Summary:

NtAddAtom(>) 1 NtGdiHfontCreate(>) 2 NtWaitForMultipleObjects(>) 6 NtEnumerateKey(>) 26
NtCallbackReturn(>) 1 NtOpenDirectoryObject(>) 2 NtUserCallNoParam(>) 7 NtOpenThreadToken(>) 26
NtCreateProcessEx(>) 1 NtOpenMutant(>) 2 NtQueryVolumeInformationFile(>) 8 NtSetValueKey(>) 26
NtDeleteValueKey(>) 1 NtRaiseException(>) 2 NtCreateSemaphore(>) 9 NtUserRegisterWindowMessage(>) 31
NtGdiCreateBitmap(>) 1 NtRegisterThreadTerminatePort(>) 2 NtLockFile(>) 9 NtOpenSection(>) 36
NtGdiCreatePatternBrushInternal(>) 1 NtResumeThread(>) 2 NtQueryVirtualMemory(>) 9 NtCreateEvent(>) 37
NtGdiDeleteObjectApp(>) 1 NtSetEventBoostPriority(>) 2 NtUnlockFile(>) 9 NtCreateSection(>) 37
NtGdiInit(>) 1 NtTerminateProcess(>) 2 NtUserGetWindowDC(>) 10 NtReadVirtualMemory(>) 40
NtGdiQueryFontAssocInfo(>) 1 NtTestAlert(>) 2 NtUserBuildHwndList(>) 11 NtSetInformationProcess(>) 40
NtGdiSelectBitmap(>) 1 NtUserCreateWindowEx(>) 2 NtEnumerateValueKey(>) 12 NtReleaseSemaphore(>) 48
NtOpenKeyedEvent(>) 1 NtUserDestroyWindow(>) 2 NtFsControlFile(>) 12 NtDeviceIoControlFile(>) 49
NtQueryEvent(>) 1 NtUserGetThreadDesktop(>) 2 NtUserSystemParametersInfo(>) 12 NtUserFindExistingCursorIcon(>) 51
NtQueryInformationJobObject(>) 1 NtUserMessageCall(>) 2 NtContinue(>) 13 NtMapViewOfSection(>) 62
NtQueryInformationThread(>) 1 NtUserOpenDesktop(>) 2 NtOpenProcess(>) 13 NtUserRegisterClassExWOW(>) 63
NtQueryInstallUILanguage(>) 1 NtUserPostThreadMessage(>) 2 NtUserCallOneParam(>) 14 NtQueryAttributesFile(>) 82
NtQueryObject(>) 1 NtUserSetWindowsHookEx(>) 2 NtCreateMutant(>) 15 NtOpenProcessTokenEx(>) 92
NtQuerySystemTime(>) 1 NtUserUnhookWindowsHookEx(>) 2 NtNotifyChangeKey(>) 15 NtOpenThreadTokenEx(>) 92
NtSecureConnectPort(>) 1 NtConnectPort(>) 3 NtReadFile(>) 15 NtQueryKey(>) 92
NtSetSecurityObject(>) 1 NtGdiCreateCompatibleDC(>) 3 NtSetInformationFile(>) 15 NtOpenFile(>) 95
NtUserBuildNameList(>) 1 NtOpenEvent(>) 3 NtOpenProcessToken(>) 16 NtQuerySystemInformation(>) 96
NtUserCloseDesktop(>) 1 NtUserGetObjectInformation(>) 3 NtQueryDefaultUILanguage(>) 16 NtSetEvent(>) 100
NtUserGetAtomName(>) 1 NtUserRemoveProp(>) 3 NtQuerySection(>) 16 NtQueryInformationToken(>) 105
NtUserGetDC(>) 1 NtQueryPerformanceCounter(>) 4 NtReleaseMutant(>) 16 NtAllocateVirtualMemory(>) 108
NtUserGetForegroundWindow(>) 1 NtSetInformationObject(>) 4 NtFreeVirtualMemory(>) 18 NtQueryInformationProcess(>) 123
NtUserGetGUIThreadInfo(>) 1 NtUserFindWindowEx(>) 4 NtQueryDefaultLocale(>) 18 NtFlushInstructionCache(>) 133
NtUserGetThreadState(>) 1 NtWriteVirtualMemory(>) 4 NtSetInformationThread(>) 18 NtWaitForSingleObject(>) 158
NtUserSetProp(>) 1 NtAccessCheck(>) 5 NtRequestWaitReplyPort(>) 20 NtQueryValueKey(>) 232
NtUserUnregisterClass(>) 1 NtGdiGetStockObject(>) 5 NtCreateFile(>) 21 NtProtectVirtualMemory(>) 289
NtAdjustPrivilegesToken(>) 2 NtOpenSymbolicLinkObject(>) 5 NtQueryDirectoryFile(>) 23 NtUserQueryWindow(>) 367
NtCreateIoCompletion(>) 2 NtQuerySymbolicLinkObject(>) 5 NtQueryInformationFile(>) 23 NtUserValidateHandleSecure(>) 443
NtCreateThread(>) 2 NtUserGetProcessWindowStation(>) 5 NtUnmapViewOfSection(>) 23 NtOpenKey(>) 586
NtDuplicateToken(>) 2 NtWriteFile(>) 5 NtCreateKey(>) 24 NtClose(>) 606
NtGdiCreateSolidBrush(>) 2 NtDuplicateObject(>) 6 NtQueryDebugFilterState(>) 24

Trace:

00001 464 NtOpenFile (0x80100000, {24, 0, 0x240, 0, 0, (0x80100000, {24, 0, 0x240, 0, 0, "\SystemRoot\Prefetch\PACKED.EXE-09ED06A1.pf"}, 0, 32, ... ) }, 0, 32, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00002 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00003 464 NtOpenKeyedEvent (0x2000000, {24, 0, 0x0, 0, 0, (0x2000000, {24, 0, 0x0, 0, 0, "\KernelObjects\CritSecOutOfMemoryEvent"}, ... 4, ) }, ... 4, ) == 0x0 00004 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00005 464 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 1376256, 1048576, ) == 0x0 00006 464 NtAllocateVirtualMemory (-1, 1376256, 0, 4096, 4096, 4, ... 1376256, 4096, ) == 0x0 00007 464 NtAllocateVirtualMemory (-1, 1380352, 0, 8192, 4096, 4, ... 1380352, 8192, ) == 0x0 00008 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00009 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 2424832, 65536, ) == 0x0 00010 464 NtAllocateVirtualMemory (-1, 2424832, 0, 24576, 4096, 4, ... 2424832, 24576, ) == 0x0 00011 464 NtOpenDirectoryObject (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\KnownDlls"}, ... 8, ) }, ... 8, ) == 0x0 00012 464 NtOpenSymbolicLinkObject (0x1, {24, 8, 0x40, 0, 0, (0x1, {24, 8, 0x40, 0, 0, "KnownDllPath"}, ... 12, ) }, ... 12, ) == 0x0 00013 464 NtQuerySymbolicLinkObject (12, ... (12, ... "C:\WINDOWS\system32", 0x0, ) , 0x0, ) == 0x0 00014 464 NtClose (12, ... ) == 0x0 00015 464 NtOpenFile (0x100020, {24, 0, 0x42, 0, 0, (0x100020, {24, 0, 0x42, 0, 0, "\??\C:\scripts\"}, 3, 33, ... 12, {status=0x0, info=1}, ) }, 3, 33, ... 12, {status=0x0, info=1}, ) == 0x0 00016 464 NtQueryVolumeInformationFile (12, 1243852, 8, Device, ... {status=0x0, info=8}, ) == 0x0 00017 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "kernel32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00018 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7c800000), 0x0, 1003520, ) == 0x0 00019 464 NtClose (16, ... ) == 0x0 00020 464 NtProtectVirtualMemory (-1, (0x7c801000), 1568, 4, ... (0x7c801000), 4096, 32, ) == 0x0 00021 464 NtProtectVirtualMemory (-1, (0x7c801000), 4096, 32, ... (0x7c801000), 4096, 4, ) == 0x0 00022 464 NtFlushInstructionCache (-1, 2088767488, 1568, ... ) == 0x0 00023 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 00024 464 NtQuerySystemInformation (RangeStart, 4, ... {system info, class 50, size 4}, 0x0, ) == 0x0 00025 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00026 464 NtCreateSection (0xf001f, 0x0, {65536, 0}, 4, 67108864, 0, ... 16, ) == 0x0 00027 464 NtSecureConnectPort ( ("\Windows\ApiPort", {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1385208, {12, 0, 0}, 1241944, 44, ... 24, {24, 16, 0, 65536, 2490368, 18415616}, {0, 0, 0}, 200, 44, ) , {0, 2, 1, 1}, {24, 16, 0, 65536, 0, 0}, 1385208, {12, 0, 0}, 1241944, 44, ... 24, {24, 16, 0, 65536, 2490368, 18415616}, {0, 0, 0}, 200, 44, ) == 0x0 00028 464 NtClose (16, ... ) == 0x0 00029 464 NtQueryObject (24, Handle, 2, ... {Inherit=0,ProtectFromClose=0,}, -1, ) == 0x0 00030 464 NtSetInformationObject (24, Handle, {Inherit=0,ProtectFromClose=1,}, 256, ... ) == 0x0 00031 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00032 464 NtQueryVirtualMemory (-1, 0x260000, Basic, 28, ... {BaseAddress=0x260000,AllocationBase=0x260000,AllocationProtect=0x4,RegionSize=0x10000,State=0x2000,Protect=0x0,Type=0x40000,}, 0x0, ) == 0x0 00033 464 NtAllocateVirtualMemory (-1, 2490368, 0, 4096, 4096, 4, ... 2490368, 4096, ) == 0x0 00034 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} "\210\6\31\1\0\0\0\0eZ\221|\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 1036, 464, 57970, 0} "0\346\26\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57970, 0} (24, {28, 56, new_msg, 0, 1242260, 1242460, 2089900544, 1242184} "\210\6\31\1\0\0\0\0eZ\221|\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ... {28, 56, reply, 0, 1036, 464, 57970, 0} "0\346\26\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\234\6\31\1\4\0\0\0" ) ) == 0x0 00035 464 NtRegisterThreadTerminatePort (24, ... ) == 0x0 00036 464 NtAllocateVirtualMemory (-1, 1232896, 0, 4096, 4096, 260, ... 1232896, 4096, ) == 0x0 00037 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00038 464 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00039 464 NtClose (16, ... ) == 0x0 00040 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionUnicode"}, ... 16, ) }, ... 16, ) == 0x0 00041 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x270000), 0x0, 90112, ) == 0x0 00042 464 NtClose (16, ... ) == 0x0 00043 464 NtQueryDefaultLocale (0, 2089305000, ... ) == 0x0 00044 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionLocale"}, ... 16, ) }, ... 16, ) == 0x0 00045 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x290000), 0x0, 249856, ) == 0x0 00046 464 NtClose (16, ... ) == 0x0 00047 464 NtOpenSection (0x5, {24, 0, 0x40, 0, 0, (0x5, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey"}, ... 16, ) }, ... 16, ) == 0x0 00048 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x2d0000), 0x0, 266240, ) == 0x0 00049 464 NtQuerySection (16, Basic, 16, ... {BaseAddress=0x0,Attributes=0x800000,Size={0x40004, 0x0},}, 0x0, ) == 0x0 00050 464 NtClose (16, ... ) == 0x0 00051 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortTbls"}, ... 16, ) }, ... 16, ) == 0x0 00052 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x320000), 0x0, 24576, ) == 0x0 00053 464 NtClose (16, ... ) == 0x0 00054 464 NtQueryVirtualMemory (-1, 0x7ffd2000, Basic, 28, ... {BaseAddress=0x7ffd2000,AllocationBase=0x7ffb0000,AllocationProtect=0x2,RegionSize=0x2000,State=0x1000,Protect=0x2,Type=0x40000,}, 0x0, ) == 0x0 00055 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00056 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionSortkey00000409"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00057 464 NtAllocateVirtualMemory (-1, 2494464, 0, 8192, 4096, 4, ... 2494464, 8192, ) == 0x0 00058 464 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} "\210\6\31\1\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ... {24, 52, reply, 0, 1036, 464, 57971, 0} "\10P\30\0\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ) ... {24, 52, reply, 0, 1036, 464, 57971, 0} (24, {24, 52, new_msg, 0, 7012468, 7929957, 3145776, 3145776} "\210\6\31\1\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ... {24, 52, reply, 0, 1036, 464, 57971, 0} "\10P\30\0\36\0\1\0\0\0\0\0\377\377\377\377\234\6\31\1p\30\0\0" ) ) == 0x0 00059 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 1036, 464, 57972, 0} "\250\202\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57972, 0} (24, {28, 56, new_msg, 0, 2089305760, 2090321376, 0, 0} "\210\6\31\1\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ... {28, 56, reply, 0, 1036, 464, 57972, 0} "\250\202\26\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0\234\6\31\18\6\0\0" ) ) == 0x0 00060 464 NtProtectVirtualMemory (-1, (0x45b000), 204800, 4, ... (0x45b000), 204800, 128, ) == 0x0 00061 464 NtProtectVirtualMemory (-1, (0x45b000), 204800, 128, ... (0x45b000), 204800, 4, ) == 0x0 00062 464 NtFlushInstructionCache (-1, 4567040, 204800, ... ) == 0x0 00063 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "user32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00064 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7e410000), 0x0, 589824, ) == 0x0 00065 464 NtClose (16, ... ) == 0x0 00066 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "GDI32.dll"}, ... 16, ) }, ... 16, ) == 0x0 00067 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77f10000), 0x0, 290816, ) == 0x0 00068 464 NtClose (16, ... ) == 0x0 00069 464 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00070 464 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00071 464 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00072 464 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00073 464 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00074 464 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00075 464 NtProtectVirtualMemory (-1, (0x77f11000), 508, 4, ... (0x77f11000), 4096, 32, ) == 0x0 00076 464 NtProtectVirtualMemory (-1, (0x77f11000), 4096, 32, ... (0x77f11000), 4096, 4, ) == 0x0 00077 464 NtFlushInstructionCache (-1, 2012286976, 508, ... ) == 0x0 00078 464 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00079 464 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00080 464 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00081 464 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00082 464 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00083 464 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00084 464 NtProtectVirtualMemory (-1, (0x7e411000), 1252, 4, ... (0x7e411000), 4096, 32, ) == 0x0 00085 464 NtProtectVirtualMemory (-1, (0x7e411000), 4096, 32, ... (0x7e411000), 4096, 4, ) == 0x0 00086 464 NtFlushInstructionCache (-1, 2118193152, 1252, ... ) == 0x0 00087 464 NtProtectVirtualMemory (-1, (0x45b000), 204800, 4, ... (0x45b000), 204800, 64, ) == 0x0 00088 464 NtProtectVirtualMemory (-1, (0x45b000), 204800, 64, ... (0x45b000), 204800, 4, ) == 0x0 00089 464 NtFlushInstructionCache (-1, 4567040, 204800, ... ) == 0x0 00090 464 NtQueryInformationProcess (-1, 37, 48, ... {process info, class 37, size 48}, 0x0, ) == 0x0 00091 464 NtSetInformationProcess (-1, 34, {process info, class 34, size 4}, 4, ... ) == 0x0 00092 464 NtOpenProcessToken (-1, 0x8, ... 16, ) == 0x0 00093 464 NtQueryInformationToken (16, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00094 464 NtClose (16, ... ) == 0x0 00095 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 16, ) }, ... 16, ) == 0x0 00096 464 NtQueryValueKey (16, (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (16, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00097 464 NtClose (16, ... ) == 0x0 00098 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00099 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\user32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00100 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00101 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 2089900645, 2012282880, 2090320576, 1242028} (24, {28, 56, new_msg, 0, 2089900645, 2012282880, 2090320576, 1242028} "\210\6\31\1\0\0\0\0\344\0\23\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 1036, 464, 57973, 0} "\320G\26\0\0\0\0\0\0\0\0\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57973, 0} (24, {28, 56, new_msg, 0, 2089900645, 2012282880, 2090320576, 1242028} "\210\6\31\1\0\0\0\0\344\0\23\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ... {28, 56, reply, 0, 1036, 464, 57973, 0} "\320G\26\0\0\0\0\0\0\0\0\0\4\0\0\0\3\0\0\0\234\6\31\1$\1\0\0" ) ) == 0x0 00102 464 NtFsControlFile (12, 0, 0x0, 0x0, 0x90028, 0x0, 0, 0, ... {status=0x0, info=0}, 0x0, ) == 0x0 00103 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager"}, ... 16, ) }, ... 16, ) == 0x0 00104 464 NtQueryValueKey (16, (16, "SafeDllSearchMode", Partial, 16, ... ) , Partial, 16, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00105 464 NtClose (16, ... ) == 0x0 00106 464 NtAllocateVirtualMemory (-1, 1388544, 0, 4096, 4096, 4, ... 1388544, 4096, ) == 0x0 00107 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239420, ... ) }, 1239420, ... ) == 0x0 00108 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 16, {status=0x0, info=1}, ) }, 5, 96, ... 16, {status=0x0, info=1}, ) == 0x0 00109 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 16, ... 28, ) == 0x0 00110 464 NtClose (16, ... ) == 0x0 00111 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x490000), 0x0, 110592, ) == 0x0 00112 464 NtClose (28, ... ) == 0x0 00113 464 NtUnmapViewOfSection (-1, 0x490000, ... ) == 0x0 00114 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239328, ... ) }, 1239328, ... ) == 0x0 00115 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 28, {status=0x0, info=1}, ) }, 5, 96, ... 28, {status=0x0, info=1}, ) == 0x0 00116 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 28, ... 16, ) == 0x0 00117 464 NtClose (28, ... ) == 0x0 00118 464 NtMapViewOfSection (16, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x490000), 0x0, 110592, ) == 0x0 00119 464 NtClose (16, ... ) == 0x0 00120 464 NtUnmapViewOfSection (-1, 0x490000, ... ) == 0x0 00121 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239636, ... ) }, 1239636, ... ) == 0x0 00122 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 5, 96, ... 16, {status=0x0, info=1}, ) }, 5, 96, ... 16, {status=0x0, info=1}, ) == 0x0 00123 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 16, ... 28, ) == 0x0 00124 464 NtQuerySection (28, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00125 464 NtOpenProcessToken (-1, 0x8, ... 32, ) == 0x0 00126 464 NtQueryInformationToken (32, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 00127 464 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00128 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 36, ) }, ... 36, ) == 0x0 00129 464 NtQueryValueKey (36, (36, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (36, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 00130 464 NtClose (36, ... ) == 0x0 00131 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 00132 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 36, ) == 0x0 00133 464 NtQueryInformationToken (36, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 00134 464 NtClose (36, ... ) == 0x0 00135 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00136 464 NtClose (32, ... ) == 0x0 00137 464 NtClose (16, ... ) == 0x0 00138 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76390000), 0x0, 118784, ) == 0x0 00139 464 NtClose (28, ... ) == 0x0 00140 464 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00141 464 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00142 464 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00143 464 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00144 464 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00145 464 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00146 464 NtProtectVirtualMemory (-1, (0x76391000), 696, 4, ... (0x76391000), 4096, 32, ) == 0x0 00147 464 NtProtectVirtualMemory (-1, (0x76391000), 4096, 32, ... (0x76391000), 4096, 4, ) == 0x0 00148 464 NtFlushInstructionCache (-1, 1983451136, 696, ... ) == 0x0 00149 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ADVAPI32.dll"}, ... 28, ) }, ... 28, ) == 0x0 00150 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77dd0000), 0x0, 634880, ) == 0x0 00151 464 NtClose (28, ... ) == 0x0 00152 464 NtProtectVirtualMemory (-1, (0x77dd1000), 1700, 4, ... (0x77dd1000), 4096, 32, ) == 0x0 00153 464 NtProtectVirtualMemory (-1, (0x77dd1000), 4096, 32, ... (0x77dd1000), 4096, 4, ) == 0x0 00154 464 NtFlushInstructionCache (-1, 2010976256, 1700, ... ) == 0x0 00155 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "RPCRT4.dll"}, ... 28, ) }, ... 28, ) == 0x0 00156 464 NtMapViewOfSection (28, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77e70000), 0x0, 593920, ) == 0x0 00157 464 NtClose (28, ... ) == 0x0 00158 464 NtAllocateVirtualMemory (-1, 1228800, 0, 4096, 4096, 260, ... 1228800, 4096, ) == 0x0 00159 464 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00160 464 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00161 464 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00162 464 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00163 464 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00164 464 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00165 464 NtProtectVirtualMemory (-1, (0x77e71000), 868, 4, ... (0x77e71000), 4096, 32, ) == 0x0 00166 464 NtProtectVirtualMemory (-1, (0x77e71000), 4096, 32, ... (0x77e71000), 4096, 4, ) == 0x0 00167 464 NtFlushInstructionCache (-1, 2011631616, 868, ... ) == 0x0 00168 464 NtProtectVirtualMemory (-1, (0x77dd1000), 1700, 4, ... (0x77dd1000), 4096, 32, ) == 0x0 00169 464 NtProtectVirtualMemory (-1, (0x77dd1000), 4096, 32, ... (0x77dd1000), 4096, 4, ) == 0x0 00170 464 NtFlushInstructionCache (-1, 2010976256, 1700, ... ) == 0x0 00171 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00172 464 NtAllocateVirtualMemory (-1, 1392640, 0, 4096, 4096, 4, ... 1392640, 4096, ) == 0x0 00173 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00174 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Terminal Server"}, ... 28, ) }, ... 28, ) == 0x0 00175 464 NtQueryValueKey (28, (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSAppCompat", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00176 464 NtQueryValueKey (28, (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 548, ... TitleIdx=0, Type=4, Data= (28, "TSUserEnabled", Partial, 548, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 00177 464 NtClose (28, ... ) == 0x0 00178 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"}, ... 28, ) }, ... 28, ) == 0x0 00179 464 NtQueryValueKey (28, (28, "LeakTrack", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00180 464 NtClose (28, ... ) == 0x0 00181 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\MACHINE"}, ... 28, ) }, ... 28, ) == 0x0 00182 464 NtSetInformationObject (28, Handle, {Inherit=0,ProtectFromClose=1,}, 2011431168, ... ) == 0x0 00183 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Diagnostics"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00184 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00185 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 00186 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1236552, ... ) }, 1236552, ... ) == 0x0 00187 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00188 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernel32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00189 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\IMM32.DLL"}, 1239956, ... ) }, 1239956, ... ) == 0x0 00190 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\Error Message Instrument\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00191 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize"}, ... 16, ) }, ... 16, ) == 0x0 00192 464 NtQueryValueKey (16, (16, "DisableMetaFiles", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00193 464 NtClose (16, ... ) == 0x0 00194 464 NtMapViewOfSection (-2147482584, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x490000), 0x0, 1060864, ) == 0x0 00195 464 NtClose (-2147482584, ... ) == 0x0 00196 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 16, ) == 0x0 00197 464 NtOpenThreadTokenEx (-2, 0x8, 1, 512, ... ) == STATUS_NO_TOKEN 00198 464 NtOpenProcessTokenEx (-1, 0x8, 512, ... -2147482584, ) == 0x0 00199 464 NtQueryInformationToken (-2147482584, Statistics, 0, ... ) == STATUS_BUFFER_TOO_SMALL 00200 464 NtQueryInformationToken (-2147482584, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 00201 464 NtClose (-2147482584, ... ) == 0x0 00202 464 NtAllocateVirtualMemory (-1, 0, 0, 32, 4096, 4, ... 5898240, 4096, ) == 0x0 00203 464 NtFreeVirtualMemory (-1, (0x5a0000), 4096, 32768, ... (0x5a0000), 4096, ) == 0x0 00204 464 NtDuplicateObject (-1, 32, -1, 0x0, 0, 2, ... 40, ) == 0x0 00205 464 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 00206 464 NtQueryValueKey (-2147482584, (-2147482584, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00207 464 NtClose (-2147482584, ... ) == 0x0 00208 464 NtOpenKey (0x20019, {24, 0, 0x240, 0, 0, (0x20019, {24, 0, 0x240, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 00209 464 NtQueryValueKey (-2147482584, (-2147482584, "packed", Partial, 172, ... ) , Partial, 172, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00210 464 NtClose (-2147482584, ... ) == 0x0 00211 464 NtQueryDefaultLocale (0, -106645172, ... ) == 0x0 00212 464 NtGdiQueryFontAssocInfo (0, ... ) == 0x0 00213 464 NtUserCallNoParam (24, ... ) == 0x0 00214 464 NtGdiCreateCompatibleDC (0, ... 00215 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 5898240, 4096, ) == 0x0 00214 464 NtGdiCreateCompatibleDC ... ) == 0xee0105b0 00216 464 NtGdiGetStockObject (0, ... ) == 0x1900010 00217 464 NtGdiGetStockObject (4, ... ) == 0x1900011 00218 464 NtGdiCreateBitmap (8, 8, 1, 1, 2118200212, ... ) == 0x76050581 00219 464 NtGdiCreateSolidBrush (0, 0, ... 00220 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 12288, 4, ... 9109504, 4096, ) == 0x0 00219 464 NtGdiCreateSolidBrush ... ) == 0xa51003d2 00221 464 NtGdiGetStockObject (13, ... ) == 0x18a0021 00222 464 NtGdiCreateCompatibleDC (0, ... ) == 0x5201039b 00223 464 NtGdiSelectBitmap (1375798171, 1980040577, ... ) == 0x185000f 00224 464 NtUserGetThreadDesktop (464, 0, ... ) == 0x24 00225 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows"}, ... 44, ) }, ... 44, ) == 0x0 00226 464 NtQueryValueKey (44, (44, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 64, ... TitleIdx=0, Type=1, Data= (44, "AppInit_DLLs", Partial, 64, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 00227 464 NtClose (44, ... ) == 0x0 00228 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00229 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 673, 128, 0, ... ) == 0x81aec017 00230 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00231 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 674, 128, 0, ... ) == 0x81aec01c 00232 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00233 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 675, 128, 0, ... ) == 0x81aec01e 00234 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00235 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 676, 128, 0, ... ) == 0x81ae8002 00236 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10013 00237 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 677, 128, 0, ... ) == 0x81aec018 00238 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00239 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 678, 128, 0, ... ) == 0x81aec01a 00240 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00241 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 679, 128, 0, ... ) == 0x81aec01d 00242 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00243 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 681, 128, 0, ... ) == 0x81aec026 00244 464 NtUserFindExistingCursorIcon (1241132, 1241148, 1241196, ... ) == 0x10011 00245 464 NtUserRegisterClassExWOW (1241144, 1241212, 1241228, 1241244, 680, 128, 0, ... ) == 0x81aec019 00246 464 NtUserRegisterClassExWOW (1241096, 1241164, 1241180, 1241196, 0, 128, 0, ... ) == 0x81aec020 00247 464 NtUserRegisterClassExWOW (1241352, 1241448, 1241432, 1241420, 0, 130, 0, ... ) == 0x81aec022 00248 464 NtUserRegisterClassExWOW (1241096, 1241164, 1241180, 1241196, 0, 128, 0, ... ) == 0x81aec023 00249 464 NtUserRegisterClassExWOW (1241352, 1241448, 1241432, 1241420, 0, 130, 0, ... ) == 0x81aec024 00250 464 NtUserRegisterClassExWOW (1241096, 1241164, 1241180, 1241196, 0, 128, 0, ... ) == 0x81aec025 00251 464 NtCallbackReturn (0, 0, 0, ... 00252 464 NtGdiInit (... ) == 0x1 00253 464 NtGdiGetStockObject (18, ... ) == 0x290001c 00254 464 NtGdiGetStockObject (19, ... ) == 0x1b00019 00255 464 NtAllocateVirtualMemory (-1, 0, 0, 17878, 4096, 4, ... 9175040, 20480, ) == 0x0 00256 464 NtFreeVirtualMemory (-1, (0x8c0000), 0, 32768, ... (0x8c0000), 20480, ) == 0x0 00257 464 NtQueryVirtualMemory (-1, 0x401000, Basic, 52, ... {BaseAddress=0x401000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x22000,State=0x1000,Protect=0x80,Type=0x1000000,}, 28, ) == 0x0 00258 464 NtQueryVirtualMemory (-1, 0x440972, Basic, 28, ... {BaseAddress=0x440000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x1c000,State=0x1000,Protect=0x40,Type=0x1000000,}, 28, ) == 0x0 00259 464 NtAllocateVirtualMemory (-1, 1396736, 0, 4096, 4096, 4, ... 1396736, 4096, ) == 0x0 00260 464 NtProtectVirtualMemory (-1, (0x4001f8), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00261 464 NtProtectVirtualMemory (-1, (0x4001f8), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00262 464 NtProtectVirtualMemory (-1, (0x400220), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00263 464 NtProtectVirtualMemory (-1, (0x400220), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00264 464 NtProtectVirtualMemory (-1, (0x400248), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00265 464 NtProtectVirtualMemory (-1, (0x400248), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00266 464 NtProtectVirtualMemory (-1, (0x400270), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00267 464 NtProtectVirtualMemory (-1, (0x400270), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00268 464 NtProtectVirtualMemory (-1, (0x400298), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00269 464 NtProtectVirtualMemory (-1, (0x400298), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00270 464 NtProtectVirtualMemory (-1, (0x4002c0), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00271 464 NtProtectVirtualMemory (-1, (0x4002c0), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00272 464 NtProtectVirtualMemory (-1, (0x4002e8), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00273 464 NtProtectVirtualMemory (-1, (0x4002e8), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00274 464 NtProtectVirtualMemory (-1, (0x400310), 40, 4, ... (0x400000), 4096, 2, ) == 0x0 00275 464 NtProtectVirtualMemory (-1, (0x400310), 40, 2, ... (0x400000), 4096, 4, ) == 0x0 00276 464 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00277 464 NtUserFindWindowEx (0, 0, (0, 0, "WispWindowClass", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00278 464 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 52, ) == 0x0 00279 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 00280 464 NtUserQueryWindow (327838, 0, ... ) == 0x6b8 00281 464 NtUserQueryWindow (327838, 1, ... ) == 0x6d4 00282 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {1720, 0}, ... 44, ) == 0x0 00283 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\350\0\0\0", 64, ) , 64, ) == 0x0 00284 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... (44, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00285 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... (44, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00286 464 NtClose (44, ... ) == 0x0 00287 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 00288 464 NtUserQueryWindow (262394, 0, ... ) == 0x6b8 00289 464 NtUserQueryWindow (262394, 1, ... ) == 0x6d4 00290 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 00291 464 NtUserQueryWindow (65652, 0, ... ) == 0x6b8 00292 464 NtUserQueryWindow (65652, 1, ... ) == 0x6d4 00293 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 00294 464 NtUserQueryWindow (65664, 0, ... ) == 0x6b8 00295 464 NtUserQueryWindow (65664, 1, ... ) == 0x6d4 00296 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 00297 464 NtUserQueryWindow (65648, 0, ... ) == 0x6b8 00298 464 NtUserQueryWindow (65648, 1, ... ) == 0x6d4 00299 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 00300 464 NtUserQueryWindow (65668, 0, ... ) == 0x6b8 00301 464 NtUserQueryWindow (65668, 1, ... ) == 0x6d4 00302 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 00303 464 NtUserQueryWindow (196680, 0, ... ) == 0x6b8 00304 464 NtUserQueryWindow (196680, 1, ... ) == 0x6d4 00305 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 00306 464 NtUserQueryWindow (65650, 0, ... ) == 0x6b8 00307 464 NtUserQueryWindow (65650, 1, ... ) == 0x6d4 00308 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 00309 464 NtUserQueryWindow (131154, 0, ... ) == 0x6b8 00310 464 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 00311 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 00312 464 NtUserQueryWindow (327836, 0, ... ) == 0x6b8 00313 464 NtUserQueryWindow (327836, 1, ... ) == 0x6d4 00314 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 00315 464 NtUserQueryWindow (65680, 0, ... ) == 0x6b8 00316 464 NtUserQueryWindow (65680, 1, ... ) == 0x6bc 00317 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 00318 464 NtUserQueryWindow (327842, 0, ... ) == 0x6b8 00319 464 NtUserQueryWindow (327842, 1, ... ) == 0x6d4 00320 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 00321 464 NtUserQueryWindow (65744, 0, ... ) == 0x19c 00322 464 NtUserQueryWindow (65744, 1, ... ) == 0x1a0 00323 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {412, 0}, ... 44, ) == 0x0 00324 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0", 64, ) , 64, ) == 0x0 00325 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... (44, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00326 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... (44, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00327 464 NtClose (44, ... ) == 0x0 00328 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 00329 464 NtUserQueryWindow (131248, 0, ... ) == 0xa0 00330 464 NtUserQueryWindow (131248, 1, ... ) == 0xe4 00331 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {160, 0}, ... 44, ) == 0x0 00332 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\1\0\0", 64, ) , 64, ) == 0x0 00333 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... 00334 464 NtContinue (-106648268, 0, ... 00333 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00335 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... 00336 464 NtContinue (-106648268, 0, ... 00335 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00337 464 NtClose (44, ... ) == 0x0 00338 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 00339 464 NtUserQueryWindow (65740, 0, ... ) == 0x19c 00340 464 NtUserQueryWindow (65740, 1, ... ) == 0x1a0 00341 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 00342 464 NtUserQueryWindow (459012, 0, ... ) == 0x49c 00343 464 NtUserQueryWindow (459012, 1, ... ) == 0x180 00344 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {1180, 0}, ... 44, ) == 0x0 00345 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00346 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... 00347 464 NtContinue (-106648268, 0, ... 00346 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00348 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... 00349 464 NtContinue (-106648268, 0, ... 00348 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00350 464 NtClose (44, ... ) == 0x0 00351 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 00352 464 NtUserQueryWindow (459008, 0, ... ) == 0x5e8 00353 464 NtUserQueryWindow (459008, 1, ... ) == 0x1dc 00354 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {1512, 0}, ... 44, ) == 0x0 00355 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\330\0\0\0", 64, ) , 64, ) == 0x0 00356 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... (44, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00357 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... (44, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00358 464 NtClose (44, ... ) == 0x0 00359 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 00360 464 NtUserQueryWindow (131352, 0, ... ) == 0x6ac 00361 464 NtUserQueryWindow (131352, 1, ... ) == 0x7f4 00362 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {1708, 0}, ... 44, ) == 0x0 00363 464 NtReadVirtualMemory (44, 0x400000, 64, ... 00364 464 NtContinue (-106648268, 0, ... 00363 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00365 464 NtClose (44, ... ) == 0x0 00366 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 00367 464 NtUserQueryWindow (196940, 0, ... ) == 0x4b4 00368 464 NtUserQueryWindow (196940, 1, ... ) == 0x474 00369 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {1204, 0}, ... 44, ) == 0x0 00370 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 64, ) , 64, ) == 0x0 00371 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... (44, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00372 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... (44, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\15\0\37\0\0\1\14\0P\220g\274\212\301\212\301\0\0\0\0\0\0\0\0\0\0\0\0\0\0\202\1\0\0\0\0\0\0\0\0\0\0\0\0\260\221g\274\0\0\0\0\0\0\0\0\10(\0\0H/\20@\0\0\0\0\0\0\0\0\0\0\13@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\222g\274\0\0\0\0$\0\0\0!\1,\0\0\0\17\0\330:e\2748\203g\274Form\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\0\0\14\0\34\1\5\0\0\0\14\0@Sf\274`^g\274\260[\263\341\0\0\0\0@\222g\274\10\0\6\240\200\3\0\200\1\1\0\0\0\0\310\206\0\0\13@\0\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\371\1\0\0~\1\0\0\7\3\0\0\1\2\0\0\374\1\0\0\233\1\0\0\4\3\0\0\376\1\0\0", 256, ) , 256, ) == 0x0 00373 464 NtClose (44, ... ) == 0x0 00374 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 00375 464 NtUserQueryWindow (65820, 0, ... ) == 0x22c 00376 464 NtUserQueryWindow (65820, 1, ... ) == 0x220 00377 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {556, 0}, ... 44, ) == 0x0 00378 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\350\0\0\0", 64, ) , 64, ) == 0x0 00379 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... (44, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00380 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... (44, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00381 464 NtClose (44, ... ) == 0x0 00382 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 00383 464 NtUserQueryWindow (65766, 0, ... ) == 0x6b8 00384 464 NtUserQueryWindow (65766, 1, ... ) == 0x13c 00385 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 00386 464 NtUserQueryWindow (65750, 0, ... ) == 0x6b8 00387 464 NtUserQueryWindow (65750, 1, ... ) == 0x13c 00388 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 00389 464 NtUserQueryWindow (65746, 0, ... ) == 0x6b8 00390 464 NtUserQueryWindow (65746, 1, ... ) == 0x6d4 00391 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 00392 464 NtUserQueryWindow (65738, 0, ... ) == 0x19c 00393 464 NtUserQueryWindow (65738, 1, ... ) == 0x1a0 00394 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 00395 464 NtUserQueryWindow (65736, 0, ... ) == 0xa0 00396 464 NtUserQueryWindow (65736, 1, ... ) == 0xe4 00397 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 00398 464 NtUserQueryWindow (65722, 0, ... ) == 0x104 00399 464 NtUserQueryWindow (65722, 1, ... ) == 0x108 00400 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {260, 0}, ... 44, ) == 0x0 00401 464 NtReadVirtualMemory (44, 0x400000, 64, ... 00402 464 NtContinue (-106648268, 0, ... 00401 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00403 464 NtClose (44, ... ) == 0x0 00404 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 00405 464 NtUserQueryWindow (65710, 0, ... ) == 0x104 00406 464 NtUserQueryWindow (65710, 1, ... ) == 0x108 00407 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 00408 464 NtUserQueryWindow (65708, 0, ... ) == 0x120 00409 464 NtUserQueryWindow (65708, 1, ... ) == 0x124 00410 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {288, 0}, ... 44, ) == 0x0 00411 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\340\0\0\0", 64, ) , 64, ) == 0x0 00412 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... (44, 0x4b1c86, 4, ... "\0\0\0\0", 4, ) , 4, ) == 0x0 00413 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... (44, 0x4c91a0, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 00414 464 NtClose (44, ... ) == 0x0 00415 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 00416 464 NtUserQueryWindow (196774, 0, ... ) == 0xc4 00417 464 NtUserQueryWindow (196774, 1, ... ) == 0xc8 00418 464 NtOpenProcess (0x10, {24, 0, 0x0, 0, 0, 0x0}, {196, 0}, ... 44, ) == 0x0 00419 464 NtReadVirtualMemory (44, 0x400000, 64, ... (44, 0x400000, 64, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\20\1\0\0", 64, ) , 64, ) == 0x0 00420 464 NtReadVirtualMemory (44, 0x4b1c86, 4, ... 00421 464 NtContinue (-106648268, 0, ... 00420 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00422 464 NtReadVirtualMemory (44, 0x4c91a0, 256, ... 00423 464 NtContinue (-106648268, 0, ... 00422 464 NtReadVirtualMemory ... ) == STATUS_PARTIAL_COPY 00424 464 NtClose (44, ... ) == 0x0 00425 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 00426 464 NtUserQueryWindow (65656, 0, ... ) == 0x6b8 00427 464 NtUserQueryWindow (65656, 1, ... ) == 0x6ec 00428 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 00429 464 NtUserQueryWindow (196706, 0, ... ) == 0x6b8 00430 464 NtUserQueryWindow (196706, 1, ... ) == 0x6bc 00431 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 00432 464 NtUserQueryWindow (327734, 0, ... ) == 0x6b8 00433 464 NtUserQueryWindow (327734, 1, ... ) == 0x6bc 00434 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 00435 464 NtUserQueryWindow (327772, 0, ... ) == 0x6b8 00436 464 NtUserQueryWindow (327772, 1, ... ) == 0x6bc 00437 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 00438 464 NtUserQueryWindow (65726, 0, ... ) == 0x19c 00439 464 NtUserQueryWindow (65726, 1, ... ) == 0x1a0 00440 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 00441 464 NtUserQueryWindow (262398, 0, ... ) == 0x6b8 00442 464 NtUserQueryWindow (262398, 1, ... ) == 0x6d4 00443 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 00444 464 NtUserQueryWindow (65682, 0, ... ) == 0x6b8 00445 464 NtUserQueryWindow (65682, 1, ... ) == 0x6bc 00446 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 00447 464 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 00448 464 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 00449 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 00450 464 NtUserQueryWindow (262196, 0, ... ) == 0x6b8 00451 464 NtUserQueryWindow (262196, 1, ... ) == 0x6d4 00452 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 00453 464 NtUserQueryWindow (327760, 0, ... ) == 0x6b8 00454 464 NtUserQueryWindow (327760, 1, ... ) == 0x6d4 00455 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 00456 464 NtUserQueryWindow (65852, 0, ... ) == 0x22c 00457 464 NtUserQueryWindow (65852, 1, ... ) == 0x220 00458 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 00459 464 NtUserQueryWindow (65824, 0, ... ) == 0x22c 00460 464 NtUserQueryWindow (65824, 1, ... ) == 0x220 00461 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 00462 464 NtUserQueryWindow (65730, 0, ... ) == 0xa0 00463 464 NtUserQueryWindow (65730, 1, ... ) == 0xe4 00464 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 00465 464 NtUserQueryWindow (65724, 0, ... ) == 0xa0 00466 464 NtUserQueryWindow (65724, 1, ... ) == 0xe4 00467 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 00468 464 NtUserQueryWindow (131406, 0, ... ) == 0x4b4 00469 464 NtUserQueryWindow (131406, 1, ... ) == 0x474 00470 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 00471 464 NtUserQueryWindow (65752, 0, ... ) == 0x6b8 00472 464 NtUserQueryWindow (65752, 1, ... ) == 0x13c 00473 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 00474 464 NtUserQueryWindow (65718, 0, ... ) == 0x104 00475 464 NtUserQueryWindow (65718, 1, ... ) == 0x108 00476 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 00477 464 NtUserQueryWindow (65720, 0, ... ) == 0x120 00478 464 NtUserQueryWindow (65720, 1, ... ) == 0x124 00479 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 00480 464 NtUserQueryWindow (65716, 0, ... ) == 0xc4 00481 464 NtUserQueryWindow (65716, 1, ... ) == 0xc8 00482 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 00483 464 NtUserQueryWindow (65728, 0, ... ) == 0x19c 00484 464 NtUserQueryWindow (65728, 1, ... ) == 0x1a0 00485 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 00486 464 NtUserQueryWindow (65690, 0, ... ) == 0x6b8 00487 464 NtUserQueryWindow (65690, 1, ... ) == 0x6bc 00488 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 00489 464 NtUserQueryWindow (327774, 0, ... ) == 0x6b8 00490 464 NtUserQueryWindow (327774, 1, ... ) == 0x6bc 00491 464 NtRaiseException (1242648, 1241908, 1, ... 00492 464 NtQueryVirtualMemory (-1, 0x7c85a0a0, Basic, 28, ... {BaseAddress=0x7c85a000,AllocationBase=0x7c800000,AllocationProtect=0x80,RegionSize=0x2a000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 00493 464 NtContinue (1240868, 0, ... 00494 464 NtOpenDirectoryObject (0x2000f, {24, 0, 0x40, 0, 0, (0x2000f, {24, 0, 0x40, 0, 0, "\BaseNamedObjects"}, ... 44, ) }, ... 44, ) == 0x0 00495 464 NtOpenMutant (0x120001, {24, 44, 0x2, 0, 0, (0x120001, {24, 44, 0x2, 0, 0, "DBWinMutex"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00496 464 NtCreateMutant (0x1f0001, {24, 44, 0x82, 1242668, 0, (0x1f0001, {24, 44, 0x82, 1242668, 0, "DBWinMutex"}, 0, ... 48, ) }, 0, ... 48, ) == 0x0 00497 464 NtWaitForSingleObject (48, 0, 0x0, ... ) == 0x0 00498 464 NtOpenSection (0x2, {24, 44, 0x0, 0, 0, (0x2, {24, 44, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00499 464 NtReleaseMutant (48, ... 0x0, ) == 0x0 00500 464 NtDuplicateObject (-1, 2894, -1, 0x0, 0, 2, ... ) == STATUS_INVALID_HANDLE 00501 464 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00502 464 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00503 464 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 52, ) == 0x0 00504 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 00505 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 00506 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 00507 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 00508 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 00509 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 00510 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 00511 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 00512 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 00513 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 00514 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 00515 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 00516 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 00517 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 00518 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 00519 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 00520 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 00521 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 00522 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 00523 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 00524 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 00525 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 00526 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 00527 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 00528 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 00529 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 00530 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 00531 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 00532 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 00533 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 00534 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 00535 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 00536 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 00537 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 00538 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 00539 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 00540 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 00541 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 00542 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 00543 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 00544 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 00545 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 00546 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 00547 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 00548 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 00549 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 00550 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 00551 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 00552 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 00553 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 00554 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 00555 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 00556 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 00557 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 00558 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 00559 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 00560 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 00561 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 00562 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 00563 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 00564 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 00565 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 00566 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 00567 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 00568 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 00569 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 00570 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 00571 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 00572 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 00573 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 00574 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 00575 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 00576 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 00577 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 00578 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 00579 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 00580 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 00581 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 00582 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 00583 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 00584 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 00585 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 00586 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 00587 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 00588 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 00589 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 00590 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 00591 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 00592 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 00593 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 00594 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 00595 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 00596 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 00597 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 00598 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 00599 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 00600 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 00601 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 00602 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 00603 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 00604 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 00605 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 00606 464 NtUserFindWindowEx (0, 0, (0, 0, "OLLYDBG", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00607 464 NtUserFindWindowEx (0, 0, (0, 0, "WispWindowClass", 0x0, 0, ... ) , 0x0, 0, ... ) == 0x0 00608 464 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 52, ) == 0x0 00609 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 00610 464 NtUserQueryWindow (327838, 0, ... ) == 0x6b8 00611 464 NtUserQueryWindow (327838, 1, ... ) == 0x6d4 00612 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 00613 464 NtUserQueryWindow (262394, 0, ... ) == 0x6b8 00614 464 NtUserQueryWindow (262394, 1, ... ) == 0x6d4 00615 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 00616 464 NtUserQueryWindow (65652, 0, ... ) == 0x6b8 00617 464 NtUserQueryWindow (65652, 1, ... ) == 0x6d4 00618 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 00619 464 NtUserQueryWindow (65664, 0, ... ) == 0x6b8 00620 464 NtUserQueryWindow (65664, 1, ... ) == 0x6d4 00621 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 00622 464 NtUserQueryWindow (65648, 0, ... ) == 0x6b8 00623 464 NtUserQueryWindow (65648, 1, ... ) == 0x6d4 00624 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 00625 464 NtUserQueryWindow (65668, 0, ... ) == 0x6b8 00626 464 NtUserQueryWindow (65668, 1, ... ) == 0x6d4 00627 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 00628 464 NtUserQueryWindow (196680, 0, ... ) == 0x6b8 00629 464 NtUserQueryWindow (196680, 1, ... ) == 0x6d4 00630 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 00631 464 NtUserQueryWindow (65650, 0, ... ) == 0x6b8 00632 464 NtUserQueryWindow (65650, 1, ... ) == 0x6d4 00633 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 00634 464 NtUserQueryWindow (131154, 0, ... ) == 0x6b8 00635 464 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 00636 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 00637 464 NtUserQueryWindow (327836, 0, ... ) == 0x6b8 00638 464 NtUserQueryWindow (327836, 1, ... ) == 0x6d4 00639 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 00640 464 NtUserQueryWindow (65680, 0, ... ) == 0x6b8 00641 464 NtUserQueryWindow (65680, 1, ... ) == 0x6bc 00642 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 00643 464 NtUserQueryWindow (327842, 0, ... ) == 0x6b8 00644 464 NtUserQueryWindow (327842, 1, ... ) == 0x6d4 00645 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 00646 464 NtUserQueryWindow (65744, 0, ... ) == 0x19c 00647 464 NtUserQueryWindow (65744, 1, ... ) == 0x1a0 00648 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 00649 464 NtUserQueryWindow (131248, 0, ... ) == 0xa0 00650 464 NtUserQueryWindow (131248, 1, ... ) == 0xe4 00651 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 00652 464 NtUserQueryWindow (65740, 0, ... ) == 0x19c 00653 464 NtUserQueryWindow (65740, 1, ... ) == 0x1a0 00654 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 00655 464 NtUserQueryWindow (459012, 0, ... ) == 0x49c 00656 464 NtUserQueryWindow (459012, 1, ... ) == 0x180 00657 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 00658 464 NtUserQueryWindow (459008, 0, ... ) == 0x5e8 00659 464 NtUserQueryWindow (459008, 1, ... ) == 0x1dc 00660 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 00661 464 NtUserQueryWindow (131352, 0, ... ) == 0x6ac 00662 464 NtUserQueryWindow (131352, 1, ... ) == 0x7f4 00663 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 00664 464 NtUserQueryWindow (196940, 0, ... ) == 0x4b4 00665 464 NtUserQueryWindow (196940, 1, ... ) == 0x474 00666 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 00667 464 NtUserQueryWindow (65820, 0, ... ) == 0x22c 00668 464 NtUserQueryWindow (65820, 1, ... ) == 0x220 00669 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 00670 464 NtUserQueryWindow (65766, 0, ... ) == 0x6b8 00671 464 NtUserQueryWindow (65766, 1, ... ) == 0x13c 00672 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 00673 464 NtUserQueryWindow (65750, 0, ... ) == 0x6b8 00674 464 NtUserQueryWindow (65750, 1, ... ) == 0x13c 00675 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 00676 464 NtUserQueryWindow (65746, 0, ... ) == 0x6b8 00677 464 NtUserQueryWindow (65746, 1, ... ) == 0x6d4 00678 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 00679 464 NtUserQueryWindow (65738, 0, ... ) == 0x19c 00680 464 NtUserQueryWindow (65738, 1, ... ) == 0x1a0 00681 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 00682 464 NtUserQueryWindow (65736, 0, ... ) == 0xa0 00683 464 NtUserQueryWindow (65736, 1, ... ) == 0xe4 00684 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 00685 464 NtUserQueryWindow (65722, 0, ... ) == 0x104 00686 464 NtUserQueryWindow (65722, 1, ... ) == 0x108 00687 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 00688 464 NtUserQueryWindow (65710, 0, ... ) == 0x104 00689 464 NtUserQueryWindow (65710, 1, ... ) == 0x108 00690 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 00691 464 NtUserQueryWindow (65708, 0, ... ) == 0x120 00692 464 NtUserQueryWindow (65708, 1, ... ) == 0x124 00693 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 00694 464 NtUserQueryWindow (196774, 0, ... ) == 0xc4 00695 464 NtUserQueryWindow (196774, 1, ... ) == 0xc8 00696 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 00697 464 NtUserQueryWindow (65656, 0, ... ) == 0x6b8 00698 464 NtUserQueryWindow (65656, 1, ... ) == 0x6ec 00699 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 00700 464 NtUserQueryWindow (196706, 0, ... ) == 0x6b8 00701 464 NtUserQueryWindow (196706, 1, ... ) == 0x6bc 00702 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 00703 464 NtUserQueryWindow (327734, 0, ... ) == 0x6b8 00704 464 NtUserQueryWindow (327734, 1, ... ) == 0x6bc 00705 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 00706 464 NtUserQueryWindow (327772, 0, ... ) == 0x6b8 00707 464 NtUserQueryWindow (327772, 1, ... ) == 0x6bc 00708 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 00709 464 NtUserQueryWindow (65726, 0, ... ) == 0x19c 00710 464 NtUserQueryWindow (65726, 1, ... ) == 0x1a0 00711 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 00712 464 NtUserQueryWindow (262398, 0, ... ) == 0x6b8 00713 464 NtUserQueryWindow (262398, 1, ... ) == 0x6d4 00714 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 00715 464 NtUserQueryWindow (65682, 0, ... ) == 0x6b8 00716 464 NtUserQueryWindow (65682, 1, ... ) == 0x6bc 00717 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 00718 464 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 00719 464 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 00720 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 00721 464 NtUserQueryWindow (262196, 0, ... ) == 0x6b8 00722 464 NtUserQueryWindow (262196, 1, ... ) == 0x6d4 00723 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 00724 464 NtUserQueryWindow (327760, 0, ... ) == 0x6b8 00725 464 NtUserQueryWindow (327760, 1, ... ) == 0x6d4 00726 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 00727 464 NtUserQueryWindow (65852, 0, ... ) == 0x22c 00728 464 NtUserQueryWindow (65852, 1, ... ) == 0x220 00729 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 00730 464 NtUserQueryWindow (65824, 0, ... ) == 0x22c 00731 464 NtUserQueryWindow (65824, 1, ... ) == 0x220 00732 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 00733 464 NtUserQueryWindow (65730, 0, ... ) == 0xa0 00734 464 NtUserQueryWindow (65730, 1, ... ) == 0xe4 00735 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 00736 464 NtUserQueryWindow (65724, 0, ... ) == 0xa0 00737 464 NtUserQueryWindow (65724, 1, ... ) == 0xe4 00738 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 00739 464 NtUserQueryWindow (131406, 0, ... ) == 0x4b4 00740 464 NtUserQueryWindow (131406, 1, ... ) == 0x474 00741 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 00742 464 NtUserQueryWindow (65752, 0, ... ) == 0x6b8 00743 464 NtUserQueryWindow (65752, 1, ... ) == 0x13c 00744 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 00745 464 NtUserQueryWindow (65718, 0, ... ) == 0x104 00746 464 NtUserQueryWindow (65718, 1, ... ) == 0x108 00747 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 00748 464 NtUserQueryWindow (65720, 0, ... ) == 0x120 00749 464 NtUserQueryWindow (65720, 1, ... ) == 0x124 00750 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 00751 464 NtUserQueryWindow (65716, 0, ... ) == 0xc4 00752 464 NtUserQueryWindow (65716, 1, ... ) == 0xc8 00753 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 00754 464 NtUserQueryWindow (65728, 0, ... ) == 0x19c 00755 464 NtUserQueryWindow (65728, 1, ... ) == 0x1a0 00756 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 00757 464 NtUserQueryWindow (65690, 0, ... ) == 0x6b8 00758 464 NtUserQueryWindow (65690, 1, ... ) == 0x6bc 00759 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 00760 464 NtUserQueryWindow (327774, 0, ... ) == 0x6b8 00761 464 NtUserQueryWindow (327774, 1, ... ) == 0x6bc 00762 464 NtRaiseException (1242592, 1241852, 1, ... 00763 464 NtContinue (1240812, 0, ... 00764 464 NtWaitForSingleObject (48, 0, 0x0, ... ) == 0x0 00765 464 NtOpenSection (0x2, {24, 44, 0x0, 0, 0, (0x2, {24, 44, 0x0, 0, 0, "DBWIN_BUFFER"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00766 464 NtReleaseMutant (48, ... 0x0, ) == 0x0 00767 464 NtDuplicateObject (-1, 3608, -1, 0x0, 0, 2, ... ) == STATUS_INVALID_HANDLE 00768 464 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00769 464 NtClose (0, ... ) == STATUS_INVALID_HANDLE 00770 464 NtUserBuildHwndList (0, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 52, ) == 0x0 00771 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 00772 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 00773 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 00774 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 00775 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 00776 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 00777 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 00778 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 00779 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 00780 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 00781 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 00782 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 00783 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 00784 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 00785 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 00786 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 00787 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 00788 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 00789 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 00790 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 00791 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 00792 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 00793 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 00794 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 00795 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 00796 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 00797 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 00798 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 00799 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 00800 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 00801 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 00802 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 00803 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 00804 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 00805 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 00806 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 00807 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 00808 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 00809 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 00810 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 00811 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 00812 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 00813 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 00814 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 00815 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 00816 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 00817 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 00818 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 00819 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 00820 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 00821 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 00822 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 00823 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 00824 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 00825 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 00826 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 00827 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 00828 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 00829 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 00830 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 00831 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 00832 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 00833 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 00834 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 00835 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 00836 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 00837 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 00838 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 00839 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 00840 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 00841 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 00842 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 00843 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 00844 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 00845 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 00846 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 00847 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 00848 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 00849 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 00850 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 00851 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 00852 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 00853 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 00854 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 00855 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 00856 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 00857 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 00858 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 00859 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 00860 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 00861 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 00862 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 00863 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 00864 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 00865 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 00866 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 00867 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 00868 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 00869 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 00870 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 00871 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 00872 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 00873 464 NtSetSecurityObject (-1, 4, {1, 0, 0x4, 0, 0, 0, 1242436}, ... ) == 0x0 00874 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "MPR.dll"}, ... 52, ) }, ... 52, ) == 0x0 00875 464 NtMapViewOfSection (52, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71b20000), 0x0, 73728, ) == 0x0 00876 464 NtClose (52, ... ) == 0x0 00877 464 NtProtectVirtualMemory (-1, (0x71b21000), 440, 4, ... (0x71b21000), 4096, 32, ) == 0x0 00878 464 NtProtectVirtualMemory (-1, (0x71b21000), 4096, 32, ... (0x71b21000), 4096, 4, ) == 0x0 00879 464 NtFlushInstructionCache (-1, 1907494912, 440, ... ) == 0x0 00880 464 NtProtectVirtualMemory (-1, (0x71b21000), 440, 4, ... (0x71b21000), 4096, 32, ) == 0x0 00881 464 NtProtectVirtualMemory (-1, (0x71b21000), 4096, 32, ... (0x71b21000), 4096, 4, ) == 0x0 00882 464 NtFlushInstructionCache (-1, 1907494912, 440, ... ) == 0x0 00883 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPR.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00884 464 NtCreateSemaphore (0x1f0003, 0x0, 1, 1, ... 52, ) == 0x0 00885 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 56, ) == 0x0 00886 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "system\CurrentControlSet\control\NetworkProvider\HwOrder"}, ... 60, ) }, ... 60, ) == 0x0 00887 464 NtNotifyChangeKey (60, 56, 0, 0, 2011455960, 4, 0, 0, 0, 1, ... ) == 0x103 00888 464 NtQueryInformationProcess (-1, 28, 4, ... {process info, class 28, size 4}, 0x0, ) == 0x0 00889 464 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 64, ) == 0x0 00890 464 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 68, ) == 0x0 00891 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ODBC32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00892 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\ODBC32.dll"}, 1241376, ... ) }, 1241376, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 00893 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ODBC32.dll"}, 1241376, ... ) }, 1241376, ... ) == 0x0 00894 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ODBC32.dll"}, 5, 96, ... 72, {status=0x0, info=1}, ) }, 5, 96, ... 72, {status=0x0, info=1}, ) == 0x0 00895 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 72, ... 76, ) == 0x0 00896 464 NtQuerySection (76, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 00897 464 NtClose (72, ... ) == 0x0 00898 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x74320000), 0x0, 249856, ) == 0x0 00899 464 NtClose (76, ... ) == 0x0 00900 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "msvcrt.dll"}, ... 76, ) }, ... 76, ) == 0x0 00901 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c10000), 0x0, 360448, ) == 0x0 00902 464 NtClose (76, ... ) == 0x0 00903 464 NtProtectVirtualMemory (-1, (0x77c11000), 632, 4, ... (0x77c11000), 4096, 32, ) == 0x0 00904 464 NtProtectVirtualMemory (-1, (0x77c11000), 4096, 32, ... (0x77c11000), 4096, 4, ) == 0x0 00905 464 NtFlushInstructionCache (-1, 2009141248, 632, ... ) == 0x0 00906 464 NtProtectVirtualMemory (-1, (0x74321000), 840, 4, ... (0x74321000), 4096, 32, ) == 0x0 00907 464 NtProtectVirtualMemory (-1, (0x74321000), 4096, 32, ... (0x74321000), 4096, 4, ) == 0x0 00908 464 NtFlushInstructionCache (-1, 1949437952, 840, ... ) == 0x0 00909 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMCTL32.dll"}, ... 76, ) }, ... 76, ) == 0x0 00910 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5d090000), 0x0, 630784, ) == 0x0 00911 464 NtClose (76, ... ) == 0x0 00912 464 NtProtectVirtualMemory (-1, (0x5d091000), 1656, 4, ... (0x5d091000), 4096, 32, ) == 0x0 00913 464 NtProtectVirtualMemory (-1, (0x5d091000), 4096, 32, ... (0x5d091000), 4096, 4, ) == 0x0 00914 464 NtFlushInstructionCache (-1, 1560875008, 1656, ... ) == 0x0 00915 464 NtProtectVirtualMemory (-1, (0x5d091000), 1656, 4, ... (0x5d091000), 4096, 32, ) == 0x0 00916 464 NtProtectVirtualMemory (-1, (0x5d091000), 4096, 32, ... (0x5d091000), 4096, 4, ) == 0x0 00917 464 NtFlushInstructionCache (-1, 1560875008, 1656, ... ) == 0x0 00918 464 NtProtectVirtualMemory (-1, (0x5d091000), 1656, 4, ... (0x5d091000), 4096, 32, ) == 0x0 00919 464 NtProtectVirtualMemory (-1, (0x5d091000), 4096, 32, ... (0x5d091000), 4096, 4, ) == 0x0 00920 464 NtFlushInstructionCache (-1, 1560875008, 1656, ... ) == 0x0 00921 464 NtProtectVirtualMemory (-1, (0x5d091000), 1656, 4, ... (0x5d091000), 4096, 32, ) == 0x0 00922 464 NtProtectVirtualMemory (-1, (0x5d091000), 4096, 32, ... (0x5d091000), 4096, 4, ) == 0x0 00923 464 NtFlushInstructionCache (-1, 1560875008, 1656, ... ) == 0x0 00924 464 NtProtectVirtualMemory (-1, (0x5d091000), 1656, 4, ... (0x5d091000), 4096, 32, ) == 0x0 00925 464 NtProtectVirtualMemory (-1, (0x5d091000), 4096, 32, ... (0x5d091000), 4096, 4, ) == 0x0 00926 464 NtFlushInstructionCache (-1, 1560875008, 1656, ... ) == 0x0 00927 464 NtProtectVirtualMemory (-1, (0x74321000), 840, 4, ... (0x74321000), 4096, 32, ) == 0x0 00928 464 NtProtectVirtualMemory (-1, (0x74321000), 4096, 32, ... (0x74321000), 4096, 4, ) == 0x0 00929 464 NtFlushInstructionCache (-1, 1949437952, 840, ... ) == 0x0 00930 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHELL32.dll"}, ... 76, ) }, ... 76, ) == 0x0 00931 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x7c9c0000), 0x0, 8482816, ) == 0x0 00932 464 NtClose (76, ... ) == 0x0 00933 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00934 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00935 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00936 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00937 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00938 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00939 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00940 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00941 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00942 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00943 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00944 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00945 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00946 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00947 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00948 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00949 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00950 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00951 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SHLWAPI.dll"}, ... 76, ) }, ... 76, ) == 0x0 00952 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77f60000), 0x0, 483328, ) == 0x0 00953 464 NtClose (76, ... ) == 0x0 00954 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00955 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00956 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00957 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00958 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00959 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00960 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00961 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00962 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00963 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00964 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00965 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00966 464 NtProtectVirtualMemory (-1, (0x77f61000), 2076, 4, ... (0x77f61000), 4096, 32, ) == 0x0 00967 464 NtProtectVirtualMemory (-1, (0x77f61000), 4096, 32, ... (0x77f61000), 4096, 4, ) == 0x0 00968 464 NtFlushInstructionCache (-1, 2012614656, 2076, ... ) == 0x0 00969 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00970 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00971 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00972 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 4476, 4, ... (0x7c9c1000), 8192, 32, ) == 0x0 00973 464 NtProtectVirtualMemory (-1, (0x7c9c1000), 8192, 32, ... (0x7c9c1000), 8192, 4, ) == 0x0 00974 464 NtFlushInstructionCache (-1, 2090602496, 4476, ... ) == 0x0 00975 464 NtProtectVirtualMemory (-1, (0x74321000), 840, 4, ... (0x74321000), 4096, 32, ) == 0x0 00976 464 NtProtectVirtualMemory (-1, (0x74321000), 4096, 32, ... (0x74321000), 4096, 4, ) == 0x0 00977 464 NtFlushInstructionCache (-1, 1949437952, 840, ... ) == 0x0 00978 464 NtProtectVirtualMemory (-1, (0x74321000), 840, 4, ... (0x74321000), 4096, 32, ) == 0x0 00979 464 NtProtectVirtualMemory (-1, (0x74321000), 4096, 32, ... (0x74321000), 4096, 4, ) == 0x0 00980 464 NtFlushInstructionCache (-1, 1949437952, 840, ... ) == 0x0 00981 464 NtProtectVirtualMemory (-1, (0x74321000), 840, 4, ... (0x74321000), 4096, 32, ) == 0x0 00982 464 NtProtectVirtualMemory (-1, (0x74321000), 4096, 32, ... (0x74321000), 4096, 4, ) == 0x0 00983 464 NtFlushInstructionCache (-1, 1949437952, 840, ... ) == 0x0 00984 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "comdlg32.dll"}, ... 76, ) }, ... 76, ) == 0x0 00985 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x763b0000), 0x0, 299008, ) == 0x0 00986 464 NtClose (76, ... ) == 0x0 00987 464 NtProtectVirtualMemory (-1, (0x763b1000), 1552, 4, ... (0x763b1000), 4096, 32, ) == 0x0 00988 464 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 00989 464 NtFlushInstructionCache (-1, 1983582208, 1552, ... ) == 0x0 00990 464 NtProtectVirtualMemory (-1, (0x763b1000), 1552, 4, ... (0x763b1000), 4096, 32, ) == 0x0 00991 464 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 00992 464 NtFlushInstructionCache (-1, 1983582208, 1552, ... ) == 0x0 00993 464 NtProtectVirtualMemory (-1, (0x763b1000), 1552, 4, ... (0x763b1000), 4096, 32, ) == 0x0 00994 464 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 00995 464 NtFlushInstructionCache (-1, 1983582208, 1552, ... ) == 0x0 00996 464 NtProtectVirtualMemory (-1, (0x763b1000), 1552, 4, ... (0x763b1000), 4096, 32, ) == 0x0 00997 464 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 00998 464 NtFlushInstructionCache (-1, 1983582208, 1552, ... ) == 0x0 00999 464 NtProtectVirtualMemory (-1, (0x763b1000), 1552, 4, ... (0x763b1000), 4096, 32, ) == 0x0 01000 464 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 01001 464 NtFlushInstructionCache (-1, 1983582208, 1552, ... ) == 0x0 01002 464 NtProtectVirtualMemory (-1, (0x763b1000), 1552, 4, ... (0x763b1000), 4096, 32, ) == 0x0 01003 464 NtProtectVirtualMemory (-1, (0x763b1000), 4096, 32, ... (0x763b1000), 4096, 4, ) == 0x0 01004 464 NtFlushInstructionCache (-1, 1983582208, 1552, ... ) == 0x0 01005 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvcrt.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01006 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01007 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 9175040, 65536, ) == 0x0 01008 464 NtAllocateVirtualMemory (-1, 9175040, 0, 4096, 4096, 4, ... 9175040, 4096, ) == 0x0 01009 464 NtAllocateVirtualMemory (-1, 9179136, 0, 8192, 4096, 4, ... 9179136, 8192, ) == 0x0 01010 464 NtAllocateVirtualMemory (-1, 9187328, 0, 4096, 4096, 4, ... 9187328, 4096, ) == 0x0 01011 464 NtOpenSection (0x4, {24, 0, 0x40, 0, 0, (0x4, {24, 0, 0x40, 0, 0, "\NLS\NlsSectionCType"}, ... 76, ) }, ... 76, ) == 0x0 01012 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0x8d0000), 0x0, 12288, ) == 0x0 01013 464 NtClose (76, ... ) == 0x0 01014 464 NtAllocateVirtualMemory (-1, 9191424, 0, 4096, 4096, 4, ... 9191424, 4096, ) == 0x0 01015 464 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 01016 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01017 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01018 464 NtQueryVirtualMemory (-1, 0x0, Basic, 28, ... {BaseAddress=0x0,AllocationBase=0x0,AllocationProtect=0x0,RegionSize=0x10000,State=0x10000,Protect=0x1,Type=0x0,}, 28, ) == 0x0 01019 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COMCTL32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01020 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01021 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 9306112, 65536, ) == 0x0 01022 464 NtAllocateVirtualMemory (-1, 9306112, 0, 4096, 4096, 4, ... 9306112, 4096, ) == 0x0 01023 464 NtAllocateVirtualMemory (-1, 9310208, 0, 8192, 4096, 4, ... 9310208, 8192, ) == 0x0 01024 464 NtAllocateVirtualMemory (-1, 9318400, 0, 4096, 4096, 4, ... 9318400, 4096, ) == 0x0 01025 464 NtAllocateVirtualMemory (-1, 9322496, 0, 4096, 4096, 4, ... 9322496, 4096, ) == 0x0 01026 464 NtQueryDefaultUILanguage (1239704, ... 01027 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01028 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 01029 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01030 464 NtClose (-2147482584, ... ) == 0x0 01031 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01032 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01033 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 01034 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01035 464 NtClose (-2147481332, ... ) == 0x0 01036 464 NtClose (-2147482584, ... ) == 0x0 01026 464 NtQueryDefaultUILanguage ... ) == 0x0 01037 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\COMCTL32.dll"}, 1, 96, ... 76, {status=0x0, info=1}, ) }, 1, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01038 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 76, ... 72, ) == 0x0 01039 464 NtMapViewOfSection (72, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x8f0000), 0x0, 618496, ) == 0x0 01040 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\COMCTL32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01041 464 NtQueryDefaultUILanguage (2090319928, ... 01042 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01043 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 01044 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01045 464 NtClose (-2147482584, ... ) == 0x0 01046 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01047 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01048 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 01049 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01050 464 NtClose (-2147481332, ... ) == 0x0 01051 464 NtClose (-2147482584, ... ) == 0x0 01041 464 NtQueryDefaultUILanguage ... ) == 0x0 01052 464 NtQueryInstallUILanguage (2090319930, ... ) == 0x0 01053 464 NtQueryDefaultLocale (1, 1237800, ... ) == 0x0 01054 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\COMCTL32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01055 464 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 1238836, 1179817, 1238560} (24, {128, 156, new_msg, 0, 2088850039, 1238836, 1179817, 1238560} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0@\0D\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0\340q\226\0\0\0\0\0k\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\354\6\31\1\0\0\0\0\0\0\0\0(\353\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57974, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0@\0D\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0\340q\226\0\0\0\0\0k\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\354\6\31\1\0\0\0\0\0\0\0\0(\353\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 1036, 464, 57974, 0} (24, {128, 156, new_msg, 0, 2088850039, 1238836, 1179817, 1238560} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0@\0D\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0\340q\226\0\0\0\0\0k\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\354\6\31\1\0\0\0\0\0\0\0\0(\353\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57974, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0@\0D\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0\340q\226\0\0\0\0\0k\10\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\354\6\31\1\0\0\0\0\0\0\0\0(\353\22\0\0\0\0\0" ) ) == 0x0 01056 464 NtClose (76, ... ) == 0x0 01057 464 NtClose (72, ... ) == 0x0 01058 464 NtUnmapViewOfSection (-1, 0x8f0000, ... ) == 0x0 01059 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01060 464 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {1036, 0}, ... 72, ) == 0x0 01061 464 NtQueryInformationProcess (72, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 01062 464 NtClose (72, ... ) == 0x0 01063 464 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 01064 464 NtUserSystemParametersInfo (104, 0, 1561338260, 0, ... ) == 0x1 01065 464 NtUserSystemParametersInfo (38, 4, 1561337988, 0, ... ) == 0x1 01066 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01067 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 72, ) == 0x0 01068 464 NtQueryInformationToken (72, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01069 464 NtClose (72, ... ) == 0x0 01070 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 72, ) }, ... 72, ) == 0x0 01071 464 NtOpenProcessToken (-1, 0x8, ... 76, ) == 0x0 01072 464 NtAccessCheck (1396112, 76, 0x1, 1240896, 1240948, 56, 1240928, ... ) == STATUS_NO_IMPERSONATION_TOKEN 01073 464 NtClose (76, ... ) == 0x0 01074 464 NtOpenKey (0x20019, {24, 72, 0x40, 0, 0, (0x20019, {24, 72, 0x40, 0, 0, "Control Panel\Desktop"}, ... 76, ) }, ... 76, ) == 0x0 01075 464 NtQueryValueKey (76, (76, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01076 464 NtClose (76, ... ) == 0x0 01077 464 NtUserSystemParametersInfo (41, 500, 1241076, 0, ... ) == 0x1 01078 464 NtUserSystemParametersInfo (102, 0, 1561338280, 0, ... ) == 0x1 01079 464 NtClose (72, ... ) == 0x0 01080 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01081 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec03b 01082 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec03d 01083 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01084 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec03f 01085 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01086 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec041 01087 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01088 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec043 01089 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec045 01090 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01091 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec047 01092 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01093 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec049 01094 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01095 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec04b 01096 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01097 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec04d 01098 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01099 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec04f 01100 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec051 01101 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01102 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec053 01103 464 NtUserFindExistingCursorIcon (1240824, 1240840, 1240888, ... ) == 0x10011 01104 464 NtUserRegisterClassExWOW (1240768, 1240836, 1240852, 1240868, 0, 384, 0, ... ) == 0x81aec055 01105 464 NtUserFindExistingCursorIcon (1240824, 1240840, 1240888, ... ) == 0x10011 01106 464 NtUserRegisterClassExWOW (1240768, 1240836, 1240852, 1240868, 0, 384, 0, ... ) == 0x81aec057 01107 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01108 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec059 01109 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10013 01110 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec05b 01111 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01112 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec05d 01113 464 NtUserFindExistingCursorIcon (1240828, 1240844, 1240892, ... ) == 0x10011 01114 464 NtUserRegisterClassExWOW (1240772, 1240840, 1240856, 1240872, 0, 384, 0, ... ) == 0x81aec05f 01115 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHLWAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01116 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Performance"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01117 464 NtCreateSemaphore (0x1f0003, {24, 44, 0x80, 1397072, 0, (0x1f0003, {24, 44, 0x80, 1397072, 0, "shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}"}, 0, 2147483647, ... 72, ) }, 0, 2147483647, ... 72, ) == STATUS_OBJECT_NAME_EXISTS 01118 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHELL32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01119 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 76, ) }, ... 76, ) == 0x0 01120 464 NtQueryValueKey (76, (76, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (76, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01121 464 NtClose (76, ... ) == 0x0 01122 464 NtQueryDefaultUILanguage (1239708, ... 01123 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01124 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 01125 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01126 464 NtClose (-2147482584, ... ) == 0x0 01127 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01128 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01129 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 01130 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01131 464 NtClose (-2147481332, ... ) == 0x0 01132 464 NtClose (-2147482584, ... ) == 0x0 01122 464 NtQueryDefaultUILanguage ... ) == 0x0 01133 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1, 96, ... 76, {status=0x0, info=1}, ) }, 1, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01134 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 76, ... 80, ) == 0x0 01135 464 NtMapViewOfSection (80, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x9a0000), 0x0, 8462336, ) == 0x0 01136 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01137 464 NtQueryDefaultLocale (1, 1237804, ... ) == 0x0 01138 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll.124.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01139 464 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 1238840, 1179817, 1238564} (24, {128, 156, new_msg, 0, 2088850039, 1238840, 1179817, 1238564} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0@ \275\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\353\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57975, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0@ \275\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\353\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 1036, 464, 57975, 0} (24, {128, 156, new_msg, 0, 2088850039, 1238840, 1179817, 1238564} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0@ \275\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\353\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57975, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1L\0\0\0\377\377\377\377\0\0\0\0@ \275\0\0\0\0\0\236\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0,\353\22\0\0\0\0\0" ) ) == 0x0 01140 464 NtClose (76, ... ) == 0x0 01141 464 NtClose (80, ... ) == 0x0 01142 464 NtUnmapViewOfSection (-1, 0x9a0000, ... ) == 0x0 01143 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01144 464 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01145 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01146 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01147 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1236996, ... ) }, 1236996, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01148 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01149 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01150 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01151 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 1237060, ... ) }, 1237060, ... ) == 0x0 01152 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 3, 33, ... 80, {status=0x0, info=1}, ) }, 3, 33, ... 80, {status=0x0, info=1}, ) == 0x0 01153 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01154 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll"}, 5, 96, ... 76, {status=0x0, info=1}, ) }, 5, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01155 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 76, ... 84, ) == 0x0 01156 464 NtClose (76, ... ) == 0x0 01157 464 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x9a0000), 0x0, 1056768, ) == 0x0 01158 464 NtClose (84, ... ) == 0x0 01159 464 NtUnmapViewOfSection (-1, 0x9a0000, ... ) == 0x0 01160 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll"}, 5, 96, ... 84, {status=0x0, info=1}, ) }, 5, 96, ... 84, {status=0x0, info=1}, ) == 0x0 01161 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 84, ... 76, ) == 0x0 01162 464 NtQuerySection (76, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01163 464 NtClose (84, ... ) == 0x0 01164 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x773d0000), 0x0, 1060864, ) == 0x0 01165 464 NtClose (76, ... ) == 0x0 01166 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01167 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01168 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01169 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01170 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01171 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01172 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01173 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01174 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01175 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01176 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01177 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01178 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01179 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01180 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01181 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01182 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01183 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01184 464 NtProtectVirtualMemory (-1, (0x773d1000), 1924, 4, ... (0x773d1000), 4096, 32, ) == 0x0 01185 464 NtProtectVirtualMemory (-1, (0x773d1000), 4096, 32, ... (0x773d1000), 4096, 4, ) == 0x0 01186 464 NtFlushInstructionCache (-1, 2000490496, 1924, ... ) == 0x0 01187 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01188 464 NtAddAtom ( ("T\0h\0e\0m\0e\0P\0r\0o\0p\0S\0c\0r\0o\0l\0l\0B\0a\0r\0C\0t\0l\0", 42, 1238540, ... ) , 42, 1238540, ... ) == 0x0 01189 464 NtQueryDefaultUILanguage (1237224, ... 01190 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01191 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 01192 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01193 464 NtClose (-2147482584, ... ) == 0x0 01194 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01195 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01196 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 01197 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01198 464 NtClose (-2147481332, ... ) == 0x0 01199 464 NtClose (-2147482584, ... ) == 0x0 01189 464 NtQueryDefaultUILanguage ... ) == 0x0 01200 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1236064, ... ) }, 1236064, ... ) == 0x0 01201 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 5, 96, ... 76, {status=0x0, info=1}, ) }, 5, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01202 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 76, ... 84, ) == 0x0 01203 464 NtClose (76, ... ) == 0x0 01204 464 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x900000), 0x0, 4096, ) == 0x0 01205 464 NtClose (84, ... ) == 0x0 01206 464 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 01207 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1235660, ... ) }, 1235660, ... ) == 0x0 01208 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1236404, (0x80100080, {24, 0, 0x40, 0, 1236404, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 0x0, 0, 5, 1, 96, 0, 0, ... 84, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 84, {status=0x0, info=1}, ) == 0x0 01209 464 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 84, ... 76, ) == 0x0 01210 464 NtClose (84, ... ) == 0x0 01211 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0x900000), {0, 0}, 4096, ) == 0x0 01212 464 NtClose (76, ... ) == 0x0 01213 464 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 01214 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Manifest"}, 1, 96, ... 76, {status=0x0, info=1}, ) }, 1, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01215 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 76, ... 84, ) == 0x0 01216 464 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 2, ... (0x900000), 0x0, 4096, ) == 0x0 01217 464 NtQueryInformationFile (76, 1236056, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 01218 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WindowsShell.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01219 464 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 1236356, 1179817, 1236080} (24, {128, 156, new_msg, 0, 2088850039, 1236356, 1179817, 1236080} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1L\0\0\0T\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\341\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57976, 0} "\260d\27\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1L\0\0\0T\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\341\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 1036, 464, 57976, 0} (24, {128, 156, new_msg, 0, 2088850039, 1236356, 1179817, 1236080} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1L\0\0\0T\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\341\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57976, 0} "\260d\27\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\3\0@\0D\0\250\6\31\1L\0\0\0T\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\355\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\26\0\30\0\354\6\31\1\0\0\0\0\0\0\0\0x\341\22\0\0\0\0\0" ) ) == 0x0 01220 464 NtClose (76, ... ) == 0x0 01221 464 NtClose (84, ... ) == 0x0 01222 464 NtUnmapViewOfSection (-1, 0x900000, ... ) == 0x0 01223 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01224 464 NtUserRegisterWindowMessage ( ("ShellGetDragImage", ... ) , ... ) == 0xc03a 01225 464 NtUserSystemParametersInfo (104, 0, 2001084812, 0, ... ) == 0x1 01226 464 NtUserGetDC (0, ... ) == 0x1010051 01227 464 NtUserCallOneParam (16842833, 57, ... ) == 0x1 01228 464 NtUserSystemParametersInfo (38, 4, 2001086940, 0, ... ) == 0x1 01229 464 NtAllocateVirtualMemory (-1, 1400832, 0, 4096, 4096, 4, ... 1400832, 4096, ) == 0x0 01230 464 NtUserSystemParametersInfo (66, 12, 1238056, 0, ... ) == 0x1 01231 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01232 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 84, ) == 0x0 01233 464 NtQueryInformationToken (84, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01234 464 NtClose (84, ... ) == 0x0 01235 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 84, ) }, ... 84, ) == 0x0 01236 464 NtOpenProcessToken (-1, 0x8, ... 76, ) == 0x0 01237 464 NtAccessCheck (1396112, 76, 0x1, 1237888, 1237940, 56, 1237920, ... ) == STATUS_NO_IMPERSONATION_TOKEN 01238 464 NtClose (76, ... ) == 0x0 01239 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Control Panel\Desktop"}, ... 76, ) }, ... 76, ) == 0x0 01240 464 NtQueryValueKey (76, (76, "SmoothScroll", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01241 464 NtClose (76, ... ) == 0x0 01242 464 NtUserSystemParametersInfo (41, 500, 1238084, 0, ... ) == 0x1 01243 464 NtOpenProcessToken (-1, 0x8, ... 76, ) == 0x0 01244 464 NtAccessCheck (1396112, 76, 0x1, 1237888, 1237940, 56, 1237920, ... ) == STATUS_NO_IMPERSONATION_TOKEN 01245 464 NtClose (76, ... ) == 0x0 01246 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"}, ... 76, ) }, ... 76, ) == 0x0 01247 464 NtQueryValueKey (76, (76, "EnableBalloonTips", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01248 464 NtClose (76, ... ) == 0x0 01249 464 NtUserSystemParametersInfo (27, 0, 2001085788, 0, ... ) == 0x1 01250 464 NtUserSystemParametersInfo (102, 0, 2001086828, 0, ... ) == 0x1 01251 464 NtClose (84, ... ) == 0x0 01252 464 NtUserSystemParametersInfo (4130, 0, 1238588, 0, ... ) == 0x1 01253 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\LanguagePack"}, ... 84, ) }, ... 84, ) == 0x0 01254 464 NtEnumerateValueKey (84, 0, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 01255 464 NtClose (84, ... ) == 0x0 01256 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01257 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec03b 01258 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec03d 01259 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01260 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec03f 01261 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01262 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec041 01263 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01264 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec043 01265 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec045 01266 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01267 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec047 01268 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01269 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec049 01270 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01271 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec04b 01272 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01273 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec04d 01274 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01275 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec04f 01276 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec051 01277 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01278 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec053 01279 464 NtUserFindExistingCursorIcon (1237832, 1237848, 1237896, ... ) == 0x10011 01280 464 NtUserRegisterClassExWOW (1237776, 1237844, 1237860, 1237876, 0, 384, 0, ... ) == 0x81aec055 01281 464 NtUserFindExistingCursorIcon (1237832, 1237848, 1237896, ... ) == 0x10011 01282 464 NtUserRegisterClassExWOW (1237776, 1237844, 1237860, 1237876, 0, 384, 0, ... ) == 0x81aec057 01283 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01284 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec059 01285 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10013 01286 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec05b 01287 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01288 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec05d 01289 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01290 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec05f 01291 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01292 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec017 01293 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01294 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec019 01295 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10013 01296 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec018 01297 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01298 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec01a 01299 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01300 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec01c 01301 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01302 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec01e 01303 464 NtUserFindExistingCursorIcon (1237828, 1237844, 1237892, ... ) == 0x10011 01304 464 NtUserRegisterClassExWOW (1237828, 1237896, 1237912, 1237928, 0, 384, 0, ... ) == 0x81aec01b 01305 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01306 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec068 01307 464 NtUserFindExistingCursorIcon (1237836, 1237852, 1237900, ... ) == 0x10011 01308 464 NtUserRegisterClassExWOW (1237780, 1237848, 1237864, 1237880, 0, 384, 0, ... ) == 0x81aec06a 01309 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comdlg32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01310 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ODBC32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01311 464 NtUserRegisterWindowMessage ( ("WOWLFChange", ... ) , ... ) == 0xc06c 01312 464 NtUserRegisterWindowMessage ( ("WOWDirChange", ... ) , ... ) == 0xc06d 01313 464 NtUserRegisterWindowMessage ( ("WOWCHOOSEFONT_GETLOGFONT", ... ) , ... ) == 0xc06e 01314 464 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06f 01315 464 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc070 01316 464 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc071 01317 464 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc072 01318 464 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc073 01319 464 NtUserRegisterWindowMessage ( ("commdlg_LBSelChangedNotify", ... ) , ... ) == 0xc06f 01320 464 NtUserRegisterWindowMessage ( ("commdlg_ShareViolation", ... ) , ... ) == 0xc070 01321 464 NtUserRegisterWindowMessage ( ("commdlg_FileNameOK", ... ) , ... ) == 0xc071 01322 464 NtUserRegisterWindowMessage ( ("commdlg_ColorOK", ... ) , ... ) == 0xc072 01323 464 NtUserRegisterWindowMessage ( ("commdlg_SetRGBColor", ... ) , ... ) == 0xc073 01324 464 NtUserRegisterWindowMessage ( ("Shell IDList Array", ... ) , ... ) == 0xc074 01325 464 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc075 01326 464 NtUserRegisterWindowMessage ( ("commdlg_help", ... ) , ... ) == 0xc075 01327 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\BidInterface\Loader"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01328 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\MDAC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01329 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01330 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01331 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01332 464 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 9568256, 262144, ) == 0x0 01333 464 NtAllocateVirtualMemory (-1, 9568256, 0, 4096, 4096, 4, ... 9568256, 4096, ) == 0x0 01334 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01335 464 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 10092544, 262144, ) == 0x0 01336 464 NtAllocateVirtualMemory (-1, 10092544, 0, 4096, 4096, 4, ... 10092544, 4096, ) == 0x0 01337 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01338 464 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 10354688, 262144, ) == 0x0 01339 464 NtAllocateVirtualMemory (-1, 10354688, 0, 4096, 4096, 4, ... 10354688, 4096, ) == 0x0 01340 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01341 464 NtAllocateVirtualMemory (-1, 0, 0, 262144, 8192, 4, ... 10616832, 262144, ) == 0x0 01342 464 NtAllocateVirtualMemory (-1, 10616832, 0, 4096, 4096, 4, ... 10616832, 4096, ) == 0x0 01343 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01344 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01345 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01346 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01347 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\odbcint.dll"}, 1237748, ... ) }, 1237748, ... ) == 0x0 01348 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\odbcint.dll"}, 5, 96, ... 84, {status=0x0, info=1}, ) }, 5, 96, ... 84, {status=0x0, info=1}, ) == 0x0 01349 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 84, ... 76, ) == 0x0 01350 464 NtClose (84, ... ) == 0x0 01351 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0x960000), 0x0, 94208, ) == 0x0 01352 464 NtClose (76, ... ) == 0x0 01353 464 NtUnmapViewOfSection (-1, 0x960000, ... ) == 0x0 01354 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\odbcint.dll"}, 1238056, ... ) }, 1238056, ... ) == 0x0 01355 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\odbcint.dll"}, 5, 96, ... 76, {status=0x0, info=1}, ) }, 5, 96, ... 76, {status=0x0, info=1}, ) == 0x0 01356 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 76, ... 84, ) == 0x0 01357 464 NtQuerySection (84, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01358 464 NtClose (76, ... ) == 0x0 01359 464 NtMapViewOfSection (84, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x20000000), 0x0, 94208, ) == 0x0 01360 464 NtClose (84, ... ) == 0x0 01361 464 NtQueryDefaultLocale (1, 1239888, ... ) == 0x0 01362 464 NtAllocateVirtualMemory (-1, 9572352, 0, 4096, 4096, 4, ... 9572352, 4096, ) == 0x0 01363 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE"}, ... 84, ) }, ... 84, ) == 0x0 01364 464 NtClose (84, ... ) == 0x0 01365 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01366 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 84, ) == 0x0 01367 464 NtQueryInformationToken (84, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01368 464 NtClose (84, ... ) == 0x0 01369 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 84, ) }, ... 84, ) == 0x0 01370 464 NtSetInformationObject (84, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 01371 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01372 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01373 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01374 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\ODBC\ODBC.INI\ODBC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01375 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odbcint.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01376 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WININET.dll"}, ... 76, ) }, ... 76, ) == 0x0 01377 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x42c10000), 0x0, 847872, ) == 0x0 01378 464 NtClose (76, ... ) == 0x0 01379 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01380 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01381 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01382 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01383 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01384 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01385 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01386 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01387 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01388 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01389 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01390 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01391 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01392 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01393 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01394 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01395 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01396 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01397 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "Normaliz.dll"}, ... 76, ) }, ... 76, ) == 0x0 01398 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x900000), 0x0, 36864, ) == STATUS_IMAGE_NOT_AT_BASE 01399 464 NtProtectVirtualMemory (-1, (0x901000), 18944, 4, ... (0x901000), 20480, 32, ) == 0x0 01400 464 NtProtectVirtualMemory (-1, (0x907000), 1024, 4, ... (0x907000), 4096, 2, ) == 0x0 01401 464 NtProtectVirtualMemory (-1, (0x908000), 1536, 4, ... (0x908000), 4096, 2, ) == 0x0 01402 464 NtMapViewOfSection (76, -1, (0x900000), 0, 0, 0x0, 36864, 1, 0, 4, ... ) == STATUS_CONFLICTING_ADDRESSES 01403 464 NtProtectVirtualMemory (-1, (0x901000), 18944, 16, ... (0x901000), 20480, 4, ) == 0x0 01404 464 NtProtectVirtualMemory (-1, (0x907000), 1024, 2, ... (0x907000), 4096, 8, ) == 0x0 01405 464 NtProtectVirtualMemory (-1, (0x908000), 1536, 2, ... (0x908000), 4096, 8, ) == 0x0 01406 464 NtFlushInstructionCache (-1, 0, 0, ... ) == 0x0 01407 464 NtClose (76, ... ) == 0x0 01408 464 NtProtectVirtualMemory (-1, (0x901000), 160, 4, ... (0x901000), 4096, 16, ) == 0x0 01409 464 NtProtectVirtualMemory (-1, (0x901000), 4096, 16, ... (0x901000), 4096, 4, ) == 0x0 01410 464 NtFlushInstructionCache (-1, 9441280, 160, ... ) == 0x0 01411 464 NtProtectVirtualMemory (-1, (0x901000), 160, 4, ... (0x901000), 4096, 16, ) == 0x0 01412 464 NtProtectVirtualMemory (-1, (0x901000), 4096, 16, ... (0x901000), 4096, 4, ) == 0x0 01413 464 NtFlushInstructionCache (-1, 9441280, 160, ... ) == 0x0 01414 464 NtProtectVirtualMemory (-1, (0x901000), 160, 4, ... (0x901000), 4096, 16, ) == 0x0 01415 464 NtProtectVirtualMemory (-1, (0x901000), 4096, 16, ... (0x901000), 4096, 4, ) == 0x0 01416 464 NtFlushInstructionCache (-1, 9441280, 160, ... ) == 0x0 01417 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01418 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01419 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01420 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "iertutil.dll"}, ... 76, ) }, ... 76, ) == 0x0 01421 464 NtMapViewOfSection (76, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x42990000), 0x0, 282624, ) == 0x0 01422 464 NtClose (76, ... ) == 0x0 01423 464 NtProtectVirtualMemory (-1, (0x42991000), 616, 4, ... (0x42991000), 4096, 32, ) == 0x0 01424 464 NtProtectVirtualMemory (-1, (0x42991000), 4096, 32, ... (0x42991000), 4096, 4, ) == 0x0 01425 464 NtFlushInstructionCache (-1, 1117327360, 616, ... ) == 0x0 01426 464 NtProtectVirtualMemory (-1, (0x42991000), 616, 4, ... (0x42991000), 4096, 32, ) == 0x0 01427 464 NtProtectVirtualMemory (-1, (0x42991000), 4096, 32, ... (0x42991000), 4096, 4, ) == 0x0 01428 464 NtFlushInstructionCache (-1, 1117327360, 616, ... ) == 0x0 01429 464 NtProtectVirtualMemory (-1, (0x42991000), 616, 4, ... (0x42991000), 4096, 32, ) == 0x0 01430 464 NtProtectVirtualMemory (-1, (0x42991000), 4096, 32, ... (0x42991000), 4096, 4, ) == 0x0 01431 464 NtFlushInstructionCache (-1, 1117327360, 616, ... ) == 0x0 01432 464 NtProtectVirtualMemory (-1, (0x42991000), 616, 4, ... (0x42991000), 4096, 32, ) == 0x0 01433 464 NtProtectVirtualMemory (-1, (0x42991000), 4096, 32, ... (0x42991000), 4096, 4, ) == 0x0 01434 464 NtFlushInstructionCache (-1, 1117327360, 616, ... ) == 0x0 01435 464 NtProtectVirtualMemory (-1, (0x42991000), 616, 4, ... (0x42991000), 4096, 32, ) == 0x0 01436 464 NtProtectVirtualMemory (-1, (0x42991000), 4096, 32, ... (0x42991000), 4096, 4, ) == 0x0 01437 464 NtFlushInstructionCache (-1, 1117327360, 616, ... ) == 0x0 01438 464 NtProtectVirtualMemory (-1, (0x42991000), 616, 4, ... (0x42991000), 4096, 32, ) == 0x0 01439 464 NtProtectVirtualMemory (-1, (0x42991000), 4096, 32, ... (0x42991000), 4096, 4, ) == 0x0 01440 464 NtFlushInstructionCache (-1, 1117327360, 616, ... ) == 0x0 01441 464 NtProtectVirtualMemory (-1, (0x42c11000), 1452, 4, ... (0x42c11000), 4096, 32, ) == 0x0 01442 464 NtProtectVirtualMemory (-1, (0x42c11000), 4096, 32, ... (0x42c11000), 4096, 4, ) == 0x0 01443 464 NtFlushInstructionCache (-1, 1119948800, 1452, ... ) == 0x0 01444 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Normaliz.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01445 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iertutil.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01446 464 NtQueryPerformanceCounter (... {935690655, 10}, {3579545, 0}, ) == 0x0 01447 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WININET.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01448 464 NtQueryPerformanceCounter (... {935692046, 10}, {3579545, 0}, ) == 0x0 01449 464 NtAllocateVirtualMemory (-1, 1404928, 0, 8192, 4096, 4, ... 1404928, 8192, ) == 0x0 01450 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01451 464 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 10878976, 1048576, ) == 0x0 01452 464 NtAllocateVirtualMemory (-1, 10878976, 0, 4096, 4096, 4, ... 10878976, 4096, ) == 0x0 01453 464 NtAllocateVirtualMemory (-1, 10883072, 0, 8192, 4096, 4, ... 10883072, 8192, ) == 0x0 01454 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 76, ) == 0x0 01455 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1240816, (0xc0100080, {24, 0, 0x40, 0, 1240816, "\??\WMIDataDevice"}, 0x0, 128, 0, 1, 64, 0, 0, ... 88, {status=0x0, info=0}, ) }, 0x0, 128, 0, 1, 64, 0, 0, ... 88, {status=0x0, info=0}, ) == 0x0 01456 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 92, ) == 0x0 01457 464 NtDeviceIoControlFile (88, 92, 0x0, 0x12ef50, 0x22414c, (88, 92, 0x0, 0x12ef50, 0x22414c, "\230\357\22\0\0\0\0\0\1\0\0\0\2\0\0\0\24\0\0\0\34\0\0\0P\0\0\0\0\0\0\0L\0\0\0\0\0\0\0\2\0\0\0U\4\376\14\272\223\15D\243\376U9s\320\267#\0\20\10\0\0\0\0\0\0\0\0\0U\4\376\14\272\223\15D\243\376U9s\320\267#\0\0\10\0\0\0\0\0\0\0\0\0\2\0\0\0", 104, 80, ... , 104, 80, ... 01458 464 NtOpenKey (0x82000000, {24, 0, 0x240, 0, 0, (0x82000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\WMI\Security"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01459 464 NtQueryValueKey (-2147482584, (-2147482584, "DF8480A1-7492-4F45-AB78-1084642581FB", Full, 130, ... ) , Full, 130, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01460 464 NtQueryValueKey (-2147482584, (-2147482584, "00000000-0000-0000-0000-000000000000", Full, 130, ... ) , Full, 130, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01461 464 NtClose (-2147482584, ... ) == 0x0 01462 464 NtClose (1064, ... ) == 0x0 01457 464 NtDeviceIoControlFile ... {status=0x0, info=80}, ... {status=0x0, info=80}, "\220\272<\342\0\0\0\0U\4\376\14\272\223\15D\243\376U9s\320\267#8\0s\0p\0\0\0\0\0\0\0\0\0\0\0\2\0\0\0U\4\376\14\272\223\15D\243\376U9s\320\267#\0\20\10\0`\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 01463 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1241032, (0xc0100080, {24, 0, 0x40, 0, 1241032, "\??\WMIDataDevice"}, 0x0, 128, 0, 1, 64, 0, 0, ... 100, {status=0x0, info=0}, ) }, 0x0, 128, 0, 1, 64, 0, 0, ... 100, {status=0x0, info=0}, ) == 0x0 01464 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 104, ) == 0x0 01465 464 NtDuplicateObject (-1, -1, -1, 0x0, 0, 2, ... 108, ) == 0x0 01466 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 112, ) == 0x0 01467 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 116, ) == 0x0 01468 464 NtAllocateVirtualMemory (-1, 10891264, 0, 8192, 4096, 4, ... 10891264, 8192, ) == 0x0 01469 464 NtAllocateVirtualMemory (-1, 0, 0, 1048576, 8192, 4, ... 11927552, 1048576, ) == 0x0 01470 464 NtAllocateVirtualMemory (-1, 12967936, 0, 8192, 4096, 4, ... 12967936, 8192, ) == 0x0 01471 464 NtProtectVirtualMemory (-1, (0xc5e000), 4096, 260, ... (0xc5e000), 4096, 4, ) == 0x0 01472 464 NtCreateThread (0x1f03ff, 0x0, -1, 1240116, 1240060, 1, ... 120, {1036, 1292}, ) == 0x0 01473 464 NtQueryInformationThread (120, Basic, 28, ... {ExitStatus=0x103,TebBaseAddress=0x7ffdc000,Pid=1036,Tid=1292,}, 0x0, ) == 0x0 01474 464 NtRequestWaitReplyPort (24, {28, 56, new_msg, 0, 0, 0, 0, 10879352} (24, {28, 56, new_msg, 0, 0, 0, 0, 10879352} "\0\0\0\0\1\0\1\0\0\0\0\0(\2\0\0x\0\0\0\14\4\0\0\14\5\0\0" ... {28, 56, reply, 0, 1036, 464, 57977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0(\2\0\0x\0\0\0\14\4\0\0\14\5\0\0" ) ... {28, 56, reply, 0, 1036, 464, 57977, 0} (24, {28, 56, new_msg, 0, 0, 0, 0, 10879352} "\0\0\0\0\1\0\1\0\0\0\0\0(\2\0\0x\0\0\0\14\4\0\0\14\5\0\0" ... {28, 56, reply, 0, 1036, 464, 57977, 0} "\0\0\0\0\1\0\1\0\0\0\0\0(\2\0\0x\0\0\0\14\4\0\0\14\5\0\0" ) ) == 0x0 01475 464 NtResumeThread (120, ... 1, ) == 0x0 01476 464 NtClose (120, ... ) == 0x0 01477 464 NtSetEvent (104, ... 0x0, ) == 0x0 01478 464 NtSetEvent (76, ... 01479 1292 NtCreateEvent (0x100003, 0x0, 1, 0, ... 120, ) == 0x0 01480 1292 NtWaitForSingleObject (120, 0, 0x0, ... 01478 464 NtSetEvent ... 0x0, ) == 0x0 01481 464 NtClose (76, ... ) == 0x0 01482 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 76, ) == 0x0 01483 464 NtAllocateVirtualMemory (-1, 10899456, 0, 4096, 4096, 4, ... 10899456, 4096, ) == 0x0 01484 464 NtDeviceIoControlFile (88, 92, 0x0, 0x12ef50, 0x22414c, (88, 92, 0x0, 0x12ef50, 0x22414c, "\230\357\22\0\0\0\0\0\2\0\0\0\2\0\0\0\24\0\0\0\34\0\0\0P\0\0\0\0\0\0\0L\0\0\0\0\0\0\0\2\0\0\0\254\253\177yX{\226G\271$\325\21x\245\234\344\0\20\10\0\0\0\0\0\0\0\0\0\254\253\177yX{\226G\271$\325\21x\245\234\344\0\0\10\0\0\0\0\0\0\0\0\0\2\0\0\0", 104, 80, ... , 104, 80, ... 01485 464 NtOpenKey (0x82000000, {24, 0, 0x240, 0, 0, (0x82000000, {24, 0, 0x240, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\WMI\Security"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01486 464 NtQueryValueKey (-2147482584, (-2147482584, "DF8480A1-7492-4F45-AB78-1084642581FB", Full, 130, ... ) , Full, 130, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01487 464 NtQueryValueKey (-2147482584, (-2147482584, "00000000-0000-0000-0000-000000000000", Full, 130, ... ) , Full, 130, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01488 464 NtClose (-2147482584, ... ) == 0x0 01489 464 NtClose (1064, ... ) == 0x0 01484 464 NtDeviceIoControlFile ... {status=0x0, info=80}, ... {status=0x0, info=80}, "x\222\357\341\0\0\0\0\254\253\177yX{\226G\271$\325\21x\245\234\34416\4\0 \0\20\0\0\0\0\0\0\0\0\0\2\0\0\0\254\253\177yX{\226G\271$\325\21x\245\234\344\0\20\10\0|\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 01490 464 NtSetEvent (104, ... 0x0, ) == 0x0 01491 464 NtSetEvent (76, ... 0x0, ) == 0x0 01492 464 NtClose (76, ... ) == 0x0 01493 464 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 01494 464 NtOpenProcessToken (-1, 0xa, ... 76, ) == 0x0 01495 464 NtDuplicateToken (76, 0xc, {24, 0, 0x0, 0, 1241300, 0x0}, 0, 2, ... 128, ) == 0x0 01496 464 NtClose (76, ... ) == 0x0 01497 464 NtAccessCheck (1396112, 128, 0x1, 1241376, 1241428, 56, 1241408, ... (0x1), ) == 0x0 01498 464 NtClose (128, ... ) == 0x0 01499 464 NtQueryDefaultUILanguage (1240180, ... 01500 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01501 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 01502 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01503 464 NtClose (-2147482584, ... ) == 0x0 01504 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01505 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01506 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 01507 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01508 464 NtClose (-2147481332, ... ) == 0x0 01509 464 NtClose (-2147482584, ... ) == 0x0 01499 464 NtQueryDefaultUILanguage ... ) == 0x0 01510 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01511 464 NtQueryDefaultLocale (1, 1238276, ... ) == 0x0 01512 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WININET.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01513 464 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 1239312, 1179817, 1239036} (24, {128, 156, new_msg, 0, 2088850039, 1239312, 1179817, 1239036} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0PR\313B\0\0\0\0\370\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\4\355\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57978, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0PR\313B\0\0\0\0\370\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\4\355\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 1036, 464, 57978, 0} (24, {128, 156, new_msg, 0, 2088850039, 1239312, 1179817, 1239036} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0PR\313B\0\0\0\0\370\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\4\355\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57978, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0>\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0PR\313B\0\0\0\0\370\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0\4\355\22\0\0\0\0\0" ) ) == 0x0 01514 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01515 464 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01516 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01517 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01518 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1237504, ... ) }, 1237504, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01519 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01520 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01521 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01522 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 1237568, ... ) }, 1237568, ... ) == 0x0 01523 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 3, 33, ... 128, {status=0x0, info=1}, ) }, 3, 33, ... 128, {status=0x0, info=1}, ) == 0x0 01524 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 01525 464 NtCreateKey (0x2001f, {24, 84, 0x40, 0, 0, (0x2001f, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, 0, 0x0, 0, ... 76, 2, ) }, 0, 0x0, 0, ... 76, 2, ) == 0x0 01526 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2_32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01527 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2_32.dll"}, 1241376, ... ) }, 1241376, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01528 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2_32.dll"}, 1241376, ... ) }, 1241376, ... ) == 0x0 01529 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2_32.dll"}, 5, 96, ... 132, {status=0x0, info=1}, ) }, 5, 96, ... 132, {status=0x0, info=1}, ) == 0x0 01530 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 132, ... 136, ) == 0x0 01531 464 NtQuerySection (136, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01532 464 NtClose (132, ... ) == 0x0 01533 464 NtMapViewOfSection (136, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71ab0000), 0x0, 94208, ) == 0x0 01534 464 NtClose (136, ... ) == 0x0 01535 464 NtProtectVirtualMemory (-1, (0x71ab1000), 468, 4, ... (0x71ab1000), 4096, 32, ) == 0x0 01536 464 NtProtectVirtualMemory (-1, (0x71ab1000), 4096, 32, ... (0x71ab1000), 4096, 4, ) == 0x0 01537 464 NtFlushInstructionCache (-1, 1907036160, 468, ... ) == 0x0 01538 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01539 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\WS2HELP.dll"}, 1240560, ... ) }, 1240560, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01540 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2HELP.dll"}, 1240560, ... ) }, 1240560, ... ) == 0x0 01541 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\WS2HELP.dll"}, 5, 96, ... 136, {status=0x0, info=1}, ) }, 5, 96, ... 136, {status=0x0, info=1}, ) == 0x0 01542 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 136, ... 132, ) == 0x0 01543 464 NtQuerySection (132, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01544 464 NtClose (136, ... ) == 0x0 01545 464 NtMapViewOfSection (132, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x71aa0000), 0x0, 32768, ) == 0x0 01546 464 NtClose (132, ... ) == 0x0 01547 464 NtProtectVirtualMemory (-1, (0x71aa1000), 352, 4, ... (0x71aa1000), 4096, 32, ) == 0x0 01548 464 NtProtectVirtualMemory (-1, (0x71aa1000), 4096, 32, ... (0x71aa1000), 4096, 4, ) == 0x0 01549 464 NtFlushInstructionCache (-1, 1906970624, 352, ... ) == 0x0 01550 464 NtProtectVirtualMemory (-1, (0x71ab1000), 468, 4, ... (0x71ab1000), 4096, 32, ) == 0x0 01551 464 NtProtectVirtualMemory (-1, (0x71ab1000), 4096, 32, ... (0x71ab1000), 4096, 4, ) == 0x0 01552 464 NtFlushInstructionCache (-1, 1907036160, 468, ... ) == 0x0 01553 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2HELP.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01554 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2_32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01555 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01556 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01557 464 NtSetEventBoostPriority (120, ... 01480 1292 NtWaitForSingleObject ... ) == 0x0 01558 1292 NtTestAlert (... ) == 0x0 01559 1292 NtContinue (12975408, 1, ... 01560 1292 NtRegisterThreadTerminatePort (24, ... ) == 0x0 01561 1292 NtDeviceIoControlFile (100, 112, 0x0, 0x77e466a0, 0x228144, (100, 112, 0x0, 0x77e466a0, 0x228144, "\2\0\0\0\1\0\0\0\\370\342w\0\0\0\0l\0\0\0\0\0\0\0|\0\0\0\0\0\0\0`\0\0\0\0\0\0\0", 40, 4096, ... , 40, 4096, ... 01557 464 NtSetEventBoostPriority ... ) == 0x0 01562 464 NtTestAlert (... ) == 0x0 01563 464 NtContinue (1244464, 1, ... 01564 464 NtSetInformationThread (-2, Win32StartAddress(LpcReceivedMessageId), {StartAddress(LpcReceivedMsgId)=0x48cdd3,}, 4, ... ) == 0x0 01565 464 NtQueryPerformanceCounter (... {935845233, 10}, {3579545, 0}, ) == 0x0 01561 1292 NtDeviceIoControlFile ... {status=0x103, info=0}, "", ) == 0x103 01566 1292 NtWaitForMultipleObjects (2, (104, 112, ), 1, 1, {1294967296, -1}, ... ) == 0x0 01567 1292 NtDeviceIoControlFile (100, 116, 0x0, 0x77e46680, 0x228144, (100, 116, 0x0, 0x77e46680, 0x228144, "\2\0\0\0\1\0\0\0\\370\342w\0\0\0\0l\0\0\0\0\0\0\0|\0\0\0\0\0\0\0`\0\0\0\0\0\0\0", 40, 4096, ... {status=0x103, info=0}, "", ) , 40, 4096, ... {status=0x103, info=0}, "", ) == 0x103 01568 1292 NtWaitForMultipleObjects (2, (104, 116, ), 1, 1, {1294967296, -1}, ... 01569 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01570 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 4, ... 9895936, 65536, ) == 0x0 01571 464 NtAllocateVirtualMemory (-1, 9895936, 0, 4096, 4096, 4, ... 9895936, 4096, ) == 0x0 01572 464 NtAllocateVirtualMemory (-1, 9900032, 0, 8192, 4096, 4, ... 9900032, 8192, ) == 0x0 01573 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01574 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01575 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01576 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01577 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01578 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01579 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01580 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01581 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01582 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01583 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01584 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01585 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01586 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01587 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01588 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01589 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01590 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01591 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01592 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01593 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01594 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01595 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01596 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01597 464 NtAllocateVirtualMemory (-1, 9908224, 0, 4096, 4096, 4, ... 9908224, 4096, ) == 0x0 01598 464 NtAllocateVirtualMemory (-1, 9912320, 0, 4096, 4096, 4, ... 9912320, 4096, ) == 0x0 01599 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01600 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01601 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01602 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01603 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01604 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01605 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01606 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01607 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01608 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01609 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01610 464 NtQueryVirtualMemory (-1, 0x40b4cd, Basic, 28, ... {BaseAddress=0x40b000,AllocationBase=0x400000,AllocationProtect=0x80,RegionSize=0x18000,State=0x1000,Protect=0x40,Type=0x1000000,}, 28, ) == 0x0 01611 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01612 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01613 464 NtQueryVirtualMemory (-1, 0x77c2807c, Basic, 28, ... {BaseAddress=0x77c28000,AllocationBase=0x77c10000,AllocationProtect=0x80,RegionSize=0x35000,State=0x1000,Protect=0x20,Type=0x1000000,}, 28, ) == 0x0 01614 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01615 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01616 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01617 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01618 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01619 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01620 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01621 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01622 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01623 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01624 464 NtAllocateVirtualMemory (-1, 9916416, 0, 4096, 4096, 4, ... 9916416, 4096, ) == 0x0 01625 464 NtAllocateVirtualMemory (-1, 0, 0, 6, 12288, 64, ... 9961472, 4096, ) == 0x0 01626 464 NtProtectVirtualMemory (-1, (0x980000), 6, 64, ... 01627 464 NtContinue (-106647612, 0, ... 01626 464 NtProtectVirtualMemory ... ) == STATUS_ACCESS_VIOLATION 01628 464 NtFreeVirtualMemory (-1, (0x980000), 0, 32768, ... (0x980000), 4096, ) == 0x0 01629 464 NtCreateKey (0xf003f, {24, 28, 0x40, 0, 0, (0xf003f, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Run"}, 0, 0x0, 0, ... 132, 2, ) }, 0, 0x0, 0, ... 132, 2, ) == 0x0 01630 464 NtDeleteValueKey (132, (132, "Win32 Information Service", ... ) , ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01631 464 NtClose (132, ... ) == 0x0 01632 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01633 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01634 464 NtQueryInformationProcess (-1, 36, 4, ... {process info, class 36, size 4}, 0x0, ) == 0x0 01635 464 NtCreateFile (0x40100080, {24, 0, 0x42, 0, 1241344, (0x40100080, {24, 0, 0x42, 0, 1241344, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 0x0, 128, 3, 5, 96, 0, 0, ... }, 0x0, 128, 3, 5, 96, 0, 0, ... 01636 464 NtClose (-2147482584, ... ) == 0x0 01635 464 NtCreateFile ... 132, {status=0x0, info=2}, ) == 0x0 01637 464 NtQueryVolumeInformationFile (132, 1241448, 8, Device, ... {status=0x0, info=8}, ) == 0x0 01638 464 NtAllocateVirtualMemory (-1, 9920512, 0, 8192, 4096, 4, ... 9920512, 8192, ) == 0x0 01639 464 NtWriteFile (132, 0, 0, 0, (132, 0, 0, 0, "@echo off\15\15\12:1\15\15\12del "u:\work\packed.exe"\15\15\12if exist "u:\work\packed.exe" goto 1\15\15\12del "%0"\15\15\12", 94, 0x0, 0, ... {status=0x0, info=94}, ) u:\work\packed.exe (132, 0, 0, 0, "@echo off\15\15\12:1\15\15\12del "u:\work\packed.exe"\15\15\12if exist "u:\work\packed.exe" goto 1\15\15\12del "%0"\15\15\12", 94, 0x0, 0, ... {status=0x0, info=94}, ) u:\work\packed.exe (132, 0, 0, 0, "@echo off\15\15\12:1\15\15\12del "u:\work\packed.exe"\15\15\12if exist "u:\work\packed.exe" goto 1\15\15\12del "%0"\15\15\12", 94, 0x0, 0, ... {status=0x0, info=94}, ) %0 (132, 0, 0, 0, "@echo off\15\15\12:1\15\15\12del "u:\work\packed.exe"\15\15\12if exist "u:\work\packed.exe" goto 1\15\15\12del "%0"\15\15\12", 94, 0x0, 0, ... {status=0x0, info=94}, ) , 94, 0x0, 0, ... {status=0x0, info=94}, ) == 0x0 01640 464 NtClose (132, ... ) == 0x0 01641 464 NtOpenKey (0x9, {24, 28, 0x40, 0, 0, (0x9, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01642 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "ole32.dll"}, ... 132, ) }, ... 132, ) == 0x0 01643 464 NtMapViewOfSection (132, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x774e0000), 0x0, 1298432, ) == 0x0 01644 464 NtClose (132, ... ) == 0x0 01645 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01646 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01647 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01648 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01649 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01650 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01651 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01652 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01653 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01654 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01655 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01656 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01657 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01658 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01659 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01660 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01661 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01662 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01663 464 NtProtectVirtualMemory (-1, (0x774e1000), 2352, 4, ... (0x774e1000), 4096, 32, ) == 0x0 01664 464 NtProtectVirtualMemory (-1, (0x774e1000), 4096, 32, ... (0x774e1000), 4096, 4, ) == 0x0 01665 464 NtFlushInstructionCache (-1, 2001604608, 2352, ... ) == 0x0 01666 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01667 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\Device\KsecDD"}, 7, 16, ... 132, {status=0x0, info=0}, ) }, 7, 16, ... 132, {status=0x0, info=0}, ) == 0x0 01668 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270CACA\307\3063X\345\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01669 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01670 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01671 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01672 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01673 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01674 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01675 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01676 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01677 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "\334\302y\256"r\10Xb~\360\367\2736r\313\270@v\200\211T\331\347U", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "\334\302y\256"r\10Xb~\360\367\2736r\313\270@v\200\211T\331\347U", 80, ... ) r\10Xb~\360\367\2736r\313\270@v\200\211T\331\347U", 80, ... ) == 0x0 01678 464 NtClose (-2147482584, ... ) == 0x0 01668 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\363\70\22X\346,\332\330\316\262\312\327\335\204\30\265\34pT\264\241\363\325\221c\246\23\327\336\372X\200\237\314\317X\334J\2\214\225?\37\334\204\256\276\204I;\6\260jB+\30.n\224\215\34\35\2719\345\242\236*\20073YU\2077\273`\35\224'&\300\252\341\242s\374[\6\346\10x:\335\376'\26\210\27\2126\362\13\223\3122p\327\251\260\177\240\360H\37+gNL\36C\25-\215b\303\332\4\330\217q\334\376\255\200R\223EKq\336[&\214\255\266-+\244\20!xf\35_j\252\303\261\324\267\276\252\256\30\364\2d7\347\360-\273i\305\25J\343z\3175RW\210\355\21\345\212\345\264\3232\202\270\16\317z\211\13\21\274\345u\353C\2723:\224(T\317,f\30Z\210\13\324\342\257n9*z\362+\253\311\331\344\20\215p\316\215\377d@\335\4>jp\300\372\301c\207\203\252\303\363", ) , ) == 0x0 01679 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01680 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01681 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\Session Manager"}, ... 136, ) }, ... 136, ) == 0x0 01682 464 NtQueryValueKey (136, (136, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (136, "CriticalSectionTimeout", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\215'\0"}, 16, ) }, 16, ) == 0x0 01683 464 NtClose (136, ... ) == 0x0 01684 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Ole"}, ... 136, ) }, ... 136, ) == 0x0 01685 464 NtQueryValueKey (136, (136, "RWLockResourceTimeOut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01686 464 NtClose (136, ... ) == 0x0 01687 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01688 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01689 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01690 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 01691 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface"}, ... 136, ) }, ... 136, ) == 0x0 01692 464 NtQueryValueKey (136, (136, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01693 464 NtQueryValueKey (136, (136, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01694 464 NtQueryValueKey (136, (136, "InterfaceHelperDisableTypeLib", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01695 464 NtClose (136, ... ) == 0x0 01696 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Interface\{00020400-0000-0000-C000-000000000046}"}, ... 136, ) }, ... 136, ) == 0x0 01697 464 NtQueryValueKey (136, (136, "InterfaceHelperDisableAll", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01698 464 NtQueryValueKey (136, (136, "InterfaceHelperDisableAllForOle32", Full, 0, ... ) , Full, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01699 464 NtClose (136, ... ) == 0x0 01700 464 NtOpenEvent (0x1f0003, {24, 44, 0x0, 0, 0, (0x1f0003, {24, 44, 0x0, 0, 0, "HookSwitchHookEnabledEvent"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01701 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 1234984, ... ) }, 1234984, ... ) == 0x0 01702 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\rpcss.dll"}, 5, 96, ... 136, {status=0x0, info=1}, ) }, 5, 96, ... 136, {status=0x0, info=1}, ) == 0x0 01703 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 136, ... 140, ) == 0x0 01704 464 NtClose (136, ... ) == 0x0 01705 464 NtMapViewOfSection (140, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xc60000), 0x0, 401408, ) == 0x0 01706 464 NtClose (140, ... ) == 0x0 01707 464 NtUnmapViewOfSection (-1, 0xc60000, ... ) == 0x0 01708 464 NtAllocateVirtualMemory (-1, 1413120, 0, 4096, 4096, 4, ... 1413120, 4096, ) == 0x0 01709 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01710 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01711 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 01712 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265-\31\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01713 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01714 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01715 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01716 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01717 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01718 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01719 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01720 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01721 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "X\214\332\257\305\257[\243I\342\5\203\331C\357i\344p\336%\320\12\320r\227%X\26B\324\14\375\307\214D\265X\332\337\26\217\26\340\20\325\314\262I\237\340\277\177o$\202\357\334\227\1\33\357\33\367\12\375j\231\33\260\265\224\37e9\221p\326\300\361\270", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "X\214\332\257\305\257[\243I\342\5\203\331C\357i\344p\336%\320\12\320r\227%X\26B\324\14\375\307\214D\265X\332\337\26\217\26\340\20\325\314\262I\237\340\277\177o$\202\357\334\227\1\33\357\33\367\12\375j\231\33\260\265\224\37e9\221p\326\300\361\270", 80, ... ) , 80, ... ) == 0x0 01722 464 NtClose (-2147482584, ... ) == 0x0 01712 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\350\247y\271\213yCw\302\32%H\325\36\3246\3735, ) , ) == 0x0 01723 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265\223S e/\364`k@\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01724 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01725 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01726 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01727 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01728 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01729 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01730 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01731 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01732 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "\377\20\360\221\244\372\232\205\367z?\205\274\270(.y/\221`5\241\225]\10\34\301BG\307\217\237\5\344G>\17\261\374JM\367,\4\316\371\236\261&\11\32\3079\351A\275\13\277\265\313%\305\3\35\316\276\304\364Z@\350\31\31[\2\324\37\342'|", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "\377\20\360\221\244\372\232\205\367z?\205\274\270(.y/\221`5\241\225]\10\34\301BG\307\217\237\5\344G>\17\261\374JM\367,\4\316\371\236\261&\11\32\3079\351A\275\13\277\265\313%\305\3\35\316\276\304\364Z@\350\31\31[\2\324\37\342'|", 80, ... ) , 80, ... ) == 0x0 01733 464 NtClose (-2147482584, ... ) == 0x0 01723 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, ".\271Y\276\22;\331\363\30HHFL;\311~\315\262'5w;\260\2066c\12\20L\273\252\370z\326\240\30K\364>e\340|\327\300\69u\301\376\210\303R(\26\360\246U\3>\324\247\240+\227N\372\204c\350N\371\3600\255\257gA \211h\12/x\310\263R\271\265\237\277^\260\1g\350\3N<\302\370\226\226\272U\260\14\216\301\366p\367\306\e3\272\375\353\230\376\364\202\33b\212*X\241\16\234\272\377&\214m\212~1\25\267\262&\37d/\262\363\212\371d\0\2/\6\263?u\203\3018\200\2552\235PHB\354.o`u\360f\212g\321\217\371Z\215-\326\223?\264?\177\275Mh\108~h\26\274\16\323NV\253\337u\271\215\325_d\22}\315\12\22\362/\35\331mdp\6\235\20W", ) \226\272U\260\14\216\301\366p\367\306\e3\272\375\353\230\376\364\202\33b\212*X\241\16\234\272\377&\214m\212~1\25\267\262&\37d/\262\363\212\371d\0\2/\6\263?u\203\3018\200\2552\235PHB\354.o`u\360f\212g\321\217\371Z\215-\326\223?\264?\177\275Mh\108~h\26\274\16\323NV\253\337u\271\215\325_d\22}\315\12\22\362/\35\331mdp\6\235\20W", ) == 0x0 01734 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265\223S e/\364`\325\12 e/\364`k@\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01735 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01736 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01737 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01738 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01739 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01740 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01741 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01742 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01743 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "\350\323\326\27\317\342eR)2\3607\266?\177\321\364\37n\330\361\266\305\242\270\210d\\3777 \3361h\233<\200\204\210_j\233\27\331\237\346\264&\267]\364\256:A\351\344G\203\14$;"hv\376\234\212\5\370\270\361``\373\11>a&\", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "\350\323\326\27\317\342eR)2\3607\266?\177\321\364\37n\330\361\266\305\242\270\210d\\3777 \3361h\233<\200\204\210_j\233\27\331\237\346\264&\267]\364\256:A\351\344G\203\14$;"hv\376\234\212\5\370\270\361``\373\11>a&\", 80, ... ) hv\376\234\212\5\370\270\361``\373\11>a&\", 80, ... ) == 0x0 01744 464 NtClose (-2147482584, ... ) == 0x0 01734 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "B\10p\371\353\39\365\316Y\2227\261\310{\36\1\361\202i\3004\273k\201\203J\225\317g\206\323\345\371\265d\21\37\24\366\310|\2046op\337\223\252\207\315\260|\375\241\342\3603J|\356\207B\366mU\256\324\302\336\276K\336`_\33\26\13\210096\310\374\2y\242\333+\206"\332\322\27574~G\342\273P\332\255\313\275\22\27\320\374\205]\265\4"\27e\362\351\320\356\347\250\347Z3~D\234\316+\211\15\0\245\3450\25\30\375\226l\214\367\242\273Y\312\360R\3352\342\344:C\373\261\314rQb\357M\252\276S\230\215K\5\223\2322\335\204\214\226\237A\364\214_\303\256\27\243"\12Y\246\207\363\266B\237\20\247?l\234\325si\311\223\1\15\210\337e\332\347\361kl\11C\312x\4\304\212\2226\230d).\363\262\371\238\3661\244\240\224>::\213`\326$a\7W\330q\301`Xb\300", ) \332\322\27574~G\342\273P\332\255\313\275\22\27\320\374\205]\265\4 ... {status=0x0, info=256}, "B\10p\371\353\39\365\316Y\2227\261\310{\36\1\361\202i\3004\273k\201\203J\225\317g\206\323\345\371\265d\21\37\24\366\310|\2046op\337\223\252\207\315\260|\375\241\342\3603J|\356\207B\366mU\256\324\302\336\276K\336`_\33\26\13\210096\310\374\2y\242\333+\206"\332\322\27574~G\342\273P\332\255\313\275\22\27\320\374\205]\265\4"\27e\362\351\320\356\347\250\347Z3~D\234\316+\211\15\0\245\3450\25\30\375\226l\214\367\242\273Y\312\360R\3352\342\344:C\373\261\314rQb\357M\252\276S\230\215K\5\223\2322\335\204\214\226\237A\364\214_\303\256\27\243"\12Y\246\207\363\266B\237\20\247?l\234\325si\311\223\1\15\210\337e\332\347\361kl\11C\312x\4\304\212\2226\230d).\363\262\371\238\3661\244\240\224>::\213`\326$a\7W\330q\301`Xb\300", ) \12Y\246\207\363\266B\237\20\247?l\234\325si\311\223\1\15\210\337e\332\347\361kl\11C\312x\4\304\212\2226\230d).\363\262\371\238\3661\244\240\224>::\213`\326$a\7W\330q\301`Xb\300", ) == 0x0 01745 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265\223S e/\364`\325\12 e/\364`\325\12 e/\364`k@\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01746 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01747 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01748 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01749 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01750 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01751 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01752 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01753 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01754 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "v(\3+\372\241S\6q\242\14\227\324\203)W\307\31\223\27\235\247P/\347z\223\31\220\321'\203M\0G\26q,U\222/E1'\273\303\214%\231\353|4\10\3\264b\343\23\300\21p\261\325\327K?\227\240\237D\4\224>h\202\204\364\331[", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "v(\3+\372\241S\6q\242\14\227\324\203)W\307\31\223\27\235\247P/\347z\223\31\220\321'\203M\0G\26q,U\222/E1'\273\303\214%\231\353|4\10\3\264b\343\23\300\21p\261\325\327K?\227\240\237D\4\224>h\202\204\364\331[", 80, ... ) , 80, ... ) == 0x0 01755 464 NtClose (-2147482584, ... ) == 0x0 01745 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\1#\246Z\277,v\31\365\305\330B\20-I[\37\270\0\25\27B\\366QD9?\2249\202\275>D}=\347\237\4\376\302\327\266\272\370H\327C\273$>8\335\\275\27|9p\361\301\222e\256\3q\2228\257\213\21\216\2116*\205\345\266\5\363\360\317\2670\207%`?\20\27=\275\306\23=\242"I\35\323bI\250\360\244\347\314\236O\16=r#\253@\321\211&t3\242\325\311\246\21\310\316\2434(\340\356\376\2\205\244J\331\250.\252\264\335\21P\345IVV\356\320\2\34\262j\261=~\364\212\17\314\35z\345\31\314\230\1\323\375hU\363K\351%\232V'\211)\246\332\235ER\200\245\251l1{\206V\342\14\201\372\254\200\30\330\\270\315C\320Aq>\336\203\261\347\354\37Q\6\H\230\21\301\312Y\354i\277\3002\326\3706\333\226\270s\314\275\274BV\215\21\241\272\210\264b\244\260\2\301\310\223", ) I\35\323bI\250\360\244\347\314\236O\16=r#\253@\321\211&t3\242\325\311\246\21\310\316\2434(\340\356\376\2\205\244J\331\250.\252\264\335\21P\345IVV\356\320\2\34\262j\261=~\364\212\17\314\35z\345\31\314\230\1\323\375hU\363K\351%\232V'\211)\246\332\235ER\200\245\251l1{\206V\342\14\201\372\254\200\30\330\\270\315C\320Aq>\336\203\261\347\354\37Q\6\H\230\21\301\312Y\354i\277\3002\326\3706\333\226\270s\314\275\274BV\215\21\241\272\210\264b\244\260\2\301\310\223", ) == 0x0 01756 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265\223S e/\364`\325\12 e/\364`\325\12 e/\364`\325\12 e/\364`k@\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01757 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01758 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01759 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01760 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01761 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01762 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01763 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01764 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01765 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "\30u\222\33\201\323\210m\230\37\222\302wB_\275.\247\23\366m\362\1\320~<\371\205\314\2279]\372\356\304\301\316\10\225\346\17\330\221fe3\301\356p\6PQ\342\3<\374\362\2332oA\24C:\206\375\352\346(j\322\224Z5\36\27\14\312:\347", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "\30u\222\33\201\323\210m\230\37\222\302wB_\275.\247\23\366m\362\1\320~<\371\205\314\2279]\372\356\304\301\316\10\225\346\17\330\221fe3\301\356p\6PQ\342\3<\374\362\2332oA\24C:\206\375\352\346(j\322\224Z5\36\27\14\312:\347", 80, ... ) , 80, ... ) == 0x0 01766 464 NtClose (-2147482584, ... ) == 0x0 01756 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "O\221O\17\234\307\220\31\206\371\337\223\363\2246(\275J\0\316\317S\15\2327\365q\27\237SW\360|\\237\340\305_\205\227\2277\25\215k\342\357\227\222\266A~\207`\276+}\273!u#\4\10\312m\325\354\334\262\227\370{\11_kR\25\312Z\207\332\253\374\237\275d\1\315,L\364k\340\356\233\275\255\244\2\213\15K\3028 \331y4\262;\12%\227p\36\241O\234B\2271ea3\333\340\2F[Q\24\363\323g\4\254\347\313j\2345G@\313\27\341\342 f4\262\352'\357\352^\373\302\340n\305~\236\271\3431'\353\352y,9\311w\316T\325\230\325\177\371\267\260H\246\355\236\205\355l\16\202\321d\353u\7\257>~$J\14Q\177X\352F"-qj\266\231\221\331\263\371\355\36\312P\235&\24\27\257{X\360\303\0\212\20\26\217*8@\222\251\333\365>8\365h'\226\272\212\241K\344\354\235", ) -qj\266\231\221\331\263\371\355\36\312P\235&\24\27\257{X\360\303\0\212\20\26\217*8@\222\251\333\365>8\365h'\226\272\212\241K\344\354\235", ) == 0x0 01767 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265\223S e/\364`\325\12 e/\364`\325\12 e/\364`\325\12 e/\364`\325\12 e/\364`k@\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01768 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01769 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01770 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01771 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01772 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01773 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01774 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01775 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01776 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "+UQ\327\311\344\1\275&!\356pr\26\302\236G\350\315q\317L\365\22\317\212\2u\13b\315\237\257\356\225\212\231\334\317\370\277\323C@\331\7\271\1I1\310\2D\206\0\366d5=F\2217v\35E\362\36;\321Z0\230\10r`\20;\24\271\177", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "+UQ\327\311\344\1\275&!\356pr\26\302\236G\350\315q\317L\365\22\317\212\2u\13b\315\237\257\356\225\212\231\334\317\370\277\323C@\331\7\271\1I1\310\2D\206\0\366d5=F\2217v\35E\362\36;\321Z0\230\10r`\20;\24\271\177", 80, ... ) , 80, ... ) == 0x0 01777 464 NtClose (-2147482584, ... ) == 0x0 01767 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "\217\324\30\233O\210\1\307\227\250=\235\351\201\2436\314\365\242p\37\201\12\355\243o\277\231\324\344W\235\6\21\240\12e\367\201`\374\254\257\330%\364\27\312\370\222wP\256\306\37q\320<\330K6\363\33&\0TX\215{\365\215\322?\271\256\202\200\244\303\30\14\33\246\332\241\205\22\10\204!\351'B\35\26\204=\226\373\300\212>r\332\3430^=\7+m6\312\313s\205\225\247}\325\371>M\265\363\15\314\235\342R\35\\253\301\32\20\210\330\363V\355\201\243d\37/k]\23\244\226j\3753\20\351\343S/\177\377\241-\21\224\202\270u\256\271$\3708\33z\253\240\3157\15\253\2\251\10\376\352\221<\7\14\2\2\253\265\352\307iT\31\351#\336\264\300\37\223\235\273\233L\375i{b\334\5\232~\323\372\207\230\1\22\232\330\377a\232\367\345\235.\12\17\23\16\2\0\236\255\311\230\347L\33\270a\256\215:\226;>", ) , ) == 0x0 01778 464 NtDeviceIoControlFile (132, 0, 0x0, 0x0, 0x390008, (132, 0, 0x0, 0x0, 0x390008, "\227@%k\372\256\270\375\13\246\253\305A\265\223S e/\364`\325\12 e/\364`\325\12 e/\364`\325\12 e/\364`\325\12 e/\364`\325\12 e/\364`k@\305\217-s\346\36\274\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 256, 256, ... , 256, 256, ... 01779 464 NtQuerySystemInformation (TimeOfDay, 48, ... {system info, class 3, size 48}, 48, ) == 0x0 01780 464 NtQuerySystemInformation (ProcessorTimes, 48, ... {system info, class 8, size 48}, 48, ) == 0x0 01781 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 312, ) == 0x0 01782 464 NtQuerySystemInformation (Exception, 16, ... {system info, class 33, size 16}, 16, ) == 0x0 01783 464 NtQuerySystemInformation (Lookaside, 32, ... {system info, class 45, size 32}, 32, ) == 0x0 01784 464 NtQuerySystemInformation (ProcessorStatistics, 3016, ... {system info, class 23, size 0}, 0, ) == 0x0 01785 464 NtQuerySystemInformation (ProcessesAndThreads, 3008, ... ) == STATUS_INFO_LENGTH_MISMATCH 01786 464 NtCreateKey (0x2, {24, 0, 0x240, 0, 0, (0x2, {24, 0, 0x240, 0, 0, "\Registry\Machine\SOFTWARE\Microsoft\Cryptography\RNG"}, 0, 0x0, 0, ... -2147482584, 2, ) }, 0, 0x0, 0, ... -2147482584, 2, ) == 0x0 01787 464 NtSetValueKey (-2147482584, (-2147482584, "Seed", 0, 3, "\270\207\7\204+\300`\330\0\254\373\177\350\353\311\345\240\266r\267\305p;\341\275\346\3759,\11\2366\3q\\210A\300\275\273\301\261\357\35\202\320t\4\217<\241\232\272B\32\367\13t\361\222)|\271Vcoc?\21\373\367t\31\354W\270M\321\244\243", 80, ... ) , 0, 3, (-2147482584, "Seed", 0, 3, "\270\207\7\204+\300`\330\0\254\373\177\350\353\311\345\240\266r\267\305p;\341\275\346\3759,\11\2366\3q\\210A\300\275\273\301\261\357\35\202\320t\4\217<\241\232\272B\32\367\13t\361\222)|\271Vcoc?\21\373\367t\31\354W\270M\321\244\243", 80, ... ) , 80, ... ) == 0x0 01788 464 NtClose (-2147482584, ... ) == 0x0 01778 464 NtDeviceIoControlFile ... {status=0x0, info=256}, ... {status=0x0, info=256}, "V]M\333\23@D8\211\346A\200\273\326\341>)^`no\243\33\202\312\27\345\0\22\277;+\302O\225\322A\224Vq]P3a\265\25Y\3338\345a\10|J\15\31Wa\376\215x;X\322j\32`)\376\325n\267\257\20n\355\3261\21f>,\315yv\235X[I\315\236\334Ov!\331@\343\36\221f\333F\34~\5\27A\177\234?\33\207\231\204\13R\23,\6\304\231\354\324'\321g\270\25\236a'C\375\25\304}_\377&N*\200$5H\37\12\260B,%P\360\324\300\263\13Y\335\333\265$\323a\324\344,\307L\227\353\241\3\304\223\361>Q\14\314\357\360\225\354\256\202;bKM\25\373\32se\304\177)&\313\201\334\330\343\357\230'\235\225\3527\336m\343\4\220\333\374\372\364(\210f\17\231\215\222\177l\21}\3318\4(\315F\221Z\05\3004\34\342\25\37\22i\32\354o\273", ) , ) == 0x0 01789 464 NtAllocateVirtualMemory (-1, 1417216, 0, 16384, 4096, 4, ... 1417216, 16384, ) == 0x0 01790 464 NtUserRegisterClassExWOW (1236592, 1236660, 1236676, 1236692, 0, 384, 0, ... ) == 0x81aec038 01791 464 NtUserGetAtomName (49208, 1235920, ... ) == 0x15 01792 464 NtUserCreateWindowEx (0, 49208, 49208, (0, 49208, 49208, "OleMainThreadWndName", -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 2001600512, 0, 1073742848, 0, ... , -2013265920, -2147483648, -2147483648, -2147483648, -2147483648, -3, 0, 2001600512, 0, 1073742848, 0, ... 01793 464 NtAllocateVirtualMemory (-1, 1224704, 0, 4096, 4096, 260, ... 1224704, 4096, ) == 0x0 01794 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1233392, ... ) }, 1233392, ... ) == 0x0 01795 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 140, {status=0x0, info=1}, ) }, 5, 96, ... 140, {status=0x0, info=1}, ) == 0x0 01796 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 140, ... 136, ) == 0x0 01797 464 NtClose (140, ... ) == 0x0 01798 464 NtMapViewOfSection (136, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xc60000), 0x0, 221184, ) == 0x0 01799 464 NtClose (136, ... ) == 0x0 01800 464 NtUnmapViewOfSection (-1, 0xc60000, ... ) == 0x0 01801 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1233700, ... ) }, 1233700, ... ) == 0x0 01802 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 5, 96, ... 136, {status=0x0, info=1}, ) }, 5, 96, ... 136, {status=0x0, info=1}, ) == 0x0 01803 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 136, ... 140, ) == 0x0 01804 464 NtQuerySection (140, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01805 464 NtClose (136, ... ) == 0x0 01806 464 NtMapViewOfSection (140, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5ad70000), 0x0, 229376, ) == 0x0 01807 464 NtClose (140, ... ) == 0x0 01808 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 01809 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 01810 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 01811 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 01812 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 01813 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 01814 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 01815 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 01816 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 01817 464 NtProtectVirtualMemory (-1, (0x5ad71000), 1300, 4, ... (0x5ad71000), 4096, 32, ) == 0x0 01818 464 NtProtectVirtualMemory (-1, (0x5ad71000), 4096, 32, ... (0x5ad71000), 4096, 4, ) == 0x0 01819 464 NtFlushInstructionCache (-1, 1524043776, 1300, ... ) == 0x0 01820 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uxtheme.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01821 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01822 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01823 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01824 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 140, ) == 0x0 01825 464 NtQueryInformationToken (140, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01826 464 NtClose (140, ... ) == 0x0 01827 464 NtOpenKey (0x2001f, {24, 0, 0x640, 0, 0, (0x2001f, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 140, ) }, ... 140, ) == 0x0 01828 464 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\ThemeManager"}, ... 136, ) }, ... 136, ) == 0x0 01829 464 NtQueryValueKey (136, (136, "Compositing", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01830 464 NtClose (136, ... ) == 0x0 01831 464 NtClose (140, ... ) == 0x0 01832 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01833 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 140, ) == 0x0 01834 464 NtQueryInformationToken (140, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01835 464 NtClose (140, ... ) == 0x0 01836 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 140, ) }, ... 140, ) == 0x0 01837 464 NtOpenKey (0x1, {24, 140, 0x40, 0, 0, (0x1, {24, 140, 0x40, 0, 0, "Control Panel\Desktop"}, ... 136, ) }, ... 136, ) == 0x0 01838 464 NtQueryValueKey (136, (136, "LameButtonText", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01839 464 NtClose (136, ... ) == 0x0 01840 464 NtClose (140, ... ) == 0x0 01841 464 NtUserGetProcessWindowStation (... ) == 0x20 01842 464 NtUserGetObjectInformation (32, 2, 1235488, 64, 1235484, ... ) == 0x1 01843 464 NtUserGetGUIThreadInfo (464, 1235508, ... ) == 0x1 01844 464 NtConnectPort ( ("\ThemeApiPort", {12, 2, 1, 1}, 0x0, 0x0, 1235352, 64, ... 140, 0x0, 0x0, 0x0, 64, ) , {12, 2, 1, 1}, 0x0, 0x0, 1235352, 64, ... 140, 0x0, 0x0, 0x0, 64, ) == 0x0 01845 464 NtRequestWaitReplyPort (140, {32, 56, new_msg, 0, 0, 0, 0, 0} (140, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 1036, 464, 57980, 0} (140, {32, 56, new_msg, 0, 0, 0, 0, 0} "\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57980, 0} "\0\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01846 464 NtRequestWaitReplyPort (140, {32, 56, new_msg, 0, 0, 0, 0, 0} (140, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57981, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 1036, 464, 57981, 0} (140, {32, 56, new_msg, 0, 0, 0, 0, 0} "\355\3\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57981, 0} "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01847 464 NtUserCallNoParam (29, ... 01848 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1232748, ... ) }, 1232748, ... ) == 0x0 01847 464 NtUserCallNoParam ... ) == 0x0 01849 464 NtUserSystemParametersInfo (41, 0, 1524240760, 0, ... ) == 0x1 01850 464 NtGdiHfontCreate (1234876, 356, 0, 0, 1396184, ... ) == 0x340a04e1 01851 464 NtGdiHfontCreate (1234876, 356, 0, 0, 1396176, ... ) == 0x520a0634 01852 464 NtRequestWaitReplyPort (140, {32, 56, new_msg, 0, 0, 0, 0, 0} (140, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57982, 0} "\0\0\0\0\0\0\0\0\210\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ... {32, 56, reply, 0, 1036, 464, 57982, 0} (140, {32, 56, new_msg, 0, 0, 0, 0, 0} "\7\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {32, 56, reply, 0, 1036, 464, 57982, 0} "\0\0\0\0\0\0\0\0\210\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) ) == 0x0 01853 464 NtMapViewOfSection (136, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xc60000), {0, 0}, 327680, ) == 0x0 01854 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01855 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01856 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01857 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01858 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01859 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01860 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01861 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01862 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01863 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01864 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01865 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01866 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01867 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01868 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01869 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01870 464 NtUserGetWindowDC (0, ... ) == 0x1010052 01871 464 NtGdiCreatePatternBrushInternal (59048383, 0, 0, ... ) == 0x72100798 01872 464 NtUserCallOneParam (16842834, 57, ... ) == 0x1 01873 464 NtUserCallNoParam (29, ... 01874 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1232188, ... ) }, 1232188, ... ) == 0x0 01873 464 NtUserCallNoParam ... ) == 0x0 01875 464 NtUserCallNoParam (29, ... 01876 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\uxtheme.dll"}, 1232184, ... ) }, 1232184, ... ) == 0x0 01875 464 NtUserCallNoParam ... ) == 0x0 01877 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 1233396, ... ) }, 1233396, ... ) == 0x0 01878 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 5, 96, ... 144, {status=0x0, info=1}, ) }, 5, 96, ... 144, {status=0x0, info=1}, ) == 0x0 01879 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 144, ... 148, ) == 0x0 01880 464 NtClose (144, ... ) == 0x0 01881 464 NtMapViewOfSection (148, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xcb0000), 0x0, 294912, ) == 0x0 01882 464 NtClose (148, ... ) == 0x0 01883 464 NtUnmapViewOfSection (-1, 0xcb0000, ... ) == 0x0 01884 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 1233704, ... ) }, 1233704, ... ) == 0x0 01885 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\MSCTF.dll"}, 5, 96, ... 148, {status=0x0, info=1}, ) }, 5, 96, ... 148, {status=0x0, info=1}, ) == 0x0 01886 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 148, ... 144, ) == 0x0 01887 464 NtQuerySection (144, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 01888 464 NtClose (148, ... ) == 0x0 01889 464 NtMapViewOfSection (144, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x74720000), 0x0, 307200, ) == 0x0 01890 464 NtClose (144, ... ) == 0x0 01891 464 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 01892 464 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 01893 464 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 01894 464 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 01895 464 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 01896 464 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 01897 464 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 01898 464 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 01899 464 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 01900 464 NtProtectVirtualMemory (-1, (0x74721000), 928, 4, ... (0x74721000), 4096, 32, ) == 0x0 01901 464 NtProtectVirtualMemory (-1, (0x74721000), 4096, 32, ... (0x74721000), 4096, 4, ) == 0x0 01902 464 NtFlushInstructionCache (-1, 1953632256, 928, ... ) == 0x0 01903 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSCTF.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01904 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\ntdll.dll"}, 1231060, ... ) }, 1231060, ... ) == 0x0 01905 464 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 01906 464 NtUserCallOneParam (0, 40, ... ) == 0x4090409 01907 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.Private", ... ) , ... ) == 0xc0a1 01908 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.SetFocus", ... ) , ... ) == 0xc0a2 01909 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ThreadTerminate", ... ) , ... ) == 0xc0a3 01910 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ThreadItemChange", ... ) , ... ) == 0xc0a4 01911 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.LangBarModal", ... ) , ... ) == 0xc0a5 01912 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.RpcSendReceive", ... ) , ... ) == 0xc0a6 01913 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ThreadMarshal", ... ) , ... ) == 0xc0a7 01914 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.CheckThreadInputIdel", ... ) , ... ) == 0xc0a8 01915 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.StubCleanUp", ... ) , ... ) == 0xc0a9 01916 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.ShowFloating", ... ) , ... ) == 0xc0aa 01917 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.LBUpdate", ... ) , ... ) == 0xc0ab 01918 464 NtUserRegisterWindowMessage ( ("MSUIM.Msg.MuiMgrDirtyUpdate", ... ) , ... ) == 0xc0ac 01919 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\imm32.dll"}, 1231068, ... ) }, 1231068, ... ) == 0x0 01920 464 NtRequestWaitReplyPort (24, {24, 52, new_msg, 0, 3998, 1233460, 0, 0} (24, {24, 52, new_msg, 0, 3998, 1233460, 0, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0\320\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 1036, 464, 57983, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0\320\1\0\0\0\0\0\0" ) ... {24, 52, reply, 0, 1036, 464, 57983, 0} (24, {24, 52, new_msg, 0, 3998, 1233460, 0, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0\320\1\0\0\0\0\0\0" ... {24, 52, reply, 0, 1036, 464, 57983, 0} "\0\0\0\0\5\4\3\0\0\0\0\0\1\0\0\0\320\1\0\0\0\0\0\0" ) ) == 0x0 01921 464 NtUserGetThreadDesktop (464, 0, ... ) == 0x24 01922 464 NtUserGetObjectInformation (36, 2, 1384080, 520, 1233368, ... ) == 0x1 01923 464 NtOpenProcessToken (-1, 0x8, ... 144, ) == 0x0 01924 464 NtQueryInformationToken (144, User, 0, ... ) == STATUS_BUFFER_TOO_SMALL 01925 464 NtQueryInformationToken (144, User, 36, ... {token info, class 1, size 36}, 36, ) == 0x0 01926 464 NtClose (144, ... ) == 0x0 01927 464 NtCreateSection (0xf0007, {24, 44, 0x80, 0, 0, (0xf0007, {24, 44, 0x80, 0, 0, "CiceroSharedMemDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, {3240, 0}, 4, 134217728, 0, ... 144, ) }, {3240, 0}, 4, 134217728, 0, ... 144, ) == STATUS_OBJECT_NAME_EXISTS 01928 464 NtMapViewOfSection (144, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0x980000), {0, 0}, 4096, ) == 0x0 01929 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\Compatibility\packed.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01930 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\SystemShared\"}, ... 148, ) }, ... 148, ) == 0x0 01931 464 NtQueryValueKey (148, (148, "CUAS", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (148, "CUAS", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 01932 464 NtClose (148, ... ) == 0x0 01933 464 NtUserFindExistingCursorIcon (1232900, 1232916, 1232964, ... ) == 0x10011 01934 464 NtUserRegisterClassExWOW (1233172, 1233268, 1233252, 1233240, 0, 386, 0, ... ) == 0x81aec0ad 01935 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "CTF.LBES.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 148, ) }, 0, ... 148, ) == STATUS_OBJECT_NAME_EXISTS 01936 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "CTF.Compart.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 152, ) }, 0, ... 152, ) == STATUS_OBJECT_NAME_EXISTS 01937 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "CTF.Asm.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 156, ) }, 0, ... 156, ) == STATUS_OBJECT_NAME_EXISTS 01938 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "CTF.Layouts.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 160, ) }, 0, ... 160, ) == STATUS_OBJECT_NAME_EXISTS 01939 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "CTF.TMD.MutexDefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 164, ) }, 0, ... 164, ) == STATUS_OBJECT_NAME_EXISTS 01940 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Keyboard Layout\Toggle"}, ... 168, ) }, ... 168, ) == 0x0 01941 464 NtQueryValueKey (168, (168, "Language Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01942 464 NtQueryValueKey (168, (168, "Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01943 464 NtQueryValueKey (168, (168, "Layout Hotkey", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01944 464 NtClose (168, ... ) == 0x0 01945 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\KERNEL32.dll"}, 1230888, ... ) }, 1230888, ... ) == 0x0 01946 464 NtQueryDefaultUILanguage (1233448, ... 01947 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 01948 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 01949 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 01950 464 NtClose (-2147482584, ... ) == 0x0 01951 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 01952 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01953 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 01954 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01955 464 NtClose (-2147481332, ... ) == 0x0 01956 464 NtClose (-2147482584, ... ) == 0x0 01946 464 NtQueryDefaultUILanguage ... ) == 0x0 01957 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\CTF\"}, ... 168, ) }, ... 168, ) == 0x0 01958 464 NtQueryValueKey (168, (168, "EnableAnchorContext", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01959 464 NtClose (168, ... ) == 0x0 01960 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "CTF.TimListCache.FMPDefaultS-1-5-21-1292428093-1383384898-725345543-1003MUTEX.DefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, 0, ... 168, ) }, 0, ... 168, ) == STATUS_OBJECT_NAME_EXISTS 01961 464 NtOpenSection (0xf001f, {24, 44, 0x0, 0, 0, (0xf001f, {24, 44, 0x0, 0, 0, "CTF.TimListCache.FMPDefaultS-1-5-21-1292428093-1383384898-725345543-1003SFM.DefaultS-1-5-21-1292428093-1383384898-725345543-1003"}, ... 172, ) }, ... 172, ) == 0x0 01962 464 NtMapViewOfSection (172, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xcb0000), {0, 0}, 262144, ) == 0x0 01963 464 NtWaitForSingleObject (168, 0, {-50000000, -1}, ... ) == 0x0 01964 464 NtReleaseMutant (168, ... 0x0, ) == 0x0 01965 464 NtWaitForSingleObject (168, 0, {-50000000, -1}, ... ) == 0x0 01966 464 NtReleaseMutant (168, ... 0x0, ) == 0x0 01967 464 NtWaitForSingleObject (168, 0, {-50000000, -1}, ... ) == 0x0 01968 464 NtReleaseMutant (168, ... 0x0, ) == 0x0 01969 464 NtUserSetWindowsHookEx (1953628160, 1234892, 464, 2, 1953694283, 2, ... ) == 0x601df 01970 464 NtUserSetWindowsHookEx (1953628160, 1234892, 464, 7, 1953693577, 2, ... ) == 0x18022f 01971 464 NtUserMessageCall (0xa0102, WM_NCCREATE, 0x0, 0x12db7c, 0, 670, 0, ... ) == 0x1 01972 464 NtUserMessageCall (0xa0102, WM_NCCALCSIZE, 0x0, 0x12dba4, 0, 670, 0, ... ) == 0x0 01973 464 NtUserSetProp (655618, 43288, -1, ... ) == 0x1 01792 464 NtUserCreateWindowEx ... ) == 0xa0102 01974 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 176, ) }, ... 176, ) == 0x0 01975 464 NtQueryValueKey (176, (176, "MaximizeApps", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01976 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 180, ) }, ... 180, ) == 0x0 01977 464 NtQueryValueKey (180, (180, "MaximizeApps", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 01978 464 NtClose (180, ... ) == 0x0 01979 464 NtClose (176, ... ) == 0x0 01980 464 NtAllocateVirtualMemory (-1, 1433600, 0, 28672, 4096, 4, ... 1433600, 28672, ) == 0x0 01981 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "netapi32.dll"}, ... 176, ) }, ... 176, ) == 0x0 01982 464 NtMapViewOfSection (176, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x5b860000), 0x0, 344064, ) == 0x0 01983 464 NtClose (176, ... ) == 0x0 01984 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 01985 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 01986 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 01987 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 01988 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 01989 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 01990 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 01991 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 01992 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 01993 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 01994 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 01995 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 01996 464 NtProtectVirtualMemory (-1, (0x5b861000), 1168, 4, ... (0x5b861000), 4096, 32, ) == 0x0 01997 464 NtProtectVirtualMemory (-1, (0x5b861000), 4096, 32, ... (0x5b861000), 4096, 4, ) == 0x0 01998 464 NtFlushInstructionCache (-1, 1535512576, 1168, ... ) == 0x0 01999 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netapi32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02000 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 02001 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Rpc\PagedBuffers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02002 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Rpc"}, ... 176, ) }, ... 176, ) == 0x0 02003 464 NtQueryValueKey (176, (176, "MaxRpcSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02004 464 NtClose (176, ... ) == 0x0 02005 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\packed.exe\RpcThreadPoolThrottle"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02006 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 176, ) == 0x0 02007 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 180, ) == 0x0 02008 464 NtQuerySystemTime (... {594664602, 29916438}, ) == 0x0 02009 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 184, ) == 0x0 02010 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows NT\Rpc"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02011 464 NtQuerySystemInformation (Performance, 312, ... {system info, class 2, size 312}, 0x0, ) == 0x0 02012 464 NtQueryInformationProcess (-1, QuotaLimits, 32, ... {process info, class 1, size 32}, 0x0, ) == 0x0 02013 464 NtQueryInformationProcess (-1, VmCounters, 44, ... {process info, class 3, size 44}, 0x0, ) == 0x0 02014 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 188, ) == 0x0 02015 464 NtDuplicateObject (-1, -2, -1, 0x0, 0, 2, ... 192, ) == 0x0 02016 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName"}, ... 196, ) }, ... 196, ) == 0x0 02017 464 NtOpenKey (0x20019, {24, 196, 0x40, 0, 0, (0x20019, {24, 196, 0x40, 0, 0, "ActiveComputerName"}, ... 200, ) }, ... 200, ) == 0x0 02018 464 NtQueryValueKey (200, (200, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 108, ... TitleIdx=0, Type=1, Name= (200, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (200, "ComputerName", Full, 108, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 02019 464 NtClose (200, ... ) == 0x0 02020 464 NtClose (196, ... ) == 0x0 02021 464 NtCreateIoCompletion (0x1f0003, 0x0, 0, ... 196, ) == 0x0 02022 464 NtCreateIoCompletion (0x1f0003, 0x0, -1, ... 200, ) == 0x0 02023 464 NtDuplicateObject (-1, 196, -1, 0x0, 0, 2, ... 204, ) == 0x0 02024 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02025 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 208, ) == 0x0 02026 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02027 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02028 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1235612, (0xc0100080, {24, 0, 0x40, 0, 1235612, "\??\PIPE\wkssvc"}, 0x0, 0, 3, 1, 4194368, 0, 0, ... 212, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 4194368, 0, 0, ... 212, {status=0x0, info=1}, ) == 0x0 02029 464 NtSetInformationFile (212, 1235668, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02030 464 NtSetInformationFile (212, 1235656, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02031 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02032 464 NtAllocateVirtualMemory (-1, 1462272, 0, 4096, 4096, 4, ... 1462272, 4096, ) == 0x0 02033 464 NtWriteFile (212, 189, 0, 0, (212, 189, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0\230\320\377k\22\241\206\2303F\303\370~4Z\1\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02034 464 NtReadFile (212, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (212, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20W2\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02035 464 NtFsControlFile (212, 189, 0x0, 0x0, 0x11c017, (212, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20W2\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 32, 1024, ... {status=0x103, info=68}, (212, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0 \0\0\0\1\0\0\0\10\0\0\0\0\0\24\0\0\0\0\0\0\0\0\0", 32, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20W2\0\0\15\0\PIPE\wkssvc\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02036 464 NtClose (208, ... ) == 0x0 02037 464 NtClose (212, ... ) == 0x0 02038 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\scripts"}, 1235672, ... ) }, 1235672, ... ) == 0x0 02039 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02040 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02041 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1235476, ... ) }, 1235476, ... ) == 0x0 02042 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02043 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02044 464 NtCreateSemaphore (0x1f0003, {24, 44, 0x80, 1397072, 0, (0x1f0003, {24, 44, 0x80, 1397072, 0, "shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}"}, 0, 2147483647, ... 212, ) }, 0, 2147483647, ... 212, ) == STATUS_OBJECT_NAME_EXISTS 02045 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02046 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02047 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02048 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 208, ) }, ... 208, ) == 0x0 02049 464 NtQueryValueKey (208, (208, "NoNetHood", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02050 464 NtClose (208, ... ) == 0x0 02051 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02052 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02053 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02054 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 208, ) }, ... 208, ) == 0x0 02055 464 NtQueryValueKey (208, (208, "NoPropertiesMyComputer", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02056 464 NtClose (208, ... ) == 0x0 02057 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02058 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02059 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02060 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 208, ) }, ... 208, ) == 0x0 02061 464 NtQueryValueKey (208, (208, "NoInternetIcon", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02062 464 NtClose (208, ... ) == 0x0 02063 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02064 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02065 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02066 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 208, ) }, ... 208, ) == 0x0 02067 464 NtQueryValueKey (208, (208, "NoCommonGroups", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02068 464 NtClose (208, ... ) == 0x0 02069 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02070 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02071 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02072 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02073 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 208, ) }, ... 208, ) == 0x0 02074 464 NtQueryValueKey (208, (208, "NoControlPanel", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02075 464 NtClose (208, ... ) == 0x0 02076 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02077 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02078 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02079 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 208, ) }, ... 208, ) == 0x0 02080 464 NtQueryValueKey (208, (208, "NoSetFolders", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02081 464 NtClose (208, ... ) == 0x0 02082 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02083 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 208, ) == 0x0 02084 464 NtQueryInformationToken (208, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02085 464 NtClose (208, ... ) == 0x0 02086 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes"}, ... 208, ) }, ... 208, ) == 0x0 02087 464 NtSetInformationObject (210, Handle, {Inherit=0,ProtectFromClose=1,}, 1179904, ... ) == 0x0 02088 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02089 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, "CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02090 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... 216, ) }, ... 216, ) == 0x0 02091 464 NtQueryKey (218, Name, 392, ... {Name= (218, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, 192, ) }, 192, ) == 0x0 02092 464 NtAllocateVirtualMemory (-1, 1466368, 0, 4096, 4096, 4, ... 1466368, 4096, ) == 0x0 02093 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02094 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 02095 464 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02096 464 NtClose (220, ... ) == 0x0 02097 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02098 464 NtQueryValueKey (218, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data= (218, 0x0, Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0s\0y\0s\0t\0e\0m\03\02\0\\0S\0H\0E\0L\0L\03\02\0.\0d\0l\0l\0\0\0"}, 80, ) }, 80, ) == 0x0 02099 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SHELL32.dll"}, 1233284, ... ) }, 1233284, ... ) == 0x0 02100 464 NtClose (218, ... ) == 0x0 02101 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02102 464 NtOpenKey (0x8, {24, 210, 0x40, 0, 0, (0x8, {24, 210, 0x40, 0, 0, "Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02103 464 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions"}, ... 216, ) }, ... 216, ) == 0x0 02104 464 NtQueryKey (218, Name, 392, ... {Name= (218, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensionsl"}, 134, ) }, 134, ) == 0x0 02105 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02106 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 220, ) == 0x0 02107 464 NtQueryInformationToken (220, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02108 464 NtClose (220, ... ) == 0x0 02109 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Drive\shellex\FolderExtensions"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02110 464 NtEnumerateKey (218, 0, Node, 288, ... {LastWrite={0xdb6f03de,0x1c74da8}, TitleIdx=0, Name= (218, 0, Node, 288, ... {LastWrite={0xdb6f03de,0x1c74da8}, TitleIdx=0, Name="{fbeb8a05-beee-4442-804e-409d6c4515e9}", Class=""}, 100, ) , Class=""}, 100, ) == 0x0 02111 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02112 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, "Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02113 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... 220, ) }, ... 220, ) == 0x0 02114 464 NtQueryKey (222, Name, 392, ... {Name= (222, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, 212, ) }, 212, ) == 0x0 02115 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02116 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 224, ) == 0x0 02117 464 NtQueryInformationToken (224, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02118 464 NtClose (224, ... ) == 0x0 02119 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02120 464 NtQueryValueKey (222, (222, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (222, "DriveMask", Partial, 144, ... TitleIdx=0, Type=4, Data=" \0\0\0"}, 16, ) }, 16, ) == 0x0 02121 464 NtClose (222, ... ) == 0x0 02122 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02123 464 NtEnumerateKey (218, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 02124 464 NtClose (218, ... ) == 0x0 02125 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02126 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02127 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02128 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 216, ) }, ... 216, ) == 0x0 02129 464 NtQueryValueKey (216, (216, "AllowFileCLSIDJunctions", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02130 464 NtClose (216, ... ) == 0x0 02131 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02132 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer"}, ... 216, ) }, ... 216, ) == 0x0 02133 464 NtOpenKey (0x2000000, {24, 216, 0x40, 0, 0, (0x2000000, {24, 216, 0x40, 0, 0, "FileExts"}, ... 220, ) }, ... 220, ) == 0x0 02134 464 NtOpenKey (0x2000000, {24, 220, 0x40, 0, 0, (0x2000000, {24, 220, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02135 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02136 464 NtOpenKey (0x2000000, {24, 220, 0x40, 0, 0, (0x2000000, {24, 220, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02137 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02138 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02139 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 224, ) }, ... 224, ) == 0x0 02140 464 NtQueryKey (226, Name, 392, ... {Name= (226, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 02141 464 NtAllocateVirtualMemory (-1, 1470464, 0, 4096, 4096, 4, ... 1470464, 4096, ) == 0x0 02142 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02143 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 228, ) == 0x0 02144 464 NtQueryInformationToken (228, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02145 464 NtClose (228, ... ) == 0x0 02146 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02147 464 NtQueryValueKey (226, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (226, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="b\0a\0t\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 02148 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02149 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02150 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\batfile"}, ... 228, ) }, ... 228, ) == 0x0 02151 464 NtQueryKey (230, Name, 384, ... {Name= (230, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02152 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02153 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 232, ) == 0x0 02154 464 NtQueryInformationToken (232, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02155 464 NtClose (232, ... ) == 0x0 02156 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02157 464 NtOpenKey (0x1, {24, 230, 0x40, 0, 0, (0x1, {24, 230, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02158 464 NtQueryKey (230, Name, 384, ... {Name= (230, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02159 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02160 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 232, ) == 0x0 02161 464 NtQueryInformationToken (232, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02162 464 NtClose (232, ... ) == 0x0 02163 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02164 464 NtOpenKey (0x2000000, {24, 230, 0x40, 0, 0, ""}, ... 232, ) == 0x0 02165 464 NtClose (230, ... ) == 0x0 02166 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02167 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02168 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02169 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02170 464 NtQueryValueKey (228, (228, "DontShowSuperHidden", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02171 464 NtClose (228, ... ) == 0x0 02172 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02173 464 NtOpenKey (0x2000000, {24, 216, 0x40, 0, 0, ""}, ... 228, ) == 0x0 02174 464 NtQueryValueKey (228, (228, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (228, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) }, 48, ) == 0x0 02175 464 NtQueryValueKey (228, (228, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (228, "ShellState", Partial, 144, ... TitleIdx=0, Type=3, Data="$\0\0\00(\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\15\0\0\0\0\0\0\0\2\0\0\0"}, 48, ) }, 48, ) == 0x0 02176 464 NtClose (228, ... ) == 0x0 02177 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02178 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02179 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02180 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02181 464 NtQueryValueKey (228, (228, "ForceActiveDesktopOn", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02182 464 NtClose (228, ... ) == 0x0 02183 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02184 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02185 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02186 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02187 464 NtQueryValueKey (228, (228, "NoActiveDesktop", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02188 464 NtClose (228, ... ) == 0x0 02189 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\System"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02190 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02191 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02192 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02193 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02194 464 NtQueryValueKey (228, (228, "NoWebView", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02195 464 NtClose (228, ... ) == 0x0 02196 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02197 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02198 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02199 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02200 464 NtQueryValueKey (228, (228, "ClassicShell", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02201 464 NtClose (228, ... ) == 0x0 02202 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02203 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02204 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02205 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02206 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02207 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02208 464 NtQueryValueKey (228, (228, "SeparateProcess", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02209 464 NtClose (228, ... ) == 0x0 02210 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02211 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02212 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02213 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02214 464 NtQueryValueKey (228, (228, "NoNetCrawling", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02215 464 NtClose (228, ... ) == 0x0 02216 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02217 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02218 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02219 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 228, ) }, ... 228, ) == 0x0 02220 464 NtQueryValueKey (228, (228, "NoSimpleStartMenu", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02221 464 NtClose (228, ... ) == 0x0 02222 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02223 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02224 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02225 464 NtOpenKey (0x2000000, {24, 216, 0x40, 0, 0, (0x2000000, {24, 216, 0x40, 0, 0, "Advanced"}, ... 228, ) }, ... 228, ) == 0x0 02226 464 NtQueryValueKey (228, (228, "Hidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "Hidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02227 464 NtQueryValueKey (228, (228, "ShowCompColor", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "ShowCompColor", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02228 464 NtQueryValueKey (228, (228, "HideFileExt", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "HideFileExt", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02229 464 NtQueryValueKey (228, (228, "DontPrettyPath", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "DontPrettyPath", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02230 464 NtQueryValueKey (228, (228, "ShowInfoTip", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "ShowInfoTip", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02231 464 NtQueryValueKey (228, (228, "HideIcons", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "HideIcons", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02232 464 NtQueryValueKey (228, (228, "MapNetDrvBtn", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "MapNetDrvBtn", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02233 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02234 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02235 464 NtQueryValueKey (228, (228, "WebView", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "WebView", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02236 464 NtQueryValueKey (228, (228, "Filter", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "Filter", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02237 464 NtQueryValueKey (228, (228, "ShowSuperHidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "ShowSuperHidden", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02238 464 NtQueryValueKey (228, (228, "SeparateProcess", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "SeparateProcess", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02239 464 NtQueryValueKey (228, (228, "NoNetCrawling", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (228, "NoNetCrawling", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02240 464 NtClose (228, ... ) == 0x0 02241 464 NtCreateSemaphore (0x1f0003, {24, 44, 0x80, 1397072, 0, (0x1f0003, {24, 44, 0x80, 1397072, 0, "shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57}"}, 0, 2147483647, ... 228, ) }, 0, 2147483647, ... 228, ) == STATUS_OBJECT_NAME_EXISTS 02242 464 NtReleaseSemaphore (228, 1, ... 59, ) == 0x0 02243 464 NtWaitForSingleObject (228, 0, {0, 0}, ... ) == 0x0 02244 464 NtQueryKey (234, Name, 384, ... {Name= (234, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02245 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02246 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 236, ) == 0x0 02247 464 NtQueryInformationToken (236, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02248 464 NtClose (236, ... ) == 0x0 02249 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02250 464 NtOpenKey (0x1, {24, 234, 0x40, 0, 0, (0x1, {24, 234, 0x40, 0, 0, "ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02251 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02252 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "SystemFileAssociations\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02253 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\SystemFileAssociations\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02254 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02255 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "SystemFileAssociations\application"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02256 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\SystemFileAssociations\application"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02257 464 NtQueryKey (234, Name, 392, ... {Name= (234, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02258 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02259 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 236, ) == 0x0 02260 464 NtQueryInformationToken (236, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02261 464 NtClose (236, ... ) == 0x0 02262 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02263 464 NtQueryValueKey (234, (234, "DocObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02264 464 NtQueryKey (234, Name, 392, ... {Name= (234, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02265 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02266 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 236, ) == 0x0 02267 464 NtQueryInformationToken (236, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02268 464 NtClose (236, ... ) == 0x0 02269 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02270 464 NtQueryValueKey (234, (234, "BrowseInPlace", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02271 464 NtQueryKey (234, Name, 384, ... {Name= (234, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02272 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02273 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 236, ) == 0x0 02274 464 NtQueryInformationToken (236, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02275 464 NtClose (236, ... ) == 0x0 02276 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02277 464 NtOpenKey (0x1, {24, 234, 0x40, 0, 0, (0x1, {24, 234, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02278 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02279 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "*"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02280 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\*"}, ... 236, ) }, ... 236, ) == 0x0 02281 464 NtQueryKey (238, Name, 384, ... {Name= (238, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\*"}, 76, ) }, 76, ) == 0x0 02282 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02283 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 240, ) == 0x0 02284 464 NtQueryInformationToken (240, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02285 464 NtClose (240, ... ) == 0x0 02286 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\*\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02287 464 NtOpenKey (0x1, {24, 238, 0x40, 0, 0, (0x1, {24, 238, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02288 464 NtQueryKey (234, Name, 392, ... {Name= (234, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02289 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02290 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 240, ) == 0x0 02291 464 NtQueryInformationToken (240, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02292 464 NtClose (240, ... ) == 0x0 02293 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02294 464 NtQueryValueKey (234, (234, "IsShortcut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02295 464 NtQueryKey (234, Name, 392, ... {Name= (234, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02296 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02297 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 240, ) == 0x0 02298 464 NtQueryInformationToken (240, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02299 464 NtClose (240, ... ) == 0x0 02300 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02301 464 NtQueryValueKey (234, (234, "AlwaysShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02302 464 NtQueryKey (234, Name, 392, ... {Name= (234, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 02303 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02304 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 240, ) == 0x0 02305 464 NtQueryInformationToken (240, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02306 464 NtClose (240, ... ) == 0x0 02307 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02308 464 NtQueryValueKey (234, (234, "NeverShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02309 464 NtClose (226, ... ) == 0x0 02310 464 NtClose (234, ... ) == 0x0 02311 464 NtClose (238, ... ) == 0x0 02312 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02313 464 NtCreateSemaphore (0x1f0003, {24, 44, 0x80, 1397072, 0, (0x1f0003, {24, 44, 0x80, 1397072, 0, "shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}"}, 0, 2147483647, ... 236, ) }, 0, 2147483647, ... 236, ) == STATUS_OBJECT_NAME_EXISTS 02314 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02315 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02316 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02317 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02318 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 232, 2, ) }, 0, 0x0, 0, ... 232, 2, ) == 0x0 02319 464 NtQueryValueKey (232, (232, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (232, "Personal", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 66, ) }, 66, ) == 0x0 02320 464 NtClose (232, ... ) == 0x0 02321 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents"}, 1235632, ... ) }, 1235632, ... ) == 0x0 02322 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 232, 2, ) }, 0, 0x0, 0, ... 232, 2, ) == 0x0 02323 464 NtSetValueKey (232, (232, "Personal", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 108, ... ) , 0, 1, (232, "Personal", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0M\0y\0 \0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 108, ... ) , 108, ... ) == 0x0 02324 464 NtClose (232, ... ) == 0x0 02325 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02326 464 NtOpenEvent (0x100000, {24, 44, 0x0, 0, 0, (0x100000, {24, 44, 0x0, 0, 0, "_fCanRegisterWithShellService"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02327 464 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 02328 464 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 02329 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02330 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\SETUPAPI.dll"}, 1233388, ... ) }, 1233388, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02331 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SETUPAPI.dll"}, 1233388, ... ) }, 1233388, ... ) == 0x0 02332 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\SETUPAPI.dll"}, 5, 96, ... 232, {status=0x0, info=1}, ) }, 5, 96, ... 232, {status=0x0, info=1}, ) == 0x0 02333 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 232, ... 224, ) == 0x0 02334 464 NtQuerySection (224, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02335 464 NtClose (232, ... ) == 0x0 02336 464 NtMapViewOfSection (224, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77920000), 0x0, 995328, ) == 0x0 02337 464 NtClose (224, ... ) == 0x0 02338 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02339 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02340 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02341 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02342 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02343 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02344 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02345 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02346 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02347 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02348 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02349 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02350 464 NtProtectVirtualMemory (-1, (0x77921000), 1368, 4, ... (0x77921000), 4096, 32, ) == 0x0 02351 464 NtProtectVirtualMemory (-1, (0x77921000), 4096, 32, ... (0x77921000), 4096, 4, ) == 0x0 02352 464 NtFlushInstructionCache (-1, 2006061056, 1368, ... ) == 0x0 02353 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPAPI.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02354 464 NtQueryDefaultLocale (1, 1233292, ... ) == 0x0 02355 464 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 02356 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02357 464 NtQueryValueKey (224, (224, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (224, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02358 464 NtClose (224, ... ) == 0x0 02359 464 NtUserGetProcessWindowStation (... ) == 0x20 02360 464 NtUserGetObjectInformation (32, 1, 1232888, 12, 1232900, ... ) == 0x1 02361 464 NtOpenKey (0xf003f, {24, 28, 0x40, 0, 0, (0xf003f, {24, 28, 0x40, 0, 0, "SYSTEM\CurrentControlSet\Control\MiniNT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02362 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\WPA\PnP"}, ... 224, ) }, ... 224, ) == 0x0 02363 464 NtQueryValueKey (224, (224, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\240d\351\211"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (224, "seed", Partial, 144, ... TitleIdx=0, Type=4, Data="\240d\351\211"}, 16, ) }, 16, ) == 0x0 02364 464 NtClose (224, ... ) == 0x0 02365 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02366 464 NtQueryValueKey (224, (224, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 02367 464 NtQueryValueKey (224, (224, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "OsLoaderPath", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0\0\0"}, 16, ) }, 16, ) == 0x0 02368 464 NtClose (224, ... ) == 0x0 02369 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SYSTEM\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02370 464 NtQueryValueKey (224, (224, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 02371 464 NtQueryValueKey (224, (224, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "SystemPartition", Partial, 144, ... TitleIdx=0, Type=1, Data="\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\0\0"}, 60, ) }, 60, ) == 0x0 02372 464 NtClose (224, ... ) == 0x0 02373 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02374 464 NtQueryValueKey (224, (224, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02375 464 NtQueryValueKey (224, (224, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "SourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02376 464 NtClose (224, ... ) == 0x0 02377 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02378 464 NtQueryValueKey (224, (224, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02379 464 NtQueryValueKey (224, (224, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "ServicePackSourcePath", Partial, 144, ... TitleIdx=0, Type=1, Data="D\0:\0\\0\0\0"}, 20, ) }, 20, ) == 0x0 02380 464 NtClose (224, ... ) == 0x0 02381 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02382 464 NtQueryValueKey (224, (224, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) }, 102, ) == 0x0 02383 464 NtQueryValueKey (224, (224, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (224, "ServicePackCachePath", Partial, 144, ... TitleIdx=0, Type=1, Data="c\0:\0\\0w\0i\0n\0d\0o\0w\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0F\0i\0l\0e\0s\0\\0S\0e\0r\0v\0i\0c\0e\0P\0a\0c\0k\0C\0a\0c\0h\0e\0\0\0"}, 102, ) }, 102, ) == 0x0 02384 464 NtClose (224, ... ) == 0x0 02385 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 224, ) }, ... 224, ) == 0x0 02386 464 NtQueryValueKey (224, (224, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (224, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 02387 464 NtQueryValueKey (224, (224, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (224, "DriverCachePath", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0D\0r\0i\0v\0e\0r\0 \0C\0a\0c\0h\0e\0\0\0"}, 64, ) }, 64, ) == 0x0 02388 464 NtClose (224, ... ) == 0x0 02389 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion"}, ... 224, ) }, ... 224, ) == 0x0 02390 464 NtQueryValueKey (224, (224, "DevicePath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02391 464 NtQueryValueKey (224, (224, "DevicePath", Partial, 346, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0c\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0r\0i\0c\0h\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0c\0e\0r\0c\0s\0r\06\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\03\02\00\0r\0a\0i\0d\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0i\0a\0s\0t\0o\0r\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0n\0v\0r\0a\0i\0d\0\0\0"}, 346, ) , Partial, 346, ... TitleIdx=0, Type=2, Data= (224, "DevicePath", Partial, 346, ... TitleIdx=0, Type=2, Data="%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0i\0n\0f\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0c\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\0a\0r\0i\0c\0h\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0c\0e\0r\0c\0s\0r\06\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0a\03\02\00\0r\0a\0i\0d\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0i\0a\0s\0t\0o\0r\0;\0%\0S\0y\0s\0t\0e\0m\0R\0o\0o\0t\0%\0\\0d\0e\0l\0l\0\\0n\0v\0r\0a\0i\0d\0\0\0"}, 346, ) }, 346, ) == 0x0 02392 464 NtAllocateVirtualMemory (-1, 1474560, 0, 4096, 4096, 4, ... 1474560, 4096, ) == 0x0 02393 464 NtClose (224, ... ) == 0x0 02394 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 224, ) == 0x0 02395 464 NtCreateMutant (0x1f0001, 0x0, 0, ... 232, ) == 0x0 02396 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 240, ) == 0x0 02397 464 NtCreateMutant (0x1f0001, 0x0, 0, ... 244, ) == 0x0 02398 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 248, ) == 0x0 02399 464 NtCreateMutant (0x1f0001, 0x0, 0, ... 252, ) == 0x0 02400 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Setup"}, ... 256, ) }, ... 256, ) == 0x0 02401 464 NtQueryValueKey (256, (256, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (256, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02402 464 NtQueryValueKey (256, (256, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (256, "LogLevel", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 02403 464 NtQueryValueKey (256, (256, "LogPath", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02404 464 NtOpenKey (0x1, {24, 256, 0x40, 0, 0, (0x1, {24, 256, 0x40, 0, 0, "AppLogLevels"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02405 464 NtClose (256, ... ) == 0x0 02406 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 1232804, ... ) }, 1232804, ... ) == 0x0 02407 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Control\ComputerName\ActiveComputerName"}, ... 256, ) }, ... 256, ) == 0x0 02408 464 NtQueryValueKey (256, (256, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (256, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) , Data= (256, "ComputerName", Full, 128, ... TitleIdx=0, Type=1, Name="ComputerName", Data="V\0I\0R\0T\0U\0A\0L\0\0\0"}, 60, ) }, 60, ) == 0x0 02409 464 NtClose (256, ... ) == 0x0 02410 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 256, ) }, ... 256, ) == 0x0 02411 464 NtQueryValueKey (256, (256, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (256, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) , Data= (256, "Hostname", Full, 128, ... TitleIdx=0, Type=1, Name="Hostname", Data="v\0i\0r\0t\0u\0a\0l\0\0\0"}, 52, ) }, 52, ) == 0x0 02412 464 NtClose (256, ... ) == 0x0 02413 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\System\DNSclient"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02414 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\CurrentControlSet\Services\Tcpip\Parameters"}, ... 256, ) }, ... 256, ) == 0x0 02415 464 NtQueryValueKey (256, (256, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Full, 128, ... TitleIdx=0, Type=1, Name= (256, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) , Data= (256, "Domain", Full, 128, ... TitleIdx=0, Type=1, Name="Domain", Data="\0\0"}, 34, ) }, 34, ) == 0x0 02416 464 NtClose (256, ... ) == 0x0 02417 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02418 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 256, ) == 0x0 02419 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02420 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02421 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1233644, (0xc0100080, {24, 0, 0x40, 0, 1233644, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 260, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 260, {status=0x0, info=1}, ) == 0x0 02422 464 NtSetInformationFile (260, 1233700, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02423 464 NtSetInformationFile (260, 1233688, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02424 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02425 464 NtWriteFile (260, 189, 0, 0, (260, 189, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02426 464 NtReadFile (260, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (260, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02427 464 NtFsControlFile (260, 189, 0x0, 0x0, 0x11c017, (260, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\264\331\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (260, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\264\331\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20,+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02428 464 NtFsControlFile (260, 189, 0x0, 0x0, 0x11c017, (260, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0j\0\0\0\2\0\0\0R\0\0\0\0\0\37\0\0\0\0\0\6'L\222k\204\320K\253\330\325\251\35510\310*\0,\0\374\217\222w\26\0\0\0\0\0\0\0\25\0\0\0S\0e\0L\0o\0a\0d\0D\0r\0i\0v\0e\0r\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 106, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\6'L\222k\204\320K\253\330\325\251\35510\310\0\0\0\0", ) , 106, 1024, ... {status=0x103, info=48}, (260, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0j\0\0\0\2\0\0\0R\0\0\0\0\0\37\0\0\0\0\0\6'L\222k\204\320K\253\330\325\251\35510\310*\0,\0\374\217\222w\26\0\0\0\0\0\0\0\25\0\0\0S\0e\0L\0o\0a\0d\0D\0r\0i\0v\0e\0r\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 106, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\6'L\222k\204\320K\253\330\325\251\35510\310\0\0\0\0", ) , ) == 0x103 02429 464 NtFsControlFile (260, 189, 0x0, 0x0, 0x11c017, (260, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\6'L\222k\204\320K\253\330\325\251\35510\310", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\12\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=36}, (260, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\6'L\222k\204\320K\253\330\325\251\35510\310", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\12\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02430 464 NtClose (256, ... ) == 0x0 02431 464 NtClose (260, ... ) == 0x0 02432 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02433 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 260, ) == 0x0 02434 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02435 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02436 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1233644, (0xc0100080, {24, 0, 0x40, 0, 1233644, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 256, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 256, {status=0x0, info=1}, ) == 0x0 02437 464 NtSetInformationFile (256, 1233700, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 02438 464 NtSetInformationFile (256, 1233688, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 02439 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 02440 464 NtWriteFile (256, 189, 0, 0, (256, 189, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 02441 464 NtReadFile (256, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (256, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 02442 464 NtFsControlFile (256, 189, 0x0, 0x0, 0x11c017, (256, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\264\331\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 64, 1024, ... {status=0x103, info=68}, (256, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0@\0\0\0\1\0\0\0(\0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\264\331\22\0\14\0\0\0\2\0\1\0\0\10\0\0", 64, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20-+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 02443 464 NtFsControlFile (256, 189, 0x0, 0x0, 0x11c017, (256, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0b\0\0\0\2\0\0\0J\0\0\0\0\0\37\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22"\0$\0\0\217\222w\22\0\0\0\0\0\0\0\21\0\0\0S\0e\0U\0n\0d\0o\0c\0k\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 98, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) \0$\0\0\217\222w\22\0\0\0\0\0\0\0\21\0\0\0S\0e\0U\0n\0d\0o\0c\0k\0P\0r\0i\0v\0i\0l\0e\0g\0e\0 (256, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0b\0\0\0\2\0\0\0J\0\0\0\0\0\37\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22"\0$\0\0\217\222w\22\0\0\0\0\0\0\0\21\0\0\0S\0e\0U\0n\0d\0o\0c\0k\0P\0r\0i\0v\0i\0l\0e\0g\0e\0", 98, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) \5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22\0\0\0\0", ) == 0x103 02444 464 NtFsControlFile (256, 189, 0x0, 0x0, 0x11c017, (256, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\31\0\0\0\0\0\0\0\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=36}, (256, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\3\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\24\316\274T\274\235tH\233\354\372\234W@\301\22", 44, 1024, ... {status=0x103, info=36}, "\5\0\2\3\20\0\0\0$\0\0\0\2\0\0\0\14\0\0\0\0\0\0\0\31\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x103 02445 464 NtClose (260, ... ) == 0x0 02446 464 NtClose (256, ... ) == 0x0 02447 464 NtOpenThreadToken (-2, 0x20, 1, ... ) == STATUS_NO_TOKEN 02448 464 NtOpenProcessToken (-1, 0x20, ... 256, ) == 0x0 02449 464 NtAdjustPrivilegesToken (256, 0, 1474208, 0, 0, 0, ... ) == 0x0 02450 464 NtClose (256, ... ) == 0x0 02451 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 256, ) == 0x0 02452 464 NtConnectPort ( ("\RPC Control\ntsvcs", {12, 2, 1, 1}, 0x0, 0x0, 1233888, 188, ... 260, 0x0, 0x0, 0x0, 188, ) , {12, 2, 1, 1}, 0x0, 0x0, 1233888, 188, ... 260, 0x0, 0x0, 0x0, 188, ) == 0x0 02453 464 NtRequestWaitReplyPort (260, {200, 224, new_msg, 0, 2621478, 1475528, 12, 2} (260, {200, 224, new_msg, 0, 2621478, 1475528, 12, 2} "\0\1\25\0\10\0\0\0\274\0\0\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\2\0\4\0\0\0\3008\25\0\4\0\0\0\10\0\0\0\310\1\25\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0\272\362\352\347j\365\24tP~\26\0\320\223\207L\12\0\0\0\0\0\0\0P~\26\0(\0\0\0X~\26\0\252\13\271\363\240\1\25\0\310\200\26\0jc\0\0\0\0\0\0\0\0\0\0\310\200\26\0P\0\0\0\320\200\26\0\360\6\221|\310\1\25\0P\0\0\0\346\31\0\0\0\0\25\0`\322\22\0\372\31\221|\364\331\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ... {200, 224, reply, 0, 1036, 464, 57987, 0} "\7\1\25\0\10\0\0\0\274\0\0\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\3008\25\0\377\377\377\377\10\0\0\0\310\1\25\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0\272\362\352\347j\365\24tP~\26\0\320\223\207L\12\0\0\0\0\0\0\0P~\26\0(\0\0\0X~\26\0\252\13\271\363\240\1\25\0\310\200\26\0jc\0\0\0\0\0\0\0\0\0\0\310\200\26\0P\0\0\0\320\200\26\0\360\6\221|\310\1\25\0P\0\0\0\346\31\0\0\0\0\25\0`\322\22\0\372\31\221|\364\331\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ) ... {200, 224, reply, 0, 1036, 464, 57987, 0} (260, {200, 224, new_msg, 0, 2621478, 1475528, 12, 2} "\0\1\25\0\10\0\0\0\274\0\0\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\2\0\4\0\0\0\3008\25\0\4\0\0\0\10\0\0\0\310\1\25\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0\272\362\352\347j\365\24tP~\26\0\320\223\207L\12\0\0\0\0\0\0\0P~\26\0(\0\0\0X~\26\0\252\13\271\363\240\1\25\0\310\200\26\0jc\0\0\0\0\0\0\0\0\0\0\310\200\26\0P\0\0\0\320\200\26\0\360\6\221|\310\1\25\0P\0\0\0\346\31\0\0\0\0\25\0`\322\22\0\372\31\221|\364\331\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ... {200, 224, reply, 0, 1036, 464, 57987, 0} "\7\1\25\0\10\0\0\0\274\0\0\0@N\237\215=\240\316\21\217i\10\0>0\5\33\1\0\0\0\1\0\0\0\0\0\0\0\4\0\0\0\3008\25\0\377\377\377\377\10\0\0\0\310\1\25\0\0\0\0\0\0\0\0\0\0\0\377\377\4\0\0\0\272\362\352\347j\365\24tP~\26\0\320\223\207L\12\0\0\0\0\0\0\0P~\26\0(\0\0\0X~\26\0\252\13\271\363\240\1\25\0\310\200\26\0jc\0\0\0\0\0\0\0\0\0\0\310\200\26\0P\0\0\0\320\200\26\0\360\6\221|\310\1\25\0P\0\0\0\346\31\0\0\0\0\25\0`\322\22\0\372\31\221|\364\331\22\0\30\356\220|\0\0\0\0\0\0\0\0\0\0\0\0\351\201\347w" ) ) == 0x0 02454 464 NtRequestWaitReplyPort (260, {112, 136, new_msg, 0, 44, 3, 20, 0} (260, {112, 136, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\27\0\274\235tH\233\354\372\234W@\301\22"\0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {68, 92, reply, 0, 1036, 464, 57988, 0} "\2+\263\341\1\0T\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) \0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0 (260, {112, 136, new_msg, 0, 44, 3, 20, 0} "\1\0\0\0A\2\27\0\274\235tH\233\354\372\234W@\301\22"\0$\0\377\377\377\377\22\0\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\0\0\0\0P\0r\0i\0v\0i\0l\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {68, 92, reply, 0, 1036, 464, 57988, 0} "\2+\263\341\1\0T\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) \2+\263\341\1\0T\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ) == 0x0 02455 464 NtOpenThreadToken (-2, 0x20, 1, ... ) == STATUS_NO_TOKEN 02456 464 NtOpenProcessToken (-1, 0x20, ... 264, ) == 0x0 02457 464 NtAdjustPrivilegesToken (264, 0, 1475984, 0, 0, 0, ... ) == 0x0 02458 464 NtClose (264, ... ) == 0x0 02459 464 NtRequestWaitReplyPort (260, {140, 164, new_msg, 0, 1036, 464, 57988, 0} (260, {140, 164, new_msg, 0, 1036, 464, 57988, 0} "\1+\0\0A\2\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\1\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {40, 64, reply, 0, 1036, 464, 57989, 0} "\2\314\274\201\4\0[\200\377\3\37\0\240\314\274\201\0\374\340\377H=\266\367U&\\200d=\266\367\274\1\0\0\360>\11\0" ) ... {40, 64, reply, 0, 1036, 464, 57989, 0} (260, {140, 164, new_msg, 0, 1036, 464, 57988, 0} "\1+\0\0A\2\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\377\377\377\377\0\1\0\0\15c\365S\277\266\320\21\224\362\0\240\311\36\373\213\0\0\0\0\306\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0e\0g\0e\0l\0e\0g\0e\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0" ... {40, 64, reply, 0, 1036, 464, 57989, 0} "\2\314\274\201\4\0[\200\377\3\37\0\240\314\274\201\0\374\340\377H=\266\367U&\\200d=\266\367\274\1\0\0\360>\11\0" ) ) == 0x0 02460 464 NtRequestWaitReplyPort (260, {64, 88, new_msg, 56, 1470688, 1234392, 1234492, 0} (260, {64, 88, new_msg, 56, 1470688, 1234392, 1234492, 0} "\10\326\22\0@\0\26\0\346\277\347w<\326\22\0\330\325\22\0\20\0\0\0\300j\222wTq\26\0\1\0\0\0\270\205\26\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\210k\26\0" ... {64, 88, reply, 56, 1036, 464, 57990, 0} "\10\326\22\0@\0\26\0\346\277\347w<\326\22\0\330\325\22\0\20\0\0\0\300j\222wTq\26\0\1\0\0\0\270\205\26\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\210k\26\0" ) ... {64, 88, reply, 56, 1036, 464, 57990, 0} (260, {64, 88, new_msg, 56, 1470688, 1234392, 1234492, 0} "\10\326\22\0@\0\26\0\346\277\347w<\326\22\0\330\325\22\0\20\0\0\0\300j\222wTq\26\0\1\0\0\0\270\205\26\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\210k\26\0" ... {64, 88, reply, 56, 1036, 464, 57990, 0} "\10\326\22\0@\0\26\0\346\277\347w<\326\22\0\330\325\22\0\20\0\0\0\300j\222wTq\26\0\1\0\0\0\270\205\26\0\274\1\0\0\274\1\0\0\360>\11\0\0\0\0\0\0\0\0\0\210k\26\0" ) ) == 0x0 02461 464 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 264, {status=0x0, info=1}, ) }, 3, 96, ... 264, {status=0x0, info=1}, ) == 0x0 02462 464 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 268, ) }, ... 268, ) == 0x0 02463 464 NtQuerySymbolicLinkObject (268, ... (268, ... "\Device\FloppyPDO0", 38, ) , 38, ) == 0x0 02464 464 NtClose (268, ... ) == 0x0 02465 464 NtQueryVolumeInformationFile (264, 1233164, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02466 464 NtClose (264, ... ) == 0x0 02467 464 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 264, {status=0x0, info=1}, ) }, 3, 16, ... 264, {status=0x0, info=1}, ) == 0x0 02468 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, (264, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=32}, "\36\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", ) , ) == 0x0 02469 464 NtClose (264, ... ) == 0x0 02470 464 NtQueryInformationFile (-1, 1234216, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 02471 464 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1234168, (0x100080, {24, 0, 0x40, 0, 1234168, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) == 0x0 02472 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0008, (264, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 32, ... , 54, 32, ... 02473 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482584, {status=0x0, info=1}, ) }, 0, 64, ... -2147482584, {status=0x0, info=1}, ) == 0x0 02474 464 NtClose (-2147482584, ... ) == 0x0 02472 464 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 02475 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0008, (264, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0\36\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0", 54, 374, ... , 54, 374, ... 02476 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\Floppy0"}, 0, 64, ... -2147482584, {status=0x0, info=1}, ) }, 0, 64, ... -2147482584, {status=0x0, info=1}, ) == 0x0 02477 464 NtClose (-2147482584, ... ) == 0x0 02475 464 NtDeviceIoControlFile ... {status=0x0, info=374}, ... {status=0x0, info=374}, "v\1\0\0\2\0\0\0\372\0\0\0`\0\0\08\0\0\0\244\0\0\0\334\0\0\0\36\0v\0Z\1\0\0\34\0\\08\0\0\0\244\0p\0\334\0\0\0\36\0\0\0\\0?\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\\0D\0e\0v\0i\0c\0e\0\\0F\0l\0o\0p\0p\0y\00\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0A\0:\0", ) , ) == 0x0 02478 464 NtClose (264, ... ) == 0x0 02479 464 NtAllocateVirtualMemory (-1, 1478656, 0, 4096, 4096, 4, ... 1478656, 4096, ) == 0x0 02480 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 264, ) }, ... 264, ) == 0x0 02481 464 NtOpenKey (0x2000000, {24, 264, 0x40, 0, 0, (0x2000000, {24, 264, 0x40, 0, 0, "{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, ... 268, ) }, ... 268, ) == 0x0 02482 464 NtClose (264, ... ) == 0x0 02483 464 NtQueryValueKey (268, (268, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02484 464 NtQueryValueKey (268, (268, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\265\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\14\1\0\0\265\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\266\11\0\0\14\4\0\0\320\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0T\0\0\0$\325\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0`\325\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) , Partial, 710, ... TitleIdx=0, Type=3, Data= (268, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0F\0D\0C\0#\0G\0E\0N\0E\0R\0I\0C\0_\0F\0L\0O\0P\0P\0Y\0_\0D\0R\0I\0V\0E\0#\06\0&\01\04\03\05\0b\02\0e\02\0&\00\0&\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\265\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\14\1\0\0\265\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\266\11\0\0\14\4\0\0\320\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0T\0\0\0$\325\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0`\325\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) }, 710, ) == 0x0 02485 464 NtClose (268, ... ) == 0x0 02486 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 268, ) }, ... 268, ) == 0x0 02487 464 NtOpenKey (0x2000000, {24, 268, 0x40, 0, 0, (0x2000000, {24, 268, 0x40, 0, 0, "{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, ... 264, ) }, ... 264, ) == 0x0 02488 464 NtClose (268, ... ) == 0x0 02489 464 NtQueryValueKey (264, (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02490 464 NtClose (264, ... ) == 0x0 02491 464 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 96, ... 264, {status=0x0, info=0}, ) }, 3, 96, ... 264, {status=0x0, info=0}, ) == 0x0 02492 464 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, ... 268, ) }, ... 268, ) == 0x0 02493 464 NtQuerySymbolicLinkObject (268, ... (268, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 02494 464 NtClose (268, ... ) == 0x0 02495 464 NtQueryVolumeInformationFile (264, 1233164, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02496 464 NtClose (264, ... ) == 0x0 02497 464 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\STORAGE#Volume#1&30a96598&0&Signature14C814C8Offset7E00Length1FF582800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"}, 3, 16, ... 264, {status=0x0, info=0}, ) }, 3, 16, ... 264, {status=0x0, info=0}, ) == 0x0 02498 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, (264, 0, 0x0, 0x0, 0x4d0008, 0x0, 0, 520, ... {status=0x0, info=48}, ".\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", ) , ) == 0x0 02499 464 NtClose (264, ... ) == 0x0 02500 464 NtQueryInformationFile (-1, 1234216, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 02501 464 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1234168, (0x100080, {24, 0, 0x40, 0, 1234168, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) == 0x0 02502 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0008, (264, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 32, ... , 70, 32, ... 02503 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482584, {status=0x0, info=0}, ) }, 0, 64, ... -2147482584, {status=0x0, info=0}, ) == 0x0 02504 464 NtClose (-2147482584, ... ) == 0x0 02502 464 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 02505 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0008, (264, 0, 0x0, 0x0, 0x6d0008, "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\0\0\0.\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0", 70, 238, ... , 70, 238, ... 02506 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\Device\HarddiskVolume1"}, 0, 64, ... -2147482584, {status=0x0, info=0}, ) }, 0, 64, ... -2147482584, {status=0x0, info=0}, ) == 0x0 02507 464 NtClose (-2147482584, ... ) == 0x0 02505 464 NtDeviceIoControlFile ... {status=0x0, info=238}, ... {status=0x0, info=238}, "\356\0\0\0\2\0\0\0r\0\0\0`\0\0\08\0\0\0\14\0\0\0D\0\0\0.\0v\0\322\0\0\0\34\0\\08\0\0\0\14\0d\0D\0\0\0.\0k\0\310\24\310\24\0~\0\0\0\0\0\0\\0D\0e\0v\0i\0c\0e\0\\0H\0a\0r\0d\0d\0i\0s\0k\0V\0o\0l\0u\0m\0e\01\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\\0D\0o\0s\0D\0e\0v\0i\0c\0e\0s\0\\0C\0:\0", ) , ) == 0x0 02508 464 NtClose (264, ... ) == 0x0 02509 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 264, ) }, ... 264, ) == 0x0 02510 464 NtOpenKey (0x2000000, {24, 264, 0x40, 0, 0, (0x2000000, {24, 264, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 268, ) }, ... 268, ) == 0x0 02511 464 NtClose (264, ... ) == 0x0 02512 464 NtQueryValueKey (268, (268, "Data", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 02513 464 NtQueryValueKey (268, (268, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\322\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\14\1\0\0\322\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\323\11\0\0\14\4\0\0\320\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0T\0\0\0$\325\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0`\325\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) , Partial, 710, ... TitleIdx=0, Type=3, Data= (268, "Data", Partial, 710, ... TitleIdx=0, Type=3, Data="\0\0\0\0\\0\\0?\0\\0S\0T\0O\0R\0A\0G\0E\0#\0V\0o\0l\0u\0m\0e\0#\01\0&\03\00\0a\09\06\05\09\08\0&\00\0&\0S\0i\0g\0n\0a\0t\0u\0r\0e\01\04\0C\08\01\04\0C\08\0O\0f\0f\0s\0e\0t\07\0E\00\00\0L\0e\0n\0g\0t\0h\01\0F\0F\05\08\02\08\00\00\0#\0{\05\03\0f\05\06\03\00\0d\0-\0b\06\0b\0f\0-\01\01\0d\00\0-\09\04\0f\02\0-\00\00\0a\00\0c\09\01\0e\0f\0b\08\0b\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\\0\\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\0\0\0\0\0\306\2\0\0\322\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\14\1\0\0\322\11\0\0\14\4\0\0\320\1\0\0\17\0\0\0\1\0\1\0\0\0\0\0\0\0\0\0\323\11\0\0\14\4\0\0\320\1\0\0Q\0\0\0\0\0\1\0\0\0\0\0\304\0\0\0\0\0\0\2\0\0\0\0\30\0\0\0T\0\0\0$\325\22\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\224\0\226\0`\325\22\0\0\0\0\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0"}, 710, ) }, 710, ) == 0x0 02514 464 NtClose (268, ... ) == 0x0 02515 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 268, ) }, ... 268, ) == 0x0 02516 464 NtOpenKey (0x2000000, {24, 268, 0x40, 0, 0, (0x2000000, {24, 268, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 264, ) }, ... 264, ) == 0x0 02517 464 NtClose (268, ... ) == 0x0 02518 464 NtQueryValueKey (264, (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02519 464 NtClose (264, ... ) == 0x0 02520 464 NtQueryInformationFile (-1, 1235556, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 02521 464 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1235508, (0x100080, {24, 0, 0x40, 0, 1235508, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) == 0x0 02522 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 02523 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=0}, ) }, 0, 64, ... -2147482584, {status=0x0, info=0}, ) == 0x0 02524 464 NtClose (-2147482584, ... ) == 0x0 02522 464 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 02525 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 02526 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=0}, ) }, 0, 64, ... -2147482584, {status=0x0, info=0}, ) == 0x0 02527 464 NtClose (-2147482584, ... ) == 0x0 02525 464 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 02528 464 NtClose (264, ... ) == 0x0 02529 464 NtQueryInformationFile (-1, 1235556, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 02530 464 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1235508, (0x100080, {24, 0, 0x40, 0, 1235508, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) == 0x0 02531 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 02532 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=0}, ) }, 0, 64, ... -2147482584, {status=0x0, info=0}, ) == 0x0 02533 464 NtClose (-2147482584, ... ) == 0x0 02531 464 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 02534 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\03\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 02535 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d3-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=0}, ) }, 0, 64, ... -2147482584, {status=0x0, info=0}, ) == 0x0 02536 464 NtClose (-2147482584, ... ) == 0x0 02534 464 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0C\0:\0\0\0\0\0", ) , ) == 0x0 02537 464 NtClose (264, ... ) == 0x0 02538 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, 0, 0x0, 0, ... 264, 2, ) }, 0, 0x0, 0, ... 264, 2, ) == 0x0 02539 464 NtSetValueKey (264, (264, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (264, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 02540 464 NtClose (264, ... ) == 0x0 02541 464 NtQueryInformationFile (-1, 1235556, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 02542 464 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1235508, (0x100080, {24, 0, 0x40, 0, 1235508, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) == 0x0 02543 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 02544 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=1}, ) }, 0, 64, ... -2147482584, {status=0x0, info=1}, ) == 0x0 02545 464 NtClose (-2147482584, ... ) == 0x0 02543 464 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 02546 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 02547 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=1}, ) }, 0, 64, ... -2147482584, {status=0x0, info=1}, ) == 0x0 02548 464 NtClose (-2147482584, ... ) == 0x0 02546 464 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 02549 464 NtClose (264, ... ) == 0x0 02550 464 NtQueryInformationFile (-1, 1235556, 4, Ea, ... ) == STATUS_OBJECT_TYPE_MISMATCH 02551 464 NtCreateFile (0x100080, {24, 0, 0x40, 0, 1235508, (0x100080, {24, 0, 0x40, 0, 1235508, "\??\MountPointManager"}, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) }, 0x0, 128, 3, 1, 96, 0, 0, ... 264, {status=0x0, info=0}, ) == 0x0 02552 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 8, ... , 520, 8, ... 02553 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=1}, ) }, 0, 64, ... -2147482584, {status=0x0, info=1}, ) == 0x0 02554 464 NtClose (-2147482584, ... ) == 0x0 02552 464 NtDeviceIoControlFile ... ) == STATUS_BUFFER_OVERFLOW 02555 464 NtDeviceIoControlFile (264, 0, 0x0, 0x0, 0x6d0034, (264, 0, 0x0, 0x0, 0x6d0034, "`\0\\0?\0?\0\\0V\0o\0l\0u\0m\0e\0{\0a\0c\05\03\0e\07\0d\00\0-\0b\09\06\0f\0-\01\01\0d\0b\0-\0a\04\08\08\0-\08\00\06\0d\06\01\07\02\06\09\06\0f\0}\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 520, 16, ... , 520, 16, ... 02556 464 NtOpenFile (0x80, {24, 0, 0x200, 0, 0, (0x80, {24, 0, 0x200, 0, 0, "\??\Volume{ac53e7d0-b96f-11db-a488-806d6172696f}"}, 0, 64, ... -2147482584, {status=0x0, info=1}, ) }, 0, 64, ... -2147482584, {status=0x0, info=1}, ) == 0x0 02557 464 NtClose (-2147482584, ... ) == 0x0 02555 464 NtDeviceIoControlFile ... {status=0x0, info=12}, ... {status=0x0, info=12}, "\10\0\0\0A\0:\0\0\0\0\0", ) , ) == 0x0 02558 464 NtClose (264, ... ) == 0x0 02559 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac53e7d0-b96f-11db-a488-806d6172696f}\"}, 0, 0x0, 0, ... 264, 2, ) }, 0, 0x0, 0, ... 264, 2, ) == 0x0 02560 464 NtSetValueKey (264, (264, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 0, 1, (264, "BaseClass", 0, 1, "D\0r\0i\0v\0e\0\0\0", 12, ... ) , 12, ... ) == 0x0 02561 464 NtClose (264, ... ) == 0x0 02562 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02563 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02564 464 NtOpenFile (0x100080, {24, 0, 0x40, 0, 0, (0x100080, {24, 0, 0x40, 0, 0, "\??\U:"}, 3, 96, ... 264, {status=0x0, info=1}, ) }, 3, 96, ... 264, {status=0x0, info=1}, ) == 0x0 02565 464 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\U:"}, ... 268, ) }, ... 268, ) == 0x0 02566 464 NtQuerySymbolicLinkObject (268, ... (268, ... "\Device\WinDfs\U:0000000000009f43", 66, ) , 66, ) == 0x0 02567 464 NtClose (268, ... ) == 0x0 02568 464 NtQueryVolumeInformationFile (264, 1234552, 8, Device, ... {status=0x0, info=8}, ) == 0x0 02569 464 NtClose (264, ... ) == 0x0 02570 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02571 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 264, ) }, ... 264, ) == 0x0 02572 464 NtOpenKey (0x2000000, {24, 264, 0x40, 0, 0, (0x2000000, {24, 264, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 268, ) }, ... 268, ) == 0x0 02573 464 NtClose (264, ... ) == 0x0 02574 464 NtQueryValueKey (268, (268, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (268, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02575 464 NtClose (268, ... ) == 0x0 02576 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 268, {status=0x0, info=1}, ) }, 3, 16417, ... 268, {status=0x0, info=1}, ) == 0x0 02577 464 NtQueryDirectoryFile (268, 0, 0, 0, 1233832, 616, BothDirectory, 1, (268, 0, 0, 0, 1233832, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02578 464 NtClose (268, ... ) == 0x0 02579 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02580 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02581 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Directory"}, ... 268, ) }, ... 268, ) == 0x0 02582 464 NtQueryKey (270, Name, 384, ... {Name= (270, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02583 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02584 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 264, ) == 0x0 02585 464 NtQueryInformationToken (264, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02586 464 NtClose (264, ... ) == 0x0 02587 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02588 464 NtOpenKey (0x1, {24, 270, 0x40, 0, 0, (0x1, {24, 270, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02589 464 NtQueryKey (270, Name, 384, ... {Name= (270, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02590 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02591 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 264, ) == 0x0 02592 464 NtQueryInformationToken (264, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02593 464 NtClose (264, ... ) == 0x0 02594 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02595 464 NtOpenKey (0x2000000, {24, 270, 0x40, 0, 0, ""}, ... 264, ) == 0x0 02596 464 NtClose (270, ... ) == 0x0 02597 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02598 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02599 464 NtReleaseSemaphore (228, 1, ... 59, ) == 0x0 02600 464 NtWaitForSingleObject (228, 0, {0, 0}, ... ) == 0x0 02601 464 NtQueryKey (266, Name, 384, ... {Name= (266, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02602 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02603 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 268, ) == 0x0 02604 464 NtQueryInformationToken (268, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02605 464 NtClose (268, ... ) == 0x0 02606 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory\ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02607 464 NtOpenKey (0x1, {24, 266, 0x40, 0, 0, (0x1, {24, 266, 0x40, 0, 0, "ShellEx\IconHandler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02608 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02609 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02610 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 268, ) == 0x0 02611 464 NtQueryInformationToken (268, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02612 464 NtClose (268, ... ) == 0x0 02613 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02614 464 NtQueryValueKey (266, (266, "DocObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02615 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02616 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02617 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 268, ) == 0x0 02618 464 NtQueryInformationToken (268, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02619 464 NtClose (268, ... ) == 0x0 02620 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02621 464 NtQueryValueKey (266, (266, "BrowseInPlace", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02622 464 NtQueryKey (266, Name, 384, ... {Name= (266, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02623 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02624 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 268, ) == 0x0 02625 464 NtQueryInformationToken (268, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02626 464 NtClose (268, ... ) == 0x0 02627 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02628 464 NtOpenKey (0x1, {24, 266, 0x40, 0, 0, (0x1, {24, 266, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02629 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02630 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "Folder"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02631 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Folder"}, ... 268, ) }, ... 268, ) == 0x0 02632 464 NtQueryKey (270, Name, 384, ... {Name= (270, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Foldert"}, 86, ) }, 86, ) == 0x0 02633 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02634 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 272, ) == 0x0 02635 464 NtQueryInformationToken (272, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02636 464 NtClose (272, ... ) == 0x0 02637 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Folder\Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02638 464 NtOpenKey (0x1, {24, 270, 0x40, 0, 0, (0x1, {24, 270, 0x40, 0, 0, "Clsid"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02639 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02640 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02641 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 272, ) == 0x0 02642 464 NtQueryInformationToken (272, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02643 464 NtClose (272, ... ) == 0x0 02644 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02645 464 NtQueryValueKey (266, (266, "IsShortcut", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02646 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02647 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02648 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 272, ) == 0x0 02649 464 NtQueryInformationToken (272, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02650 464 NtClose (272, ... ) == 0x0 02651 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02652 464 NtQueryValueKey (266, (266, "AlwaysShowExt", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (266, "AlwaysShowExt", Partial, 144, ... TitleIdx=0, Type=1, Data="\0\0"}, 14, ) }, 14, ) == 0x0 02653 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\Directory"}, 92, ) }, 92, ) == 0x0 02654 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02655 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 272, ) == 0x0 02656 464 NtQueryInformationToken (272, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02657 464 NtClose (272, ... ) == 0x0 02658 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\Directory"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02659 464 NtQueryValueKey (266, (266, "NeverShowExt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02660 464 NtClose (266, ... ) == 0x0 02661 464 NtClose (270, ... ) == 0x0 02662 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 268, {status=0x0, info=1}, ) }, 3, 16417, ... 268, {status=0x0, info=1}, ) == 0x0 02663 464 NtQueryDirectoryFile (268, 0, 0, 0, 1233712, 616, BothDirectory, 1, (268, 0, 0, 0, 1233712, 616, BothDirectory, 1, "Martim Carbone", 0, ... {status=0x0, info=122}, ) , 0, ... {status=0x0, info=122}, ) == 0x0 02664 464 NtClose (268, ... ) == 0x0 02665 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\"}, 3, 16417, ... 268, {status=0x0, info=1}, ) }, 3, 16417, ... 268, {status=0x0, info=1}, ) == 0x0 02666 464 NtQueryDirectoryFile (268, 0, 0, 0, 1233620, 616, BothDirectory, 1, (268, 0, 0, 0, 1233620, 616, BothDirectory, 1, "My Documents", 0, ... {status=0x0, info=118}, ) , 0, ... {status=0x0, info=118}, ) == 0x0 02667 464 NtClose (268, ... ) == 0x0 02668 464 NtAllocateVirtualMemory (-1, 1220608, 0, 4096, 4096, 260, ... 1220608, 4096, ) == 0x0 02669 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02670 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02671 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02672 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 1228896, ... ) }, 1228896, ... ) == 0x0 02673 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02674 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02675 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02676 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02677 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02678 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 268, ) }, ... 268, ) == 0x0 02679 464 NtQueryValueKey (268, (268, "UseDesktopIniCache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02680 464 NtClose (268, ... ) == 0x0 02681 464 NtAllocateVirtualMemory (-1, 1482752, 0, 4096, 4096, 4, ... 1482752, 4096, ) == 0x0 02682 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 7, 96, ... 268, {status=0x0, info=1}, ) }, 7, 96, ... 268, {status=0x0, info=1}, ) == 0x0 02683 464 NtLockFile (268, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=31}, ) == 0x0 02684 464 NtQueryInformationFile (268, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02685 464 NtAllocateVirtualMemory (-1, 0, 0, 1048665, 8192, 4, ... 13565952, 1052672, ) == 0x0 02686 464 NtAllocateVirtualMemory (-1, 13565952, 0, 89, 4096, 4, ... 13565952, 4096, ) == 0x0 02687 464 NtReadFile (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, "[DeleteOnCopy]\15\12Owner=Martim Carbone\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02688 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02689 464 NtUnlockFile (268, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02690 464 NtClose (268, ... ) == 0x0 02691 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02692 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02693 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 7, 96, ... 268, {status=0x0, info=1}, ) }, 7, 96, ... 268, {status=0x0, info=1}, ) == 0x0 02694 464 NtLockFile (268, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=1228472}, ) == 0x0 02695 464 NtQueryInformationFile (268, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02696 464 NtAllocateVirtualMemory (-1, 0, 0, 1048665, 8192, 4, ... 13565952, 1052672, ) == 0x0 02697 464 NtAllocateVirtualMemory (-1, 13565952, 0, 89, 4096, 4, ... 13565952, 4096, ) == 0x0 02698 464 NtReadFile (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, "[DeleteOnCopy]\15\12Owner=Martim Carbone\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02699 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02700 464 NtUnlockFile (268, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02701 464 NtClose (268, ... ) == 0x0 02702 464 NtOpenProcessToken (-1, 0x8, ... 268, ) == 0x0 02703 464 NtQueryInformationToken (268, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02704 464 NtClose (268, ... ) == 0x0 02705 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02706 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02707 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02708 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 1228896, ... ) }, 1228896, ... ) == 0x0 02709 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02710 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02711 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02712 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02713 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 7, 96, ... 268, {status=0x0, info=1}, ) }, 7, 96, ... 268, {status=0x0, info=1}, ) == 0x0 02714 464 NtLockFile (268, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=1228472}, ) == 0x0 02715 464 NtQueryInformationFile (268, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02716 464 NtAllocateVirtualMemory (-1, 0, 0, 1048665, 8192, 4, ... 13565952, 1052672, ) == 0x0 02717 464 NtAllocateVirtualMemory (-1, 13565952, 0, 89, 4096, 4, ... 13565952, 4096, ) == 0x0 02718 464 NtReadFile (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, "[DeleteOnCopy]\15\12Owner=Martim Carbone\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02719 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02720 464 NtUnlockFile (268, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02721 464 NtClose (268, ... ) == 0x0 02722 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02723 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02724 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 7, 96, ... 268, {status=0x0, info=1}, ) }, 7, 96, ... 268, {status=0x0, info=1}, ) == 0x0 02725 464 NtLockFile (268, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=31}, ) == 0x0 02726 464 NtQueryInformationFile (268, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02727 464 NtAllocateVirtualMemory (-1, 0, 0, 1048665, 8192, 4, ... 13565952, 1052672, ) == 0x0 02728 464 NtAllocateVirtualMemory (-1, 13565952, 0, 89, 4096, 4, ... 13565952, 4096, ) == 0x0 02729 464 NtReadFile (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, "[DeleteOnCopy]\15\12Owner=Martim Carbone\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02730 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02731 464 NtUnlockFile (268, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02732 464 NtClose (268, ... ) == 0x0 02733 464 NtOpenProcessToken (-1, 0x8, ... 268, ) == 0x0 02734 464 NtQueryInformationToken (268, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02735 464 NtClose (268, ... ) == 0x0 02736 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02737 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02738 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02739 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 1230956, ... ) }, 1230956, ... ) == 0x0 02740 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02741 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02742 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02743 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02744 464 NtAllocateVirtualMemory (-1, 1486848, 0, 4096, 4096, 4, ... 1486848, 4096, ) == 0x0 02745 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 7, 96, ... 268, {status=0x0, info=1}, ) }, 7, 96, ... 268, {status=0x0, info=1}, ) == 0x0 02746 464 NtLockFile (268, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=1231736}, ) == 0x0 02747 464 NtQueryInformationFile (268, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02748 464 NtAllocateVirtualMemory (-1, 0, 0, 1048665, 8192, 4, ... 13565952, 1052672, ) == 0x0 02749 464 NtAllocateVirtualMemory (-1, 13565952, 0, 89, 4096, 4, ... 13565952, 4096, ) == 0x0 02750 464 NtReadFile (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, "[DeleteOnCopy]\15\12Owner=Martim Carbone\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02751 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02752 464 NtUnlockFile (268, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02753 464 NtClose (268, ... ) == 0x0 02754 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02755 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02756 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02757 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 1229400, ... ) }, 1229400, ... ) == 0x0 02758 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02759 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02760 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02761 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02762 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\My Documents\desktop.ini"}, 7, 96, ... 268, {status=0x0, info=1}, ) }, 7, 96, ... 268, {status=0x0, info=1}, ) == 0x0 02763 464 NtLockFile (268, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=31}, ) == 0x0 02764 464 NtQueryInformationFile (268, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02765 464 NtAllocateVirtualMemory (-1, 0, 0, 1048665, 8192, 4, ... 13565952, 1052672, ) == 0x0 02766 464 NtAllocateVirtualMemory (-1, 13565952, 0, 89, 4096, 4, ... 13565952, 4096, ) == 0x0 02767 464 NtReadFile (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, (268, 0, 0, 0, 85, 0x0, 2089305604, ... {status=0x0, info=85}, "[DeleteOnCopy]\15\12Owner=Martim Carbone\15\12Personalized=5\15\12PersonalizedName=My Documents\15\12", ) , ) == 0x0 02768 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02769 464 NtUnlockFile (268, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02770 464 NtClose (268, ... ) == 0x0 02771 464 NtOpenProcessToken (-1, 0x8, ... 268, ) == 0x0 02772 464 NtQueryInformationToken (268, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02773 464 NtClose (268, ... ) == 0x0 02774 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02775 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02776 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02777 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02778 464 NtCreateKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 268, 2, ) }, 0, 0x0, 0, ... 268, 2, ) == 0x0 02779 464 NtQueryValueKey (268, (268, "Common Documents", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 68, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (268, "Common Documents", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0"}, 68, ) }, 68, ) == 0x0 02780 464 NtClose (268, ... ) == 0x0 02781 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents"}, 1235632, ... ) }, 1235632, ... ) == 0x0 02782 464 NtCreateKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 268, 2, ) }, 0, 0x0, 0, ... 268, 2, ) == 0x0 02783 464 NtSetValueKey (268, (268, "Common Documents", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 92, ... ) , 0, 1, (268, "Common Documents", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0\0\0", 92, ... ) , 92, ... ) == 0x0 02784 464 NtClose (268, ... ) == 0x0 02785 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02786 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02787 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 268, ) }, ... 268, ) == 0x0 02788 464 NtOpenKey (0x2000000, {24, 268, 0x40, 0, 0, (0x2000000, {24, 268, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 264, ) }, ... 264, ) == 0x0 02789 464 NtClose (268, ... ) == 0x0 02790 464 NtQueryValueKey (264, (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02791 464 NtClose (264, ... ) == 0x0 02792 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 02793 464 NtQueryDirectoryFile (264, 0, 0, 0, 1233848, 616, BothDirectory, 1, (264, 0, 0, 0, 1233848, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02794 464 NtClose (264, ... ) == 0x0 02795 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 02796 464 NtQueryDirectoryFile (264, 0, 0, 0, 1233744, 616, BothDirectory, 1, (264, 0, 0, 0, 1233744, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02797 464 NtClose (264, ... ) == 0x0 02798 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 02799 464 NtQueryDirectoryFile (264, 0, 0, 0, 1233660, 616, BothDirectory, 1, (264, 0, 0, 0, 1233660, 616, BothDirectory, 1, "Documents", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02800 464 NtClose (264, ... ) == 0x0 02801 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02802 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02803 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02804 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1228936, ... ) }, 1228936, ... ) == 0x0 02805 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02806 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02807 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02808 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02809 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 264, {status=0x0, info=1}, ) }, 7, 96, ... 264, {status=0x0, info=1}, ) == 0x0 02810 464 NtLockFile (264, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=1228512}, ) == 0x0 02811 464 NtQueryInformationFile (264, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02812 464 NtAllocateVirtualMemory (-1, 0, 0, 1048710, 8192, 4, ... 13565952, 1052672, ) == 0x0 02813 464 NtAllocateVirtualMemory (-1, 13565952, 0, 134, 4096, 4, ... 13565952, 4096, ) == 0x0 02814 464 NtReadFile (264, 0, 0, 0, 130, 0x0, 2089305604, ... {status=0x0, info=130}, (264, 0, 0, 0, 130, 0x0, 2089305604, ... {status=0x0, info=130}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on VIRTUAL\15\12", ) , ) == 0x0 02815 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02816 464 NtUnlockFile (264, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02817 464 NtClose (264, ... ) == 0x0 02818 464 NtOpenProcessToken (-1, 0x8, ... 264, ) == 0x0 02819 464 NtQueryInformationToken (264, Statistics, 56, ... {token info, class 10, size 56}, 56, ) == 0x0 02820 464 NtClose (264, ... ) == 0x0 02821 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02822 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02823 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02824 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1228908, ... ) }, 1228908, ... ) == 0x0 02825 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02826 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02827 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02828 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02829 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 264, {status=0x0, info=1}, ) }, 7, 96, ... 264, {status=0x0, info=1}, ) == 0x0 02830 464 NtLockFile (264, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=31}, ) == 0x0 02831 464 NtQueryInformationFile (264, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02832 464 NtAllocateVirtualMemory (-1, 0, 0, 1048710, 8192, 4, ... 13565952, 1052672, ) == 0x0 02833 464 NtAllocateVirtualMemory (-1, 13565952, 0, 134, 4096, 4, ... 13565952, 4096, ) == 0x0 02834 464 NtReadFile (264, 0, 0, 0, 130, 0x0, 2089305604, ... {status=0x0, info=130}, (264, 0, 0, 0, 130, 0x0, 2089305604, ... {status=0x0, info=130}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on VIRTUAL\15\12", ) , ) == 0x0 02835 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02836 464 NtUnlockFile (264, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02837 464 NtClose (264, ... ) == 0x0 02838 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02839 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02840 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02841 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 1229440, ... ) }, 1229440, ... ) == 0x0 02842 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 02843 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 02844 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 02845 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 02846 464 NtOpenFile (0x80100000, {24, 0, 0x40, 0, 0, (0x80100000, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Documents\desktop.ini"}, 7, 96, ... 264, {status=0x0, info=1}, ) }, 7, 96, ... 264, {status=0x0, info=1}, ) == 0x0 02847 464 NtLockFile (264, 0, 0, 0, {0, 0}, {-1, -1}, 1, 0, 0, ... {status=0x0, info=1230788}, ) == 0x0 02848 464 NtQueryInformationFile (264, 1483600, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 02849 464 NtAllocateVirtualMemory (-1, 0, 0, 1048710, 8192, 4, ... 13565952, 1052672, ) == 0x0 02850 464 NtAllocateVirtualMemory (-1, 13565952, 0, 134, 4096, 4, ... 13565952, 4096, ) == 0x0 02851 464 NtReadFile (264, 0, 0, 0, 130, 0x0, 2089305604, ... {status=0x0, info=130}, (264, 0, 0, 0, 130, 0x0, 2089305604, ... {status=0x0, info=130}, "[.ShellClassInfo]\15\12LocalizedResourceName=@shell32.dll,-21785\15\12[FileSharingInformation]\15\12ShortcutName=Shared Documents on VIRTUAL\15\12", ) , ) == 0x0 02852 464 NtFreeVirtualMemory (-1, (0xcf0000), 1052672, 32768, ... (0xcf0000), 1052672, ) == 0x0 02853 464 NtUnlockFile (264, {0, 0}, {-1, -1}, 464, ... ) == STATUS_RANGE_NOT_LOCKED 02854 464 NtClose (264, ... ) == 0x0 02855 464 NtAllocateVirtualMemory (-1, 1490944, 0, 4096, 4096, 4, ... 1490944, 4096, ) == 0x0 02856 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 02857 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02858 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02859 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02860 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02861 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 264, 2, ) }, 0, 0x0, 0, ... 264, 2, ) == 0x0 02862 464 NtQueryValueKey (264, (264, "Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (264, "Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 56, ) }, 56, ) == 0x0 02863 464 NtClose (264, ... ) == 0x0 02864 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Desktop"}, 1235632, ... ) }, 1235632, ... ) == 0x0 02865 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 264, 2, ) }, 0, 0x0, 0, ... 264, 2, ) == 0x0 02866 464 NtSetValueKey (264, (264, "Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 98, ... ) , 0, 1, (264, "Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 98, ... ) , 98, ... ) == 0x0 02867 464 NtClose (264, ... ) == 0x0 02868 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02869 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02870 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 264, ) }, ... 264, ) == 0x0 02871 464 NtOpenKey (0x2000000, {24, 264, 0x40, 0, 0, (0x2000000, {24, 264, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 268, ) }, ... 268, ) == 0x0 02872 464 NtClose (264, ... ) == 0x0 02873 464 NtQueryValueKey (268, (268, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (268, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02874 464 NtClose (268, ... ) == 0x0 02875 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 268, {status=0x0, info=1}, ) }, 3, 16417, ... 268, {status=0x0, info=1}, ) == 0x0 02876 464 NtQueryDirectoryFile (268, 0, 0, 0, 1233844, 616, BothDirectory, 1, (268, 0, 0, 0, 1233844, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02877 464 NtClose (268, ... ) == 0x0 02878 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 268, {status=0x0, info=1}, ) }, 3, 16417, ... 268, {status=0x0, info=1}, ) == 0x0 02879 464 NtQueryDirectoryFile (268, 0, 0, 0, 1233732, 616, BothDirectory, 1, (268, 0, 0, 0, 1233732, 616, BothDirectory, 1, "Martim Carbone", 0, ... {status=0x0, info=122}, ) , 0, ... {status=0x0, info=122}, ) == 0x0 02880 464 NtClose (268, ... ) == 0x0 02881 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\"}, 3, 16417, ... 268, {status=0x0, info=1}, ) }, 3, 16417, ... 268, {status=0x0, info=1}, ) == 0x0 02882 464 NtQueryDirectoryFile (268, 0, 0, 0, 1233652, 616, BothDirectory, 1, (268, 0, 0, 0, 1233652, 616, BothDirectory, 1, "Desktop", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02883 464 NtClose (268, ... ) == 0x0 02884 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02885 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02886 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 02887 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 02888 464 NtCreateKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 268, 2, ) }, 0, 0x0, 0, ... 268, 2, ) == 0x0 02889 464 NtQueryValueKey (268, (268, "Common Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 64, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (268, "Common Desktop", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0%\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0"}, 64, ) }, 64, ) == 0x0 02890 464 NtClose (268, ... ) == 0x0 02891 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\Desktop"}, 1235632, ... ) }, 1235632, ... ) == 0x0 02892 464 NtCreateKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 268, 2, ) }, 0, 0x0, 0, ... 268, 2, ) == 0x0 02893 464 NtSetValueKey (268, (268, "Common Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 88, ... ) , 0, 1, (268, "Common Desktop", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\\0D\0e\0s\0k\0t\0o\0p\0\0\0", 88, ... ) , 88, ... ) == 0x0 02894 464 NtClose (268, ... ) == 0x0 02895 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02896 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 02897 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume"}, ... 268, ) }, ... 268, ) == 0x0 02898 464 NtOpenKey (0x2000000, {24, 268, 0x40, 0, 0, (0x2000000, {24, 268, 0x40, 0, 0, "{ac53e7d3-b96f-11db-a488-806d6172696f}\"}, ... 264, ) }, ... 264, ) == 0x0 02899 464 NtClose (268, ... ) == 0x0 02900 464 NtQueryValueKey (264, (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (264, "Generation", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02901 464 NtClose (264, ... ) == 0x0 02902 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 02903 464 NtQueryDirectoryFile (264, 0, 0, 0, 1233852, 616, BothDirectory, 1, (264, 0, 0, 0, 1233852, 616, BothDirectory, 1, "Documents and Settings", 0, ... {status=0x0, info=138}, ) , 0, ... {status=0x0, info=138}, ) == 0x0 02904 464 NtClose (264, ... ) == 0x0 02905 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 02906 464 NtQueryDirectoryFile (264, 0, 0, 0, 1233752, 616, BothDirectory, 1, (264, 0, 0, 0, 1233752, 616, BothDirectory, 1, "All Users", 0, ... {status=0x0, info=112}, ) , 0, ... {status=0x0, info=112}, ) == 0x0 02907 464 NtClose (264, ... ) == 0x0 02908 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\All Users\"}, 3, 16417, ... 264, {status=0x0, info=1}, ) }, 3, 16417, ... 264, {status=0x0, info=1}, ) == 0x0 02909 464 NtQueryDirectoryFile (264, 0, 0, 0, 1233672, 616, BothDirectory, 1, (264, 0, 0, 0, 1233672, 616, BothDirectory, 1, "Desktop", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 02910 464 NtClose (264, ... ) == 0x0 02911 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks"}, ... 264, ) }, ... 264, ) == 0x0 02912 464 NtEnumerateValueKey (264, 0, Full, 220, ... TitleIdx=0, Type=1, Name= (264, 0, Full, 220, ... TitleIdx=0, Type=1, Name="{AEB6717E-7E19-11d0-97EE-00C04FD91972}", Data="\0\0"}, 98, ) , Data= (264, 0, Full, 220, ... TitleIdx=0, Type=1, Name="{AEB6717E-7E19-11d0-97EE-00C04FD91972}", Data="\0\0"}, 98, ) }, 98, ) == 0x0 02913 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02914 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, "CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02915 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\InProcServer32"}, ... 268, ) }, ... 268, ) == 0x0 02916 464 NtQueryKey (270, Name, 392, ... {Name= (270, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, 192, ) }, 192, ) == 0x0 02917 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02918 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 272, ) == 0x0 02919 464 NtQueryInformationToken (272, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02920 464 NtClose (272, ... ) == 0x0 02921 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02922 464 NtQueryValueKey (270, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (270, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="s\0h\0e\0l\0l\03\02\0.\0d\0l\0l\0\0\0"}, 36, ) }, 36, ) == 0x0 02923 464 NtQueryKey (270, Name, 392, ... {Name= (270, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, 192, ) }, 192, ) == 0x0 02924 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02925 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 272, ) == 0x0 02926 464 NtQueryInformationToken (272, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02927 464 NtClose (272, ... ) == 0x0 02928 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02929 464 NtQueryValueKey (270, (270, "LoadWithoutCOM", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02930 464 NtClose (270, ... ) == 0x0 02931 464 NtEnumerateValueKey (264, 1, Full, 220, ... ) == STATUS_NO_MORE_ENTRIES 02932 464 NtClose (264, ... ) == 0x0 02933 464 NtReleaseSemaphore (72, 1, ... 0, ) == 0x0 02934 464 NtWaitForSingleObject (72, 0, {0, 0}, ... ) == 0x0 02935 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02936 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02937 464 NtReleaseSemaphore (72, 1, ... 0, ) == 0x0 02938 464 NtWaitForSingleObject (72, 0, {0, 0}, ... ) == 0x0 02939 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02940 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02941 464 NtReleaseSemaphore (72, 1, ... 0, ) == 0x0 02942 464 NtWaitForSingleObject (72, 0, {0, 0}, ... ) == 0x0 02943 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02944 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02945 464 NtReleaseSemaphore (72, 1, ... 0, ) == 0x0 02946 464 NtWaitForSingleObject (72, 0, {0, 0}, ... ) == 0x0 02947 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02948 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Associations"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02949 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02950 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02951 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 264, ) }, ... 264, ) == 0x0 02952 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 02953 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02954 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 268, ) == 0x0 02955 464 NtQueryInformationToken (268, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02956 464 NtClose (268, ... ) == 0x0 02957 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02958 464 NtQueryValueKey (266, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (266, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="b\0a\0t\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 02959 464 NtClose (266, ... ) == 0x0 02960 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02961 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, ".ade"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02962 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.ade"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02963 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02964 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, ".adp"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02965 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.adp"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02966 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02967 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, ".app"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02968 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.app"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02969 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02970 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, ".asp"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02971 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.asp"}, ... 264, ) }, ... 264, ) == 0x0 02972 464 NtQueryKey (266, Name, 392, ... {Name= (266, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.aspo"}, 82, ) }, 82, ) == 0x0 02973 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 02974 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 268, ) == 0x0 02975 464 NtQueryInformationToken (268, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 02976 464 NtClose (268, ... ) == 0x0 02977 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\.asp"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02978 464 NtQueryValueKey (266, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (266, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="a\0s\0p\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 02979 464 NtClose (266, ... ) == 0x0 02980 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 02981 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, ".bas"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02982 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bas"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02983 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 264, ) }, ... 264, ) == 0x0 02984 464 NtQueryValueKey (264, (264, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (264, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 02985 464 NtClose (264, ... ) == 0x0 02986 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "CLBCATQ.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02987 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\CLBCATQ.DLL"}, 1234564, ... ) }, 1234564, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02988 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\CLBCATQ.DLL"}, 1234564, ... ) }, 1234564, ... ) == 0x0 02989 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\CLBCATQ.DLL"}, 5, 96, ... 264, {status=0x0, info=1}, ) }, 5, 96, ... 264, {status=0x0, info=1}, ) == 0x0 02990 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 264, ... 268, ) == 0x0 02991 464 NtQuerySection (268, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 02992 464 NtClose (264, ... ) == 0x0 02993 464 NtMapViewOfSection (268, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x76fd0000), 0x0, 520192, ) == 0x0 02994 464 NtClose (268, ... ) == 0x0 02995 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 02996 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 02997 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 02998 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "COMRes.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 02999 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\COMRes.dll"}, 1233776, ... ) }, 1233776, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03000 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\COMRes.dll"}, 1233776, ... ) }, 1233776, ... ) == 0x0 03001 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\COMRes.dll"}, 5, 96, ... 268, {status=0x0, info=1}, ) }, 5, 96, ... 268, {status=0x0, info=1}, ) == 0x0 03002 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 268, ... 264, ) == 0x0 03003 464 NtQuerySection (264, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03004 464 NtClose (268, ... ) == 0x0 03005 464 NtMapViewOfSection (264, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77050000), 0x0, 806912, ) == 0x0 03006 464 NtClose (264, ... ) == 0x0 03007 464 NtProtectVirtualMemory (-1, (0x77051000), 8, 4, ... (0x77051000), 4096, 32, ) == 0x0 03008 464 NtProtectVirtualMemory (-1, (0x77051000), 4096, 32, ... (0x77051000), 4096, 4, ) == 0x0 03009 464 NtFlushInstructionCache (-1, 1996820480, 8, ... ) == 0x0 03010 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03011 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03012 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03013 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03014 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03015 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03016 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03017 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03018 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03019 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03020 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03021 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03022 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03023 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03024 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03025 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "OLEAUT32.dll"}, ... 264, ) }, ... 264, ) == 0x0 03026 464 NtMapViewOfSection (264, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77120000), 0x0, 569344, ) == 0x0 03027 464 NtClose (264, ... ) == 0x0 03028 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03029 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03030 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03031 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03032 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03033 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03034 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03035 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03036 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03037 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03038 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03039 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03040 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03041 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03042 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03043 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03044 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03045 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03046 464 NtProtectVirtualMemory (-1, (0x77121000), 1272, 4, ... (0x77121000), 4096, 32, ) == 0x0 03047 464 NtProtectVirtualMemory (-1, (0x77121000), 4096, 32, ... (0x77121000), 4096, 4, ) == 0x0 03048 464 NtFlushInstructionCache (-1, 1997672448, 1272, ... ) == 0x0 03049 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03050 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03051 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03052 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03053 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03054 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03055 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03056 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03057 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03058 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "VERSION.dll"}, ... 264, ) }, ... 264, ) == 0x0 03059 464 NtMapViewOfSection (264, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77c00000), 0x0, 32768, ) == 0x0 03060 464 NtClose (264, ... ) == 0x0 03061 464 NtProtectVirtualMemory (-1, (0x77c01000), 304, 4, ... (0x77c01000), 4096, 32, ) == 0x0 03062 464 NtProtectVirtualMemory (-1, (0x77c01000), 4096, 32, ... (0x77c01000), 4096, 4, ) == 0x0 03063 464 NtFlushInstructionCache (-1, 2009075712, 304, ... ) == 0x0 03064 464 NtProtectVirtualMemory (-1, (0x76fd1000), 1060, 4, ... (0x76fd1000), 4096, 32, ) == 0x0 03065 464 NtProtectVirtualMemory (-1, (0x76fd1000), 4096, 32, ... (0x76fd1000), 4096, 4, ) == 0x0 03066 464 NtFlushInstructionCache (-1, 1996296192, 1060, ... ) == 0x0 03067 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COMRes.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03068 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLEAUT32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03069 464 NtUserRegisterWindowMessage ( ("{FB8F0821-0164-101B-84ED-08002B2EC713}", ... ) , ... ) == 0xc077 03070 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03071 464 NtOpenKey (0x9, {24, 28, 0x40, 0, 0, (0x9, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT\UserEra"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03072 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLEAUT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03073 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VERSION.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03074 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLBCATQ.DLL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03075 464 NtOpenKey (0xf003f, {24, 28, 0x40, 0, 0, (0xf003f, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3\Debug"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03076 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3\Debug"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03077 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\OLE"}, ... 264, ) }, ... 264, ) == 0x0 03078 464 NtQueryValueKey (264, (264, "MinimumFreeMemPercentageToCreateProcess", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03079 464 NtQueryValueKey (264, (264, "MinimumFreeMemPercentageToCreateObject", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03080 464 NtClose (264, ... ) == 0x0 03081 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\Registration"}, 1234648, ... ) }, 1234648, ... ) == 0x0 03082 464 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 03083 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 264, ) }, ... 264, ) == 0x0 03084 464 NtQueryValueKey (264, (264, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (264, "Com+Enabled", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03085 464 NtClose (264, ... ) == 0x0 03086 464 NtOpenThreadToken (-2, 0x4, 1, ... ) == STATUS_NO_TOKEN 03087 464 NtOpenProcessToken (-1, 0x8, ... 264, ) == 0x0 03088 464 NtQueryInformationToken (264, User, 100, ... {token info, class 1, size 36}, 36, ) == 0x0 03089 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\User\S-1-5-21-1292428093-1383384898-725345543-1003_Classes"}, ... 268, ) }, ... 268, ) == 0x0 03090 464 NtClose (264, ... ) == 0x0 03091 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes"}, ... 264, ) }, ... 264, ) == 0x0 03092 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 272, ) == 0x0 03093 464 NtNotifyChangeKey (264, 272, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03094 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 276, ) }, ... 276, ) == 0x0 03095 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 280, ) == 0x0 03096 464 NtNotifyChangeKey (276, 280, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03097 464 NtOpenKey (0x10, {24, 0, 0x40, 0, 0, (0x10, {24, 0, 0x40, 0, 0, "\REGISTRY\USER"}, ... 284, ) }, ... 284, ) == 0x0 03098 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 288, ) == 0x0 03099 464 NtNotifyChangeKey (284, 288, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03100 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes"}, ... 292, ) }, ... 292, ) == 0x0 03101 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 296, ) == 0x0 03102 464 NtNotifyChangeKey (292, 296, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03103 464 NtOpenKey (0x10, {24, 0, 0x40, 0, 0, (0x10, {24, 0, 0x40, 0, 0, "\REGISTRY\USER"}, ... 300, ) }, ... 300, ) == 0x0 03104 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 304, ) == 0x0 03105 464 NtNotifyChangeKey (300, 304, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03106 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 308, ) }, ... 308, ) == 0x0 03107 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 312, ) == 0x0 03108 464 NtNotifyChangeKey (308, 312, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03109 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 316, ) }, ... 316, ) == 0x0 03110 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 320, ) == 0x0 03111 464 NtNotifyChangeKey (316, 320, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03112 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes\CLSID"}, ... 324, ) }, ... 324, ) == 0x0 03113 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 328, ) == 0x0 03114 464 NtNotifyChangeKey (324, 328, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03115 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes"}, ... 332, ) }, ... 332, ) == 0x0 03116 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 336, ) == 0x0 03117 464 NtNotifyChangeKey (332, 336, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03118 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 340, ) }, ... 340, ) == 0x0 03119 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 344, ) == 0x0 03120 464 NtNotifyChangeKey (340, 344, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03121 464 NtOpenKey (0x10, {24, 0, 0x40, 0, 0, (0x10, {24, 0, 0x40, 0, 0, "\REGISTRY\USER"}, ... 348, ) }, ... 348, ) == 0x0 03122 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 352, ) == 0x0 03123 464 NtNotifyChangeKey (348, 352, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03124 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 356, ) }, ... 356, ) == 0x0 03125 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 360, ) == 0x0 03126 464 NtNotifyChangeKey (356, 360, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03127 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 364, ) }, ... 364, ) == 0x0 03128 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 368, ) == 0x0 03129 464 NtNotifyChangeKey (364, 368, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03130 464 NtOpenKey (0x2000000, {24, 28, 0x40, 0, 0, (0x2000000, {24, 28, 0x40, 0, 0, "Software\Classes\CLSID"}, ... 372, ) }, ... 372, ) == 0x0 03131 464 NtCreateEvent (0x1f0003, 0x0, 0, 0, ... 376, ) == 0x0 03132 464 NtNotifyChangeKey (372, 376, 0, 0, 2011455960, 5, 1, 0, 0, 1, ... ) == 0x103 03133 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 380, ) }, ... 380, ) == 0x0 03134 464 NtQueryValueKey (380, (380, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (380, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 03135 464 NtClose (380, ... ) == 0x0 03136 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 03137 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 03138 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1235408, (0x80100080, {24, 0, 0x40, 0, 1235408, "\??\C:\WINDOWS\Registration\R000000000007.clb"}, 0x0, 0, 1, 1, 96, 0, 0, ... 380, {status=0x0, info=1}, ) }, 0x0, 0, 1, 1, 96, 0, 0, ... 380, {status=0x0, info=1}, ) == 0x0 03139 464 NtQueryInformationFile (380, 1235476, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 03140 464 NtSetInformationFile (380, 1235508, 8, Position, ... {status=0x0, info=0}, ) == 0x0 03141 464 NtAllocateVirtualMemory (-1, 1495040, 0, 24576, 4096, 4, ... 1495040, 24576, ) == 0x0 03142 464 NtSetInformationFile (380, 1235404, 8, Position, ... {status=0x0, info=0}, ) == 0x0 03143 464 NtReadFile (380, 0, 0, 0, 22512, 0x0, 0, ... {status=0x0, info=22512}, (380, 0, 0, 0, 22512, 0x0, 0, ... {status=0x0, info=22512}, "COM+\1\0\0\0\1\0\22\0$\0\0\0\0\1\1\0c\0\0\0\0\0\0\1\1\0\0\0\0\1\20\0\0\0\0\0\300\0\0\0\0\0\0F\16\0\0\00\1\0\0\240\3\0\03_0\0\320\4\0\0\14\0\0\03_1\0\334\4\0\0\210\2\0\03_2\0d\7\0\0<\0\0\03_3\0\240\7\0\0\220\10\0\03_4\00\20\0\0(\0\0\03_5\0X\20\0\0(\0\0\03_6\0\200\20\0\0(\0\0\03_7\0\250\20\0\0\210\20\0\03_8\00!\0\0\250\11\0\03_9\0\330*\0\0<\4\0\03_10\0\0\0\0\24/\0\0\14\1\0\03_11\0\0\0\0 0\0\0\34\0\0\03_12\0\0\0\0<0\0\0\24\0\0\03_16\0\0\0\0P0\0\0\220\16\0\0#Schema\0\340>\0\0d\17\0\0#Strings\0\0\0\0DN\0\0\14\4\0\0#Blob\0\0\0PR\0\0\240\5\0\0#GUID\0\0\0\5\0\0\0\270\0\0\0\0\0\0\0\2\0\0\0\1\0\0\0\4\0\0\0\3\0\0\0\1\0\0\0\0\0\0\0\3\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\1\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\17\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\0\0\0\0\0\0\0\0\1\0\0\0R\0A\13\0\0\0\0\345\16\275\13\377\377R\2\231\6\231\6\377\377\237\10\231\6\231\6\0\0\377\377\377\377\231\6\0\0\334\12Z\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", ) , ) == 0x0 03144 464 NtClose (380, ... ) == 0x0 03145 464 NtAllocateVirtualMemory (-1, 9195520, 0, 8192, 4096, 4, ... 9195520, 8192, ) == 0x0 03146 464 NtAllocateVirtualMemory (-1, 9203712, 0, 8192, 4096, 4, ... 9203712, 8192, ) == 0x0 03147 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\COM3"}, ... 380, ) }, ... 380, ) == 0x0 03148 464 NtQueryValueKey (380, (380, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (380, "REGDBVersion", Partial, 144, ... TitleIdx=0, Type=3, Data="\7\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 03149 464 NtClose (380, ... ) == 0x0 03150 464 NtQuerySystemInformation (Basic, 44, ... {Unknown=0,MaximumIncrement=156250,PhysicalPageSize=0x1000,NumberOfPhysicalPages=0xff7c,LowestPhysicalPage=0x1,HighestPhysicalPage=0xffff,AllocationGranularity=0x10000,LowestUserAddress=0x10000,HighestUserAddress=0x7ffeffff,ActiveProcessors=1,NumberProcessors=1,}, 0x0, ) == 0x0 03151 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 03152 464 NtAllocateVirtualMemory (-1, 0, 0, 65536, 8192, 1, ... 13565952, 65536, ) == 0x0 03153 464 NtAllocateVirtualMemory (-1, 13565952, 0, 4096, 4096, 4, ... 13565952, 4096, ) == 0x0 03154 464 NtQueryKey (270, Name, 384, ... {Name= (270, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03155 464 NtOpenKey (0x20019, {24, 270, 0x40, 0, 0, (0x20019, {24, 270, 0x40, 0, 0, "CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03156 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... 380, ) }, ... 380, ) == 0x0 03157 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}1"}, 162, ) }, 162, ) == 0x0 03158 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03159 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 384, ) == 0x0 03160 464 NtQueryInformationToken (384, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03161 464 NtClose (384, ... ) == 0x0 03162 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03163 464 NtOpenKey (0x1, {24, 382, 0x40, 0, 0, (0x1, {24, 382, 0x40, 0, 0, "TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03164 464 NtQueryKey (270, Name, 384, ... {Name= (270, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03165 464 NtOpenKey (0x20019, {24, 270, 0x40, 0, 0, ""}, ... 384, ) == 0x0 03166 464 NtClose (382, ... ) == 0x0 03167 464 NtQueryKey (386, Name, 384, ... {Name= (386, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03168 464 NtOpenKey (0x20019, {24, 386, 0x40, 0, 0, (0x20019, {24, 386, 0x40, 0, 0, "CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03169 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... 380, ) }, ... 380, ) == 0x0 03170 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}1"}, 162, ) }, 162, ) == 0x0 03171 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03172 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03173 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03174 464 NtClose (388, ... ) == 0x0 03175 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03176 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "InprocServer32"}, ... 388, ) }, ... 388, ) == 0x0 03177 464 NtQueryKey (390, Name, 392, ... {Name= (390, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, 192, ) }, 192, ) == 0x0 03178 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03179 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 392, ) == 0x0 03180 464 NtQueryInformationToken (392, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03181 464 NtClose (392, ... ) == 0x0 03182 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03183 464 NtQueryValueKey (390, (390, "InprocServer32", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03184 464 NtClose (390, ... ) == 0x0 03185 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03186 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03187 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03188 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03189 464 NtClose (388, ... ) == 0x0 03190 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03191 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "InprocServerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03192 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03193 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03194 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03195 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03196 464 NtClose (388, ... ) == 0x0 03197 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03198 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03199 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03200 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03201 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03202 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03203 464 NtClose (388, ... ) == 0x0 03204 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03205 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "InprocServer32"}, ... 388, ) }, ... 388, ) == 0x0 03206 464 NtQueryKey (390, Name, 392, ... {Name= (390, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, 192, ) }, 192, ) == 0x0 03207 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03208 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 392, ) == 0x0 03209 464 NtQueryInformationToken (392, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03210 464 NtClose (392, ... ) == 0x0 03211 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03212 464 NtQueryValueKey (390, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (390, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0s\0y\0s\0t\0e\0m\03\02\0\\0u\0r\0l\0m\0o\0n\0.\0d\0l\0l\0\0\0"}, 74, ) }, 74, ) == 0x0 03213 464 NtClose (390, ... ) == 0x0 03214 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03215 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03216 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03217 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03218 464 NtClose (388, ... ) == 0x0 03219 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandler32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03220 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "InprocHandler32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03221 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03222 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03223 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03224 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03225 464 NtClose (388, ... ) == 0x0 03226 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocHandlerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03227 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "InprocHandlerX86"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03228 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03229 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03230 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03231 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03232 464 NtClose (388, ... ) == 0x0 03233 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03234 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "LocalServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03235 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}3"}, 162, ) }, 162, ) == 0x0 03236 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03237 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03238 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03239 464 NtClose (388, ... ) == 0x0 03240 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03241 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "LocalServer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03242 464 NtQueryKey (386, Name, 384, ... {Name= (386, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03243 464 NtOpenKey (0x20019, {24, 386, 0x40, 0, 0, (0x20019, {24, 386, 0x40, 0, 0, "CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03244 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... 388, ) }, ... 388, ) == 0x0 03245 464 NtQueryKey (390, Name, 392, ... {Name= (390, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}1"}, 162, ) }, 162, ) == 0x0 03246 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03247 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 392, ) == 0x0 03248 464 NtQueryInformationToken (392, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03249 464 NtClose (392, ... ) == 0x0 03250 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03251 464 NtQueryValueKey (390, (390, "AppID", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03252 464 NtClose (390, ... ) == 0x0 03253 464 NtClose (382, ... ) == 0x0 03254 464 NtOpenProcess (0x400, {24, 0, 0x0, 0, 0, 0x0}, {1036, 0}, ... 380, ) == 0x0 03255 464 NtQueryInformationProcess (380, Session, 4, ... {SessionId=0,}, 0x0, ) == 0x0 03256 464 NtClose (380, ... ) == 0x0 03257 464 NtQueryKey (386, Name, 384, ... {Name= (386, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03258 464 NtOpenKey (0x20019, {24, 386, 0x40, 0, 0, (0x20019, {24, 386, 0x40, 0, 0, "CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03259 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... 380, ) }, ... 380, ) == 0x0 03260 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}1"}, 162, ) }, 162, ) == 0x0 03261 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03262 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03263 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03264 464 NtClose (388, ... ) == 0x0 03265 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03266 464 NtOpenKey (0x2000000, {24, 382, 0x40, 0, 0, (0x2000000, {24, 382, 0x40, 0, 0, "InprocServer32"}, ... 388, ) }, ... 388, ) == 0x0 03267 464 NtQueryKey (390, Name, 392, ... {Name= (390, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, 192, ) }, 192, ) == 0x0 03268 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03269 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 392, ) == 0x0 03270 464 NtQueryInformationToken (392, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03271 464 NtClose (392, ... ) == 0x0 03272 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03273 464 NtQueryValueKey (390, (390, "ThreadingModel", Partial, 144, ... TitleIdx=0, Type=1, Data="B\0o\0t\0h\0\0\0"}, 22, ) , Partial, 144, ... TitleIdx=0, Type=1, Data= (390, "ThreadingModel", Partial, 144, ... TitleIdx=0, Type=1, Data="B\0o\0t\0h\0\0\0"}, 22, ) }, 22, ) == 0x0 03274 464 NtClose (390, ... ) == 0x0 03275 464 NtClose (382, ... ) == 0x0 03276 464 NtAllocateVirtualMemory (-1, 1519616, 0, 8192, 4096, 4, ... 1519616, 8192, ) == 0x0 03277 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03278 464 NtOpenKey (0x20019, {24, 210, 0x40, 0, 0, (0x20019, {24, 210, 0x40, 0, 0, "CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03279 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}"}, ... 380, ) }, ... 380, ) == 0x0 03280 464 NtQueryKey (382, Name, 384, ... {Name= (382, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}1"}, 162, ) }, 162, ) == 0x0 03281 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03282 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 388, ) == 0x0 03283 464 NtQueryInformationToken (388, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03284 464 NtClose (388, ... ) == 0x0 03285 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03286 464 NtOpenKey (0x1, {24, 382, 0x40, 0, 0, (0x1, {24, 382, 0x40, 0, 0, "TreatAs"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03287 464 NtClose (382, ... ) == 0x0 03288 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll"}, 1230936, ... ) }, 1230936, ... ) == 0x0 03289 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll"}, 5, 96, ... 380, {status=0x0, info=1}, ) }, 5, 96, ... 380, {status=0x0, info=1}, ) == 0x0 03290 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 380, ... 388, ) == 0x0 03291 464 NtClose (380, ... ) == 0x0 03292 464 NtMapViewOfSection (388, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xd00000), 0x0, 1163264, ) == 0x0 03293 464 NtClose (388, ... ) == 0x0 03294 464 NtUnmapViewOfSection (-1, 0xd00000, ... ) == 0x0 03295 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll"}, 1231244, ... ) }, 1231244, ... ) == 0x0 03296 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll"}, 5, 96, ... 388, {status=0x0, info=1}, ) }, 5, 96, ... 388, {status=0x0, info=1}, ) == 0x0 03297 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 388, ... 380, ) == 0x0 03298 464 NtQuerySection (380, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03299 464 NtClose (388, ... ) == 0x0 03300 464 NtMapViewOfSection (380, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x42cf0000), 0x0, 1208320, ) == 0x0 03301 464 NtClose (380, ... ) == 0x0 03302 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03303 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03304 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03305 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03306 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03307 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03308 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03309 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03310 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03311 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03312 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03313 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03314 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03315 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03316 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03317 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03318 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03319 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03320 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03321 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03322 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03323 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03324 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03325 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03326 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03327 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03328 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03329 464 NtProtectVirtualMemory (-1, (0x42cf1000), 2148, 4, ... (0x42cf1000), 4096, 32, ) == 0x0 03330 464 NtProtectVirtualMemory (-1, (0x42cf1000), 4096, 32, ... (0x42cf1000), 4096, 4, ) == 0x0 03331 464 NtFlushInstructionCache (-1, 1120866304, 2148, ... ) == 0x0 03332 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\urlmon.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03333 464 NtQueryPerformanceCounter (... {936889271, 10}, {3579545, 0}, ) == 0x0 03334 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "Local\ZonesCounterMutex"}, 0, ... 380, ) }, 0, ... 380, ) == STATUS_OBJECT_NAME_EXISTS 03335 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "Local\ZonesCacheCounterMutex"}, 0, ... 388, ) }, 0, ... 388, ) == STATUS_OBJECT_NAME_EXISTS 03336 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "Local\ZonesLockedCacheCounterMutex"}, 0, ... 392, ) }, 0, ... 392, ) == STATUS_OBJECT_NAME_EXISTS 03337 464 NtQueryDefaultUILanguage (1230040, ... 03338 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03339 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 03340 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03341 464 NtClose (-2147482584, ... ) == 0x0 03342 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 03343 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03344 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 03345 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03346 464 NtClose (-2147481332, ... ) == 0x0 03347 464 NtClose (-2147482584, ... ) == 0x0 03337 464 NtQueryDefaultUILanguage ... ) == 0x0 03348 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll.123.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03349 464 NtAllocateVirtualMemory (-1, 1216512, 0, 4096, 4096, 260, ... 1216512, 4096, ) == 0x0 03350 464 NtQueryDefaultLocale (1, 1228136, ... ) == 0x0 03351 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll.123.Config"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03352 464 NtRequestWaitReplyPort (24, {128, 156, new_msg, 0, 2088850039, 1229172, 1179817, 1228896} (24, {128, 156, new_msg, 0, 2088850039, 1229172, 1179817, 1228896} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0\0I\333B\0\0\0\0\361\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\305\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57991, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0\0I\333B\0\0\0\0\361\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\305\22\0\0\0\0\0" ) ... {128, 156, reply, 0, 1036, 464, 57991, 0} (24, {128, 156, new_msg, 0, 2088850039, 1229172, 1179817, 1228896} "\210\6\31\1\33\0\1\0`\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0\0I\333B\0\0\0\0\361\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\305\22\0\0\0\0\0" ... {128, 156, reply, 0, 1036, 464, 57991, 0} "\300\270\26\0\33\0\1\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\11\4\1\1\1\0<\0@\0\250\6\31\1\0\0\0\0\377\377\377\377\0\0\0\0\0I\333B\0\0\0\0\361\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0(\0,\0\350\6\31\1\0\0\0\0\0\0\0\0h\305\22\0\0\0\0\0" ) ) == 0x0 03353 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03354 464 NtOpenKey (0x8, {24, 0, 0x40, 0, 0, (0x8, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03355 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03356 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03357 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\packed.exe.Local\"}, 1227364, ... ) }, 1227364, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03358 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03359 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03360 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03361 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 1227428, ... ) }, 1227428, ... ) == 0x0 03362 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03"}, 3, 33, ... 396, {status=0x0, info=1}, ) }, 3, 33, ... 396, {status=0x0, info=1}, ) == 0x0 03363 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 03364 464 NtAllocateVirtualMemory (-1, 1527808, 0, 4096, 4096, 4, ... 1527808, 4096, ) == 0x0 03365 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03366 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "PROTOCOLS\Name-Space Handler\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03367 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\PROTOCOLS\Name-Space Handler"}, ... 400, ) }, ... 400, ) == 0x0 03368 464 NtQueryKey (402, Name, 392, ... {Name= (402, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\PROTOCOLS\Name-Space HandlerS"}, 130, ) }, 130, ) == 0x0 03369 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03370 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 404, ) == 0x0 03371 464 NtQueryInformationToken (404, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03372 464 NtClose (404, ... ) == 0x0 03373 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\PROTOCOLS\Name-Space Handler"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03374 464 NtEnumerateKey (402, 0, Node, 288, ... {LastWrite={0xdf7c22cc,0x1c74da8}, TitleIdx=0, Name= (402, 0, Node, 288, ... {LastWrite={0xdf7c22cc,0x1c74da8}, TitleIdx=0, Name="mk", Class=""}, 28, ) , Class=""}, 28, ) == 0x0 03375 464 NtEnumerateKey (402, 1, Node, 288, ... ) == STATUS_NO_MORE_ENTRIES 03376 464 NtClose (402, ... ) == 0x0 03377 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03378 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03379 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 400, ) }, ... 400, ) == 0x0 03380 464 NtQueryValueKey (400, (400, "DisableImprovedZoneCheck", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03381 464 NtClose (400, ... ) == 0x0 03382 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03383 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03384 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03385 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03386 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 400, ) }, ... 400, ) == 0x0 03387 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03388 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03389 464 NtClose (400, ... ) == 0x0 03390 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03391 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03392 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03393 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03394 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03395 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03396 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03397 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03398 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03399 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... 400, ) }, ... 400, ) == 0x0 03400 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Internet Explorer\Main\FeatureControl"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03401 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_OBJECT_CACHING"}, ... 404, ) }, ... 404, ) == 0x0 03402 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03403 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03404 464 NtClose (404, ... ) == 0x0 03405 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_ZONE_ELEVATION"}, ... 404, ) }, ... 404, ) == 0x0 03406 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03407 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03408 464 NtClose (404, ... ) == 0x0 03409 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_MIME_HANDLING"}, ... 404, ) }, ... 404, ) == 0x0 03410 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03411 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03412 464 NtClose (404, ... ) == 0x0 03413 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_MIME_SNIFFING"}, ... 404, ) }, ... 404, ) == 0x0 03414 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03415 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03416 464 NtClose (404, ... ) == 0x0 03417 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_WINDOW_RESTRICTIONS"}, ... 404, ) }, ... 404, ) == 0x0 03418 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03419 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03420 464 NtClose (404, ... ) == 0x0 03421 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_WEBOC_POPUPMANAGEMENT"}, ... 404, ) }, ... 404, ) == 0x0 03422 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03423 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03424 464 NtClose (404, ... ) == 0x0 03425 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_BEHAVIORS"}, ... 404, ) }, ... 404, ) == 0x0 03426 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03427 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "*", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03428 464 NtClose (404, ... ) == 0x0 03429 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_DISABLE_MK_PROTOCOL"}, ... 404, ) }, ... 404, ) == 0x0 03430 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03431 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (404, "*", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03432 464 NtClose (404, ... ) == 0x0 03433 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_LOCALMACHINE_LOCKDOWN"}, ... 404, ) }, ... 404, ) == 0x0 03434 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03435 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03436 464 NtClose (404, ... ) == 0x0 03437 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_SECURITYBAND"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03438 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_RESTRICT_ACTIVEXINSTALL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03439 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_VALIDATE_NAVIGATE_URL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03440 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_RESTRICT_FILEDOWNLOAD"}, ... 404, ) }, ... 404, ) == 0x0 03441 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03442 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03443 464 NtClose (404, ... ) == 0x0 03444 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_ADDON_MANAGEMENT"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03445 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_PROTOCOL_LOCKDOWN"}, ... 404, ) }, ... 404, ) == 0x0 03446 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03447 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03448 464 NtClose (404, ... ) == 0x0 03449 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_HTTP_USERNAME_PASSWORD_DISABLE"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03450 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_SAFE_BINDTOOBJECT"}, ... 404, ) }, ... 404, ) == 0x0 03451 464 NtQueryValueKey (404, (404, "packed.exe", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03452 464 NtQueryValueKey (404, (404, "*", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03453 464 NtClose (404, ... ) == 0x0 03454 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_UNC_SAVEDFILECHECK"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03455 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_GET_URL_DOM_FILEPATH_UNENCODED"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03456 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_TABBED_BROWSING"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03457 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_SSLUX"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03458 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_DISABLE_NAVIGATION_SOUNDS"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03459 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_DISABLE_LEGACY_COMPRESSION"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03460 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_FORCE_ADDR_AND_STATUS"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03461 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_XMLHTTP"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03462 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_DISABLE_TELNET_PROTOCOL"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03463 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_FEEDS"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03464 464 NtOpenKey (0x1, {24, 400, 0x40, 0, 0, (0x1, {24, 400, 0x40, 0, 0, "FEATURE_BLOCK_INPUT_PROMPTS"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03465 464 NtClose (400, ... ) == 0x0 03466 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03467 464 NtOpenKey (0x1, {24, 210, 0x40, 0, 0, (0x1, {24, 210, 0x40, 0, 0, "CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InProcServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03468 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InProcServer32"}, ... 400, ) }, ... 400, ) == 0x0 03469 464 NtQueryKey (402, Name, 392, ... {Name= (402, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, 192, ) }, 192, ) == 0x0 03470 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03471 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 404, ) == 0x0 03472 464 NtQueryInformationToken (404, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03473 464 NtClose (404, ... ) == 0x0 03474 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03475 464 NtQueryValueKey (402, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (402, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0s\0y\0s\0t\0e\0m\03\02\0\\0u\0r\0l\0m\0o\0n\0.\0d\0l\0l\0\0\0"}, 74, ) }, 74, ) == 0x0 03476 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\urlmon.dll"}, 1233608, ... ) }, 1233608, ... ) == 0x0 03477 464 NtClose (402, ... ) == 0x0 03478 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"}, ... 400, ) }, ... 400, ) == 0x0 03479 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies"}, ... 404, ) }, ... 404, ) == 0x0 03480 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies"}, ... 408, ) }, ... 408, ) == 0x0 03481 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software"}, ... 412, ) }, ... 412, ) == 0x0 03482 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software"}, ... 416, ) }, ... 416, ) == 0x0 03483 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03484 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03485 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"}, ... 420, ) }, ... 420, ) == 0x0 03486 464 NtAllocateVirtualMemory (-1, 1531904, 0, 4096, 4096, 4, ... 1531904, 4096, ) == 0x0 03487 464 NtOpenKey (0x20019, {24, 420, 0x40, 0, 0, (0x20019, {24, 420, 0x40, 0, 0, "Ranges\"}, ... 424, ) }, ... 424, ) == 0x0 03488 464 NtQueryKey (424, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 03489 464 NtClose (424, ... ) == 0x0 03490 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03491 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03492 464 NtOpenKey (0x20019, {24, 420, 0x40, 0, 0, (0x20019, {24, 420, 0x40, 0, 0, "ProtocolDefaults\"}, ... 424, ) }, ... 424, ) == 0x0 03493 464 NtQueryKey (424, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 03494 464 NtEnumerateValueKey (424, 0, Full, 220, ... TitleIdx=0, Type=1, Name=" (424, 0, Full, 220, ... TitleIdx=0, Type=1, Name="", Data="\0\0"}, 22, ) \0\0"}, 22, ) == 0x0 03495 464 NtEnumerateValueKey (424, 1, Full, 220, ... TitleIdx=0, Type=4, Name= (424, 1, Full, 220, ... TitleIdx=0, Type=4, Name="http", Data="\3\0\0\0"}, 32, ) , Data= (424, 1, Full, 220, ... TitleIdx=0, Type=4, Name="http", Data="\3\0\0\0"}, 32, ) }, 32, ) == 0x0 03496 464 NtEnumerateValueKey (424, 2, Full, 220, ... TitleIdx=0, Type=4, Name= (424, 2, Full, 220, ... TitleIdx=0, Type=4, Name="https", Data="\3\0\0\0"}, 36, ) , Data= (424, 2, Full, 220, ... TitleIdx=0, Type=4, Name="https", Data="\3\0\0\0"}, 36, ) }, 36, ) == 0x0 03497 464 NtEnumerateValueKey (424, 3, Full, 220, ... TitleIdx=0, Type=4, Name= (424, 3, Full, 220, ... TitleIdx=0, Type=4, Name="ftp", Data="\3\0\0\0"}, 32, ) , Data= (424, 3, Full, 220, ... TitleIdx=0, Type=4, Name="ftp", Data="\3\0\0\0"}, 32, ) }, 32, ) == 0x0 03498 464 NtEnumerateValueKey (424, 4, Full, 220, ... TitleIdx=0, Type=4, Name= (424, 4, Full, 220, ... TitleIdx=0, Type=4, Name="file", Data="\3\0\0\0"}, 32, ) , Data= (424, 4, Full, 220, ... TitleIdx=0, Type=4, Name="file", Data="\3\0\0\0"}, 32, ) }, 32, ) == 0x0 03499 464 NtEnumerateValueKey (424, 5, Full, 220, ... TitleIdx=0, Type=4, Name= (424, 5, Full, 220, ... TitleIdx=0, Type=4, Name="@ivt", Data="\1\0\0\0"}, 32, ) , Data= (424, 5, Full, 220, ... TitleIdx=0, Type=4, Name="@ivt", Data="\1\0\0\0"}, 32, ) }, 32, ) == 0x0 03500 464 NtEnumerateValueKey (424, 6, Full, 220, ... TitleIdx=0, Type=4, Name= (424, 6, Full, 220, ... TitleIdx=0, Type=4, Name="shell", Data="\0\0\0\0"}, 36, ) , Data= (424, 6, Full, 220, ... TitleIdx=0, Type=4, Name="shell", Data="\0\0\0\0"}, 36, ) }, 36, ) == 0x0 03501 464 NtClose (424, ... ) == 0x0 03502 464 NtOpenKey (0x20019, {24, 420, 0x40, 0, 0, (0x20019, {24, 420, 0x40, 0, 0, "Domains\"}, ... 424, ) }, ... 424, ) == 0x0 03503 464 NtQueryKey (424, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 03504 464 NtClose (424, ... ) == 0x0 03505 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\"}, ... 424, ) }, ... 424, ) == 0x0 03506 464 NtQueryKey (424, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 03507 464 NtEnumerateKey (424, 0, Basic, 288, ... {LastWrite={0xde94deb2,0x1c74da8}, TitleIdx=0, Name= (424, 0, Basic, 288, ... {LastWrite={0xde94deb2,0x1c74da8}, TitleIdx=0, Name="msn.com"}, 30, ) }, 30, ) == 0x0 03508 464 NtOpenKey (0x20019, {24, 424, 0x40, 0, 0, (0x20019, {24, 424, 0x40, 0, 0, "msn.com"}, ... 428, ) }, ... 428, ) == 0x0 03509 464 NtQueryKey (428, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 03510 464 NtEnumerateKey (428, 0, Basic, 288, ... {LastWrite={0xde94deb2,0x1c74da8}, TitleIdx=0, Name= (428, 0, Basic, 288, ... {LastWrite={0xde94deb2,0x1c74da8}, TitleIdx=0, Name="related"}, 30, ) }, 30, ) == 0x0 03511 464 NtOpenKey (0x20019, {24, 428, 0x40, 0, 0, (0x20019, {24, 428, 0x40, 0, 0, "related"}, ... 432, ) }, ... 432, ) == 0x0 03512 464 NtQueryKey (432, 4, 176, ... {key info, class 4, size 40}, 40, ) == 0x0 03513 464 NtEnumerateValueKey (432, 0, Full, 220, ... TitleIdx=0, Type=4, Name= (432, 0, Full, 220, ... TitleIdx=0, Type=4, Name="http", Data="\4\0\0\0"}, 32, ) , Data= (432, 0, Full, 220, ... TitleIdx=0, Type=4, Name="http", Data="\4\0\0\0"}, 32, ) }, 32, ) == 0x0 03514 464 NtClose (432, ... ) == 0x0 03515 464 NtEnumerateValueKey (428, 0, Full, 220, ... TitleIdx=0, Type=1, Name=" (428, 0, Full, 220, ... TitleIdx=0, Type=1, Name="", Data="\0\0"}, 22, ) \0\0"}, 22, ) == 0x0 03516 464 NtClose (428, ... ) == 0x0 03517 464 NtClose (424, ... ) == 0x0 03518 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03519 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03520 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03521 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 424, ) }, ... 424, ) == 0x0 03522 464 NtQueryValueKey (424, (424, "CreateUriCacheSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03523 464 NtClose (424, ... ) == 0x0 03524 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 424, ) }, ... 424, ) == 0x0 03525 464 NtQueryValueKey (424, (424, "CreateUriCacheSize", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03526 464 NtClose (424, ... ) == 0x0 03527 464 NtCreateEvent (0x1f0003, 0x0, 1, 1, ... 424, ) == 0x0 03528 464 NtCreateEvent (0x1f0003, 0x0, 1, 1, ... 428, ) == 0x0 03529 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03530 464 NtSetEvent (428, ... 0x0, ) == 0x0 03531 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 432, ) }, ... 432, ) == 0x0 03532 464 NtQueryValueKey (432, (432, "EnablePunycode", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03533 464 NtClose (432, ... ) == 0x0 03534 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings"}, ... 432, ) }, ... 432, ) == 0x0 03535 464 NtQueryValueKey (432, (432, "EnablePunycode", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (432, "EnablePunycode", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03536 464 NtClose (432, ... ) == 0x0 03537 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03538 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03539 464 NtSetEvent (428, ... 0x0, ) == 0x0 03540 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03541 464 NtSetEvent (428, ... 0x0, ) == 0x0 03542 464 NtSetEvent (424, ... 0x0, ) == 0x0 03543 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03544 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03545 464 NtSetEvent (428, ... 0x0, ) == 0x0 03546 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03547 464 NtSetEvent (428, ... 0x0, ) == 0x0 03548 464 NtSetEvent (424, ... 0x0, ) == 0x0 03549 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03550 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03551 464 NtSetEvent (428, ... 0x0, ) == 0x0 03552 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03553 464 NtSetEvent (428, ... 0x0, ) == 0x0 03554 464 NtSetEvent (424, ... 0x0, ) == 0x0 03555 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03556 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03557 464 NtSetEvent (428, ... 0x0, ) == 0x0 03558 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03559 464 NtSetEvent (428, ... 0x0, ) == 0x0 03560 464 NtSetEvent (424, ... 0x0, ) == 0x0 03561 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03562 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03563 464 NtSetEvent (428, ... 0x0, ) == 0x0 03564 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03565 464 NtSetEvent (428, ... 0x0, ) == 0x0 03566 464 NtSetEvent (424, ... 0x0, ) == 0x0 03567 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03568 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03569 464 NtSetEvent (428, ... 0x0, ) == 0x0 03570 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03571 464 NtSetEvent (428, ... 0x0, ) == 0x0 03572 464 NtSetEvent (424, ... 0x0, ) == 0x0 03573 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03574 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03575 464 NtSetEvent (428, ... 0x0, ) == 0x0 03576 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03577 464 NtSetEvent (428, ... 0x0, ) == 0x0 03578 464 NtSetEvent (424, ... 0x0, ) == 0x0 03579 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03580 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03581 464 NtSetEvent (428, ... 0x0, ) == 0x0 03582 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03583 464 NtSetEvent (428, ... 0x0, ) == 0x0 03584 464 NtSetEvent (424, ... 0x0, ) == 0x0 03585 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03586 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03587 464 NtSetEvent (428, ... 0x0, ) == 0x0 03588 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03589 464 NtSetEvent (428, ... 0x0, ) == 0x0 03590 464 NtSetEvent (424, ... 0x0, ) == 0x0 03591 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03592 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03593 464 NtSetEvent (428, ... 0x0, ) == 0x0 03594 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03595 464 NtSetEvent (428, ... 0x0, ) == 0x0 03596 464 NtSetEvent (424, ... 0x0, ) == 0x0 03597 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03598 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03599 464 NtSetEvent (428, ... 0x0, ) == 0x0 03600 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03601 464 NtSetEvent (428, ... 0x0, ) == 0x0 03602 464 NtSetEvent (424, ... 0x0, ) == 0x0 03603 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03604 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03605 464 NtSetEvent (428, ... 0x0, ) == 0x0 03606 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03607 464 NtSetEvent (428, ... 0x0, ) == 0x0 03608 464 NtSetEvent (424, ... 0x0, ) == 0x0 03609 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03610 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03611 464 NtSetEvent (428, ... 0x0, ) == 0x0 03612 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03613 464 NtSetEvent (428, ... 0x0, ) == 0x0 03614 464 NtSetEvent (424, ... 0x0, ) == 0x0 03615 464 NtAllocateVirtualMemory (-1, 1536000, 0, 4096, 4096, 4, ... 1536000, 4096, ) == 0x0 03616 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03617 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03618 464 NtSetEvent (428, ... 0x0, ) == 0x0 03619 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03620 464 NtSetEvent (428, ... 0x0, ) == 0x0 03621 464 NtSetEvent (424, ... 0x0, ) == 0x0 03622 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03623 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03624 464 NtSetEvent (428, ... 0x0, ) == 0x0 03625 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03626 464 NtSetEvent (428, ... 0x0, ) == 0x0 03627 464 NtSetEvent (424, ... 0x0, ) == 0x0 03628 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03629 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03630 464 NtSetEvent (428, ... 0x0, ) == 0x0 03631 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03632 464 NtSetEvent (428, ... 0x0, ) == 0x0 03633 464 NtSetEvent (424, ... 0x0, ) == 0x0 03634 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03635 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03636 464 NtSetEvent (428, ... 0x0, ) == 0x0 03637 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03638 464 NtSetEvent (428, ... 0x0, ) == 0x0 03639 464 NtSetEvent (424, ... 0x0, ) == 0x0 03640 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03641 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03642 464 NtSetEvent (428, ... 0x0, ) == 0x0 03643 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03644 464 NtSetEvent (428, ... 0x0, ) == 0x0 03645 464 NtSetEvent (424, ... 0x0, ) == 0x0 03646 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03647 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03648 464 NtSetEvent (428, ... 0x0, ) == 0x0 03649 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03650 464 NtSetEvent (428, ... 0x0, ) == 0x0 03651 464 NtSetEvent (424, ... 0x0, ) == 0x0 03652 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03653 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03654 464 NtSetEvent (428, ... 0x0, ) == 0x0 03655 464 NtSetEvent (424, ... 0x0, ) == 0x0 03656 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03657 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03658 464 NtSetEvent (428, ... 0x0, ) == 0x0 03659 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03660 464 NtSetEvent (428, ... 0x0, ) == 0x0 03661 464 NtSetEvent (424, ... 0x0, ) == 0x0 03662 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Internet Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03663 464 NtOpenKey (0x20019, {24, 412, 0x40, 0, 0, (0x20019, {24, 412, 0x40, 0, 0, "Microsoft\Internet Explorer\Security"}, ... 432, ) }, ... 432, ) == 0x0 03664 464 NtQueryValueKey (432, (432, "DisableSecuritySettingsCheck", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03665 464 NtClose (432, ... ) == 0x0 03666 464 NtOpenKey (0x20019, {24, 416, 0x40, 0, 0, (0x20019, {24, 416, 0x40, 0, 0, "Microsoft\Internet Explorer\Security"}, ... 432, ) }, ... 432, ) == 0x0 03667 464 NtQueryValueKey (432, (432, "DisableSecuritySettingsCheck", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03668 464 NtClose (432, ... ) == 0x0 03669 464 NtOpenSection (0xe, {24, 8, 0x40, 0, 0, (0xe, {24, 8, 0x40, 0, 0, "Secur32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03670 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\Secur32.dll"}, 1233812, ... ) }, 1233812, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03671 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Secur32.dll"}, 1233812, ... ) }, 1233812, ... ) == 0x0 03672 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Secur32.dll"}, 5, 96, ... 432, {status=0x0, info=1}, ) }, 5, 96, ... 432, {status=0x0, info=1}, ) == 0x0 03673 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 432, ... 436, ) == 0x0 03674 464 NtQuerySection (436, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 03675 464 NtClose (432, ... ) == 0x0 03676 464 NtMapViewOfSection (436, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77fe0000), 0x0, 69632, ) == 0x0 03677 464 NtClose (436, ... ) == 0x0 03678 464 NtProtectVirtualMemory (-1, (0x77fe1000), 388, 4, ... (0x77fe1000), 4096, 32, ) == 0x0 03679 464 NtProtectVirtualMemory (-1, (0x77fe1000), 4096, 32, ... (0x77fe1000), 4096, 4, ) == 0x0 03680 464 NtFlushInstructionCache (-1, 2013138944, 388, ... ) == 0x0 03681 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secur32.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03682 464 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 436, ) == 0x0 03683 464 NtCreateSemaphore (0x100003, 0x0, 0, 2147483647, ... 432, ) == 0x0 03684 464 NtOpenEvent (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\SECURITY\LSA_AUTHENTICATION_INITIALIZED"}, ... 440, ) }, ... 440, ) == 0x0 03685 464 NtQueryEvent (440, Basic, 8, ... {EventType=0,SignalState=1,}, 0x0, ) == 0x0 03686 464 NtClose (440, ... ) == 0x0 03687 464 NtConnectPort ( ("\LsaAuthenticationPort", {12, 2, 1, 0}, 0x0, 0x0, 1235384, 140, ... 440, 0x0, 0x0, 256, 140, ) , {12, 2, 1, 0}, 0x0, 0x0, 1235384, 140, ... 440, 0x0, 0x0, 256, 140, ) == 0x0 03688 464 NtRequestWaitReplyPort (440, {28, 52, new_msg, 0, 0, 0, 0, 0} (440, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\353\6\10\2\220\232\26\0" ... {188, 212, reply, 0, 1036, 464, 57993, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\34\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0" ) ... {188, 212, reply, 0, 1036, 464, 57993, 0} (440, {28, 52, new_msg, 0, 0, 0, 0, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\353\6\10\2\220\232\26\0" ... {188, 212, reply, 0, 1036, 464, 57993, 0} "\37\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\2\0\1\0\34\0\10\2\220\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0" ) ) == 0x0 03689 464 NtCreateSection (0xf0007, {24, 44, 0x80, 0, 0, (0xf0007, {24, 44, 0x80, 0, 0, "Local\UrlZonesSM_Martim Carbone"}, {28, 0}, 4, 134217728, 0, ... 444, ) }, {28, 0}, 4, 134217728, 0, ... 444, ) == STATUS_OBJECT_NAME_EXISTS 03690 464 NtMapViewOfSection (444, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xd10000), {0, 0}, 4096, ) == 0x0 03691 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03692 464 NtCreateEvent (0x1f0003, 0x0, 1, 0, ... 448, ) == 0x0 03693 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03694 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03695 464 NtCreateFile (0xc0100080, {24, 0, 0x40, 0, 1234152, (0xc0100080, {24, 0, 0x40, 0, 1234152, "\??\PIPE\lsarpc"}, 0x0, 0, 3, 1, 64, 0, 0, ... 452, {status=0x0, info=1}, ) }, 0x0, 0, 3, 1, 64, 0, 0, ... 452, {status=0x0, info=1}, ) == 0x0 03696 464 NtSetInformationFile (452, 1234208, 8, Pipe, ... {status=0x0, info=0}, ) == 0x0 03697 464 NtSetInformationFile (452, 1234196, 8, Completion, ... {status=0x0, info=0}, ) == 0x0 03698 464 NtSetInformationThread (-2, ImpersonationToken, {ImpToken=0,}, 4, ... ) == 0x0 03699 464 NtWriteFile (452, 189, 0, 0, (452, 189, 0, 0, "\5\0\13\3\20\0\0\0H\0\0\0\1\0\0\0\270\20\270\20\0\0\0\0\1\0\0\0\0\0\1\0xW4\224\22\315\253\357\0\1#Eg\211\253\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", 72, {0, 0}, 0, ... {status=0x0, info=72}, ) , 72, {0, 0}, 0, ... {status=0x0, info=72}, ) == 0x0 03700 464 NtReadFile (452, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, (452, 189, 0, 0, 1024, {0, 0}, 0, ... {status=0x0, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20.+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x0 03701 464 NtFsControlFile (452, 189, 0x0, 0x0, 0x11c017, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\08\0\0\0\1\0\0\0 \0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0", 56, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20.+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , 56, 1024, ... {status=0x103, info=68}, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\08\0\0\0\1\0\0\0 \0\0\0\0\0,\0\0\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0", 56, 1024, ... {status=0x103, info=68}, "\5\0\14\3\20\0\0\0D\0\0\0\1\0\0\0\270\20\270\20.+\0\0\14\0\PIPE\lsass\0\0\0\1\0\0\0\0\0\0\0\4]\210\212\353\34\311\21\237\350\10\0+\20H`\2\0\0\0", ) , ) == 0x103 03702 464 NtFsControlFile (452, 189, 0x0, 0x0, 0x11c017, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0.\0\0\0\2\0\0\0\26\0\0\0\0\0.\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\14\0", 46, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , 46, 1024, ... {status=0x103, info=48}, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0.\0\0\0\2\0\0\0\26\0\0\0\0\0.\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\14\0", 46, 1024, ... {status=0x103, info=48}, "\5\0\2\3\20\0\0\00\0\0\0\1\0\0\0\30\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\0\0\0\0", ) , ) == 0x103 03703 464 NtFsControlFile (452, 189, 0x0, 0x0, 0x11c017, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0.\0\0\0\3\0\0\0\26\0\0\0\0\0\7\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\5\0", 46, 1024, ... {status=0x103, info=104}, "\5\0\2\3\20\0\0\0h\0\0\0\2\0\0\0P\0\0\0\0\0\0\00\220\26\0\14\0\4V\14\0\16\0`\220\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\0\0\0\0\6\0\0\0M\0S\0H\0O\0M\0E\0\0\0\0\0", ) , 46, 1024, ... {status=0x103, info=104}, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0.\0\0\0\3\0\0\0\26\0\0\0\0\0\7\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216\5\0", 46, 1024, ... {status=0x103, info=104}, "\5\0\2\3\20\0\0\0h\0\0\0\2\0\0\0P\0\0\0\0\0\0\00\220\26\0\14\0\4V\14\0\16\0`\220\26\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\0\0\0\0\6\0\0\0M\0S\0H\0O\0M\0E\0\0\0\0\0", ) , ) == 0x103 03704 464 NtFsControlFile (452, 189, 0x0, 0x0, 0x11c017, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\4\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=104}, "\5\0\2\3\20\0\0\0h\0\0\0\3\0\0\0P\0\0\0\0\0\0\0\240}\27\0\5\0\4V\16\0\20\0\320}\27\0\340}\27\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\0\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\0\0\0\0", ) , 44, 1024, ... {status=0x103, info=104}, (452, 189, 0x0, 0x0, 0x11c017, "\5\0\0\3\20\0\0\0,\0\0\0\4\0\0\0\24\0\0\0\0\0\0\0\0\0\0\0\2169\4V\276h{J\225\236o\243\366\340=\216", 44, 1024, ... {status=0x103, info=104}, "\5\0\2\3\20\0\0\0h\0\0\0\3\0\0\0P\0\0\0\0\0\0\0\240}\27\0\5\0\4V\16\0\20\0\320}\27\0\340}\27\0\10\0\0\0\0\0\0\0\7\0\0\0V\0I\0R\0T\0U\0A\0L\0\0\0\4\0\0\0\1\4\0\0\0\0\0\5\25\0\0\0=\343\10MB\307tR\7\345;+\0\0\0\0", ) , ) == 0x103 03705 464 NtClose (448, ... ) == 0x0 03706 464 NtClose (452, ... ) == 0x0 03707 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "Local\ZoneAttributeCacheCounterMutex"}, 0, ... 452, ) }, 0, ... 452, ) == STATUS_OBJECT_NAME_EXISTS 03708 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "System\Setup"}, ... 448, ) }, ... 448, ) == 0x0 03709 464 NtQueryValueKey (448, (448, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (448, "SystemSetupInProgress", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 03710 464 NtClose (448, ... ) == 0x0 03711 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... 448, ) }, ... 448, ) == 0x0 03712 464 NtOpenKey (0x20019, {24, 448, 0x40, 0, 0, (0x20019, {24, 448, 0x40, 0, 0, "0"}, ... 456, ) }, ... 456, ) == 0x0 03713 464 NtClose (456, ... ) == 0x0 03714 464 NtOpenKey (0x20019, {24, 448, 0x40, 0, 0, (0x20019, {24, 448, 0x40, 0, 0, "1"}, ... 456, ) }, ... 456, ) == 0x0 03715 464 NtClose (456, ... ) == 0x0 03716 464 NtOpenKey (0x20019, {24, 448, 0x40, 0, 0, (0x20019, {24, 448, 0x40, 0, 0, "2"}, ... 456, ) }, ... 456, ) == 0x0 03717 464 NtClose (456, ... ) == 0x0 03718 464 NtOpenKey (0x20019, {24, 448, 0x40, 0, 0, (0x20019, {24, 448, 0x40, 0, 0, "3"}, ... 456, ) }, ... 456, ) == 0x0 03719 464 NtClose (456, ... ) == 0x0 03720 464 NtOpenKey (0x20019, {24, 448, 0x40, 0, 0, (0x20019, {24, 448, 0x40, 0, 0, "4"}, ... 456, ) }, ... 456, ) == 0x0 03721 464 NtClose (456, ... ) == 0x0 03722 464 NtClose (448, ... ) == 0x0 03723 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03724 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03725 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03726 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03727 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03728 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\"}, ... 448, ) }, ... 448, ) == 0x0 03729 464 NtEnumerateKey (448, 0, Basic, 288, ... {LastWrite={0x435b806e,0x1c74db1}, TitleIdx=0, Name= (448, 0, Basic, 288, ... {LastWrite={0x435b806e,0x1c74db1}, TitleIdx=0, Name="0"}, 18, ) }, 18, ) == 0x0 03730 464 NtAllocateVirtualMemory (-1, 1540096, 0, 4096, 4096, 4, ... 1540096, 4096, ) == 0x0 03731 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... 456, ) }, ... 456, ) == 0x0 03732 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03733 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03734 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03735 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... 460, ) }, ... 460, ) == 0x0 03736 464 NtQueryValueKey (460, (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="!\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="!\0\0\0"}, 16, ) }, 16, ) == 0x0 03737 464 NtClose (460, ... ) == 0x0 03738 464 NtClose (456, ... ) == 0x0 03739 464 NtEnumerateKey (448, 1, Basic, 288, ... {LastWrite={0x437357f2,0x1c74db1}, TitleIdx=0, Name= (448, 1, Basic, 288, ... {LastWrite={0x437357f2,0x1c74db1}, TitleIdx=0, Name="1"}, 18, ) }, 18, ) == 0x0 03740 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"}, ... 456, ) }, ... 456, ) == 0x0 03741 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03742 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03743 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03744 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"}, ... 460, ) }, ... 460, ) == 0x0 03745 464 NtQueryValueKey (460, (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\333\1\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\333\1\0\0"}, 16, ) }, 16, ) == 0x0 03746 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03747 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03748 464 NtOpenKey (0x2001f, {24, 84, 0x40, 0, 0, (0x2001f, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"}, ... 464, ) }, ... 464, ) == 0x0 03749 464 NtSetValueKey (464, (464, "ProxyBypass", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (464, "ProxyBypass", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03750 464 NtSetValueKey (464, (464, "IntranetName", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (464, "IntranetName", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03751 464 NtSetValueKey (464, (464, "UNCAsIntranet", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (464, "UNCAsIntranet", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03752 464 NtSetValueKey (464, (464, "AutoDetect", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (464, "AutoDetect", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03753 464 NtClose (464, ... ) == 0x0 03754 464 NtClose (460, ... ) == 0x0 03755 464 NtClose (456, ... ) == 0x0 03756 464 NtEnumerateKey (448, 2, Basic, 288, ... {LastWrite={0x4369ce8a,0x1c74db1}, TitleIdx=0, Name= (448, 2, Basic, 288, ... {LastWrite={0x4369ce8a,0x1c74db1}, TitleIdx=0, Name="2e"}, 18, ) }, 18, ) == 0x0 03757 464 NtAllocateVirtualMemory (-1, 1544192, 0, 4096, 4096, 4, ... 1544192, 4096, ) == 0x0 03758 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"}, ... 456, ) }, ... 456, ) == 0x0 03759 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03760 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03761 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03762 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"}, ... 460, ) }, ... 460, ) == 0x0 03763 464 NtQueryValueKey (460, (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="G\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="G\0\0\0"}, 16, ) }, 16, ) == 0x0 03764 464 NtClose (460, ... ) == 0x0 03765 464 NtClose (456, ... ) == 0x0 03766 464 NtEnumerateKey (448, 3, Basic, 288, ... {LastWrite={0x31a6291,0x1c7701e}, TitleIdx=0, Name= (448, 3, Basic, 288, ... {LastWrite={0x31a6291,0x1c7701e}, TitleIdx=0, Name="3"}, 18, ) }, 18, ) == 0x0 03767 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"}, ... 456, ) }, ... 456, ) == 0x0 03768 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03769 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03770 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03771 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"}, ... 460, ) }, ... 460, ) == 0x0 03772 464 NtQueryValueKey (460, (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03773 464 NtClose (460, ... ) == 0x0 03774 464 NtClose (456, ... ) == 0x0 03775 464 NtEnumerateKey (448, 4, Basic, 288, ... {LastWrite={0x43604522,0x1c74db1}, TitleIdx=0, Name= (448, 4, Basic, 288, ... {LastWrite={0x43604522,0x1c74db1}, TitleIdx=0, Name="4"}, 18, ) }, 18, ) == 0x0 03776 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"}, ... 456, ) }, ... 456, ) == 0x0 03777 464 NtAllocateVirtualMemory (-1, 1548288, 0, 4096, 4096, 4, ... 1548288, 4096, ) == 0x0 03778 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03779 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03780 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03781 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"}, ... 460, ) }, ... 460, ) == 0x0 03782 464 NtQueryValueKey (460, (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (460, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) }, 16, ) == 0x0 03783 464 NtClose (460, ... ) == 0x0 03784 464 NtClose (456, ... ) == 0x0 03785 464 NtEnumerateKey (448, 5, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 03786 464 NtClose (448, ... ) == 0x0 03787 464 NtCreateMutant (0x1f0001, {24, 44, 0x80, 0, 0, (0x1f0001, {24, 44, 0x80, 0, 0, "Local\ZoneAttributeCacheCounterMutex"}, 0, ... 448, ) }, 0, ... 448, ) == STATUS_OBJECT_NAME_EXISTS 03788 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03789 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03790 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03791 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03792 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03793 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\"}, ... 456, ) }, ... 456, ) == 0x0 03794 464 NtEnumerateKey (456, 0, Basic, 288, ... {LastWrite={0x4362a77c,0x1c74db1}, TitleIdx=0, Name= (456, 0, Basic, 288, ... {LastWrite={0x4362a77c,0x1c74db1}, TitleIdx=0, Name="0"}, 18, ) }, 18, ) == 0x0 03795 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"}, ... 460, ) }, ... 460, ) == 0x0 03796 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03797 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03798 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03799 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... 464, ) }, ... 464, ) == 0x0 03800 464 NtQueryValueKey (464, (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="!\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="!\0\0\0"}, 16, ) }, 16, ) == 0x0 03801 464 NtClose (464, ... ) == 0x0 03802 464 NtClose (460, ... ) == 0x0 03803 464 NtEnumerateKey (456, 1, Basic, 288, ... {LastWrite={0x4362a77c,0x1c74db1}, TitleIdx=0, Name= (456, 1, Basic, 288, ... {LastWrite={0x4362a77c,0x1c74db1}, TitleIdx=0, Name="1"}, 18, ) }, 18, ) == 0x0 03804 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"}, ... 460, ) }, ... 460, ) == 0x0 03805 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03806 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03807 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03808 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1"}, ... 464, ) }, ... 464, ) == 0x0 03809 464 NtQueryValueKey (464, (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\333\1\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\333\1\0\0"}, 16, ) }, 16, ) == 0x0 03810 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03811 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03812 464 NtOpenKey (0x2001f, {24, 84, 0x40, 0, 0, (0x2001f, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\"}, ... 468, ) }, ... 468, ) == 0x0 03813 464 NtSetValueKey (468, (468, "ProxyBypass", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (468, "ProxyBypass", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03814 464 NtSetValueKey (468, (468, "IntranetName", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (468, "IntranetName", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03815 464 NtSetValueKey (468, (468, "UNCAsIntranet", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (468, "UNCAsIntranet", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03816 464 NtSetValueKey (468, (468, "AutoDetect", 0, 4, "\1\0\0\0", 4, ... ) , 0, 4, (468, "AutoDetect", 0, 4, "\1\0\0\0", 4, ... ) , 4, ... ) == 0x0 03817 464 NtClose (468, ... ) == 0x0 03818 464 NtClose (464, ... ) == 0x0 03819 464 NtClose (460, ... ) == 0x0 03820 464 NtEnumerateKey (456, 2, Basic, 288, ... {LastWrite={0x436509d6,0x1c74db1}, TitleIdx=0, Name= (456, 2, Basic, 288, ... {LastWrite={0x436509d6,0x1c74db1}, TitleIdx=0, Name="2e"}, 18, ) }, 18, ) == 0x0 03821 464 NtAllocateVirtualMemory (-1, 1552384, 0, 4096, 4096, 4, ... 1552384, 4096, ) == 0x0 03822 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"}, ... 460, ) }, ... 460, ) == 0x0 03823 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03824 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03825 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03826 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"}, ... 464, ) }, ... 464, ) == 0x0 03827 464 NtQueryValueKey (464, (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="G\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="G\0\0\0"}, 16, ) }, 16, ) == 0x0 03828 464 NtClose (464, ... ) == 0x0 03829 464 NtClose (460, ... ) == 0x0 03830 464 NtEnumerateKey (456, 3, Basic, 288, ... {LastWrite={0x436509d6,0x1c74db1}, TitleIdx=0, Name= (456, 3, Basic, 288, ... {LastWrite={0x436509d6,0x1c74db1}, TitleIdx=0, Name="3"}, 18, ) }, 18, ) == 0x0 03831 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"}, ... 460, ) }, ... 460, ) == 0x0 03832 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03833 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03834 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03835 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"}, ... 464, ) }, ... 464, ) == 0x0 03836 464 NtQueryValueKey (464, (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 03837 464 NtClose (464, ... ) == 0x0 03838 464 NtClose (460, ... ) == 0x0 03839 464 NtEnumerateKey (456, 4, Basic, 288, ... {LastWrite={0x43676c30,0x1c74db1}, TitleIdx=0, Name= (456, 4, Basic, 288, ... {LastWrite={0x43676c30,0x1c74db1}, TitleIdx=0, Name="4"}, 18, ) }, 18, ) == 0x0 03840 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4"}, ... 460, ) }, ... 460, ) == 0x0 03841 464 NtAllocateVirtualMemory (-1, 1556480, 0, 4096, 4096, 4, ... 1556480, 4096, ) == 0x0 03842 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03843 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03844 464 NtOpenKey (0x20019, {24, 28, 0x40, 0, 0, (0x20019, {24, 28, 0x40, 0, 0, "Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03845 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4"}, ... 464, ) }, ... 464, ) == 0x0 03846 464 NtQueryValueKey (464, (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (464, "Flags", Partial, 144, ... TitleIdx=0, Type=4, Data="\3\0\0\0"}, 16, ) }, 16, ) == 0x0 03847 464 NtClose (464, ... ) == 0x0 03848 464 NtClose (460, ... ) == 0x0 03849 464 NtEnumerateKey (456, 5, Basic, 288, ... ) == STATUS_NO_MORE_ENTRIES 03850 464 NtClose (456, ... ) == 0x0 03851 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03852 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03853 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03854 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03855 464 NtSetEvent (428, ... 0x0, ) == 0x0 03856 464 NtSetEvent (424, ... 0x0, ) == 0x0 03857 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 03858 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03859 464 NtSetEvent (428, ... 0x0, ) == 0x0 03860 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 03861 464 NtSetEvent (428, ... 0x0, ) == 0x0 03862 464 NtSetEvent (424, ... 0x0, ) == 0x0 03863 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 03864 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03865 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 03866 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 03867 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 456, 2, ) }, 0, 0x0, 0, ... 456, 2, ) == 0x0 03868 464 NtQueryValueKey (456, (456, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (456, "Cache", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 120, ) }, 120, ) == 0x0 03869 464 NtClose (456, ... ) == 0x0 03870 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Local Settings\Temporary Internet Files"}, 1231428, ... ) }, 1231428, ... ) == 0x0 03871 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 456, 2, ) }, 0, 0x0, 0, ... 456, 2, ) == 0x0 03872 464 NtSetValueKey (456, (456, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 162, ... ) , 0, 1, (456, "Cache", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0", 162, ... ) , 162, ... ) == 0x0 03873 464 NtClose (456, ... ) == 0x0 03874 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03875 464 NtReleaseSemaphore (236, 1, ... 0, ) == 0x0 03876 464 NtWaitForSingleObject (236, 0, {0, 0}, ... ) == 0x0 03877 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"}, 0, 0x0, 0, ... 456, 2, ) }, 0, 0x0, 0, ... 456, 2, ) == 0x0 03878 464 NtQueryValueKey (456, (456, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) , Partial, 144, ... TitleIdx=0, Type=2, Data= (456, "Cookies", Partial, 144, ... TitleIdx=0, Type=2, Data="%\0U\0S\0E\0R\0P\0R\0O\0F\0I\0L\0E\0%\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0"}, 56, ) }, 56, ) == 0x0 03879 464 NtClose (456, ... ) == 0x0 03880 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\Documents and Settings\Martim Carbone\Cookies"}, 1231428, ... ) }, 1231428, ... ) == 0x0 03881 464 NtCreateKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, 0, 0x0, 0, ... 456, 2, ) }, 0, 0x0, 0, ... 456, 2, ) == 0x0 03882 464 NtSetValueKey (456, (456, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 98, ... ) , 0, 1, (456, "Cookies", 0, 1, "C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0C\0o\0o\0k\0i\0e\0s\0\0\0", 98, ... ) , 98, ... ) == 0x0 03883 464 NtClose (456, ... ) == 0x0 03884 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03885 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03886 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1232512, ... ) }, 1232512, ... ) == 0x0 03887 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 456, {status=0x0, info=1}, ) }, 3, 16417, ... 456, {status=0x0, info=1}, ) == 0x0 03888 464 NtQueryDirectoryFile (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 03889 464 NtClose (456, ... ) == 0x0 03890 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 456, {status=0x0, info=1}, ) }, 3, 16417, ... 456, {status=0x0, info=1}, ) == 0x0 03891 464 NtQueryDirectoryFile (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 03892 464 NtClose (456, ... ) == 0x0 03893 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03894 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03895 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03896 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03897 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1232512, ... ) }, 1232512, ... ) == 0x0 03898 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 456, {status=0x0, info=1}, ) }, 3, 16417, ... 456, {status=0x0, info=1}, ) == 0x0 03899 464 NtQueryDirectoryFile (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 03900 464 NtClose (456, ... ) == 0x0 03901 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 456, {status=0x0, info=1}, ) }, 3, 16417, ... 456, {status=0x0, info=1}, ) == 0x0 03902 464 NtQueryDirectoryFile (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, (456, 0, 0, 0, 1231940, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 03903 464 NtClose (456, ... ) == 0x0 03904 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03905 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03906 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03907 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03908 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1233720, ... ) }, 1233720, ... ) == 0x0 03909 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03910 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03911 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03912 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03913 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1233036, ... ) }, 1233036, ... ) == 0x0 03914 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03915 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03916 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03917 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03918 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat:Zone.Identifier"}, 1233584, ... ) }, 1233584, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03919 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 03920 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 03921 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03922 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03923 464 NtWaitForSingleObject (380, 0, 0x0, ... ) == 0x0 03924 464 NtReleaseMutant (380, ... 0x0, ) == 0x0 03925 464 NtWaitForSingleObject (388, 0, 0x0, ... ) == 0x0 03926 464 NtReleaseMutant (388, ... 0x0, ) == 0x0 03927 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0"}, ... 456, ) }, ... 456, ) == 0x0 03928 464 NtQueryValueKey (456, (456, "1806", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 144, ... TitleIdx=0, Type=4, Data= (456, "1806", Partial, 144, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 03929 464 NtWaitForSingleObject (388, 0, 0x0, ... ) == 0x0 03930 464 NtReleaseMutant (388, ... 0x0, ) == 0x0 03931 464 NtClose (456, ... ) == 0x0 03932 464 NtClose (420, ... ) == 0x0 03933 464 NtClose (400, ... ) == 0x0 03934 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 400, ) }, ... 400, ) == 0x0 03935 464 NtQueryValueKey (400, (400, "TransparentEnabled", Full, 524, ... TitleIdx=0, Type=4, Name="TransparentEnabled", Data="\1\0\0\0"}, 60, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (400, "TransparentEnabled", Full, 524, ... TitleIdx=0, Type=4, Name="TransparentEnabled", Data="\1\0\0\0"}, 60, ) , Data= (400, "TransparentEnabled", Full, 524, ... TitleIdx=0, Type=4, Name="TransparentEnabled", Data="\1\0\0\0"}, 60, ) }, 60, ) == 0x0 03936 464 NtClose (400, ... ) == 0x0 03937 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 400, ) }, ... 400, ) == 0x0 03938 464 NtQueryValueKey (400, (400, "ExecutableTypes", Partial, 0, ... ) , Partial, 0, ... ) == STATUS_BUFFER_TOO_SMALL 03939 464 NtQueryValueKey (400, (400, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) , Partial, 260, ... TitleIdx=0, Type=7, Data= (400, "ExecutableTypes", Partial, 260, ... TitleIdx=0, Type=7, Data="A\0D\0E\0\0\0A\0D\0P\0\0\0B\0A\0S\0\0\0B\0A\0T\0\0\0C\0H\0M\0\0\0C\0M\0D\0\0\0C\0O\0M\0\0\0C\0P\0L\0\0\0C\0R\0T\0\0\0E\0X\0E\0\0\0H\0L\0P\0\0\0H\0T\0A\0\0\0I\0N\0F\0\0\0I\0N\0S\0\0\0I\0S\0P\0\0\0L\0N\0K\0\0\0M\0D\0B\0\0\0M\0D\0E\0\0\0M\0S\0C\0\0\0M\0S\0I\0\0\0M\0S\0P\0\0\0M\0S\0T\0\0\0O\0C\0X\0\0\0P\0C\0D\0\0\0P\0I\0F\0\0\0R\0E\0G\0\0\0S\0C\0R\0\0\0S\0H\0S\0\0\0U\0R\0L\0\0\0V\0B\0\0\0W\0S\0C\0\0\0\0\0"}, 260, ) }, 260, ) == 0x0 03940 464 NtClose (400, ... ) == 0x0 03941 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03942 464 NtOpenKey (0x2000000, {24, 220, 0x40, 0, 0, (0x2000000, {24, 220, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03943 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 03944 464 NtOpenKey (0x2000000, {24, 220, 0x40, 0, 0, (0x2000000, {24, 220, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03945 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03946 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, ".bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03947 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\.bat"}, ... 400, ) }, ... 400, ) == 0x0 03948 464 NtQueryKey (402, Name, 392, ... {Name= (402, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\.bato"}, 82, ) }, 82, ) == 0x0 03949 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03950 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 420, ) == 0x0 03951 464 NtQueryInformationToken (420, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03952 464 NtClose (420, ... ) == 0x0 03953 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03954 464 NtQueryValueKey (402, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data= (402, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data="b\0a\0t\0f\0i\0l\0e\0\0\0"}, 28, ) }, 28, ) == 0x0 03955 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 03956 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03957 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\batfile"}, ... 420, ) }, ... 420, ) == 0x0 03958 464 NtQueryKey (422, Name, 384, ... {Name= (422, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03959 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03960 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 456, ) == 0x0 03961 464 NtQueryInformationToken (456, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03962 464 NtClose (456, ... ) == 0x0 03963 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03964 464 NtOpenKey (0x1, {24, 422, 0x40, 0, 0, (0x1, {24, 422, 0x40, 0, 0, "CurVer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03965 464 NtQueryKey (422, Name, 384, ... {Name= (422, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03966 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03967 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 456, ) == 0x0 03968 464 NtQueryInformationToken (456, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03969 464 NtClose (456, ... ) == 0x0 03970 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03971 464 NtOpenKey (0x2000000, {24, 422, 0x40, 0, 0, ""}, ... 456, ) == 0x0 03972 464 NtClose (422, ... ) == 0x0 03973 464 NtQueryKey (458, Name, 384, ... {Name= (458, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile"}, 88, ) }, 88, ) == 0x0 03974 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03975 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 420, ) == 0x0 03976 464 NtQueryInformationToken (420, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03977 464 NtClose (420, ... ) == 0x0 03978 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03979 464 NtOpenKey (0x2000000, {24, 458, 0x40, 0, 0, (0x2000000, {24, 458, 0x40, 0, 0, "shell"}, ... 420, ) }, ... 420, ) == 0x0 03980 464 NtQueryKey (422, Name, 392, ... {Name= (422, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell"}, 100, ) }, 100, ) == 0x0 03981 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03982 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 460, ) == 0x0 03983 464 NtQueryInformationToken (460, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03984 464 NtClose (460, ... ) == 0x0 03985 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03986 464 NtQueryValueKey (422, 0x0, Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03987 464 NtQueryKey (422, Name, 384, ... {Name= (422, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell"}, 100, ) }, 100, ) == 0x0 03988 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03989 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 460, ) == 0x0 03990 464 NtQueryInformationToken (460, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03991 464 NtClose (460, ... ) == 0x0 03992 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 03993 464 NtOpenKey (0x2000000, {24, 422, 0x40, 0, 0, (0x2000000, {24, 422, 0x40, 0, 0, "open"}, ... 460, ) }, ... 460, ) == 0x0 03994 464 NtClose (422, ... ) == 0x0 03995 464 NtQueryKey (462, Name, 384, ... {Name= (462, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open3"}, 110, ) }, 110, ) == 0x0 03996 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 03997 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 420, ) == 0x0 03998 464 NtQueryInformationToken (420, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 03999 464 NtClose (420, ... ) == 0x0 04000 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04001 464 NtOpenKey (0x1, {24, 462, 0x40, 0, 0, (0x1, {24, 462, 0x40, 0, 0, "command"}, ... 420, ) }, ... 420, ) == 0x0 04002 464 NtQueryKey (422, Name, 392, ... {Name= (422, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command4"}, 126, ) }, 126, ) == 0x0 04003 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04004 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 464, ) == 0x0 04005 464 NtQueryInformationToken (464, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04006 464 NtClose (464, ... ) == 0x0 04007 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04008 464 NtQueryValueKey (422, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=" (422, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=""\0%\01\0"\0 \0%\0*\0\0\0"}, 28, ) \0 \0%\0*\0\0\0"}, 28, ) == 0x0 04009 464 NtClose (422, ... ) == 0x0 04010 464 NtOpenKey (0x20019, {24, 84, 0x40, 0, 0, (0x20019, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04011 464 NtQueryKey (462, Name, 384, ... {Name= (462, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\opent"}, 110, ) }, 110, ) == 0x0 04012 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04013 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 420, ) == 0x0 04014 464 NtQueryInformationToken (420, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04015 464 NtClose (420, ... ) == 0x0 04016 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04017 464 NtOpenKey (0x1, {24, 462, 0x40, 0, 0, (0x1, {24, 462, 0x40, 0, 0, "command"}, ... 420, ) }, ... 420, ) == 0x0 04018 464 NtQueryKey (422, Name, 392, ... {Name= (422, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command4"}, 126, ) }, 126, ) == 0x0 04019 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04020 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 464, ) == 0x0 04021 464 NtQueryInformationToken (464, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04022 464 NtClose (464, ... ) == 0x0 04023 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04024 464 NtQueryValueKey (422, (422, "command", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04025 464 NtClose (422, ... ) == 0x0 04026 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04027 464 NtQueryKey (462, Name, 384, ... {Name= (462, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\opent"}, 110, ) }, 110, ) == 0x0 04028 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04029 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 420, ) == 0x0 04030 464 NtQueryInformationToken (420, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04031 464 NtClose (420, ... ) == 0x0 04032 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04033 464 NtOpenKey (0x1, {24, 462, 0x40, 0, 0, (0x1, {24, 462, 0x40, 0, 0, "command"}, ... 420, ) }, ... 420, ) == 0x0 04034 464 NtQueryKey (422, Name, 392, ... {Name= (422, Name, 392, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command4"}, 126, ) }, 126, ) == 0x0 04035 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04036 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 464, ) == 0x0 04037 464 NtQueryInformationToken (464, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04038 464 NtClose (464, ... ) == 0x0 04039 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\command"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04040 464 NtQueryValueKey (422, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=" (422, 0x0, Partial, 144, ... TitleIdx=0, Type=1, Data=""\0%\01\0"\0 \0%\0*\0\0\0"}, 28, ) \0 \0%\0*\0\0\0"}, 28, ) == 0x0 04041 464 NtClose (422, ... ) == 0x0 04042 464 NtQueryKey (462, Name, 384, ... {Name= (462, Name, 384, ... {Name="\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open3"}, 110, ) }, 110, ) == 0x0 04043 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04044 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 420, ) == 0x0 04045 464 NtQueryInformationToken (420, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04046 464 NtClose (420, ... ) == 0x0 04047 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_Classes\batfile\shell\open\ddeexec"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04048 464 NtOpenKey (0x1, {24, 462, 0x40, 0, 0, (0x1, {24, 462, 0x40, 0, 0, "ddeexec"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04049 464 NtUserGetForegroundWindow (... ) == 0x70104 04050 464 NtQueryKey (210, Name, 384, ... {Name= (210, Name, 384, ... {Name="\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003_CLASSES"}, 140, ) }, 140, ) == 0x0 04051 464 NtOpenKey (0x2000000, {24, 210, 0x40, 0, 0, (0x2000000, {24, 210, 0x40, 0, 0, "Applications\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04052 464 NtOpenKey (0x2000000, {24, 0, 0x40, 0, 0, (0x2000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Classes\Applications\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04053 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04054 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04055 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1235444, ... ) }, 1235444, ... ) == 0x0 04056 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04057 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04058 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04059 464 NtOpenKey (0x2000000, {24, 84, 0x40, 0, 0, (0x2000000, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\ShellNoRoam"}, ... 420, ) }, ... 420, ) == 0x0 04060 464 NtOpenKey (0x2000000, {24, 420, 0x40, 0, 0, (0x2000000, {24, 420, 0x40, 0, 0, "MUICache"}, ... 464, ) }, ... 464, ) == 0x0 04061 464 NtQueryDefaultUILanguage (1235768, ... 04062 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04063 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... -2147482584, ) == 0x0 04064 464 NtQueryInformationToken (-2147482584, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04065 464 NtClose (-2147482584, ... ) == 0x0 04066 464 NtOpenKey (0x2000000, {24, 0, 0x640, 0, 0, (0x2000000, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... -2147482584, ) }, ... -2147482584, ) == 0x0 04067 464 NtOpenKey (0x80000000, {24, -2147482584, 0x240, 0, 0, (0x80000000, {24, -2147482584, 0x240, 0, 0, "Software\Policies\Microsoft\Control Panel\Desktop"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04068 464 NtOpenKey (0x80000000, {24, -2147482584, 0x640, 0, 0, (0x80000000, {24, -2147482584, 0x640, 0, 0, "Control Panel\Desktop"}, ... -2147481332, ) }, ... -2147481332, ) == 0x0 04069 464 NtQueryValueKey (-2147481332, (-2147481332, "MultiUILanguageId", Partial, 256, ... ) , Partial, 256, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04070 464 NtClose (-2147481332, ... ) == 0x0 04071 464 NtClose (-2147482584, ... ) == 0x0 04061 464 NtQueryDefaultUILanguage ... ) == 0x0 04072 464 NtQueryValueKey (464, (464, "LangID", Partial, 144, ... TitleIdx=0, Type=3, Data="\11\4"}, 14, ) , Partial, 144, ... TitleIdx=0, Type=3, Data= (464, "LangID", Partial, 144, ... TitleIdx=0, Type=3, Data="\11\4"}, 14, ) }, 14, ) == 0x0 04073 464 NtOpenKey (0x2000000, {24, 464, 0x40, 0, 0, ""}, ... 468, ) == 0x0 04074 464 NtQueryValueKey (468, (468, "C:\WINDOWS\system32\tmp-490-wlr.bat", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04075 464 NtClose (468, ... ) == 0x0 04076 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04077 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04078 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1234060, ... ) }, 1234060, ... ) == 0x0 04079 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04080 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04081 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04082 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04083 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1233804, ... ) }, 1233804, ... ) == 0x0 04084 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 5, 96, ... 468, {status=0x0, info=1}, ) }, 5, 96, ... 468, {status=0x0, info=1}, ) == 0x0 04085 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 468, ... 472, ) == 0x0 04086 464 NtClose (468, ... ) == 0x0 04087 464 NtMapViewOfSection (472, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xd20000), 0x0, 4096, ) == 0x0 04088 464 NtClose (472, ... ) == 0x0 04089 464 NtUnmapViewOfSection (-1, 0xd20000, ... ) == 0x0 04090 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1233400, ... ) }, 1233400, ... ) == 0x0 04091 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1234144, (0x80100080, {24, 0, 0x40, 0, 1234144, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 0x0, 0, 5, 1, 96, 0, 0, ... 472, {status=0x0, info=1}, ) }, 0x0, 0, 5, 1, 96, 0, 0, ... 472, {status=0x0, info=1}, ) == 0x0 04092 464 NtCreateSection (0xf0005, 0x0, 0x0, 2, 134217728, 472, ... 468, ) == 0x0 04093 464 NtClose (472, ... ) == 0x0 04094 464 NtMapViewOfSection (468, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 2, ... (0xd20000), {0, 0}, 4096, ) == 0x0 04095 464 NtClose (468, ... ) == 0x0 04096 464 NtUnmapViewOfSection (-1, 0xd20000, ... ) == 0x0 04097 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04098 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04099 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 1234708, (0x80100080, {24, 0, 0x40, 0, 1234708, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 0x0, 128, 1, 1, 96, 0, 0, ... 468, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 468, {status=0x0, info=1}, ) == 0x0 04100 464 NtReadFile (468, 0, 0, 0, 2, 0x0, 0, ... {status=0x0, info=2}, (468, 0, 0, 0, 2, 0x0, 0, ... {status=0x0, info=2}, "@e", ) , ) == 0x0 04101 464 NtClose (468, ... ) == 0x0 04102 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation"}, ... 468, ) }, ... 468, ) == 0x0 04103 464 NtQueryValueKey (468, (468, "CutList", Partial, 144, ... TitleIdx=0, Type=7, Data="A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0F\0i\0l\0e\0\0\0M\0F\0C\0 \0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0\0\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=7, Data= (468, "CutList", Partial, 144, ... TitleIdx=0, Type=7, Data="A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0F\0i\0l\0e\0\0\0M\0F\0C\0 \0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0\0\0\0\0"}, 80, ) }, 80, ) == 0x0 04104 464 NtClose (468, ... ) == 0x0 04105 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation"}, ... 468, ) }, ... 468, ) == 0x0 04106 464 NtQueryValueKey (468, (468, "CutList", Partial, 144, ... TitleIdx=0, Type=7, Data="A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0F\0i\0l\0e\0\0\0M\0F\0C\0 \0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0\0\0\0\0"}, 80, ) , Partial, 144, ... TitleIdx=0, Type=7, Data= (468, "CutList", Partial, 144, ... TitleIdx=0, Type=7, Data="A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0F\0i\0l\0e\0\0\0M\0F\0C\0 \0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0\0\0\0\0"}, 80, ) }, 80, ) == 0x0 04107 464 NtClose (468, ... ) == 0x0 04108 464 NtOpenThreadToken (-2, 0xc, 1, ... ) == STATUS_NO_TOKEN 04109 464 NtOpenKey (0x2000000, {24, 464, 0x40, 0, 0, ""}, ... 468, ) == 0x0 04110 464 NtSetValueKey (468, (468, "C:\WINDOWS\system32\tmp-490-wlr.bat", 0, 1, "t\0m\0p\0-\04\09\00\0-\0w\0l\0r\0\0\0", 24, ... , 0, 1, (468, "C:\WINDOWS\system32\tmp-490-wlr.bat", 0, 1, "t\0m\0p\0-\04\09\00\0-\0w\0l\0r\0\0\0", 24, ... , 24, ... 04111 464 NtSetInformationFile (-2147482192, -106645712, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 04112 464 NtSetInformationFile (-2147482192, -106645748, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 04113 464 NtSetInformationFile (-2147482192, -106645804, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 04114 464 NtSetInformationFile (-2147482192, -106646112, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 04115 464 NtSetInformationFile (-2147482192, -106646160, 8, EndOfFile, ... {status=0x0, info=0}, ) == 0x0 04110 464 NtSetValueKey ... ) == 0x0 04116 464 NtClose (468, ... ) == 0x0 04117 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 04118 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 04119 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04120 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 468, ) }, ... 468, ) == 0x0 04121 464 NtQueryValueKey (468, (468, "InheritConsoleHandles", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04122 464 NtClose (468, ... ) == 0x0 04123 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 04124 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 04125 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04126 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 468, ) }, ... 468, ) == 0x0 04127 464 NtQueryValueKey (468, (468, "RestrictRun", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04128 464 NtClose (468, ... ) == 0x0 04129 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 04130 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 04131 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04132 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 468, ) }, ... 468, ) == 0x0 04133 464 NtQueryValueKey (468, (468, "DisallowRun", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04134 464 NtClose (468, ... ) == 0x0 04135 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04136 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04137 464 NtReleaseSemaphore (212, 1, ... 0, ) == 0x0 04138 464 NtWaitForSingleObject (212, 0, {0, 0}, ... ) == 0x0 04139 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04140 464 NtOpenKey (0x1, {24, 84, 0x40, 0, 0, (0x1, {24, 84, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer"}, ... 468, ) }, ... 468, ) == 0x0 04141 464 NtQueryValueKey (468, (468, "NoRunasInstallPrompt", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04142 464 NtClose (468, ... ) == 0x0 04143 464 NtOpenKey (0x1, {24, 28, 0x40, 0, 0, (0x1, {24, 28, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\App Paths\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04144 464 NtQueryInformationJobObject (0, BasicUIRestrictions, 4, ... ) == STATUS_ACCESS_DENIED 04145 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1231108, ... ) }, 1231108, ... ) == 0x0 04146 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1231844, ... ) }, 1231844, ... ) == 0x0 04147 464 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 5, 96, ... 468, {status=0x0, info=1}, ) }, 5, 96, ... 468, {status=0x0, info=1}, ) == 0x0 04148 464 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 468, ... ) == STATUS_INVALID_IMAGE_NOT_MZ 04149 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility"}, ... 472, ) }, ... 472, ) == 0x0 04150 464 NtQueryValueKey (472, (472, "DisableAppCompat", Partial, 20, ... ) , Partial, 20, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04151 464 NtClose (472, ... ) == 0x0 04152 464 NtQueryVolumeInformationFile (468, 1231120, 8, Device, ... {status=0x0, info=8}, ) == 0x0 04153 464 NtAllocateVirtualMemory (-1, 1560576, 0, 4096, 4096, 4, ... 1560576, 4096, ) == 0x0 04154 464 NtOpenMutant (0x120001, {24, 44, 0x0, 0, 0, (0x120001, {24, 44, 0x0, 0, 0, "ShimCacheMutex"}, ... 472, ) }, ... 472, ) == 0x0 04155 464 NtWaitForSingleObject (472, 0, {-1000000, -1}, ... ) == 0x0 04156 464 NtOpenSection (0x2, {24, 44, 0x0, 0, 0, (0x2, {24, 44, 0x0, 0, 0, "ShimSharedMemory"}, ... 476, ) }, ... 476, ) == 0x0 04157 464 NtMapViewOfSection (476, -1, (0x0), 0, 0, {0, 0}, 0, 1, 0, 4, ... (0xd20000), {0, 0}, 57344, ) == 0x0 04158 464 NtReleaseMutant (472, ... 0x0, ) == 0x0 04159 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1229052, ... ) }, 1229052, ... ) == 0x0 04160 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 480, {status=0x0, info=1}, ) }, 5, 96, ... 480, {status=0x0, info=1}, ) == 0x0 04161 464 NtCreateSection (0xe, 0x0, 0x0, 16, 134217728, 480, ... 484, ) == 0x0 04162 464 NtClose (480, ... ) == 0x0 04163 464 NtMapViewOfSection (484, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 16, ... (0xd30000), 0x0, 126976, ) == 0x0 04164 464 NtClose (484, ... ) == 0x0 04165 464 NtUnmapViewOfSection (-1, 0xd30000, ... ) == 0x0 04166 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 1229360, ... ) }, 1229360, ... ) == 0x0 04167 464 NtOpenFile (0x100020, {24, 0, 0x40, 0, 0, (0x100020, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\Apphelp.dll"}, 5, 96, ... 484, {status=0x0, info=1}, ) }, 5, 96, ... 484, {status=0x0, info=1}, ) == 0x0 04168 464 NtCreateSection (0xf, 0x0, 0x0, 16, 16777216, 484, ... 480, ) == 0x0 04169 464 NtQuerySection (480, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04170 464 NtClose (484, ... ) == 0x0 04171 464 NtMapViewOfSection (480, -1, (0x0), 0, 0, 0x0, 0, 1, 0, 4, ... (0x77b40000), 0x0, 139264, ) == 0x0 04172 464 NtClose (480, ... ) == 0x0 04173 464 NtProtectVirtualMemory (-1, (0x77b41000), 524, 4, ... (0x77b41000), 4096, 32, ) == 0x0 04174 464 NtProtectVirtualMemory (-1, (0x77b41000), 4096, 32, ... (0x77b41000), 4096, 4, ) == 0x0 04175 464 NtFlushInstructionCache (-1, 2008289280, 524, ... ) == 0x0 04176 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04177 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\sysmain.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... 480, {status=0x0, info=1}, ) }, 0x0, 128, 1, 1, 96, 0, 0, ... 480, {status=0x0, info=1}, ) == 0x0 04178 464 NtQueryInformationFile (480, 1229376, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04179 464 NtCreateSection (0x4, 0x0, 0x0, 2, 134217728, 480, ... 484, ) == 0x0 04180 464 NtMapViewOfSection (484, -1, (0x0), 0, 0, 0x0, 0, 2, 0, 2, ... (0xd30000), 0x0, 1191936, ) == 0x0 04181 464 NtQueryInformationFile (480, 1229476, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04182 464 NtCreateFile (0x80100080, {24, 0, 0x40, 0, 0, (0x80100080, {24, 0, 0x40, 0, 0, "\SystemRoot\AppPatch\systest.sdb"}, 0x0, 128, 1, 1, 96, 0, 0, ... ) }, 0x0, 128, 1, 1, 96, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04183 464 NtQuerySystemInformation (Processor, 12, ... {system info, class 1, size 12}, 0x0, ) == 0x0 04184 464 NtQueryInformationProcess (-1, Wow64, 4, ... {process info, class 26, size 4}, 0x0, ) == 0x0 04185 464 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\System\WPA\TabletPC"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04186 464 NtOpenKey (0x101, {24, 0, 0x40, 0, 0, (0x101, {24, 0, 0x40, 0, 0, "\Registry\Machine\SYSTEM\WPA\MediaCenter"}, ... 488, ) }, ... 488, ) == 0x0 04187 464 NtQueryValueKey (488, (488, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 256, ... TitleIdx=0, Type=4, Data= (488, "Installed", Partial, 256, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04188 464 NtClose (488, ... ) == 0x0 04189 464 NtCreateFile (0x120116, {24, 0, 0x40, 0, 0, (0x120116, {24, 0, 0x40, 0, 0, "\Device\NamedPipe\ShimViewer"}, 0x0, 128, 0, 1, 0, 0, 0, ... ) }, 0x0, 128, 0, 1, 0, 0, 0, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04190 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04191 464 NtQueryDirectoryFile (488, 0, 0, 0, 1227072, 616, BothDirectory, 1, (488, 0, 0, 0, 1227072, 616, BothDirectory, 1, "tmp-490-wlr.bat", 0, ... {status=0x0, info=124}, ) , 0, ... {status=0x0, info=124}, ) == 0x0 04192 464 NtClose (488, ... ) == 0x0 04193 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04194 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04195 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1227448, ... ) }, 1227448, ... ) == 0x0 04196 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04197 464 NtQueryDirectoryFile (488, 0, 0, 0, 1226876, 616, BothDirectory, 1, (488, 0, 0, 0, 1226876, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 04198 464 NtClose (488, ... ) == 0x0 04199 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04200 464 NtQueryDirectoryFile (488, 0, 0, 0, 1226876, 616, BothDirectory, 1, (488, 0, 0, 0, 1226876, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 04201 464 NtClose (488, ... ) == 0x0 04202 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04203 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04204 464 NtQueryInformationProcess (-1, DeviceMap, 36, ... {process info, class 23, size 36}, 0x0, ) == 0x0 04205 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04206 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04207 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 488, ) == 0x0 04208 464 NtQueryInformationToken (488, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04209 464 NtClose (488, ... ) == 0x0 04210 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04211 464 NtOpenKey (0x80000100, {24, 0, 0x40, 0, 0, (0x80000100, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\tmp-490-wlr.bat"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04212 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04213 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04214 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1228700, ... ) }, 1228700, ... ) == 0x0 04215 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04216 464 NtQueryDirectoryFile (488, 0, 0, 0, 1228128, 616, BothDirectory, 1, (488, 0, 0, 0, 1228128, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 04217 464 NtClose (488, ... ) == 0x0 04218 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04219 464 NtQueryDirectoryFile (488, 0, 0, 0, 1228128, 616, BothDirectory, 1, (488, 0, 0, 0, 1228128, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 04220 464 NtClose (488, ... ) == 0x0 04221 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04222 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04223 464 NtWaitForSingleObject (472, 0, {-1000000, -1}, ... ) == 0x0 04224 464 NtQueryVolumeInformationFile (468, 1229356, 8, Device, ... {status=0x0, info=8}, ) == 0x0 04225 464 NtQueryInformationFile (468, 1229336, 40, Basic, ... {status=0x0, info=40}, ) == 0x0 04226 464 NtQueryInformationFile (468, 1229376, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04227 464 NtReleaseMutant (472, ... 0x0, ) == 0x0 04228 464 NtUnmapViewOfSection (-1, 0xd30000, ... ) == 0x0 04229 464 NtClose (484, ... ) == 0x0 04230 464 NtClose (480, ... ) == 0x0 04231 464 NtOpenThreadToken (-2, 0x2000000, 1, ... ) == STATUS_NO_TOKEN 04232 464 NtOpenProcessToken (-1, 0xa, ... 480, ) == 0x0 04233 464 NtQueryInformationToken (480, User, 136, ... {token info, class 1, size 36}, 36, ) == 0x0 04234 464 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04235 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 484, ) }, ... 484, ) == 0x0 04236 464 NtQueryValueKey (484, (484, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (484, "TransparentEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\1\0\0\0"}, 16, ) }, 16, ) == 0x0 04237 464 NtQueryValueKey (484, (484, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (484, "AuthenticodeEnabled", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04238 464 NtClose (484, ... ) == 0x0 04239 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04240 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 484, ) }, ... 484, ) == 0x0 04241 464 NtQueryValueKey (484, (484, "Levels", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04242 464 NtClose (484, ... ) == 0x0 04243 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04244 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04245 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04246 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04247 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04248 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04249 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04250 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04251 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04252 464 NtQueryDefaultLocale (1, 1230548, ... ) == 0x0 04253 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... 484, ) }, ... 484, ) == 0x0 04254 464 NtEnumerateKey (484, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name= (484, 0, Basic, 280, ... {LastWrite={0x3a5edea,0x1c74da9}, TitleIdx=0, Name="{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, 92, ) }, 92, ) == 0x0 04255 464 NtOpenKey (0x20019, {24, 484, 0x40, 0, 0, (0x20019, {24, 484, 0x40, 0, 0, "{dda3f824-d8cb-441b-834d-be2efd2c1a33}"}, ... 488, ) }, ... 488, ) == 0x0 04256 464 NtQueryValueKey (488, (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) , Partial, 280, ... TitleIdx=0, Type=2, Data= (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=2, Data="%\0H\0K\0E\0Y\0_\0C\0U\0R\0R\0E\0N\0T\0_\0U\0S\0E\0R\0\\0S\0o\0f\0t\0w\0a\0r\0e\0\\0M\0i\0c\0r\0o\0s\0o\0f\0t\0\\0W\0i\0n\0d\0o\0w\0s\0\\0C\0u\0r\0r\0e\0n\0t\0V\0e\0r\0s\0i\0o\0n\0\\0E\0x\0p\0l\0o\0r\0e\0r\0\\0S\0h\0e\0l\0l\0 \0F\0o\0l\0d\0e\0r\0s\0\\0C\0a\0c\0h\0e\0%\0O\0L\0K\0*\0\0\0"}, 202, ) }, 202, ) == 0x0 04257 464 NtAllocateVirtualMemory (-1, 1564672, 0, 4096, 4096, 4, ... 1564672, 4096, ) == 0x0 04258 464 NtQueryValueKey (488, (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04259 464 NtClose (488, ... ) == 0x0 04260 464 NtEnumerateKey (484, 1, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 04261 464 NtClose (484, ... ) == 0x0 04262 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... 484, ) }, ... 484, ) == 0x0 04263 464 NtEnumerateKey (484, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (484, 0, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, 92, ) }, 92, ) == 0x0 04264 464 NtOpenKey (0x20019, {24, 484, 0x40, 0, 0, (0x20019, {24, 484, 0x40, 0, 0, "{349d35ab-37b5-462f-9b89-edd5fbde1328}"}, ... 488, ) }, ... 488, ) == 0x0 04265 464 NtQueryValueKey (488, (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="^\2530O\225zI\211j\0l\341\25@\25"}, 28, ) }, 28, ) == 0x0 04266 464 NtQueryValueKey (488, (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 04267 464 NtQueryValueKey (488, (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\13\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 04268 464 NtQueryValueKey (488, (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04269 464 NtClose (488, ... ) == 0x0 04270 464 NtEnumerateKey (484, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (484, 1, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, 92, ) }, 92, ) == 0x0 04271 464 NtOpenKey (0x20019, {24, 484, 0x40, 0, 0, (0x20019, {24, 484, 0x40, 0, 0, "{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}"}, ... 488, ) }, ... 488, ) == 0x0 04272 464 NtQueryValueKey (488, (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="g\260\324\2134:?\323\274\351\334dg\4\363\224"}, 28, ) }, 28, ) == 0x0 04273 464 NtQueryValueKey (488, (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 04274 464 NtQueryValueKey (488, (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\5\2\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 04275 464 NtQueryValueKey (488, (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04276 464 NtClose (488, ... ) == 0x0 04277 464 NtEnumerateKey (484, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (484, 2, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, 92, ) }, 92, ) == 0x0 04278 464 NtOpenKey (0x20019, {24, 484, 0x40, 0, 0, (0x20019, {24, 484, 0x40, 0, 0, "{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}"}, ... 488, ) }, ... 488, ) == 0x0 04279 464 NtQueryValueKey (488, (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="2x\2\334\376\370\310\223\334\212\260\6\335\204}\35"}, 28, ) }, 28, ) == 0x0 04280 464 NtQueryValueKey (488, (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 04281 464 NtQueryValueKey (488, (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\226\3\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 04282 464 NtQueryValueKey (488, (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04283 464 NtClose (488, ... ) == 0x0 04284 464 NtEnumerateKey (484, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (484, 3, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, 92, ) }, 92, ) == 0x0 04285 464 NtOpenKey (0x20019, {24, 484, 0x40, 0, 0, (0x20019, {24, 484, 0x40, 0, 0, "{94e3e076-8f53-42a5-8411-085bcc18a68d}"}, ... 488, ) }, ... 488, ) == 0x0 04286 464 NtQueryValueKey (488, (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="\275\232*\333B\353\330V\16%\16M\370\26/g"}, 28, ) }, 28, ) == 0x0 04287 464 NtQueryValueKey (488, (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 04288 464 NtQueryValueKey (488, (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="\345\0\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 04289 464 NtQueryValueKey (488, (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04290 464 NtClose (488, ... ) == 0x0 04291 464 NtEnumerateKey (484, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name= (484, 4, Basic, 280, ... {LastWrite={0x38ab3b74,0x1c74d7e}, TitleIdx=0, Name="{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, 92, ) }, 92, ) == 0x0 04292 464 NtOpenKey (0x20019, {24, 484, 0x40, 0, 0, (0x20019, {24, 484, 0x40, 0, 0, "{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}"}, ... 488, ) }, ... 488, ) == 0x0 04293 464 NtQueryValueKey (488, (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) , Partial, 280, ... TitleIdx=0, Type=3, Data= (488, "ItemData", Partial, 280, ... TitleIdx=0, Type=3, Data="8k\10_\204\354\366i\323k\225j"\300\36\200"}, 28, ) \300\36\200"}, 28, ) == 0x0 04294 464 NtQueryValueKey (488, (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "HashAlg", Partial, 280, ... TitleIdx=0, Type=4, Data="\3\200\0\0"}, 16, ) }, 16, ) == 0x0 04295 464 NtQueryValueKey (488, (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) , Partial, 280, ... TitleIdx=0, Type=11, Data= (488, "ItemSize", Partial, 280, ... TitleIdx=0, Type=11, Data="r\1\0\0\0\0\0\0"}, 20, ) }, 20, ) == 0x0 04296 464 NtQueryValueKey (488, (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 280, ... TitleIdx=0, Type=4, Data= (488, "SaferFlags", Partial, 280, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04297 464 NtClose (488, ... ) == 0x0 04298 464 NtEnumerateKey (484, 5, Basic, 280, ... ) == STATUS_NO_MORE_ENTRIES 04299 464 NtClose (484, ... ) == 0x0 04300 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04301 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04302 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04303 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04304 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04305 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04306 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04307 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04308 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04309 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04310 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04311 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04312 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04313 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04314 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04315 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04316 464 NtClose (484, ... ) == 0x0 04317 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04318 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04319 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04320 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04321 464 NtClose (484, ... ) == 0x0 04322 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04323 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04324 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04325 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04326 464 NtClose (484, ... ) == 0x0 04327 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04328 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04329 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04330 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04331 464 NtClose (484, ... ) == 0x0 04332 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04333 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04334 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04335 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04336 464 NtClose (484, ... ) == 0x0 04337 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04338 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04339 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04340 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04341 464 NtClose (484, ... ) == 0x0 04342 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04343 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04344 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04345 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04346 464 NtClose (484, ... ) == 0x0 04347 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04348 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04349 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04350 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04351 464 NtClose (484, ... ) == 0x0 04352 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04353 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04354 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04355 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04356 464 NtClose (484, ... ) == 0x0 04357 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04358 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04359 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04360 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04361 464 NtClose (484, ... ) == 0x0 04362 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04363 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04364 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04365 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04366 464 NtClose (484, ... ) == 0x0 04367 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04368 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04369 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04370 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04371 464 NtClose (484, ... ) == 0x0 04372 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04373 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04374 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04375 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04376 464 NtClose (484, ... ) == 0x0 04377 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04378 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04379 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04380 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04381 464 NtClose (484, ... ) == 0x0 04382 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04383 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04384 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04385 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04386 464 NtClose (484, ... ) == 0x0 04387 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04388 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 484, ) }, ... 484, ) == 0x0 04389 464 NtQueryValueKey (484, (484, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Full, 524, ... TitleIdx=0, Type=4, Name= (484, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) , Data= (484, "DefaultLevel", Full, 524, ... TitleIdx=0, Type=4, Name="DefaultLevel", Data="\0\0\4\0"}, 48, ) }, 48, ) == 0x0 04390 464 NtClose (484, ... ) == 0x0 04391 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04392 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 484, ) == 0x0 04393 464 NtQueryInformationToken (484, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04394 464 NtClose (484, ... ) == 0x0 04395 464 NtOpenKey (0x20019, {24, 0, 0x40, 0, 0, (0x20019, {24, 0, 0x40, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04396 464 NtOpenThreadToken (-2, 0x8, 0, ... ) == STATUS_NO_TOKEN 04397 464 NtOpenProcessToken (-1, 0xa, ... 484, ) == 0x0 04398 464 NtDuplicateToken (484, 0xc, {24, 0, 0x0, 0, 1230980, 0x0}, 0, 2, ... 488, ) == 0x0 04399 464 NtClose (484, ... ) == 0x0 04400 464 NtAccessCheck (1565488, 488, 0x1, 1231056, 1231108, 56, 1231088, ... (0x1), ) == 0x0 04401 464 NtClose (488, ... ) == 0x0 04402 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 488, ) }, ... 488, ) == 0x0 04403 464 NtQueryValueKey (488, (488, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) , Partial, 80, ... TitleIdx=0, Type=4, Data= (488, "PolicyScope", Partial, 80, ... TitleIdx=0, Type=4, Data="\0\0\0\0"}, 16, ) }, 16, ) == 0x0 04404 464 NtClose (488, ... ) == 0x0 04405 464 NtOpenSymbolicLinkObject (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\??\C:"}, ... 488, ) }, ... 488, ) == 0x0 04406 464 NtQuerySymbolicLinkObject (488, ... (488, ... "\Device\HarddiskVolume1", 48, ) , 48, ) == 0x0 04407 464 NtClose (488, ... ) == 0x0 04408 464 NtQueryVolumeInformationFile (468, 1228812, 8, Device, ... {status=0x0, info=8}, ) == 0x0 04409 464 NtQueryInformationFile (468, 1228928, 528, Name, ... {status=0x0, info=70}, ) == 0x0 04410 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04411 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04412 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\tmp-490-wlr.bat"}, 1228100, ... ) }, 1228100, ... ) == 0x0 04413 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04414 464 NtQueryDirectoryFile (488, 0, 0, 0, 1227528, 616, BothDirectory, 1, (488, 0, 0, 0, 1227528, 616, BothDirectory, 1, "WINDOWS", 0, ... {status=0x0, info=108}, ) , 0, ... {status=0x0, info=108}, ) == 0x0 04415 464 NtClose (488, ... ) == 0x0 04416 464 NtOpenFile (0x100001, {24, 0, 0x40, 0, 0, (0x100001, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\"}, 3, 16417, ... 488, {status=0x0, info=1}, ) }, 3, 16417, ... 488, {status=0x0, info=1}, ) == 0x0 04417 464 NtQueryDirectoryFile (488, 0, 0, 0, 1227528, 616, BothDirectory, 1, (488, 0, 0, 0, 1227528, 616, BothDirectory, 1, "system32", 0, ... {status=0x0, info=110}, ) , 0, ... {status=0x0, info=110}, ) == 0x0 04418 464 NtClose (488, ... ) == 0x0 04419 464 NtQueryInformationProcess (-1, DefaultHardErrorMode, 4, ... {process info, class 12, size 4}, 0x0, ) == 0x0 04420 464 NtSetInformationProcess (-1, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04421 464 NtQueryInformationFile (468, 1230968, 24, Standard, ... {status=0x0, info=24}, ) == 0x0 04422 464 NtCreateSection (0xf0005, 0x0, {94, 0}, 2, 134217728, 468, ... 488, ) == 0x0 04423 464 NtMapViewOfSection (488, -1, (0x0), 0, 0, {0, 0}, 94, 1, 0, 2, ... (0xd30000), {0, 0}, 4096, ) == 0x0 04424 464 NtClose (488, ... ) == 0x0 04425 464 NtOpenThreadTokenEx (-2, 0x20008, 1, 512, ... ) == STATUS_NO_TOKEN 04426 464 NtOpenProcessTokenEx (-1, 0x20008, 512, ... 488, ) == 0x0 04427 464 NtQueryInformationToken (488, User, 80, ... {token info, class 1, size 36}, 36, ) == 0x0 04428 464 NtClose (488, ... ) == 0x0 04429 464 NtOpenKey (0x20019, {24, 0, 0x640, 0, 0, (0x20019, {24, 0, 0x640, 0, 0, "\REGISTRY\USER\S-1-5-21-1292428093-1383384898-725345543-1003"}, ... 488, ) }, ... 488, ) == 0x0 04430 464 NtOpenKey (0x20019, {24, 488, 0x40, 0, 0, (0x20019, {24, 488, 0x40, 0, 0, "Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"}, ... 484, ) }, ... 484, ) == 0x0 04431 464 NtClose (488, ... ) == 0x0 04432 464 NtQueryValueKey (484, (484, "Cache", Partial, 144, ... ) , Partial, 144, ... ) == STATUS_BUFFER_OVERFLOW 04433 464 NtQueryValueKey (484, (484, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) , Partial, 174, ... TitleIdx=0, Type=1, Data= (484, "Cache", Partial, 174, ... TitleIdx=0, Type=1, Data="C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0T\0e\0m\0p\0o\0r\0a\0r\0y\0 \0I\0n\0t\0e\0r\0n\0e\0t\0 \0F\0i\0l\0e\0s\0\0\0"}, 174, ) }, 174, ) == 0x0 04434 464 NtClose (484, ... ) == 0x0 04435 464 NtUnmapViewOfSection (-1, 0xd30000, ... ) == 0x0 04436 464 NtAllocateVirtualMemory (-1, 0, 0, 4096, 8192, 4, ... 13828096, 4096, ) == 0x0 04437 464 NtAllocateVirtualMemory (-1, 13828096, 0, 4096, 4096, 4, ... 13828096, 4096, ) == 0x0 04438 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers"}, ... 484, ) }, ... 484, ) == 0x0 04439 464 NtQueryValueKey (484, (484, "LogFileName", Partial, 536, ... ) , Partial, 536, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04440 464 NtClose (484, ... ) == 0x0 04441 464 NtOpenKey (0x3, {24, 0, 0x40, 0, 0, (0x3, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04442 464 NtQueryInformationToken (480, User, 128, ... {token info, class 1, size 36}, 36, ) == 0x0 04443 464 NtQueryInformationToken (480, 15, 4, ... {token info, class 15, size 4}, 4, ) == 0x0 04444 464 NtClose (480, ... ) == 0x0 04445 464 NtClose (468, ... ) == 0x0 04446 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\u:\work\cmd.exe"}, 1231084, ... ) }, 1231084, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04447 464 NtQueryAttributesFile ({24, 12, 0x40, 0, 0, ({24, 12, 0x40, 0, 0, "cmd.exe"}, 1231084, ... ) }, 1231084, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04448 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\cmd.exe"}, 1231084, ... ) }, 1231084, ... ) == 0x0 04449 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\cmd.exe"}, 1231844, ... ) }, 1231844, ... ) == 0x0 04450 464 NtOpenFile (0x1000a1, {24, 0, 0x40, 0, 0, (0x1000a1, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\cmd.exe"}, 5, 96, ... 468, {status=0x0, info=1}, ) }, 5, 96, ... 468, {status=0x0, info=1}, ) == 0x0 04451 464 NtCreateSection (0xf001f, 0x0, 0x0, 16, 16777216, 468, ... 480, ) == 0x0 04452 464 NtOpenKey (0x1, {24, 0, 0x40, 0, 0, (0x1, {24, 0, 0x40, 0, 0, "\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04453 464 NtQuerySection (480, Image, 48, ... {section info, class 1, size 48}, 0x0, ) == 0x0 04454 464 NtOpenKey (0x80000000, {24, 0, 0x40, 0, 0, (0x80000000, {24, 0, 0x40, 0, 0, "\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe"}, ... ) }, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04455 464 NtQuerySystemInformation (71, 4, ... {system info, class 71, size 4}, 0x0, ) == 0x0 04456 464 NtCreateProcessEx (1232892, 2035711, 0, -1, 0, 480, 0, 0, 0, ... ) == 0x0 04457 464 NtSetInformationProcess (484, DefaultHardErrorMode, {process info, class 12, size 4}, 4, ... ) == 0x0 04458 464 NtQueryInformationProcess (484, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffd4000,AffinityMask=0x1,BasePriority=8,Pid=444,ParentPid=1036,}, 0x0, ) == 0x0 04459 464 NtReadVirtualMemory (484, 0x7ffd4008, 4, ... (484, 0x7ffd4008, 4, ... "\0\0\320J", 0x0, ) , 0x0, ) == 0x0 04460 464 NtOpenFile (0x1200a9, {24, 0, 0x40, 0, 0, (0x1200a9, {24, 0, 0x40, 0, 0, "\??\C:\WINDOWS\system32\cmd.exe.Manifest"}, 1, 96, ... ) }, 1, 96, ... ) == STATUS_OBJECT_NAME_NOT_FOUND 04461 464 NtAllocateVirtualMemory (-1, 1568768, 0, 8192, 4096, 4, ... 1568768, 8192, ) == 0x0 04462 464 NtReadVirtualMemory (484, 0x4ad00000, 4096, ... (484, 0x4ad00000, 4096, ... "MZ\220\0\3\0\0\0\4\0\0\0\377\377\0\0\270\0\0\0\0\0\0\0@\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\330\0\0\0\16\37\272\16\0\264\11\315!\270\1L\315!This program cannot be run in DOS mode.\15\15\12$\0\0\0\0\0\0\0\35\355\325\352Y\214\273\271Y\214\273\271Y\214\273\271\232\203\264\271_\214\273\271Y\214\272\271\200\214\273\271\232\203\346\271^\214\273\271\346\203\333\271[\214\273\271\232\203\345\271X\214\273\271\232\203\344\271m\214\273\271\232\203\341\271X\214\273\271RichY\214\273\271\0\0\0\0\0\0\0\0PE\0\0L\1\3\0\276~\20A\0\0\0\0\0\0\0\0\340\0\17\1\13\1\7\12\0\366\1\0\0\366\3\0\0\0\0\0VP\0\0\0\20\0\0\0\360\1\0\0\0\320J\0\20\0\0\0\2\0\0\5\0\1\0\5\0\1\0\4\0\0\0\0\0\0\0\0\20\6\0\0\4\0\0\224$\6\0\3\0\0\200\0\0\20\0\0\0\20\0\0\0\20\0\0\20\0\0\0\0\0\0\20\0\0\0\0\0\0\0\0\0\0\0\0\366\1\0P\0\0\0\0\340\3\0\260(\2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\204\5\2\08\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\30\223\1\0H\0\0\0H\2\0\0X\0\0\0\0\20\0\0\0\3\0\0\340\362\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0.text\0\0\0\340\365\1\0\0\20\0\0\0\366\1\0\0\4\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 4096, ) , 4096, ) == 0x0 04463 464 NtReadVirtualMemory (484, 0x4ad3e000, 256, ... (484, 0x4ad3e000, 256, ... "\0\0\0\0\0\0\0\0\0\0\0\0\0\0\4\0\3\0\0\00\0\0\200\13\0\0\0\200\0\0\200\16\0\0\0\230\0\0\200\20\0\0\0\260\0\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\10\0\1\0\0\0\310\0\0\200\2\0\0\0\340\0\0\200\3\0\0\0\370\0\0\200\4\0\0\0\20\1\0\200\5\0\0\0(\1\0\200\6\0\0\0@\1\0\200\7\0\0\0X\1\0\200\10\0\0\0p\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\1\0\0\0\210\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\200\2\0\200\240\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\1\0\0\0\270\1\0\200\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\320\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\11\4\0\0\340\1\0\0\0\0\0\0\0\0\0\0", 256, ) , 256, ) == 0x0 04464 464 NtQueryDebugFilterState (53, 2, ... ) == 0x0 04465 464 NtQueryInformationProcess (484, Basic, 24, ... {ExitStatus=0x103,PebBaseAddress=0x7ffd4000,AffinityMask=0x1,BasePriority=8,Pid=444,ParentPid=1036,}, 0x0, ) == 0x0 04466 464 NtQueryAttributesFile ({24, 0, 0x40, 0, 0, ({24, 0, 0x40, 0, 0, "\??\C:\scripts"}, 1231844, ... ) }, 1231844, ... ) == 0x0 04467 464 NtAllocateVirtualMemory (-1, 0, 0, 2436, 4096, 4, ... 13893632, 4096, ) == 0x0 04468 464 NtAllocateVirtualMemory (484, 0, 0, 6432, 4096, 4, ... 65536, 8192, ) == 0x0 04469 464 NtWriteVirtualMemory (484, 0x10000, (484, 0x10000, "=\0A\0:\0=\0A\0:\0\\0\0\0=\0C\0:\0=\0C\0:\0\\0s\0c\0r\0i\0p\0t\0s\0\0\0=\0U\0:\0=\0U\0:\0\\0\0\0A\0L\0L\0U\0S\0E\0R\0S\0P\0R\0O\0F\0I\0L\0E\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0l\0l\0 \0U\0s\0e\0r\0s\0\0\0A\0P\0P\0D\0A\0T\0A\0=\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0M\0a\0r\0t\0i\0m\0 \0C\0a\0r\0b\0o\0n\0e\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0I\0N\0C\0_\0R\0O\0O\0T\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\09\00\0~\01\0.\01\08\03\0\\0i\0n\0c\0\0\0A\0T\0L\0_\0L\0I\0B\0_\0P\0A\0T\0H\0=\0C\0:\0\\0W\0I\0N\0D\0D\0K\0\\03\07\0", 6432, ... 0x0, ) , 6432, ... 0x0, ) == 0x0 04470 464 NtAllocateVirtualMemory (484, 0, 0, 2436, 4096, 4, ... 131072, 4096, ) == 0x0 04471 464 NtWriteVirtualMemory (484, 0x20000, (484, 0x20000, "\0\20\0\0\204\11\0\0\0\0\0\0\0\0\0\0\376\377\377\377\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\24\0\10\2\220\2\0\0\0\0\0\0\364\3\366\3\230\4\0\06\08\0\220\10\0\0^\0`\0\310\10\0\0\0\0\1\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\1\0\0\0\0\0\0\06\08\0(\11\0\0\36\0 \0`\11\0\0\0\0\2\0\200\11\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 2436, ... 0x0, ) , 2436, ... 0x0, ) == 0x0 04472 464 NtWriteVirtualMemory (484, 0x7ffd4010, (484, 0x7ffd4010, "\0\0\2\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 04473 464 NtWriteVirtualMemory (484, 0x7ffd41e8, (484, 0x7ffd41e8, "\0\0\0\0", 4, ... 0x0, ) , 4, ... 0x0, ) == 0x0 04474 464 NtFreeVirtualMemory (-1, (0xd40000), 0, 32768, ... (0xd40000), 4096, ) == 0x0 04475 464 NtAllocateVirtualMemory (484, 0, 0, 1048576, 8192, 4, ... 196608, 1048576, ) == 0x0 04476 464 NtAllocateVirtualMemory (484, 196608, 0, 1048576, 4096, 4, ... 196608, 1048576, ) == 0x0 04477 464 NtCreateThread (0x1f03ff, 0x0, 484, 1232900, 1232564, 1, ... 488, {444, 1864}, ) == 0x0 04478 464 NtRequestWaitReplyPort (24, {168, 196, new_msg, 0, 1233944, 2012627920, 65535, 1234024} (24, {168, 196, new_msg, 0, 1233944, 2012627920, 65535, 1234024} "\0\0\0\0\0\0\1\0\360c\234|\4\0\0\0\344\1\0\0\350\1\0\0\274\1\0\0H\7\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\343\357\220|\334\323\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0@\375\177\0\0\0\0\0\0\0\0\0\0H\0" ... {168, 196, reply, 0, 1036, 464, 57994, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\344\1\0\0\350\1\0\0\274\1\0\0H\7\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\343\357\220|\334\323\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0@\375\177\0\0\0\0\0\0\0\0\0\0H\0" ) ... {168, 196, reply, 0, 1036, 464, 57994, 0} (24, {168, 196, new_msg, 0, 1233944, 2012627920, 65535, 1234024} "\0\0\0\0\0\0\1\0\360c\234|\4\0\0\0\344\1\0\0\350\1\0\0\274\1\0\0H\7\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\343\357\220|\334\323\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0@\375\177\0\0\0\0\0\0\0\0\0\0H\0" ... {168, 196, reply, 0, 1036, 464, 57994, 0} "\0\0\0\0\0\0\1\0\0\0\0\0\4\0\0\0\344\1\0\0\350\1\0\0\274\1\0\0H\7\0\0\0\0\0\0\0\0\0\0\20\4\0\4\0\0\0\0\343\357\220|\334\323\22\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0@\375\177\0\0\0\0\0\0\0\0\0\0H\0" ) ) == 0x0 04479 464 NtResumeThread (488, ... 1, ) == 0x0 04480 464 NtClose (468, ... ) == 0x0 04481 464 NtClose (480, ... ) == 0x0 04482 464 NtClose (462, ... ) == 0x0 04483 464 NtClose (402, ... ) == 0x0 04484 464 NtClose (458, ... ) == 0x0 04485 464 NtClose (484, ... ) == 0x0 04486 464 NtClose (488, ... ) == 0x0 04487 464 NtUserValidateHandleSecure (655618, ... ) == 0x1 04488 464 NtUserDestroyWindow (655618, ... 04489 464 NtUserValidateHandleSecure (655618, ... ) == 0x1 04490 464 NtUserValidateHandleSecure (655618, ... ) == 0x1 04491 464 NtUserGetThreadState (0, ... ) == 0x0 04492 464 NtUserBuildHwndList (0, 0, 0, 464, 64, ... (0x1, ), 1, ) == 0x0 04493 464 NtUserCallOneParam (8, 43, ... ) == 0x0 04494 464 NtUserQueryWindow (655618, 7, ... ) == 0x0 04495 464 NtUserBuildHwndList (0, 0, 0, 464, 64, ... (0x1, ), 1, ) == 0x0 04496 464 NtUserCallOneParam (8, 43, ... ) == 0x0 04497 464 NtUserValidateHandleSecure (0, ... ) == 0x0 04498 464 NtUserUnhookWindowsHookEx (393695, ... ) == 0x1 04499 464 NtUserUnhookWindowsHookEx (1573423, ... ) == 0x1 04500 464 NtUserRemoveProp (655618, 43288, ... ) == 0xffffffff 04501 464 NtUserRemoveProp (655618, 43282, ... ) == 0x0 04502 464 NtUserRemoveProp (655618, 43287, ... ) == 0x0 04488 464 NtUserDestroyWindow ... ) == 0x1 04503 464 NtUserUnregisterClass (1236836, 2001600512, 1236824, ... ) == 0x1 04504 464 NtClose (386, ... ) == 0x0 04505 464 NtClose (284, ... ) == 0x0 04506 464 NtClose (288, ... ) == 0x0 04507 464 NtClose (276, ... ) == 0x0 04508 464 NtClose (280, ... ) == 0x0 04509 464 NtClose (264, ... ) == 0x0 04510 464 NtClose (272, ... ) == 0x0 04511 464 NtClose (308, ... ) == 0x0 04512 464 NtClose (312, ... ) == 0x0 04513 464 NtClose (300, ... ) == 0x0 04514 464 NtClose (304, ... ) == 0x0 04515 464 NtClose (292, ... ) == 0x0 04516 464 NtClose (296, ... ) == 0x0 04517 464 NtClose (324, ... ) == 0x0 04518 464 NtClose (328, ... ) == 0x0 04519 464 NtClose (316, ... ) == 0x0 04520 464 NtClose (320, ... ) == 0x0 04521 464 NtClose (348, ... ) == 0x0 04522 464 NtClose (352, ... ) == 0x0 04523 464 NtClose (340, ... ) == 0x0 04524 464 NtClose (344, ... ) == 0x0 04525 464 NtClose (332, ... ) == 0x0 04526 464 NtClose (336, ... ) == 0x0 04527 464 NtClose (356, ... ) == 0x0 04528 464 NtClose (360, ... ) == 0x0 04529 464 NtClose (372, ... ) == 0x0 04530 464 NtClose (376, ... ) == 0x0 04531 464 NtClose (364, ... ) == 0x0 04532 464 NtClose (368, ... ) == 0x0 04533 464 NtClose (270, ... ) == 0x0 04534 464 NtTerminateProcess (0, 0, ... 01568 1292 NtWaitForMultipleObjects ... ) == 0xc0 04534 464 NtTerminateProcess ... ) == 0x0 04535 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x17,}, 4, ... ) == 0x0 04536 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x18,}, 4, ... ) == 0x0 04537 464 NtClose (436, ... ) == 0x0 04538 464 NtClose (432, ... ) == 0x0 04539 464 NtClose (440, ... ) == 0x0 04540 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 04541 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04542 464 NtSetEvent (428, ... 0x0, ) == 0x0 04543 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04544 464 NtSetEvent (428, ... 0x0, ) == 0x0 04545 464 NtSetEvent (424, ... 0x0, ) == 0x0 04546 464 NtWaitForSingleObject (424, 0, 0x0, ... ) == 0x0 04547 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04548 464 NtSetEvent (428, ... 0x0, ) == 0x0 04549 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04550 464 NtSetEvent (428, ... 0x0, ) == 0x0 04551 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04552 464 NtSetEvent (428, ... 0x0, ) == 0x0 04553 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04554 464 NtSetEvent (428, ... 0x0, ) == 0x0 04555 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04556 464 NtSetEvent (428, ... 0x0, ) == 0x0 04557 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04558 464 NtSetEvent (428, ... 0x0, ) == 0x0 04559 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04560 464 NtSetEvent (428, ... 0x0, ) == 0x0 04561 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04562 464 NtSetEvent (428, ... 0x0, ) == 0x0 04563 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04564 464 NtSetEvent (428, ... 0x0, ) == 0x0 04565 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04566 464 NtSetEvent (428, ... 0x0, ) == 0x0 04567 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04568 464 NtSetEvent (428, ... 0x0, ) == 0x0 04569 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04570 464 NtSetEvent (428, ... 0x0, ) == 0x0 04571 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04572 464 NtSetEvent (428, ... 0x0, ) == 0x0 04573 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04574 464 NtSetEvent (428, ... 0x0, ) == 0x0 04575 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04576 464 NtSetEvent (428, ... 0x0, ) == 0x0 04577 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04578 464 NtSetEvent (428, ... 0x0, ) == 0x0 04579 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04580 464 NtSetEvent (428, ... 0x0, ) == 0x0 04581 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04582 464 NtSetEvent (428, ... 0x0, ) == 0x0 04583 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04584 464 NtSetEvent (428, ... 0x0, ) == 0x0 04585 464 NtSetEvent (424, ... 0x0, ) == 0x0 04586 464 NtClose (424, ... ) == 0x0 04587 464 NtWaitForSingleObject (428, 0, 0x0, ... ) == 0x0 04588 464 NtSetEvent (428, ... 0x0, ) == 0x0 04589 464 NtClose (428, ... ) == 0x0 04590 464 NtClose (452, ... ) == 0x0 04591 464 NtFreeVirtualMemory (-1, (0x17b000), 4096, 16384, ... (0x17b000), 4096, ) == 0x0 04592 464 NtClose (448, ... ) == 0x0 04593 464 NtFreeVirtualMemory (-1, (0x17a000), 4096, 16384, ... (0x17a000), 4096, ) == 0x0 04594 464 NtUnmapViewOfSection (-1, 0xd10000, ... ) == 0x0 04595 464 NtClose (444, ... ) == 0x0 04596 464 NtClose (404, ... ) == 0x0 04597 464 NtClose (408, ... ) == 0x0 04598 464 NtClose (412, ... ) == 0x0 04599 464 NtClose (416, ... ) == 0x0 04600 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x15,}, 4, ... ) == 0x0 04601 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x16,}, 4, ... ) == 0x0 04602 464 NtUnmapViewOfSection (-1, 0xd00000, ... ) == 0x0 04603 464 NtClose (396, ... ) == 0x0 04604 464 NtClose (392, ... ) == 0x0 04605 464 NtClose (388, ... ) == 0x0 04606 464 NtClose (380, ... ) == 0x0 04607 464 NtFreeVirtualMemory (-1, (0x16d000), 20480, 16384, ... (0x16d000), 20480, ) == 0x0 04608 464 NtFreeVirtualMemory (-1, (0xcf0000), 4096, 16384, ... (0xcf0000), 4096, ) == 0x0 04609 464 NtFreeVirtualMemory (-1, (0xcf0000), 0, 32768, ... (0xcf0000), 65536, ) == 0x0 04610 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x14,}, 4, ... ) == 0x0 04611 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x13,}, 4, ... ) == 0x0 04612 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x12,}, 4, ... ) == 0x0 04613 464 NtWaitForMultipleObjects (2, (224, 232, ), 1, 0, 0x0, ... ) == 0x1 04614 464 NtClose (232, ... ) == 0x0 04615 464 NtSetEvent (224, ... 0x0, ) == 0x0 04616 464 NtClose (224, ... ) == 0x0 04617 464 NtWaitForMultipleObjects (2, (240, 244, ), 1, 0, 0x0, ... ) == 0x1 04618 464 NtClose (244, ... ) == 0x0 04619 464 NtSetEvent (240, ... 0x0, ) == 0x0 04620 464 NtClose (240, ... ) == 0x0 04621 464 NtWaitForMultipleObjects (2, (248, 252, ), 1, 0, 0x0, ... ) == 0x1 04622 464 NtClose (252, ... ) == 0x0 04623 464 NtSetEvent (248, ... 0x0, ) == 0x0 04624 464 NtClose (248, ... ) == 0x0 04625 464 NtUserPostThreadMessage (1748, 49315, 0, 464, ... ) == 0x1 04626 464 NtUserPostThreadMessage (416, 49315, 0, 464, ... ) == 0x1 04627 464 NtUserValidateHandleSecure (0, ... ) == 0x0 04628 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x11,}, 4, ... ) == 0x0 04629 464 NtUnmapViewOfSection (-1, 0xcb0000, ... ) == 0x0 04630 464 NtClose (172, ... ) == 0x0 04631 464 NtClose (168, ... ) == 0x0 04632 464 NtClose (148, ... ) == 0x0 04633 464 NtClose (152, ... ) == 0x0 04634 464 NtClose (156, ... ) == 0x0 04635 464 NtClose (160, ... ) == 0x0 04636 464 NtClose (164, ... ) == 0x0 04637 464 NtUnmapViewOfSection (-1, 0x980000, ... ) == 0x0 04638 464 NtClose (144, ... ) == 0x0 04639 464 NtSetInformationThread (-2, ZeroTlsCell, {ZeroTlsCell=0x10,}, 4, ... ) == 0x0 04640 464 NtUnmapViewOfSection (-1, 0xc60000, ... ) == 0x0 04641 464 NtClose (136, ... ) == 0x0 04642 464 NtGdiDeleteObjectApp (1913653144, ... ) == 0x1 04643 464 NtUserGetProcessWindowStation (... ) == 0x20 04644 464 NtUserBuildNameList (32, 522, 1559720, 1241516, ... ) == 0x0 04645 464 NtUserGetProcessWindowStation (... ) == 0x20 04646 464 NtUserOpenDesktop ({24, 32, 0x40, 0, 0, ({24, 32, 0x40, 0, 0, "Default"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x88 04647 464 NtUserBuildHwndList (136, 0, 0, 0, 64, ... (0x5009e, 0x400fa, 0x10074, 0x10080, 0x10070, 0x10084, 0x30048, 0x10072, 0x20052, 0x5009c, 0x10090, 0x500a2, 0x100d0, 0x200b0, 0x100cc, 0x90114, 0x70104, 0x70100, 0x20118, 0x3014c, 0x1011c, 0x100e6, 0x100d6, 0x100d2, 0x100ca, 0x100c8, 0x100ba, 0x100ae, 0x100ac, 0x300a6, 0x10078, 0x30062, 0x50036, 0x5005c, 0x100be, 0x400fe, 0x10092, 0x10086, 0x40034, 0x50050, 0x1013c, 0x10120, 0x100c2, 0x100bc, 0x2014e, 0x100d8, 0x100b6, 0x100b8, 0x100b4, 0x100c0, 0x1009a, 0x5005e, 0x1, ), 53, ) == 0x0 04648 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 04649 464 NtUserQueryWindow (327838, 0, ... ) == 0x6b8 04650 464 NtUserQueryWindow (327838, 1, ... ) == 0x6d4 04651 464 NtUserValidateHandleSecure (327838, ... ) == 0x1 04652 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 04653 464 NtUserQueryWindow (262394, 0, ... ) == 0x6b8 04654 464 NtUserQueryWindow (262394, 1, ... ) == 0x6d4 04655 464 NtUserValidateHandleSecure (262394, ... ) == 0x1 04656 464 NtUserBuildHwndList (0, 262394, 1, 0, 64, ... (0x80064, 0x60068, 0x6006c, 0x50094, 0x50096, 0x60066, 0x7006a, 0x90058, 0x6006e, 0x5008a, 0x50088, 0x500a0, 0x1, ), 13, ) == 0x0 04657 464 NtUserValidateHandleSecure (524388, ... ) == 0x1 04658 464 NtUserQueryWindow (524388, 0, ... ) == 0x6b8 04659 464 NtUserQueryWindow (524388, 1, ... ) == 0x6d4 04660 464 NtUserValidateHandleSecure (393320, ... ) == 0x1 04661 464 NtUserQueryWindow (393320, 0, ... ) == 0x6b8 04662 464 NtUserQueryWindow (393320, 1, ... ) == 0x6d4 04663 464 NtUserValidateHandleSecure (393324, ... ) == 0x1 04664 464 NtUserQueryWindow (393324, 0, ... ) == 0x6b8 04665 464 NtUserQueryWindow (393324, 1, ... ) == 0x6d4 04666 464 NtUserValidateHandleSecure (327828, ... ) == 0x1 04667 464 NtUserQueryWindow (327828, 0, ... ) == 0x6b8 04668 464 NtUserQueryWindow (327828, 1, ... ) == 0x6d4 04669 464 NtUserValidateHandleSecure (327830, ... ) == 0x1 04670 464 NtUserQueryWindow (327830, 0, ... ) == 0x6b8 04671 464 NtUserQueryWindow (327830, 1, ... ) == 0x6d4 04672 464 NtUserValidateHandleSecure (393318, ... ) == 0x1 04673 464 NtUserQueryWindow (393318, 0, ... ) == 0x6b8 04674 464 NtUserQueryWindow (393318, 1, ... ) == 0x6d4 04675 464 NtUserValidateHandleSecure (458858, ... ) == 0x1 04676 464 NtUserQueryWindow (458858, 0, ... ) == 0x6b8 04677 464 NtUserQueryWindow (458858, 1, ... ) == 0x6d4 04678 464 NtUserValidateHandleSecure (589912, ... ) == 0x1 04679 464 NtUserQueryWindow (589912, 0, ... ) == 0x6b8 04680 464 NtUserQueryWindow (589912, 1, ... ) == 0x6d4 04681 464 NtUserValidateHandleSecure (393326, ... ) == 0x1 04682 464 NtUserQueryWindow (393326, 0, ... ) == 0x6b8 04683 464 NtUserQueryWindow (393326, 1, ... ) == 0x6d4 04684 464 NtUserValidateHandleSecure (327818, ... ) == 0x1 04685 464 NtUserQueryWindow (327818, 0, ... ) == 0x6b8 04686 464 NtUserQueryWindow (327818, 1, ... ) == 0x6d4 04687 464 NtUserValidateHandleSecure (327816, ... ) == 0x1 04688 464 NtUserQueryWindow (327816, 0, ... ) == 0x6b8 04689 464 NtUserQueryWindow (327816, 1, ... ) == 0x6d4 04690 464 NtUserValidateHandleSecure (327840, ... ) == 0x1 04691 464 NtUserQueryWindow (327840, 0, ... ) == 0x6b8 04692 464 NtUserQueryWindow (327840, 1, ... ) == 0x6d4 04693 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 04694 464 NtUserQueryWindow (65652, 0, ... ) == 0x6b8 04695 464 NtUserQueryWindow (65652, 1, ... ) == 0x6d4 04696 464 NtUserValidateHandleSecure (65652, ... ) == 0x1 04697 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 04698 464 NtUserQueryWindow (65664, 0, ... ) == 0x6b8 04699 464 NtUserQueryWindow (65664, 1, ... ) == 0x6d4 04700 464 NtUserValidateHandleSecure (65664, ... ) == 0x1 04701 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 04702 464 NtUserQueryWindow (65648, 0, ... ) == 0x6b8 04703 464 NtUserQueryWindow (65648, 1, ... ) == 0x6d4 04704 464 NtUserValidateHandleSecure (65648, ... ) == 0x1 04705 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 04706 464 NtUserQueryWindow (65668, 0, ... ) == 0x6b8 04707 464 NtUserQueryWindow (65668, 1, ... ) == 0x6d4 04708 464 NtUserValidateHandleSecure (65668, ... ) == 0x1 04709 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 04710 464 NtUserQueryWindow (196680, 0, ... ) == 0x6b8 04711 464 NtUserQueryWindow (196680, 1, ... ) == 0x6d4 04712 464 NtUserValidateHandleSecure (196680, ... ) == 0x1 04713 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 04714 464 NtUserQueryWindow (65650, 0, ... ) == 0x6b8 04715 464 NtUserQueryWindow (65650, 1, ... ) == 0x6d4 04716 464 NtUserValidateHandleSecure (65650, ... ) == 0x1 04717 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 04718 464 NtUserQueryWindow (131154, 0, ... ) == 0x6b8 04719 464 NtUserQueryWindow (131154, 1, ... ) == 0x6d4 04720 464 NtUserValidateHandleSecure (131154, ... ) == 0x1 04721 464 NtUserBuildHwndList (0, 131154, 1, 0, 64, ... (0x3003e, 0x3003c, 0x30040, 0x30042, 0x30044, 0x30046, 0x10076, 0x10082, 0x1007a, 0x1007e, 0x1, ), 11, ) == 0x0 04722 464 NtUserValidateHandleSecure (196670, ... ) == 0x1 04723 464 NtUserQueryWindow (196670, 0, ... ) == 0x6b8 04724 464 NtUserQueryWindow (196670, 1, ... ) == 0x6d4 04725 464 NtUserValidateHandleSecure (196668, ... ) == 0x1 04726 464 NtUserQueryWindow (196668, 0, ... ) == 0x6b8 04727 464 NtUserQueryWindow (196668, 1, ... ) == 0x6d4 04728 464 NtUserValidateHandleSecure (196672, ... ) == 0x1 04729 464 NtUserQueryWindow (196672, 0, ... ) == 0x6b8 04730 464 NtUserQueryWindow (196672, 1, ... ) == 0x6d4 04731 464 NtUserValidateHandleSecure (196674, ... ) == 0x1 04732 464 NtUserQueryWindow (196674, 0, ... ) == 0x6b8 04733 464 NtUserQueryWindow (196674, 1, ... ) == 0x6d4 04734 464 NtUserValidateHandleSecure (196676, ... ) == 0x1 04735 464 NtUserQueryWindow (196676, 0, ... ) == 0x6b8 04736 464 NtUserQueryWindow (196676, 1, ... ) == 0x6d4 04737 464 NtUserValidateHandleSecure (196678, ... ) == 0x1 04738 464 NtUserQueryWindow (196678, 0, ... ) == 0x6b8 04739 464 NtUserQueryWindow (196678, 1, ... ) == 0x6d4 04740 464 NtUserValidateHandleSecure (65654, ... ) == 0x1 04741 464 NtUserQueryWindow (65654, 0, ... ) == 0x6b8 04742 464 NtUserQueryWindow (65654, 1, ... ) == 0x6d4 04743 464 NtUserValidateHandleSecure (65666, ... ) == 0x1 04744 464 NtUserQueryWindow (65666, 0, ... ) == 0x6b8 04745 464 NtUserQueryWindow (65666, 1, ... ) == 0x6d4 04746 464 NtUserValidateHandleSecure (65658, ... ) == 0x1 04747 464 NtUserQueryWindow (65658, 0, ... ) == 0x6b8 04748 464 NtUserQueryWindow (65658, 1, ... ) == 0x6d4 04749 464 NtUserValidateHandleSecure (65662, ... ) == 0x1 04750 464 NtUserQueryWindow (65662, 0, ... ) == 0x6b8 04751 464 NtUserQueryWindow (65662, 1, ... ) == 0x6d4 04752 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 04753 464 NtUserQueryWindow (327836, 0, ... ) == 0x6b8 04754 464 NtUserQueryWindow (327836, 1, ... ) == 0x6d4 04755 464 NtUserValidateHandleSecure (327836, ... ) == 0x1 04756 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 04757 464 NtUserQueryWindow (65680, 0, ... ) == 0x6b8 04758 464 NtUserQueryWindow (65680, 1, ... ) == 0x6bc 04759 464 NtUserValidateHandleSecure (65680, ... ) == 0x1 04760 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 04761 464 NtUserQueryWindow (327842, 0, ... ) == 0x6b8 04762 464 NtUserQueryWindow (327842, 1, ... ) == 0x6d4 04763 464 NtUserValidateHandleSecure (327842, ... ) == 0x1 04764 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 04765 464 NtUserQueryWindow (65744, 0, ... ) == 0x19c 04766 464 NtUserQueryWindow (65744, 1, ... ) == 0x1a0 04767 464 NtUserValidateHandleSecure (65744, ... ) == 0x1 04768 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 04769 464 NtUserQueryWindow (131248, 0, ... ) == 0xa0 04770 464 NtUserQueryWindow (131248, 1, ... ) == 0xe4 04771 464 NtUserValidateHandleSecure (131248, ... ) == 0x1 04772 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 04773 464 NtUserQueryWindow (65740, 0, ... ) == 0x19c 04774 464 NtUserQueryWindow (65740, 1, ... ) == 0x1a0 04775 464 NtUserValidateHandleSecure (65740, ... ) == 0x1 04776 464 NtUserValidateHandleSecure (590100, ... ) == 0x1 04777 464 NtUserQueryWindow (590100, 0, ... ) == 0x1bc 04778 464 NtUserQueryWindow (590100, 1, ... ) == 0x748 04779 464 NtUserValidateHandleSecure (590100, ... ) == 0x1 04780 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 04781 464 NtUserQueryWindow (459012, 0, ... ) == 0x49c 04782 464 NtUserQueryWindow (459012, 1, ... ) == 0x180 04783 464 NtUserValidateHandleSecure (459012, ... ) == 0x1 04784 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 04785 464 NtUserQueryWindow (459008, 0, ... ) == 0x5e8 04786 464 NtUserQueryWindow (459008, 1, ... ) == 0x1dc 04787 464 NtUserValidateHandleSecure (459008, ... ) == 0x1 04788 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 04789 464 NtUserQueryWindow (131352, 0, ... ) == 0x6ac 04790 464 NtUserQueryWindow (131352, 1, ... ) == 0x7f4 04791 464 NtUserValidateHandleSecure (131352, ... ) == 0x1 04792 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 04793 464 NtUserQueryWindow (196940, 0, ... ) == 0x4b4 04794 464 NtUserQueryWindow (196940, 1, ... ) == 0x474 04795 464 NtUserValidateHandleSecure (196940, ... ) == 0x1 04796 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 04797 464 NtUserQueryWindow (65820, 0, ... ) == 0x22c 04798 464 NtUserQueryWindow (65820, 1, ... ) == 0x220 04799 464 NtUserValidateHandleSecure (65820, ... ) == 0x1 04800 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 04801 464 NtUserQueryWindow (65766, 0, ... ) == 0x6b8 04802 464 NtUserQueryWindow (65766, 1, ... ) == 0x13c 04803 464 NtUserValidateHandleSecure (65766, ... ) == 0x1 04804 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 04805 464 NtUserQueryWindow (65750, 0, ... ) == 0x6b8 04806 464 NtUserQueryWindow (65750, 1, ... ) == 0x13c 04807 464 NtUserValidateHandleSecure (65750, ... ) == 0x1 04808 464 NtUserBuildHwndList (0, 65750, 1, 0, 64, ... (0x100da, 0x100dc, 0x100de, 0x100e0, 0x1, ), 5, ) == 0x0 04809 464 NtUserValidateHandleSecure (65754, ... ) == 0x1 04810 464 NtUserQueryWindow (65754, 0, ... ) == 0x6b8 04811 464 NtUserQueryWindow (65754, 1, ... ) == 0x13c 04812 464 NtUserValidateHandleSecure (65756, ... ) == 0x1 04813 464 NtUserQueryWindow (65756, 0, ... ) == 0x6b8 04814 464 NtUserQueryWindow (65756, 1, ... ) == 0x13c 04815 464 NtUserValidateHandleSecure (65758, ... ) == 0x1 04816 464 NtUserQueryWindow (65758, 0, ... ) == 0x6b8 04817 464 NtUserQueryWindow (65758, 1, ... ) == 0x13c 04818 464 NtUserValidateHandleSecure (65760, ... ) == 0x1 04819 464 NtUserQueryWindow (65760, 0, ... ) == 0x6b8 04820 464 NtUserQueryWindow (65760, 1, ... ) == 0x13c 04821 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 04822 464 NtUserQueryWindow (65746, 0, ... ) == 0x6b8 04823 464 NtUserQueryWindow (65746, 1, ... ) == 0x6d4 04824 464 NtUserValidateHandleSecure (65746, ... ) == 0x1 04825 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 04826 464 NtUserQueryWindow (65738, 0, ... ) == 0x19c 04827 464 NtUserQueryWindow (65738, 1, ... ) == 0x1a0 04828 464 NtUserValidateHandleSecure (65738, ... ) == 0x1 04829 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 04830 464 NtUserQueryWindow (65736, 0, ... ) == 0xa0 04831 464 NtUserQueryWindow (65736, 1, ... ) == 0xe4 04832 464 NtUserValidateHandleSecure (65736, ... ) == 0x1 04833 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 04834 464 NtUserQueryWindow (65722, 0, ... ) == 0x104 04835 464 NtUserQueryWindow (65722, 1, ... ) == 0x108 04836 464 NtUserValidateHandleSecure (65722, ... ) == 0x1 04837 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 04838 464 NtUserQueryWindow (65710, 0, ... ) == 0x104 04839 464 NtUserQueryWindow (65710, 1, ... ) == 0x108 04840 464 NtUserValidateHandleSecure (65710, ... ) == 0x1 04841 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 04842 464 NtUserQueryWindow (65708, 0, ... ) == 0x120 04843 464 NtUserQueryWindow (65708, 1, ... ) == 0x124 04844 464 NtUserValidateHandleSecure (65708, ... ) == 0x1 04845 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 04846 464 NtUserQueryWindow (196774, 0, ... ) == 0xc4 04847 464 NtUserQueryWindow (196774, 1, ... ) == 0xc8 04848 464 NtUserValidateHandleSecure (196774, ... ) == 0x1 04849 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 04850 464 NtUserQueryWindow (65656, 0, ... ) == 0x6b8 04851 464 NtUserQueryWindow (65656, 1, ... ) == 0x6ec 04852 464 NtUserValidateHandleSecure (65656, ... ) == 0x1 04853 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 04854 464 NtUserQueryWindow (196706, 0, ... ) == 0x6b8 04855 464 NtUserQueryWindow (196706, 1, ... ) == 0x6bc 04856 464 NtUserValidateHandleSecure (196706, ... ) == 0x1 04857 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 04858 464 NtUserQueryWindow (327734, 0, ... ) == 0x6b8 04859 464 NtUserQueryWindow (327734, 1, ... ) == 0x6bc 04860 464 NtUserValidateHandleSecure (327734, ... ) == 0x1 04861 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 04862 464 NtUserQueryWindow (327772, 0, ... ) == 0x6b8 04863 464 NtUserQueryWindow (327772, 1, ... ) == 0x6bc 04864 464 NtUserValidateHandleSecure (327772, ... ) == 0x1 04865 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 04866 464 NtUserQueryWindow (65726, 0, ... ) == 0x19c 04867 464 NtUserQueryWindow (65726, 1, ... ) == 0x1a0 04868 464 NtUserValidateHandleSecure (65726, ... ) == 0x1 04869 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 04870 464 NtUserQueryWindow (262398, 0, ... ) == 0x6b8 04871 464 NtUserQueryWindow (262398, 1, ... ) == 0x6d4 04872 464 NtUserValidateHandleSecure (262398, ... ) == 0x1 04873 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 04874 464 NtUserQueryWindow (65682, 0, ... ) == 0x6b8 04875 464 NtUserQueryWindow (65682, 1, ... ) == 0x6bc 04876 464 NtUserValidateHandleSecure (65682, ... ) == 0x1 04877 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 04878 464 NtUserQueryWindow (65670, 0, ... ) == 0x6b8 04879 464 NtUserQueryWindow (65670, 1, ... ) == 0x6bc 04880 464 NtUserValidateHandleSecure (65670, ... ) == 0x1 04881 464 NtUserBuildHwndList (0, 65670, 1, 0, 64, ... (0x1008c, 0x1008e, 0x1, ), 3, ) == 0x0 04882 464 NtUserValidateHandleSecure (65676, ... ) == 0x1 04883 464 NtUserQueryWindow (65676, 0, ... ) == 0x6b8 04884 464 NtUserQueryWindow (65676, 1, ... ) == 0x6bc 04885 464 NtUserValidateHandleSecure (65678, ... ) == 0x1 04886 464 NtUserQueryWindow (65678, 0, ... ) == 0x6b8 04887 464 NtUserQueryWindow (65678, 1, ... ) == 0x6bc 04888 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 04889 464 NtUserQueryWindow (262196, 0, ... ) == 0x6b8 04890 464 NtUserQueryWindow (262196, 1, ... ) == 0x6d4 04891 464 NtUserValidateHandleSecure (262196, ... ) == 0x1 04892 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 04893 464 NtUserQueryWindow (327760, 0, ... ) == 0x6b8 04894 464 NtUserQueryWindow (327760, 1, ... ) == 0x6d4 04895 464 NtUserValidateHandleSecure (327760, ... ) == 0x1 04896 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 04897 464 NtUserQueryWindow (65852, 0, ... ) == 0x22c 04898 464 NtUserQueryWindow (65852, 1, ... ) == 0x220 04899 464 NtUserValidateHandleSecure (65852, ... ) == 0x1 04900 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 04901 464 NtUserQueryWindow (65824, 0, ... ) == 0x22c 04902 464 NtUserQueryWindow (65824, 1, ... ) == 0x220 04903 464 NtUserValidateHandleSecure (65824, ... ) == 0x1 04904 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 04905 464 NtUserQueryWindow (65730, 0, ... ) == 0xa0 04906 464 NtUserQueryWindow (65730, 1, ... ) == 0xe4 04907 464 NtUserValidateHandleSecure (65730, ... ) == 0x1 04908 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 04909 464 NtUserQueryWindow (65724, 0, ... ) == 0xa0 04910 464 NtUserQueryWindow (65724, 1, ... ) == 0xe4 04911 464 NtUserValidateHandleSecure (65724, ... ) == 0x1 04912 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 04913 464 NtUserQueryWindow (131406, 0, ... ) == 0x4b4 04914 464 NtUserQueryWindow (131406, 1, ... ) == 0x474 04915 464 NtUserValidateHandleSecure (131406, ... ) == 0x1 04916 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 04917 464 NtUserQueryWindow (65752, 0, ... ) == 0x6b8 04918 464 NtUserQueryWindow (65752, 1, ... ) == 0x13c 04919 464 NtUserValidateHandleSecure (65752, ... ) == 0x1 04920 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 04921 464 NtUserQueryWindow (65718, 0, ... ) == 0x104 04922 464 NtUserQueryWindow (65718, 1, ... ) == 0x108 04923 464 NtUserValidateHandleSecure (65718, ... ) == 0x1 04924 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 04925 464 NtUserQueryWindow (65720, 0, ... ) == 0x120 04926 464 NtUserQueryWindow (65720, 1, ... ) == 0x124 04927 464 NtUserValidateHandleSecure (65720, ... ) == 0x1 04928 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 04929 464 NtUserQueryWindow (65716, 0, ... ) == 0xc4 04930 464 NtUserQueryWindow (65716, 1, ... ) == 0xc8 04931 464 NtUserValidateHandleSecure (65716, ... ) == 0x1 04932 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 04933 464 NtUserQueryWindow (65728, 0, ... ) == 0x19c 04934 464 NtUserQueryWindow (65728, 1, ... ) == 0x1a0 04935 464 NtUserValidateHandleSecure (65728, ... ) == 0x1 04936 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 04937 464 NtUserQueryWindow (65690, 0, ... ) == 0x6b8 04938 464 NtUserQueryWindow (65690, 1, ... ) == 0x6bc 04939 464 NtUserValidateHandleSecure (65690, ... ) == 0x1 04940 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 04941 464 NtUserQueryWindow (327774, 0, ... ) == 0x6b8 04942 464 NtUserQueryWindow (327774, 1, ... ) == 0x6bc 04943 464 NtUserValidateHandleSecure (327774, ... ) == 0x1 04944 464 NtUserCloseDesktop (136, ... ) == 0x1 04945 464 NtUserGetProcessWindowStation (... ) == 0x20 04946 464 NtUserOpenDesktop ({24, 32, 0x40, 0, 0, ({24, 32, 0x40, 0, 0, "Disconnect"}, 1, 0x41, ... ) }, 1, 0x41, ... ) == 0x0