365\23\220\177V\244\231\0H\204\266\24\236\302C!\354\361\@\1\347\326\235\252l?5(\13HU8\315H'\34\205\262\300\322\204\306nV\212q\375\350\251\0\2421\310\376\273\37\200v\0<\322\364\260\341AD\25.sB\244\1\206\240\212n\337\364z\355\16r9+\316\212W\304\200\25\310\305$\14\250\350\223\0\15\33%\20\204\247"
\232\354\12\4c\344CK,\2008\217\16\375z\377\354\342\35p\177b\214\207.P\362)D\313@\0T\215=\342J\320\206DV\33\0\35o\225\215\255,\321\272\1\277\352\13\226\204j\212\345\365Bl", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) \232\354\12\4c\344CK,\2008\217\16\375z\377\354\342\35p\177b\214\207.P\362)D\313@\0T\215=\342J\320\206DV\33\0\35o\225\215\255,\321\272\1\277\352\13\226\204j\212\345\365Bl", 61440, 0x0, 0, ... {status=0x0, info=61440}, ) == 0x0 02557 400 NtReadFile (480, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=28160}, (480, 0, 0, 0, 61440, 0x0, 0, ... {status=0x0, info=28160}, "a`\270G=T\273x\0\377[\312*\24#\14\1\36\316-\32\203\323\25\33w\270\254\252\20\3009Es\204\361\242\0m\347&\230:v\3667\177%\0\337V^zK\352\340y\2&\253\224\211=\270\300h8\271\0e\324\7\12\27F\320\177}\243\1\360\300\220B\302%\277\313\300+9K\2\312\33$\315j[\300J8`\0g\326!f\311\301\304]\0'\15\330\340\254\3542c{\306\3R^_\3569f\00\302Lw\215s\324\216\1\271\363:\204U\2067\331\246\377\250\337\252\326\362\255\2\351\347\374\360;\200\343\20\2238\330\201\203\216\0g\224a\16yxMY\3\222;D&\260\263\200\206\31\275\0\371wpZ+\212\216\234\0W\340\266\10\341\377\214r\%\\37o>\1\33\211{\243\16\200`\215dy_g\220\0\277\30\230>\225w}\342\0\260\360\12q\215@Vs\31m\302\207\240\213\334_\261\1^\233\231~\263,\352C\270$\370\346\264\37\0\106\303\34\245>+\21(\214q\350\0\306\320|kH@m\240\35\25\317\367Cx"7\11\340\30\326I\276\275(\Z\350BP\1GF\353\340\244\300\364\344\2417\234P\0|\335J\357\330\345\0B\327\360\202\17X\3662\0p\263\7(\372l\305P\236l\11c\226\243\220\300\240\250\260\26J;d\232\230\332hh\341zXY\10\0=I\250\234j5\222\16\302\256h~`\237\32\252\346\14W\361,\33280\0M\274ko\343\277\21\323\14@\266\214\206!\205\0\26}\357y\232\330\2\336\3\256\352\370\307.M\310c\261(\0\313\266)\225\222\316\14B\230X\203\264\360\275\274\216\356T\0(a\3S\205\341\277\344\300\210\300\267\317~:\7%9v\10-\341\220DA@\340\201\351c\376\227\37\253\335<\2\14\224Y'", ) 7\11\340\30\326I\276\275(\Z\350BP\1GF\353\340\244\300\364\344\2417\234P\0|\335J\357\330\345\0B\327\360\202\17X\3662\0p\263\7(\372l\305P\236l\11c\226\243\220\300\240\250\260\26J;d\232\230\332hh\341zXY\10\0=I\250\234j5\222\16\302\256h~`\237\32\252\346\14W\361,\33280\0M\274ko\343\277\21\323\14@\266\214\206!\205\0\26}\357y\232\330\2\336\3\256\352\370\307.M\310c\261(\0\313\266)\225\222\316\14B\230X\203\264\360\275\274\216\356T\0(a\3S\205\341\277\344\300\210\300\267\317~:\7%9v\10-\341\220DA@\340\201\351c\376\227\37\253\335<\2\14\224Y'", ) == 0x0 02558 400 NtWriteFile (476, 0, 0, 0, (476, 0, 0, 0, "a`\270G=T\273x\0\377[\312*\24#\14\1\36\316-\32\203\323\25\33w\270\254\252\20\3009Es\204\361\242\0m\347&\230:v\3667\177%\0\337V^zK\352\340y\2&\253\224\211=\270\300h8\271\0e\324\7\12\27F\320\177}\243\1\360\300\220B\302%\277\313\300+9K\2\312\33$\315j[\300J8`\0g\326!f\311\301\304]\0'\15\330\340\254\3542c{\306\3R^_\3569f\00\302Lw\215s\324\216\1\271\363:\204U\2067\331\246\377\250\337\252\326\362\255\2\351\347\374\360;\200\343\20\2238\330\201\203\216\0g\224a\16yxMY\3\222;D&\260\263\200\206\31\275\0\371wpZ+\212\216\234\0W\340\266\10\341\377\214r\%\\37o>\1\33\211{\243\16\200`\215dy_g\220\0\277\30\230>\225w}\342\0\260\360\12q\215@Vs\31m\302\207\240\213\334_\261\1^\233\231~\263,\352C\270$\370\346\264\37\0\106\303\34\245>+\21(\214q\350\0\306\320|kH@m\240\35\25\317\367Cx"7\11\340\30\326I\276\275(\Z\350BP\1GF\353\340\244\300\364\344\2417\234P\0|\335J\357\330\345\0B\327\360\202\17X\3662\0p\263\7(\372l\305P\236l\11c\226\243\220\300\240\250\260\26J;d\232\230\332hh\341zXY\10\0=I\250\234j5\222\16\302\256h~`\237\32\252\346\14W\361,\33280\0M\274ko\343\277\21\323\14@\266\214\206!\205\0\26}\357y\232\330\2\336\3\256\352\370\307.M\310c\261(\0\313\266)\225\222\316\14B\230X\203\264\360\275\274\216\356T\0(a\3S\205\341\277\344\300\210\300\267\317~:\7%9v\10-\341\220DA@\340\201\351c\376\227\37\253\335<\2\14\224Y'", 28160, 0x0, 0, ... {status=0x0, info=28160}, ) 7\11\340\30\326I\276\275(\Z\350BP\1GF\353\340\244\300\364\344\2417\234P\0|\335J\357\330\345\0B\327\360\202\17X\3662\0p\263\7(\372l\305P\236l\11c\226\243\220\300\240\250\260\26J;d\232\230\332hh\341zXY\10\0=I\250\234j5\222\16\302\256h~`\237\32\252\346\14W\361,\33280\0M\274ko\343\277\21\323\14@\266\214\206!\205\0\26}\357y\232\330\2\336\3\256\352\370\307.M\310c\261(\0\313\266)\225\222\316\14B\230X\203\264\360\275\274\216\356T\0(a\3S\205\341\277\344\300\210\300\267\317~:\7%9v\10-\341\220DA@\340\201\351c\376\227\37\253\335<\2\14\224Y'", 28160, 0x0, 0, ... {status=0x0, info=28160}, ) == 0x0 02559 400 NtReadFile (480, 0, 0, 0, 61440, 0x0, 0, ... ) == STATUS_END_OF_FILE 02560 400 NtFreeVirtualMemory (-1, (0x154000), 69632, 16384, ... (0x154000), 69632, ) == 0x0 02561 400 NtSetInformationFile (476, 1242904, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02562 400 NtClose (480, ... ) == 0x0 02563 400 NtClose (476, ... ) == 0x0 02564 400 NtOpenKey (0xf003f, {24, 48, 0x40, 0, 0, (0xf003f, {24, 48, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 476, ) }, ... 476, ) == 0x0 02565 400 NtQueryValueKey (476, (476, "Shell", Partial, 144, ... TitleIdx=0, Type=1, Data="E\0x\0p\0l\0o\0r\0e\0r\0.\0e\0x\0e\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (476, "Shell", Partial, 144, ... TitleIdx=0, Type=1, Data="E\0x\0p\0l\0o\0r\0e\0r\0.\0e\0x\0e\0\0\0"}, 38, ) }, 38, ) == 0x0 02566 400 NtQueryValueKey (476, (476, "Shell", Partial, 144, ... TitleIdx=0, Type=1, Data="E\0x\0p\0l\0o\0r\0e\0r\0.\0e\0x\0e\0\0\0"}, 38, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (476, "Shell", Partial, 144, ... TitleIdx=0, Type=1, Data="E\0x\0p\0l\0o\0r\0e\0r\0.\0e\0x\0e\0\0\0"}, 38, ) }, 38, ) == 0x0 02567 400 NtClose (476, ... ) == 0x0 02568 400 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1242812, (0x80100080, {24, 0, 0x40, 0, 1242812, "\??\C:\WINDOWSExplorer.exe"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02569 400 NtOpenFile (0x100100, {24, 0, 0x40, 0, 0, (0x100100, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\ntvdm.exe"}, 7, 2113568, ... 476, {status=0x0, info=1}, ) }, 7, 2113568, ... 476, {status=0x0, info=1}, ) == 0x0 02570 400 NtSetInformationFile (476, 1243104, 40, Basic, ... {status=0x0, info=0}, ) == 0x0 02571 400 NtClose (476, ... ) == 0x0 02572 400 NtAllocateVirtualMemory (-1, 1220608, 0, 4096, 4096, 260, ... 1220608, 4096, ) == 0x0 02573 400 NtAllocateVirtualMemory (-1, 1216512, 0, 4096, 4096, 260, ... 1216512, 4096, ) == 0x0 02574 400 NtAllocateVirtualMemory (-1, 1212416, 0, 4096, 4096, 260, ... 1212416, 4096, ) == 0x0 02575 400 NtAllocateVirtualMemory (-1, 1208320, 0, 4096, 4096, 260, ... 1208320, 4096, ) == 0x0 02576 400 NtAllocateVirtualMemory (-1, 1204224, 0, 4096, 4096, 260, ... 1204224, 4096, ) == 0x0 02577 400 NtAllocateVirtualMemory (-1, 1200128, 0, 4096, 4096, 260, ... 1200128, 4096, ) == 0x0 02578 400 NtAllocateVirtualMemory (-1, 1196032, 0, 4096, 4096, 260, ... 1196032, 4096, ) == 0x0 02579 400 NtAllocateVirtualMemory (-1, 1191936, 0, 4096, 4096, 260, ... 1191936, 4096, ) == 0x0 02580 400 NtAllocateVirtualMemory (-1, 1187840, 0, 4096, 4096, 260, ... 1187840, 4096, ) == 0x0 02581 400 NtAllocateVirtualMemory (-1, 1183744, 0, 4096, 4096, 260, ... 1183744, 4096, ) == 0x0 02582 400 NtAllocateVirtualMemory (-1, 1179648, 0, 4096, 4096, 260, ... 1179648, 4096, ) == 0x0 02583 400 NtAllocateVirtualMemory (-1, 1175552, 0, 4096, 4096, 260, ... 1175552, 4096, ) == 0x0 02584 400 NtAllocateVirtualMemory (-1, 1171456, 0, 4096, 4096, 260, ... 1171456, 4096, ) == 0x0 02585 400 NtCreateKey (0x20006, {24, 48, 0x40, 0, 0, (0x20006, {24, 48, 0x40, 0, 0, "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions"}, 0, 0x0, 0, ... ) }, 0, 0x0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02586 400 NtCreateKey (0x2000000, {24, 48, 0x40, 0, 0, (0x2000000, {24, 48, 0x40, 0, 0, "SOFTWARE"}, 0, 0x0, 0, ... 476, 2, ) }, 0, 0x0, 0, ... 476, 2, ) == 0x0 02587 400 NtCreateKey (0x2000000, {24, 476, 0x40, 0, 0, (0x2000000, {24, 476, 0x40, 0, 0, "Microsoft"}, 0, 0x0, 0, ... 480, 2, ) }, 0, 0x0, 0, ... 480, 2, ) == 0x0 02588 400 NtClose (476, ... ) == 0x0 02589 400 NtCreateKey (0x2000000, {24, 480, 0x40, 0, 0, (0x2000000, {24, 480, 0x40, 0, 0, "Windows"}, 0, 0x0, 0, ... 476, 2, ) }, 0, 0x0, 0, ... 476, 2, ) == 0x0 02590 400 NtClose (480, ... ) == 0x0 02591 400 NtCreateKey (0x2000000, {24, 476, 0x40, 0, 0, (0x2000000, {24, 476, 0x40, 0, 0, "CurrentVersion"}, 0, 0x0, 0, ... 480, 2, ) }, 0, 0x0, 0, ... 480, 2, ) == 0x0 02592 400 NtClose (476, ... ) == 0x0 02593 400 NtCreateKey (0x20006, {24, 480, 0x40, 0, 0, (0x20006, {24, 480, 0x40, 0, 0, "Shell Extensions"}, 0, 0x0, 0, ... 476, 2, ) }, 0, 0x0, 0, ... 476, 2, ) == 0x0 02594 400 NtClose (480, ... ) == 0x0 02595 400 NtSetValueKey (476, (476, "665578", 0, 1, "u\0:\0\\0w\0o\0r\0k\0\\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0\0\0", 38, ... , 0, 1, (476, "665578", 0, 1, "u\0:\0\\0w\0o\0r\0k\0\\0p\0a\0c\0k\0e\0d\0.\0e\0x\0e\0\0\0", 38, ... , 38, ... 02596 400 NtSetInformationFile (-2147482808, -132413644, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 02597 400 NtSetInformationFile (-2147482808, -132414044, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 02595 400 NtSetValueKey ... ) == 0x0 02598 400 NtClose (476, ... ) == 0x0 02599 400 NtOpenKey (0x1, {24, 48, 0x40, 0, 0, (0x1, {24, 48, 0x40, 0, 0, "SOFTWARE\Kazaa\LocalContent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02600 400 NtOpenEvent (0x100000, {24, 56, 0x0, 0, 0, (0x100000, {24, 56, 0x0, 0, 0, "Global\SvcctrlStartEvent_A3752DX"}, ... 476, ) }, ... 476, ) == 0x0 02601 400 NtWaitForSingleObject (476, 0, {-1800000000, -1}, ... ) == 0x0 02602 400 NtClose (476, ... ) == 0x0 02603 400 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02604 400 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Rpc\PagedBuffers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02605 400 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Rpc"}, ... 476, ) }, ... 476, ) == 0x0 02606 400 NtQueryValueKey (476, (476, "MaxRpcSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02607 400 NtClose (476, ... ) == 0x0 02608 400 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe\RpcThreadPoolThrottle"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02609 400 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 476, ) == 0x0 02610 400 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 480, ) == 0x0 02611 400 NtQuerySystemTime (... {810305382, 29873133}, ) == 0x0 02612 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 484, ) == 0x0 02613 400 NtOpenKey (0x20019, {24, 48, 0x40, 0, 0, (0x20019, {24, 48, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\Rpc"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02614 400 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 0x0, ) == 0x0 02615 400 NtQueryInformationProcess (-1, QuotaLimits, 32, ... {process info, class 1, size 32}, 0x0, ) == 0x0 02616 400 NtQueryInformationProcess (-1, VmCounters, 44, ... {process info, class 3, size 44}, 0x0, ) == 0x0 02617 400 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 488, ) == 0x0 02618 400 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 492, ) == 0x0 02619 400 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 496, ) }, ... 496, ) == 0x0 02620 400 NtOpenKey (0x20019, {24, 496, 0x40, 0, 0, (0x20019, {24, 496, 0x40, 0, 0, "ActiveComputerName"}, ... 500, ) }, ... 500, ) == 0x0 02621 400 NtQueryValueKey (500, (500, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (500, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) , Data= (500, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="M\0Y\0W\0O\0R\0L\0D\0\0\0"}, 60, ) }, 60, ) == 0x0 02622 400 NtClose (500, ... ) == 0x0 02623 400 NtClose (496, ... ) == 0x0 02624 400 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 496, ) == 0x0 02625 400 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 500, ) == 0x0 02626 400 NtDuplicateObject (-1, 496, -1, 0x0, 0, 2, ... 504, ) == 0x0 02627 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02628 400 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 508, ) == 0x0 02629 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02630 400 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02631 400 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1242088, (0xc0100080, {24, 0, 0x40, 0, 1242088, "\??\PIPE\svcctl"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 512, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 512, {status=0x0, info=1}, ) == 0x0 02632 400 NtSetInformationFile (512, 1242144, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02633 400 NtSetInformationFile (512, 1242136, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02634 400 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02635 400 NtWriteFile (512, 489, 0, 0, (512, 489, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\201\273z6D\230\3615\2552\230\3608\0\20\3\2\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02636 400 NtReadFile (512, 489, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (512, 489, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\202"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x0 02637 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0\2\0\0\0", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\202"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 36, 1024, ... {status=0x103, info=68}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\1\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0\2\0\0\0", 36, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\202"\0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) \0\0\15\0\PIPE\ntsvcs\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) == 0x103 02638 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\250\0\0\0\2\0\0\0\220\0\0\0\0\0\30\0\0\0\0\0\225\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\250\251A\0\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0\20\1\0\0\2\0\0\0\0\0\0\0\27\0\0\0\0\0\0\0\27\0\0\0"C:\WINDOWS\ntvdm.exe"\0a\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 168, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\225\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) C:\WINDOWS\ntvdm.exe (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\250\0\0\0\2\0\0\0\220\0\0\0\0\0\30\0\0\0\0\0\225\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\250\251A\0\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0\20\1\0\0\2\0\0\0\0\0\0\0\27\0\0\0\0\0\0\0\27\0\0\0"C:\WINDOWS\ntvdm.exe"\0a\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 168, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\225\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 168, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0\250\0\0\0\2\0\0\0\220\0\0\0\0\0\30\0\0\0\0\0\225\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\250\251A\0\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0\20\1\0\0\2\0\0\0\0\0\0\0\27\0\0\0\0\0\0\0\27\0\0\0"C:\WINDOWS\ntvdm.exe"\0a\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 168, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\225\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02639 400 NtWaitForSingleObject (489, 0, 0x0, ... ) == 0x0 02640 400 NtOpenEvent (0x100000, {24, 56, 0x0, 0, 0, (0x100000, {24, 56, 0x0, 0, 0, "Global\SvcctrlStartEvent_A3752DX"}, ... 516, ) }, ... 516, ) == 0x0 02641 400 NtWaitForSingleObject (516, 0, {-1800000000, -1}, ... ) == 0x0 02642 400 NtClose (516, ... ) == 0x0 02643 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02644 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\3\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0?\0\17\0", 36, 1024, ... {status=0x103, info=52}, "\5\0\2\3\20\0\0\04\0\0\0\2\0\0\0\34\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\226\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 36, 1024, ... {status=0x103, info=52}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\3\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0?\0\17\0", 36, 1024, ... {status=0x103, info=52}, "\5\0\2\3\20\0\0\04\0\0\0\2\0\0\0\34\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\226\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02645 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\4\0\0\0,\0\0\0\0\0\34\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0", 68, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\3\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 68, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\4\0\0\0,\0\0\0\0\0\34\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0", 68, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\3\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02646 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\5\0\0\0\24\0\0\0\0\0\3\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\5\0\0\0\24\0\0\0\0\0\3\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\4\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02647 400 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 1392640, 4096, ) == 0x0 02648 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\6\0\0\0,\0\0\0\0\0\34\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\2\0\0\0", 68, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\5\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\231\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 68, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\6\0\0\0,\0\0\0\0\0\34\0\0\0\0\0\227\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\2\0\0\0", 68, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\5\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\231\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02649 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0X\0\0\0\7\0\0\0@\0\0\0\0\0$\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305\2\0\0\0\2\0\0\00\372\22\0\12\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0D\372\22\0\1\0\0\0\1\0\0\0\270\13\0\0", 88, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\6\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\232\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 88, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0X\0\0\0\7\0\0\0@\0\0\0\0\0$\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305\2\0\0\0\2\0\0\00\372\22\0\12\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0D\372\22\0\1\0\0\0\1\0\0\0\270\13\0\0", 88, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\6\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\232\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02650 400 NtWaitForSingleObject (489, 0, 0x0, ... ) == 0x0 02651 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0O\0\0\0\10\0\0\07\0\0\0\0\0$\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305\1\0\0\0\1\0\0\0T\372\22\0\260\251A\0\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0", 79, 1024, ... {status=0x103, info=28}, "\5\0\2\3\20\0\0\0\34\0\0\0\7\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0", ) , 79, 1024, ... {status=0x103, info=28}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0O\0\0\0\10\0\0\07\0\0\0\0\0$\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305\1\0\0\0\1\0\0\0T\372\22\0\260\251A\0\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0", 79, 1024, ... {status=0x103, info=28}, "\5\0\2\3\20\0\0\0\34\0\0\0\7\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02652 400 NtWaitForSingleObject (489, 0, 0x0, ... ) == 0x0 02653 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\11\0\0\0\24\0\0\0\0\0\10\0\0\0\0\0\231\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=28}, "\5\0\2\3\20\0\0\0\34\0\0\0\10\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=28}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\11\0\0\0\24\0\0\0\0\0\10\0\0\0\0\0\231\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=28}, "\5\0\2\3\20\0\0\0\34\0\0\0\10\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02654 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\12\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\11\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\12\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\230\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\11\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02655 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\13\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\232\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\12\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\13\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\232\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\12\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02656 400 NtOpenEvent (0x100000, {24, 56, 0x0, 0, 0, (0x100000, {24, 56, 0x0, 0, 0, "Global\SvcctrlStartEvent_A3752DX"}, ... 516, ) }, ... 516, ) == 0x0 02657 400 NtWaitForSingleObject (516, 0, {-1800000000, -1}, ... ) == 0x0 02658 400 NtClose (516, ... ) == 0x0 02659 400 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02660 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\14\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0?\0\17\0", 36, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\13\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , 36, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0$\0\0\0\14\0\0\0\14\0\0\0\0\0\33\0\0\0\0\0\0\0\0\0?\0\17\0", 36, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\13\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02661 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\15\0\0\0,\0\0\0\0\0\34\0\0\0\0\0\233\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0", 68, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\14\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\233\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 68, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0D\0\0\0\15\0\0\0,\0\0\0\0\0\34\0\0\0\0\0\233\303!k\340?\334\21\261\310\0\14)\371\246\305\7\0\0\0\0\0\0\0\7\0\0\0NTVDM.\0\0\377\1\17\0", 68, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\14\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\233\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02662 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\04\0\0\0\16\0\0\0\34\0\0\0\0\0\37\0\0\0\0\0\234\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0\0\0\0\0", 52, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\15\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\234\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , 52, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\04\0\0\0\16\0\0\0\34\0\0\0\0\0\37\0\0\0\0\0\234\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0\0\0\0\0", 52, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\15\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\234\303!k\340?\334\21\261\310\0\14)\371\246\305\0\0\0\0", ) , ) == 0x103 02663 400 NtWaitForSingleObject (489, 0, 0x0, ... ) == 0x0 02664 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\17\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\233\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=28}, "\5\0\2\3\20\0\0\0\34\0\0\0\16\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=28}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\17\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\233\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=28}, "\5\0\2\3\20\0\0\0\34\0\0\0\16\0\0\0\4\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02665 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\20\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\234\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\17\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\20\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\234\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\17\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02666 400 NtFsControlFile (512, 489, 0x0, 0x0, 0x11c017, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\21\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\226\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\20\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=48}, (512, 489, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\21\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\226\303!k\340?\334\21\261\310\0\14)\371\246\305", 44, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\20\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02667 400 NtRaiseException (1242540, 1241800, 1, ... 02668 400 NtContinue (1240604, 0, ... 02669 400 NtTerminateProcess (0, 1, ... 00677 564 NtDelayExecution ... ) == 0xc0 00678 384 NtDelayExecution ... ) == 0xc0 00680 380 NtDelayExecution ... ) == 0xc0 00681 568 NtDelayExecution ... ) == 0xc0 00682 572 NtDelayExecution ... ) == 0xc0 00683 588 NtDelayExecution ... ) == 0xc0 00684 584 NtDelayExecution ... ) == 0xc0 00424 580 NtDelayExecution ... ) == 0xc0 00451 576 NtWaitForSingleObject ... ) == 0xc0 00977 596 NtWaitForSingleObject ... ) == 0xc0 00963 636 NtWaitForSingleObject ... ) == 0xc0 00987 740 NtWaitForSingleObject ... ) == 0xc0 00841 744 NtWaitForSingleObject ... ) == 0xc0 00967 676 NtWaitForSingleObject ... ) == 0xc0 00991 796 NtWaitForSingleObject ... ) == 0xc0 00889 792 NtWaitForSingleObject ... ) == 0xc0 00861 716 NtWaitForSingleObject ... ) == 0xc0 00906 836 NtWaitForSingleObject ... ) == 0xc0 00857 856 NtWaitForSingleObject ... ) == 0xc0 00873 860 NtWaitForSingleObject ... ) == 0xc0 00736 864 NtWaitForSingleObject ... ) == 0xc0 00910 868 NtWaitForSingleObject ... ) == 0xc0 00981 872 NtWaitForSingleObject ... ) == 0xc0 00877 876 NtWaitForSingleObject ... ) == 0xc0 00904 880 NtDelayExecution ... ) == 0xc0 02669 400 NtTerminateProcess ... ) == 0x0 02670 400 NtFreeVirtualMemory (-1, (0x2780000), 0, 32768, ... (0x2780000), 65536, ) == 0x0 02671 400 NtClose (420, ... ) == 0x0 02672 400 NtClose (424, ... ) == 0x0 02673 400 NtClose (432, ... ) == 0x0 02674 400 NtClose (428, ... ) == 0x0 02675 400 NtClose (436, ... ) == 0x0 02676 400 NtClose (408, ... ) == 0x0 02677 400 NtClose (416, ... ) == 0x0 02678 400 NtClose (452, ... ) == 0x0 02679 400 NtClose (448, ... ) == 0x0 02680 400 NtClose (444, ... ) == 0x0 02681 400 NtClose (440, ... ) == 0x0 02682 400 NtClose (412, ... ) == 0x0 02683 400 NtClose (388, ... ) == 0x0 02684 400 NtClose (396, ... ) == 0x0 02685 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xf,}, 4, ... ) == 0x0 02686 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x10,}, 4, ... ) == 0x0 02687 400 NtClose (392, ... ) == 0x0 02688 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xe,}, 4, ... ) == 0x0 02689 400 NtWaitForMultipleObjects (2, (364, 368, ), 1, 0, 0x0, ... ) == 0x1 02690 400 NtClose (368, ... ) == 0x0 02691 400 NtSetEvent (364, ... 0x0, ) == 0x0 02692 400 NtClose (364, ... ) == 0x0 02693 400 NtWaitForMultipleObjects (2, (372, 376, ), 1, 0, 0x0, ... ) == 0x1 02694 400 NtClose (376, ... ) == 0x0 02695 400 NtSetEvent (372, ... 0x0, ) == 0x0 02696 400 NtClose (372, ... ) == 0x0 02697 400 NtWaitForMultipleObjects (2, (380, 384, ), 1, 0, 0x0, ... ) == 0x1 02698 400 NtClose (384, ... ) == 0x0 02699 400 NtSetEvent (380, ... 0x0, ) == 0x0 02700 400 NtClose (380, ... ) == 0x0 02701 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xd,}, 4, ... ) == 0x0 02702 400 NtFreeVirtualMemory (-1, (0x2550000), 0, 32768, ... (0x2550000), 262144, ) == 0x0 02703 400 NtUserUnregisterClass (1243440, 1991376896, 1243428, ... ) == 0x0 02704 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xb,}, 4, ... ) == 0x0 02705 400 NtClose (296, ... ) == 0x0 02706 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x9,}, 4, ... ) == 0x0 02707 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0xa,}, 4, ... ) == 0x0 02708 400 NtClose (256, ... ) == 0x0 02709 400 NtClose (264, ... ) == 0x0 02710 400 NtClose (268, ... ) == 0x0 02711 400 NtClose (260, ... ) == 0x0 02712 400 NtClose (252, ... ) == 0x0 02713 400 NtWaitForSingleObject (312, 0, 0x0, ... ) == 0x0 02714 400 NtClearEvent (312, ... ) == 0x0 02715 400 NtSetEvent (312, ... 0x0, ) == 0x0 02716 400 NtClose (312, ... ) == 0x0 02717 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x4,}, 4, ... ) == 0x0 02718 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x5,}, 4, ... ) == 0x0 02719 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x6,}, 4, ... ) == 0x0 02720 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x2,}, 4, ... ) == 0x0 02721 400 NtClose (76, ... ) == 0x0 02722 400 NtClose (68, ... ) == 0x0 02723 400 NtClose (64, ... ) == 0x0 02724 400 NtClose (72, ... ) == 0x0 02725 400 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x0,}, 4, ... ) == 0x0 02726 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc03b 02727 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02728 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc03d 02729 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02730 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc03f 02731 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02732 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc041 02733 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02734 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc043 02735 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02736 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc045 02737 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02738 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc047 02739 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02740 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc049 02741 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02742 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc04b 02743 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02744 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc04d 02745 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02746 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc04f 02747 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02748 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc051 02749 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02750 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc053 02751 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02752 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc057 02753 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02754 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc059 02755 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02756 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc05b 02757 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02758 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc05d 02759 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02760 400 NtUserGetClassInfo (1999896576, 1243528, 1243480, 1243556, 0, ... ) == 0xc05f 02761 400 NtUserUnregisterClass (1243532, 1999896576, 1243520, ... ) == 0x1 02762 400 NtFreeVirtualMemory (-1, (0x0), 0, 32768, ... ) == STATUS_MEMORY_NOT_ALLOCATED 02763 400 NtRequestWaitReplyPort (24, {20, 48, new_msg, 0, 2013032352, 2012568799, 1379990, 1379976} (24, {20, 48, new_msg, 0, 2013032352, 2012568799, 1379990, 1379976} "\0\0\0\0\3\0\1\0\315\224s\366M>H\351\1\0\0\0" ... {20, 48, reply, 0, 396, 400, 1605, 0} "\0\0\0\0\3\0\1\0\0\0\0\0M>H\351\1\0\0\0" ) ... {20, 48, reply, 0, 396, 400, 1605, 0} (24, {20, 48, new_msg, 0, 2013032352, 2012568799, 1379990, 1379976} "\0\0\0\0\3\0\1\0\315\224s\366M>H\351\1\0\0\0" ... {20, 48, reply, 0, 396, 400, 1605, 0} "\0\0\0\0\3\0\1\0\0\0\0\0M>H\351\1\0\0\0" ) ) == 0x0 02764 400 NtTerminateProcess (-1, 1, ... 02765 400 NtClose (40, ... ) == 0x0